IPsec
Security built into the IP layer: the AH and ESP headers, IKE agreeing keys before traffic flows, and transport versus tunnel mode. Interviewers reach for it when two sites must be joined privately.
on this pageshowhide
explore
- AH vs ESP Headers6 questions
- Security Associations5 questions
- Transport vs Tunnel Mode5 questions
- IKE Key Exchange6 questions
- ESP NAT Traversal4 questions
- Policy vs Route-Based VPNs6 questions
questions
page 2 of 2Why does IPsec transport mode through a NAT leave inner TCP and UDP checksums wrong, and how does the receiver repair them?
level: seniorimportance: nice to knowfreq 10%
basics
~20 sTCP and UDP checksums cover the IP addresses through the pseudo-header, and in transport mode they travel encrypted inside ESP, so the NAT cannot fix them. The receiver learns the original addresses through IKE and fixes the checksum after decryption.
Why does the IPsec architecture keep a Peer Authorization Database beside the SPD, and what does it stop an authenticated peer from doing?
level: seniorimportance: nice to knowfreq 8%
basics
~20 sThe Peer Authorization Database lists which peers may run IKE, how each authenticates, and which identities or address ranges each may claim. It stops an authenticated peer from asserting traffic selectors for networks it is not authorised to represent.
showing 31–32 of 32