Main mode vs Aggresive Mode- IPSEC Training |

  Рет қаралды 27,257

NETWORKERS HOME

NETWORKERS HOME

Күн бұрын

Пікірлер: 20
@Jamesaepp
@Jamesaepp 3 жыл бұрын
I really like your lecture but have a couple questions. 1 - You mention that IKE phase 2 is like a data plane. I'm not sure I see this. I would call ESP and AH the data plane - they are the payload. IKE (ISAKMP & NAT-T) are your control plane -- they authenticate the peers mutually, setup the sessions and handle key negotiation. The management plane might be something like if you had some SDN that was automatically creating and tearing down tunnels. Yes, the ESP is still inside UDP 500 or UDP 4500 but it's not really a phase 2 negotiation, it's just taking advantage of the encapsulation transport provided by UDP. 2 - Around 30 minutes you ask the students where the key is coming from and you call DH the correct answer. Here I am thinking this is wrong. The diffie hellman is used to provide PFS of the IKE traffic. There is a PSK (or public keys) in use to secure the IKE traffic between the two peers. Without DH, an eavesdropper could take your conversation, brute force it offline, and figure out the PSK (or private keys). DH helps protect against this by creating a session key but only for IKE transport. Now the attacker would have to both know the PSK (or private keys) AND intercept the traffic and re-write it between both peers in order to see the traffic. Intercepting is harder than eavesdropping. So I understand the use of DH for perfect forward secrecy, but are we positive the key used in DES/3DES/AES256 comes from diffie hellman? Are we sure it doesn't come from somewhere else?
@VinayKumar-fo3cy
@VinayKumar-fo3cy 2 жыл бұрын
clear cut explanation sir ! Thank you so much for the clarity about Ipsec.❤❤
@ganeshbonal-j9j
@ganeshbonal-j9j Жыл бұрын
Best Video
@fact2891
@fact2891 3 жыл бұрын
Excellent Explanation
@amitmukherjee8076
@amitmukherjee8076 Жыл бұрын
Awsome explainations
@rajeshsingh7065
@rajeshsingh7065 2 жыл бұрын
Hi...Thanks for such good presentation and informative video. One suggestion from my side, Can you please add sequence of video link in description of IPSEC ?. Its easy for user to get know from which video he should start to know details on IPSEC protocol.
@DeepakKumar-ov8ko
@DeepakKumar-ov8ko 3 жыл бұрын
6 main +6 (3 *2 - unidirectional tunnel) quick mode messages are exchanged by isakmp ,So where i can we see " ike "in wireshark ???Encyption odf user payload is done using ESP.
@shahbazahmed6179
@shahbazahmed6179 4 ай бұрын
Is there an ikev2 videos?
@networkershome
@networkershome 4 ай бұрын
Thank you for your interest! Here is the IKEV2 Phase 1 video link - kzbin.info/www/bejne/bV7ChKune9Wia6s You can Visit our channel for any other topics
@shahbazahmed6179
@shahbazahmed6179 4 ай бұрын
@@networkershome I want from the same teacher... The above link is not a very good explanation
@rohanjamwal7651
@rohanjamwal7651 3 жыл бұрын
In the fifth and sixth packets of the Main Mode's SA negotiation when using IKEv1. What is the Identification payload ?From what I understand, when using PSK, this gets set to the IP address of the VPN peer, which can already be found in the source IP field. The source IP field might not be encrypted, but so what? Is there some advantage to having this same IP information encrypted?
@MuhamedUsman
@MuhamedUsman 4 ай бұрын
i think you are wrong isakmp is not used in ikev2
@AshutoshCK
@AshutoshCK 3 жыл бұрын
Nice explanation
@khelouiazzeddine3113
@khelouiazzeddine3113 Жыл бұрын
Graet explications
@Sriranjan_Nanda_Ramesh
@Sriranjan_Nanda_Ramesh 6 ай бұрын
43:00
@amitkumarsingh2176
@amitkumarsingh2176 8 ай бұрын
JAI SHREE RAM🙏
@Shubhontube
@Shubhontube 2 жыл бұрын
Best
@krushnakantanayak5786
@krushnakantanayak5786 2 жыл бұрын
Maja nehi aya .... video lenght is too much....
@tusharbhardwaj1048
@tusharbhardwaj1048 2 жыл бұрын
Great Content. Is it possible to get a hold of this VPN Prsesntation1.pdf file?
Как Я Брата ОБМАНУЛ (смешное видео, прикол, юмор, поржать)
00:59
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 143 МЛН
Apple sets intraday high on AI update, reported chip news
7:32
Yahoo Finance
Рет қаралды 2,1 М.
Implementing and Troubleshooting Site-to-Site VPN
1:23:11
INEtraining
Рет қаралды 72 М.
Top Most-Asked Network Engineer Interview Questions in Hindi
45:24
Network Kings
Рет қаралды 14 М.
Why Cybersecurity Training is a SCAM
10:37
Technical Institute of America
Рет қаралды 259 М.
IP Sec VPN Fundamentals
14:55
LearnCantrill
Рет қаралды 189 М.
TCP Fundamentals Part 1 // TCP/IP Explained with Wireshark
1:17:24
Chris Greer
Рет қаралды 450 М.
Understanding AH vs ESP and ISKAKMP vs IPSec in VPN tunnels
18:30
Ryan Lindfield
Рет қаралды 315 М.
OSPF Deep Dive
2:26:28
Kevin Wallace Training, LLC
Рет қаралды 223 М.
Как Я Брата ОБМАНУЛ (смешное видео, прикол, юмор, поржать)
00:59