Posts

Showing posts with the label VPN

Remote Access VPN Design: Split Tunnelling, Always-On, and What Replaced Them

A remote access VPN places a user's device onto the corporate network from wherever they are. The design decisions — what traffic goes through it, whether it is always connected, and what the device reaches once it is on — determine both the security posture and whether people work around it. Full tunnel and split tunnel Full tunnel sends all of the device's traffic through the VPN, including internet-bound traffic, which then exits through the corporate perimeter. The benefit is that every inspection and filtering control applies to a remote user exactly as it does in the office, and the organization has visibility of what the device does. The cost is that every video call and cloud application takes a detour through headquarters, adding latency and consuming concentrator and internet capacity that scales with the remote population. Split tunnel sends only corporate-destined traffic through the VPN and lets everything else go direct. The benefit is performance and f...

IPsec Transport vs Tunnel Mode: AH, ESP, and Where Each Belongs

IPsec secures traffic at the network layer, which means it protects everything above it without any application needing to know. Two choices define any deployment: which mode — transport or tunnel — and which protocol — AH or ESP. The exam tests both, and the combinations behave quite differently. Transport mode Transport mode protects the payload of the original IP packet and leaves the original header in place. Source and destination addresses stay visible, and the packet routes exactly as it would have. That makes it appropriate for end-to-end protection between two hosts that are already routable to each other: a management workstation to a server, a server to a database, or host-to-host policies inside a data center. There is no encapsulation overhead beyond the IPsec header itself, so it is the more efficient of the two. Its limitation follows from the same property. Because the original addresses are exposed, transport mode provides no topology hiding, a...

VPN Protocols Compared: IPsec, WireGuard, TLS-Based and MACsec

Four ways to encrypt traffic between systems, operating at different layers with different trade-offs. Choosing between them is mostly about where the encryption boundary sits and what has to pass through in between. IPsec Network layer, so it protects everything above it without applications knowing. Two modes — transport for host to host, tunnel for gateway to gateway — and ESP as the protocol providing confidentiality and integrity, as covered under IPsec transport and tunnel mode . Its strengths are ubiquity and interoperability: every serious network device supports it, and it is the default for site-to-site connectivity between different vendors' equipment. Its weaknesses are complexity and traversal. The configuration surface is large — two negotiation phases, many algorithm choices, traffic selectors that must mirror — which is why the failures under VPN troubleshooting are so common. And ESP is IP protocol 50 rather than a port, so it needs NAT tra...

Why VPN Tunnels Fail: Phase 1, Phase 2, NAT-T and MTU

IPsec VPN troubleshooting is mostly a matter of knowing which of two negotiations failed, because the causes are entirely different. Establish that first and the rest narrows quickly. The two phases Phase 1 authenticates the peers and builds a secure channel for the negotiation itself. Both sides must agree on the encryption and hash algorithms, the Diffie-Hellman group, the authentication method, and the lifetime. It produces a management channel, and no user traffic flows over it. Phase 2 negotiates the security associations that actually carry data: which traffic is protected, with which algorithms, and for how long. The diagnostic value is that a phase 1 failure means the peers never agreed on how to talk at all — look at algorithms, the pre-shared key or certificate, and peer addresses. A phase 2 failure means authentication succeeded and they disagree about what to protect — look at the traffic selectors. IKEv2 collapses much of this and handles reconnection, m...

NHRP and DMVPN: How Spoke-to-Spoke Tunnels Build Themselves

Next Hop Resolution Protocol solves one problem: on a network where every site has a dynamic or unknown public address, how does one spoke learn how to reach another directly instead of routing everything through headquarters? NHRP is the lookup service that answers that, and DMVPN is the architecture built on top of it. The problem with hub-and-spoke A traditional site-to-site VPN builds a tunnel between two known endpoints. With twenty branch sites, connecting every site to every other requires 190 tunnels, each configured by hand, and every new site multiplies the work. So most deployments settle for hub-and-spoke: every branch tunnels to headquarters, and traffic between two branches goes branch to hub to branch. That is simple to configure and wasteful in practice — it doubles latency for site-to-site traffic, consumes hub bandwidth twice for every flow, and makes the hub a bottleneck for voice and video between offices that may be physically close together. What NHRP d...

GRE Tunnels Explained: Encapsulation and Limitations for Network+

GRE — Generic Routing Encapsulation — wraps one protocol's packets inside IP packets so they can cross a network that would not otherwise carry them. It creates a virtual point-to-point link between two endpoints that may be many hops apart. The exam tests one thing above all: GRE does not encrypt . It is a tunnelling protocol, not a security protocol, and the two are easy to conflate. How encapsulation works The original packet becomes the payload. GRE adds its own header, and an outer IP header is added with the tunnel endpoints as source and destination. The network in between routes the outer packet normally, with no knowledge of what is inside. At the far end the outer headers are stripped and the original packet continues on its way. GRE is IP protocol number 47 — not a TCP or UDP port, which matters when writing firewall rules. A firewall that permits only TCP and UDP will silently drop GRE, and that is a classic troubleshooting scenario. What it is for Carrying traffi...