skip to content

IPsec

Security built into the IP layer: the AH and ESP headers, IKE agreeing keys before traffic flows, and transport versus tunnel mode. Interviewers reach for it when two sites must be joined privately.

on this pageshow

explore

questions

page 1 of 2

In IPsec, what does the Authentication Header (AH) protect, what does ESP protect, and why is ESP the one deployed?

level: juniorimportance: must knowfreq 45%

answer

  1. two protocols straight on IP
  2. one authenticates, one also encrypts
  3. immutable header fields in the ICV
  4. MUST versus MAY in RFC 4301

basics

~20 s

AH (IP protocol 51) authenticates the payload plus the IP header fields that do not change in transit, and encrypts nothing. ESP (protocol 50) encrypts and normally authenticates its own contents, not the outer header, and meets almost every need.

solid answer

~40 s

Both are IPsec security protocols carried directly over IP. `AH` (protocol 51, RFC 4302) gives integrity, data-origin authentication and optional anti-replay over the payload *and* the immutable fields of the IP header in front of it — version, lengths, protocol, source and destination address — while zeroing the fields routers change, such as TTL and the header checksum. It never encrypts. `ESP` (protocol 50, RFC 4303) offers the same services plus confidentiality, but its integrity check starts at its own SPI and does not reach back into the outer IP header. Because ESP with `ENCR_NULL` can provide integrity alone, RFC 4301 makes ESP a MUST and AH only a MAY — and AH's coverage of the addresses is exactly what a NAT breaks.

go deeper

for a junior

Recall the pair cleanly: AH is protocol 51 and authenticates without encrypting; ESP is protocol 50 and encrypts, normally with authentication too.

for a middle

Explain exactly which bytes each one covers: AH's ICV over immutable IP header fields with mutable ones zeroed, ESP's ICV from the SPI through the trailer and no further.

for a senior

Show why ESP displaced AH in practice: ESP with NULL encryption covers integrity-only needs, AH cannot cross a NAT, and RFC 4301 made AH optional.

for a principal

Be ready to argue when outer-header integrity is worth AH's cost, and why the specifications concluded it almost never is.

## Two security protocols directly on IP IPsec protects traffic at the network layer with two security protocols: the **Authentication Header** (`AH`, RFC 4302) and the **Encapsulating Security Payload** (`ESP`, RFC 4303), both framed by the architecture in RFC 4301. These three replaced RFC 2402, RFC 2406 and RFC 2401. Neither is natively carried inside TCP or UDP: the IP header in front of them names them directly, with protocol number **51** for AH and **50** for ESP. Both share two fields: - the **Security Parameters Index** (`SPI`, 32 bits), a label the receiver chose that tells it which security association — the negotiated keys and algorithms — applies; - a 32-bit **Sequence Number**, which a receiver may use to reject replayed packets. Everything else about them differs, and the difference is *which bytes each one protects, and how*. ## What AH protects AH computes an **Integrity Check Value** (`ICV`) — a keyed message authentication code — over three things: the IP header fields that are immutable in transit (or predictable at the receiver), the AH header itself with its ICV field zeroed, and everything after AH, which is assumed not to change. Fields that routers legitimately rewrite are set to zero before the computation, so ordinary forwarding does not break the check. RFC 4302 classifies the IPv4 base header like this: | Covered (immutable) | Zeroed for the ICV (mutable) | |---|---| | Version, Internet Header Length, Total Length | DSCP and ECN | | Identification, Protocol | Flags, Fragment Offset | | Source Address, Destination Address | TTL, Header Checksum | (A destination address rewritten by source routing is *mutable but predictable*: the sender puts the final value into the computation.) AH provides **integrity**, **data-origin authentication** and, at the receiver's discretion, **anti-replay**. It provides **no confidentiality**: every byte after the AH header crosses the network readable. ## What ESP protects ESP wraps the data it protects rather than standing beside it: 1. `SPI` (4 bytes) and `Sequence Number` (4 bytes), sent in the clear; 2. **Payload Data**, beginning with an initialisation vector when the cipher needs one; 3. the **ESP trailer** — `Padding` (0-255 bytes), `Pad Length` (1 byte) and `Next Header` (1 byte); 4. the `ICV`, when integrity is in use. The ciphertext covers the payload and the trailer. The integrity check covers the SPI, the sequence number, the payload and the trailer — and stops there. It does **not** reach back into the IP header in front of ESP. When ESP carries a whole inner IP packet, that inner header is part of the payload and is protected; the outer header never is. ## Side by side | | AH | ESP | |---|---|---| | IP protocol number | 51 | 50 | | Confidentiality | none | yes, unless NULL encryption is chosen | | Integrity and origin authentication | yes | yes, with an integrity algorithm or an AEAD cipher | | Covers the outer IP header | its immutable fields | no | | Anti-replay | optional, receiver's choice | optional, receiver's choice | | Status in RFC 4301 | implementations MAY support | implementations MUST support | ## Why ESP is the one you meet - **It does both jobs.** ESP gives confidentiality and integrity in one header. RFC 8221 calls an AEAD cipher such as `ENCR_AES_GCM_16` the fastest and most modern way to get both, with the cipher's tag serving as the ICV. - **It can do AH's job.** With `ENCR_NULL`, ESP authenticates without encrypting. RFC 4301 downgraded AH to MAY because "there are very few contexts in which ESP cannot provide the requisite security services". - **It survives address translation.** AH's ICV includes the addresses a NAT rewrites, so translated AH packets fail verification. ESP's ICV does not include them, and ESP can be carried inside UDP to cross a translator. - **Stacking them is discouraged.** RFC 8221 lists ESP for confidentiality plus AH for authentication as NOT RECOMMENDED: slower, more header bytes and a smaller effective MTU. ## Two traps in the short answer - **"AH encrypts the header."** It encrypts nothing; it authenticates part of the header. - **"ESP without integrity is fine."** RFC 4301 marks confidentiality without integrity NOT RECOMMENDED, and RFC 8221 says encryption without authentication MUST NOT be used. Integrity is what stops an attacker flipping bits in ciphertext they cannot read. The answer an interviewer wants in one breath: AH authenticates the payload and the unchanging parts of the IP header and encrypts nothing; ESP encrypts and authenticates its own contents but not the outer header; ESP is mandatory, AH optional, and NAT is why AH faded.

  • If ESP does not authenticate the outer IP header, what stops someone forging an ESP packet with a spoofed source address?
    The ICV. It is keyed with the security association's secret, so without the key an attacker cannot produce a packet that verifies; a forged packet is discarded whatever its source address says. Re-sending a captured valid packet is caught by the anti-replay window. What ESP does not prove is that the outer address is the one the peer used, which is why receivers also check the decrypted traffic against the association's policy.
  • Can AH and ESP be applied to the same packet, and should they be?
    RFC 4301 allows the two to be combined, and RFC 8221 lists ESP for confidentiality plus AH for authentication as one of three ways to get both properties. It marks that method NOT RECOMMENDED: it is the slowest, adds two headers and shrinks the effective MTU, and some configurations of ESP-without-authentication under AH have been shown insecure. ESP with an AEAD cipher such as `ENCR_AES_GCM_16` does both in one pass.

AH is a notary's stamp pressed across a postcard and its address label: anyone can read the card, and re-addressing it voids the stamp. ESP is a sealed, stamped envelope posted inside an outer envelope whose address the seal does not cover.

saying these in an interview costs you the question

  • AH encrypts the IP header while ESP encrypts the payload.
  • ESP's integrity check covers the outer IP source and destination addresses.
  • AH signs the TTL, so every router hop would break it.
  • Running ESP with encryption and no integrity algorithm is a normal choice.
  • IKE is the protocol that encrypts the data packets in an IPsec tunnel.
open as a page

In IPsec, what job does IKE do before any protected packet flows, and how did IKEv1's two phases divide that job?

level: juniorimportance: must knowfreq 45%

basics

~20 s

IKE authenticates the peers, negotiates algorithms and derives keys for ESP or AH. IKEv1 split this into Phase 1 (Main or Aggressive Mode, building a protected IKE SA) and Phase 2 (Quick Mode, negotiating IPsec SAs under it); RFC 9395 deprecates IKEv1.

open as a page

In IPsec, what is the difference between transport mode and tunnel mode, and where does the ESP header sit in each?

level: juniorimportance: must knowfreq 50%

basics

~20 s

IPsec transport mode keeps the original IP header and inserts ESP between it and the payload, protecting only that payload; tunnel mode puts the whole original packet, header included, behind ESP and a new outer IP header.

open as a page

Why does plain IPsec ESP often fail through a home router's port-translating NAT, and what does NAT traversal change on the wire?

level: juniorimportance: must knowfreq 40%

basics

~20 s

ESP is IP protocol 50 with no port numbers, so a port-translating NAT cannot tell which inside host an inbound packet is for. NAT traversal puts a UDP header on port 4500 in front of ESP, giving the NAT ports to map.

open as a page

In IPsec, what is a Security Association, and why does protecting two-way traffic between two gateways take a pair of them?

level: juniorimportance: must knowfreq 42%

basics

~20 s

An IPsec Security Association is one-way state: the keys, algorithms, counters and selectors protecting traffic in a single direction with AH or ESP. Two-way traffic therefore needs two SAs, one per direction, each with its own SPI.

open as a page

Why does an IPsec AH packet fail its integrity check after crossing a NAT, when ESP traffic can be made to work?

level: middleimportance: must knowfreq 32%

basics

~20 s

AH's integrity check covers the IP source and destination addresses, which a NAT rewrites, so the receiver's recomputed ICV no longer matches and the packet is dropped. ESP's check excludes the outer header, so only ESP can be repaired.

open as a page

In IKEv2, what do the IKE_SA_INIT and IKE_AUTH exchanges each carry, and why is the first pair sent unencrypted?

level: middleimportance: must knowfreq 38%

basics

~20 s

IKE_SA_INIT negotiates the IKE SA's algorithms and exchanges Diffie-Hellman values and nonces in the clear, because no keys exist yet. IKE_AUTH, encrypted under the derived keys, carries identities, AUTH proofs, and the first Child SA's proposal and traffic selectors.

open as a page

In IKEv2, how do the NAT_DETECTION_SOURCE_IP and NAT_DETECTION_DESTINATION_IP payloads reveal a NAT, and what changes once one is found?

level: middleimportance: must knowfreq 25%

basics

~20 s

Each IKEv2 peer sends SHA-1 hashes of the SPIs with its source and destination address and port in IKE_SA_INIT. A mismatch reveals a translator and which side is behind it; IKE and ESP then move to UDP 4500.

open as a page

In IPsec site-to-site VPNs, what is the difference between a policy-based tunnel and a route-based tunnel built on a virtual tunnel interface?

level: middleimportance: must knowfreq 34%

basics

~20 s

In a policy-based IPsec VPN, Security Policy Database selectors decide which packets are encrypted, typically one selector pair per protected subnet pair. In a route-based VPN, a virtual tunnel interface carries wide selectors and the routing table decides what enters it.

open as a page

An IPsec ESP tunnel between two gateways on 1,500-byte links receives full-size 1,500-byte IPv4 packets with DF set; what happens, and what inner MTU fits?

level: seniorimportance: must knowfreq 35%

basics

~20 s

With AES-GCM the IPsec tunnel-mode packet would be 1,556 bytes, too big, so the gateway SHOULD drop it and send an ICMP PMTU message to the source; the largest inner packet that fits is 1,446 bytes.

open as a page

With IPsec ESP and AES-CBC, how much trailer padding does a 100-byte payload need, and what do Pad Length and Next Header record?

level: middleimportance: should knowfreq 18%

basics

~20 s

Ten bytes: AES-CBC needs payload, padding, Pad Length and Next Header to fill whole 16-byte blocks, so 100 + 2 rounds up to 112. Pad Length records 10; Next Header names the payload: 6 for TCP, 4 for IPv4.

open as a page

How does an IKEv2 gateway decide its peer is dead, and why must it not treat an ICMP unreachable or an unprotected notify as proof?

level: middleimportance: should knowfreq 30%

basics

~20 s

When nothing protected has arrived recently, an IKEv2 gateway sends an empty INFORMATIONAL request and retransmits it with exponential backoff; only repeated silence, or a protected INITIAL_CONTACT on a new IKE SA, proves failure. ICMP and unprotected notifies are forgeable.

open as a page

In IKEv2, how does pre-shared-key authentication differ from certificate signature authentication in what AUTH proves and what the operator must protect?

level: middleimportance: should knowfreq 28%

basics

~20 s

Both compute AUTH over the sender's IKE_SA_INIT message, the peer's nonce and its own ID. A pre-shared key makes AUTH a keyed prf, guessable offline if the secret is weak; a signature uses a private key a certificate binds to the ID.

open as a page

What can an on-path observer learn from an IPsec ESP packet in transport mode that tunnel mode would hide?

level: middleimportance: should knowfreq 22%

basics

~20 s

In IPsec transport mode an observer reads the real source and destination hosts from the original IP header; tunnel mode shows only the two gateways. Both encrypt ports and the next-layer protocol; sizes, timing and, by default, DS marks still leak.

open as a page

A 1,400-byte IPv4 packet is protected by IPsec ESP with AES-GCM and a 16-byte ICV; how large is it in transport and tunnel mode?

level: middleimportance: should knowfreq 28%

basics

~20 s

With IPsec ESP and AES-GCM (8-byte IV, 16-byte ICV), the 1,400-byte IPv4 packet becomes 1,436 bytes in transport mode (36 bytes added) and 1,456 bytes in tunnel mode (56 added), the difference being the outer IPv4 header.

open as a page

On UDP port 4500, how does an IPsec endpoint tell an IKE message, a UDP-encapsulated ESP packet and a NAT-keepalive apart?

level: middleimportance: should knowfreq 12%

basics

~20 s

By the first bytes after the UDP header: four zero bytes, the non-ESP marker, mean IKE; a non-zero first word is an ESP SPI; a one-octet payload of 0xFF is a NAT-keepalive, which only refreshes the NAT mapping.

open as a page

How does an IPsec Security Policy Database decide whether a packet is protected, bypassed or discarded, and why does the order of its entries matter?

level: middleimportance: should knowfreq 26%

basics

~20 s

The SPD is an ordered list of entries keyed by selectors such as addresses, protocol and ports, each saying PROTECT, BYPASS or DISCARD. Overlapping ranges make order decide which entry applies, and traffic matching nothing is discarded.

open as a page

When an ESP packet reaches an IPsec gateway, how does the receiver use the SPI and the SAD, and what does it check afterwards?

level: middleimportance: should knowfreq 30%

basics

~20 s

The receiver looks up the packet's 32-bit SPI, which it chose itself, in its Security Association Database; no match means discard. It applies ESP with that entry's keys, then checks the inner headers against the SA's selectors.

open as a page

In IKEv2 remote access, how does EAP authenticate the user inside IKE_AUTH, and why must the gateway still authenticate with a signature?

level: middleimportance: should knowfreq 13%

basics

~20 s

The client omits AUTH from its first IKE_AUTH message; the gateway answers with its certificate, signed AUTH and an EAP request; the method runs over extra IKE_AUTH round trips; both sides finish with AUTH keyed from the EAP MSK.

open as a page

After QoS queuing was added after encryption on an IPsec gateway, the peer discards low-priority ESP packets as replays; what in ESP's anti-replay window explains it, and what fixes it?

level: seniorimportance: should knowfreq 22%

basics

~20 s

Sequence numbers are assigned at encryption; priority queuing then lets later numbers overtake. The receiver's window, 64 by default, moves past the delayed packets, which fall left of it and are dropped. Fix: one SA per traffic class, or a larger window.

open as a page

An IKEv2 tunnel comes up cleanly, then drops and re-forms each time its Child SA is due for rekey; what in CREATE_CHILD_SA explains that?

level: seniorimportance: should knowfreq 20%

basics

~20 s

The first Child SA, built in IKE_AUTH, uses no Diffie-Hellman group; a Child SA group is first offered at the CREATE_CHILD_SA rekey. If the peers disagree that fails, RFC 7296 makes the endpoint close the IKE SA, and a fresh setup succeeds again.

open as a page

An IKEv2 tunnel between two different makers' gateways will not come up; how do the failing exchange and its notify point you to the mismatch?

level: seniorimportance: should knowfreq 30%

basics

~20 s

Locate the failure by exchange: NO_PROPOSAL_CHOSEN in IKE_SA_INIT is an algorithm mismatch, AUTHENTICATION_FAILED in IKE_AUTH a secret, identity or certificate mismatch, TS_UNACCEPTABLE a selector mismatch with the IKE SA up, and an unanswered IKE_AUTH often dropped fragments.

open as a page

Two routers protect their GRE traffic with IPsec ESP; why is transport mode allowed there, and how many bytes does it save over tunnel mode?

level: seniorimportance: should knowfreq 18%

basics

~20 s

RFC 4301 lets a router use IPsec transport mode for packets it sources itself, and GRE packets carry the router's own address; tunnel mode would add a second IPv4 header with the same two addresses, 20 redundant bytes.

open as a page

A site-to-site IPsec tunnel comes up, traffic flows from site A to site B, but no replies return; what in the SA and SPD state explains it?

level: seniorimportance: should knowfreq 24%

basics

~20 s

Each direction is its own SA, so one can fail alone. Usually B's replies never match its PROTECT entry, or A drops them: their SPI is unknown to A, or their inner headers fall outside the SA's selectors.

open as a page

How many IPsec SAs does a cloud VPN gateway hold for 40 branches, each pairing 10 local with 10 cloud subnets, policy-based versus route-based?

level: seniorimportance: should knowfreq 15%

basics

~20 s

With one Child SA pair per subnet pair, policy-based tunnels need 100 pairs per branch: 4,000 pairs or 8,000 one-way ESP SAs at the hub. Route-based tunnels with any-to-any selectors need one pair per tunnel: 40 pairs, 80 SAs.

open as a page

An IKEv2 site-to-site tunnel is up, but only one branch subnet passes traffic and which one changes after each restart; how does traffic-selector narrowing explain it?

level: seniorimportance: should knowfreq 14%

basics

~20 s

The peers' selector configurations disagree. The initiator proposes a wide range led by the triggering packet's addresses; a narrower responder MUST keep a subset containing that first selector, so only the subnet that sent first gets a Child SA.

open as a page

Connecting 40 branches to a cloud IPsec VPN gateway that offers two tunnel endpoints per branch, how do you design tunnels, routing and failover, and what does each choice cost?

level: principalimportance: should knowfreq 12%

basics

~10 s

Build two route-based tunnels per branch with any-to-any selectors, run BGP over each, and let route withdrawal move traffic. Then decide active/standby versus active/active, how fast failure is detected, and how routes are filtered.

open as a page

Why must an IPsec ESP SA be replaced before its 32-bit sequence number wraps, and how do extended sequence numbers avoid that?

level: middleimportance: nice to knowfreq 12%

basics

~20 s

With anti-replay on, an ESP sender MUST NOT let the sequence number cycle: an SA carries at most 2^32 − 1 packets, about 72 minutes at 1 Mpps. Extended sequence numbers count in 64 bits but send only the low 32.

open as a page

With MOBIKE (RFC 4555), what happens to an IKEv2 remote-access client's SAs when the laptop moves from office Wi-Fi to a cellular network?

level: middleimportance: nice to knowfreq 9%

basics

~20 s

With MOBIKE the client keeps its IKE SA and Child SAs: it sends an UPDATE_SA_ADDRESSES notify from the new address, the gateway checks that address, and only the outer tunnel addresses change while inner addresses and selectors stay.

open as a page

When traffic needs IPsec integrity without encryption, why do current specifications prefer ESP with NULL encryption over AH, and what does that give up?

level: seniorimportance: nice to knowfreq 10%

basics

~20 s

ESP with ENCR_NULL and an integrity transform authenticates the payload, crosses NAT and is mandatory to implement; AH is optional and fails behind NAT. The cost: no outer-header integrity, and nothing in the packet shows it is unencrypted.

open as a page

showing 1–30 of 32