Documente Academic
Documente Profesional
Documente Cultură
VPN Solutions
Agenda
Introduction to IPSec
IPSec VPN Topologies
Cisco Site-to-Site VPN
Solutions
VPN Overview
www.cisco.com/go/vpn
IPSecDesignGuide.pdf.lnk
VPN Overview
www.cisco.com/go/vpn
IPSec Overview
Initiating the IPSec session
Phase oneexchanging keys
Phase twosetting up security associations
Encrypting/decrypting packets
Rebuilding security associations
Timing out security associations
Simple IPSec configuration
VPN Overview
www.cisco.com/go/vpn
VPN Overview
www.cisco.com/go/vpn
VPN Overview
www.cisco.com/go/vpn
Encrypting and
Decrypting Packets
Phase one and phase two completes
Security Associations (SA) are created at both IPSec
endpoints
Using the negotiated SA information
Outbound packets are encrypted
Inbound packets are decrypted
VPN Overview
www.cisco.com/go/vpn
Rebuilding
Security Associations
To ensure that keys are not compromised they are
periodically refreshed
Security associations will be rebuilt when:
The lifetime expires, or
Data volume has been exceeded, or
Another SA is attempted with identical parameters
VPN Overview
www.cisco.com/go/vpn
10.1.2.0/24
200.1.1.2
192.1.1.1
Internet
IPSec Tunnel
VPN Overview
www.cisco.com/go/vpn
Topologies
Standard Site-to-Site IPSec Enabled VPN Solution
Design and Engineering Guide
http://www.cisco.com/cpropart/salestools/cc/so/neso/vpn/vpne/s2sdes.ht
m
Site2SiteDesignGuide.url
VPN Overview
www.cisco.com/go/vpn
10
VPN Overview
www.cisco.com/go/vpn
11
VPN Overview
www.cisco.com/go/vpn
12
VPN Overview
www.cisco.com/go/vpn
13
Internet
Internet
a. Original Packet
b. GRE Encapsulation
c. GRE over IPSec Transport Mode
d. GRE over IPSec Tunnel Mode
a
d
VPN Overview
IP Hdr 1
TCP hdr
Data
IP hdr 2
GRE hdr
IP Hdr 1
TCP hdr
Data
IP hdr 2
ESP hdr
GRE hdr
IP Hdr 1
TCP hdr
Data
IP hdr 3
ESP hdr
IP hdr 2
GRE hdr
IP Hdr 1
TCP hdr
Data
www.cisco.com/go/vpn
14
VPN Overview
www.cisco.com/go/vpn
15
VPN Overview
www.cisco.com/go/vpn
16
VPN Overview
www.cisco.com/go/vpn
17
www.cisco.com/go/vpn
18
www.cisco.com/go/vpn
19
VPN Overview
www.cisco.com/go/vpn
20
VPN Overview
www.cisco.com/go/vpn
21
Application
Remote
Access
VPN
Remote Dial
Site-to-Site
VPN
Extranet
VPN
VPN Overview
Connectivity
As Alternative To
Dedicated
Dial
ISDN
Site-to-Site
Leased Line
Internal
Frame Relay
Connectivity
ATM
Biz-to-Biz
Fax
External
Connectivity
EDI
www.cisco.com/go/vpn
Benefits
Ubiquitous Access
Lower Cost
Extend Connectivity
Increased Bandwidth
Lower Cost
Facilitates
E-Commerce
22
Mobile User
POP
Internet
VPN
DSL
Cable
Central Site
Home Telecommuter
Site-to-Site
Remote Office
Site-to-Site VPN
Per-user manageability
23
VPN Application
Small Biz/Branch
SOHO
New
VPN 3002
Hardware Client
VPN 3000
Software Client
Remote
Access
Cisco VPN 3000
VPN 3080
VPN 3060
Concentrators
VPN 3030
Concentrator
VPN 3015
VPN 3005
Concentrators
Site-to-Site
IOS Routers
7200
7100
7100
3600
3600
2600
1700
900
800
Firewall-Based
VPN
Pix Firewall
Pix 535
Pix 525
Pix 525
Pix 515
Pix 515
Pix 506
Pix 506
VPN Overview
www.cisco.com/go/vpn
24
Primary role
All encompassing site-tosite connectivity features
VPN Overview
Basic site-to-site
functionality
Basic site-to-site
functionality
Primary role
www.cisco.com/go/vpn
25
Stateful
StatefulIOS
IOSFirewall
Firewall
Per
Perapplication
applicationcontent
contentfiltering
filteringand
andJava
Javablocking
blocking
Denial
Denialof
ofservice
serviceprotection
protectionand
andintrusion
intrusiondetection
detection
GRE
Time-based
Time-basedACLs
ACLs
VPN
VPNResiliency
Resiliency
QoS
Dynamic
DynamicRoute
RouteRecovery
Recovery- -using
usingrouting
routingprotocols
protocols
through
IPSec
secured
GRE
tunnel
through IPSec secured GRE tunnel
Dynamic
DynamicTunnel
TunnelRecovery
Recovery- -IPSec
IPSecKeep-Alives
Keep-Alives
Full
FullLayer
Layer33Routing
Routingand
andBroad
BroadInterface
InterfaceSupport
Support
EIGRP,
EIGRP,BGP,
BGP,OSPF,
OSPF,and
andothers
others
Numerous
NumerousLAN
LANand
andWAN
WANinterfaces
interfaces
VPN Overview
www.cisco.com/go/vpn
BGP
FW
IPSec
26
Cisco1700
1700Series
Series
Cisco
VPN-optimizedrouter
router
VPN-optimized
connectingremote
remoteoffices
offices
connecting
T1/E1speeds
speeds
atatT1/E1
Cisco
Cisco7100
7100&&7200
7200Series
Series
7100
for
dedicated
7100 for dedicatedVPN
VPNhead-end
head-end
7200
7200for
forhybrid
hybridprivate
privateWAN
WAN++VPN
VPN
connectivity
connectivity
Remote
Office
Main Office
Regional
Office
Cisco
Cisco2600
2600&&3600
3600Series
Series
VPN-optimized
VPN-optimizedrouters
routers
connecting
branch
connecting branchand
and
regional
offices
at
regional offices at
nxT1/E1
nxT1/E1speeds
speeds
VPN Overview
Internet
Small Office/
Home Office
Cisco800
800&&900
900Series
Series
Cisco
VPN-optimizedrouters
routersfor
forISDN,
ISDN,
VPN-optimized
DSL,and
andcable
cableconnectivity
connectivity
DSL,
www.cisco.com/go/vpn
27
VPN-Enabled Broadband
Routers
806
827/804
905
50
50
50
384 kbps
384 kbps
6 Mbps
None
None
(built-in)
WAN Interfaces
Ethernet
DSL/ISDN
Cable
LAN Interfaces
4xEthernet
1xEthernet
4xEthernet
Simultaneous Tunnels
Performance
Hardware Acceleration
VPN Overview
www.cisco.com/go/vpn
28
VPN-Enabled Routers
1710
1720/1750
2611/2621
2651
3620/3640
100
100
300
800
800
10/12
14
10/19
(built-in)
VPN Module
AIM-VPN/BP
AIM-VPN/EP
NM-VPN/MP
WAN Interfaces
1xEtherne
t
(varies)
(varies)
(varies)
(varies)
LAN Interfaces
1xFE
1xFE
2xFE
2xFE
(varies)
Simultaneous Tunnels
Performance (Mbps)
Hardware Acceleration
VPN Overview
www.cisco.com/go/vpn
29
VPN-Enabled Routers
3660
7120
7140
7140
7200
1,300
2,000
2,000
3,000
5,000
40
50
90
140
145
AIM-VPN/HP
ISM
ISM
SA-VAM
WAN Interfaces
(varies)
(varies)
(varies)
None
(varies)
LAN Interfaces
1xFE
2xFE
2xFE
2xFE
(varies)
Simultaneous Tunnels
Performance (Mbps)
Hardware Acceleration
VPN Overview
www.cisco.com/go/vpn
30
VPN Overview
www.cisco.com/go/vpn
31
New!
www.cisco.com/go/vpn
32
VPN Management
VPN Device Manager
Embedded web single device policy manager
VPN Overview
www.cisco.com/go/vpn
33
VPN Overview
www.cisco.com/go/vpn
34
Blog.router-switch.com
News, tutorials, tips, info & thoughts on
Developments in the Cisco, Cisco network, IT,
Software & Network Hardware Industry
VPN Overview
www.cisco.com/go/vpn
35
Presentation_ID
36