Network Access for Remote UsersReview of TechnologiesSite-to-Site Private InfrastructureTraditional Dialup ServiceVirtual Private NetworkVPN RoadmapTunnelling MethodsLayer 3 Tunnelling (GRE)Tunnelling In ActionLayer 2 Tunnelling (L2TP)Layer 2 Tunnelling ModesAuthenticationIP Security (IPSec)IPSec ProtocolsIPSec ModesEquipment at Remote SiteExample ConfigurationFragmentation GotchaNetwork Access for Remote Users Dr John S. GrahamULCCReview of Technologies• Remote Site– Private Leased Lines• Kilostream or Megastream Circuits•LES–ISDN–EPS9–ISP• Remote User– Private Dialup Service–ISPSite-to-Site Private InfrastructureTraditional Dialup ServiceHigh CostsSupport BurdenLimited to 56K Analogue DialupLimited Service☺Security GuaranteedVirtual Private Network☺Highly Flexible Solution☺Uses Existing Infrastructure Complex Security IssuesVPN RoadmapTunnellingSymmetric AsymmetricEncryptionEndpoints DataAuthentication IP FrameworkVP NTunnelling Methods• Layer III–GRE–IPSec• Layer II–L2F–PPTP–L2TPLayer 3 Tunnelling (GRE)TCPIP DataGREIPIP TCP DataGREpassenger protocolencapsulating protocolcarrier protocolTunnelling In ActionIP GRETCPIP Data IP GRE TCPIP DataDestination62.49.38.138Source192.168.17.26194.82.103.186192.168.17.26Layer 2 Tunnelling (L2TP)TCPIP DataL2TPUDPIP PPPTCPIP DataL2TPUDPIP PPPESP ESPL2TPL2TP + IPSecTCPIP DataPPPLayer 2 Tunnelling ModesCompulsory L2 TunnellingVoluntary L2 TunnellingAuthentication• Peer Identity–Shared Secret– Digital Certificate• Data Integrity– Digital Signatures• User Identity–Kerberos–RADIUSIP Security (IPSec)•Protocols– Authentication Header– Encapsulating Security Payload– Internet Key Exchange•Modes– Tunnel– TransportIPSec ProtocolsSequence NumberAuthentication DataSPINextHeaderPayloadLengthReservedSequence NumberSPIAuthentication DataDataNextHeaderPadLengthPadIVAuthentication Header (51)Encapsulating Security Protocol (50)IPSec ModesTunnel ModeIP AH/ESP TCPIP DataTransport ModeAH/ESP TCPIP DataEquipment at Remote Site• ‘Wires Only’ ADSL Connection– One Static IP Address• Splitter• Cisco 827H Router– Ethernet hub (4 ports) plus ATM portExample ConfigurationFragmentation Gotcha1540108Security Encapsulation150068Tunnel Encapsulation1500Initial PacketIP DataGREIPIP DataIPGREIP DataIPGREIP DataESP ESPIP DataGREIP ESP
View Full Document