Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Pix Firewall Enables a Secure VPN

Feb 10,2010 by alperen

image

Virtual private networks (VPNs) using IPSec provide standards-based authentication and encryption services to protect against modification or unauthorized viewing of the data within a network or as it passes through an unprotected network, such as the public Internet. The correct configuration steps and commands depend on several factors, which include making decisions about the following basic IPSec issues.

  1. Choosing between the two IPSec implementations—remote access or site-to-site— is necessary. You look at each in this chapter. Figure 21-1 shows a site-to-site VPN implementation.

    Click To expand
    Figure 21-1: IPSec site-to-site VPN implementation (tunnel mode)

    Remote access

    This implementation allows VPN clients, such as mobile users or telecommuters, to establish secure remote access to centralized network resources, often over the Internet.

    Site-to-site

    This implementation is used between two IPSec security gateways, such as PIX Firewall. A site-to-site VPN connects geographically separated networks, such as branch locations, to the corporate network.

  2. Which of the two security protocols supported by the IPSec standard will be used? The need for encryption may be the deciding factor.

    Authentication Header (AH)

    Implements authentication and antireplay services.

    Encapsulating Security Protocol (ESP)

    Implements authentication, antireplay services, plus encryption.

  3. Which of the two IPSec modes will be required, based on the previous choices?

    Tunnel mode

    The typical IPSec implementation between two security gateways, such as PIX Firewall units, using an untrusted network, such as the public Internet, for connectivity. See Figure 21-1.

    Transport mode

    This method of implementing IPSec for remote access to corporate network resources. This method frequently involves Windows 2000 VPN clients authenticating with L2TP. See Figure 21-2.

    Click To expand
    Figure 21-2: IPSec remote access VPN implementation (transport mode)


172 times read

Related news

» Five Steps of IPSec Revisited
by alperen posted on Sep 25,2009
» Step 2—IKE Phase One
by alperen posted on Sep 25,2009
» Security Association (SA)
by alperen posted on Sep 25,2009
» IPSec Data Transfer-Session Termination
by alperen posted on Sep 25,2009
» How IPSec Works
by alperen posted on Sep 24,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author