skip to content

IPsec

Security built into the IP layer: the AH and ESP headers, IKE agreeing keys before traffic flows, and transport versus tunnel mode. Interviewers reach for it when two sites must be joined privately.

on this pageshow

explore

questions

page 2 of 2

Why does IPsec transport mode through a NAT leave inner TCP and UDP checksums wrong, and how does the receiver repair them?

level: seniorimportance: nice to knowfreq 10%

basics

~20 s

TCP and UDP checksums cover the IP addresses through the pseudo-header, and in transport mode they travel encrypted inside ESP, so the NAT cannot fix them. The receiver learns the original addresses through IKE and fixes the checksum after decryption.

open as a page

Why does the IPsec architecture keep a Peer Authorization Database beside the SPD, and what does it stop an authenticated peer from doing?

level: seniorimportance: nice to knowfreq 8%

basics

~20 s

The Peer Authorization Database lists which peers may run IKE, how each authenticates, and which identities or address ranges each may claim. It stops an authenticated peer from asserting traffic selectors for networks it is not authorised to represent.

open as a page

showing 31–32 of 32