MicroNugget: IPsec Site to Site VPN Tunnels Explained | CBT Nuggets

  Рет қаралды 436,184

CBT Nuggets

CBT Nuggets

Күн бұрын

Пікірлер: 161
@bohemians77
@bohemians77 11 жыл бұрын
You have a remarkable gift for teaching in plain language; I have watched a few of your videos on YT and gained in understanding, even though I am not an IT novice - I sense you enjoy what you do: thanks for taking the time to assist others.
@BijouBakson
@BijouBakson 5 жыл бұрын
This stuff was pure gibberish before I started studying Cisco; now it's pure gold. Thank you very much CBT Nuggets.
@OsvaldoMaria
@OsvaldoMaria 4 жыл бұрын
Your enthusiasm made this much easier to understand
@chickenman1176
@chickenman1176 2 жыл бұрын
Thank you for not having a monotone voice!
@KeithBarker
@KeithBarker 11 жыл бұрын
You are very welcome Samer! Best wishes, Keith
@ShivamMiglani
@ShivamMiglani 4 жыл бұрын
You teach amazingly well. I can see the hard work you put into first explain the theory and then back it up with a practical example.
@KeithBarker
@KeithBarker 11 жыл бұрын
Hello Ashwin- Yes, you've got it. The outside IP header will have the source IP of the VPN gateway sending the packet, with a destination IP header of the remote VPN gateway who will be receiving the packet over the internet. When the receiving router gets the packet, it will de-encapsulate and throw away the old outside header, decrypt the contents (which include the initial IP header addresses the client was using) and continue to route the packet. Keith
@ksbpsb
@ksbpsb 12 жыл бұрын
great job by keith barker and one of the best trainer on the internet
@annehipolito7305
@annehipolito7305 3 жыл бұрын
Thanks. Been doing site to site VPN for years now. Still is reliable for small and medium sized businesses :)
@guerrillafocus
@guerrillafocus 2 жыл бұрын
AH would've been good to mention as well. You do teach very well Keith!
@felipegrings9357
@felipegrings9357 2 жыл бұрын
Simple. Easy to Understand. Straight to the point. Awesome!
@KasunMadurasinghe
@KasunMadurasinghe 2 жыл бұрын
This is one of the coolest explanations I've seen ..You've got talent.. Kudos
@agustinothadeus
@agustinothadeus 6 жыл бұрын
The way you explain it makes it seem so easy to the point where it becomes funny!!, thank you
@ManishYadav0719
@ManishYadav0719 2 жыл бұрын
You Deserved 5 star ⭐ believe me
@TheGshit1
@TheGshit1 4 ай бұрын
Dude is just too good.
@Leo-uy4qv
@Leo-uy4qv 2 жыл бұрын
Excellent, learned something new. thanks for showing packet tracer working in the background
@AfricanAstro
@AfricanAstro 6 жыл бұрын
This was incredible. Simple, clear, well-paced, sticks to the subject, practical use-case. Just very well done.
@thebluegoonie
@thebluegoonie 3 жыл бұрын
I hadn't realised how old this vid is until I saw the Windows XP Start button! Still good, though, thanks.
@ArindamChattopadhya
@ArindamChattopadhya 4 жыл бұрын
Your style of explaining is second to none. 👍🙏🙏🙏
@KeithBarker
@KeithBarker 11 жыл бұрын
My pleasure! Glad you liked the video. Keth
@AshwinRamdin
@AshwinRamdin 11 жыл бұрын
Hi Keith, thank you for taking the time and answering my question. Great video!
@MojoTojoChannel
@MojoTojoChannel 11 жыл бұрын
Man you're way of teaching is just awesome.. pls keep on doing what you're doing..
@jairusan
@jairusan 5 жыл бұрын
Best of the best! Super simplified nugget, this is the best explanation of IPsec I have seen, very informative and useful. Thank you so much, Keith!
@snehanaik4304
@snehanaik4304 3 жыл бұрын
thanks for this detailed explanation with the actual ping request!
@paulykamau
@paulykamau 5 жыл бұрын
Amazing! I'm blown away. Thank you for the intelligent explanation.
@myretarnation
@myretarnation 10 жыл бұрын
Great description and even I got. :) Very good voice to match the video tutorial. Thanks Keith!!
@pimguilherme
@pimguilherme 4 жыл бұрын
This is just so fun, thanks man!!
@elpidiagomez3701
@elpidiagomez3701 5 жыл бұрын
Thanks for the vid Mr. Barker...you take complicated topics and explain them so i can understand, keep up the great work!!
@microsoftsarker
@microsoftsarker Жыл бұрын
This series is awesome.
@KeithBarker
@KeithBarker 11 жыл бұрын
The the crypto ACL says any-any, there are 2 challenges. The two peers will need to agree on that to bring up a tunnel, and then secondly, all traffic leaving the VPN peers would be sent to the peer on the other side. There may be some corner cases where something similar to that would work, but for general site to site VPNs it would be a configuration/design error.
@ryutkin
@ryutkin 8 жыл бұрын
You are amazing! I've never heard someone explain something so well! Brilliant!
@anastasijat.4138
@anastasijat.4138 9 жыл бұрын
Awesome video, love your enthusiasm! :)
@johnson554671
@johnson554671 5 жыл бұрын
Good Job Keith!
@erikvandervelden4566
@erikvandervelden4566 Жыл бұрын
Nice explanation. What i'm missing is: Who to do this? How do i create R1 and R2? After all, it's about. How to get this to work.
@HongeraGideon
@HongeraGideon 6 жыл бұрын
How can someone thumb down this video, fantastic explanation.
@senyk1
@senyk1 2 жыл бұрын
Thanks for the video, what did you use to draw on the screen? Is that a pad you can hook up to a computer?
@ashishsontakke
@ashishsontakke 3 жыл бұрын
The VPN client installed in our home machines will do the ESP encapsulation at machine itself before it sends to our ISP ? Is that right ? In this example you said Router R1(ISP's router) is doing it.
@GL455_
@GL455_ 2 жыл бұрын
Man! You mad helpful! So glad I found ya!
@SarabjitMadan
@SarabjitMadan 8 жыл бұрын
This was so well illustrated and explained. Thanks
@proplemsolver5995
@proplemsolver5995 11 жыл бұрын
شكرا للدكتور هيازع البارقي خبير امن نظم المعلومات
@tariksotalei4808
@tariksotalei4808 3 жыл бұрын
Brilliant video...simple and practical example ...loved it.
@abhijeetagrawal5817
@abhijeetagrawal5817 2 жыл бұрын
Brilliant.. Thanks a lot for simplifying it.
@markarca6360
@markarca6360 9 жыл бұрын
To check the data integrity of the packets as they are sent means they undergo tests like CRC (cyclic redundacy checking).
@IkramKhan-gk3wl
@IkramKhan-gk3wl 7 жыл бұрын
Dear Sir, you teach very very nice "super nice" than the other
@mitpatel4268
@mitpatel4268 5 жыл бұрын
Hi Keith, I have a short question. Why do we not use SSL universally/predominantly for VPNs but use IPSec? One good reason to use SSL as opposed to IPSec is the popularity of port on which it works (443). The positive is that it's open everywhere! Am I missing something?? Maybe one similar question should be - What prevents us from using SSL instead of IPSEC protocol suite in Site-to-site tunnels?
@AshwinRamdin
@AshwinRamdin 11 жыл бұрын
Hi Keith, At around 3:05 you say the packet is going to be encapsulated. Does this mean that the Packet basically has 2 Destination and 2 Source IP adresses, from which only 1 Destination and 1 Source Address are visable when the packet is send over the Internet?
@kingofhavila9850
@kingofhavila9850 3 жыл бұрын
Your channel enlighten some dark spots i had in networking, I'd like to thank you I have my network security exam at the end of this month. Otherwise, would you tell me what software are you using for the facilitation of the course?
@ketansanil6046
@ketansanil6046 10 жыл бұрын
Great Explanation in Simple Language
@Jdiddy1792
@Jdiddy1792 9 жыл бұрын
How were you able to capture the packets sent from machine to router? Then router to web?
@ryanbarrera2595
@ryanbarrera2595 6 жыл бұрын
Hi Keith..What tool are you using in creating your topology? and also the tool you use to capture the packet
@semitangent
@semitangent 3 жыл бұрын
What I never understood is why a VPN is necessary at all - why not send a regular IP packet with encrypted payload? But I am getting the feeling that this is *exactly* what VPN (or rather IPsec) is doing. It always seemed to me that the encapsulation part, which was always presented as one of the two critical components of a VPN (the other being encryption), was a VPN-exclusive thing, but I guess when two PCs in their respective local networks talk to each other, encapsulation is *always* present - is that correct?
@techtejas804
@techtejas804 3 жыл бұрын
Superb! Got it exact
@Shake_Well_Before_Use
@Shake_Well_Before_Use 7 ай бұрын
Hi Keith, Can u help with something. I have this network that I'm working on packet tracer. I have two sites site A and B. Site A is ASN 10 and B is ASN 20. In the middle is an ISP router on the ASN 50. I use OSPF for the interior routing on my two sites and bgp has been configured successfully on all three routers and I managed to get IP connectivity from hosts on site A to B and vice versa. The thing is when I implemented the IPsec VPN tunnel, the hosts on site A can reach until the router that connects the destination hosts but never reached them. The thing is the pings from a host in A reaches all networks inside site B except the network of the destination host. Like if 192.168.1.0 / 24 is the source network in site A and 192.168.2.0 / 24 is the destination network on B, the hosts on A can reach all networks except the network on which my destination hosts live. Pls help me understand what could have gone wrong
@coveysax
@coveysax 8 жыл бұрын
Subscribed thanks to this video. You sound so happy talking about this lol. Thanks for the vid!
@Rowans9
@Rowans9 2 жыл бұрын
Would IP sec need to be configured both ways?
@ahmedabduljabar6269
@ahmedabduljabar6269 10 жыл бұрын
Keith that was amazing .. many thanks :)
@KeithBarker
@KeithBarker 10 жыл бұрын
Ahmed Abduljabar Thanks for the feedback! It is appreciated. -Keith
@SuperKirkb
@SuperKirkb 10 жыл бұрын
Keith Barker My best instructor
@AliTaj5610
@AliTaj5610 6 жыл бұрын
Excellent teacher!!! Thanks.
@AlexKontent
@AlexKontent 5 жыл бұрын
Great tutorial man! Great work, Great examples!
@IQ88612
@IQ88612 6 жыл бұрын
hi , thanks for your nice video but, software did you use??
@MaHutchy
@MaHutchy 8 жыл бұрын
IPSec or OpenVPN, which would you suggest in terms of security?
@rockinron5113
@rockinron5113 3 ай бұрын
Nice one. Cheers.
@abhyudaychattopadhyay8632
@abhyudaychattopadhyay8632 9 жыл бұрын
So.. the routing table of R1 is supposed to contain the entire range of IPs of PCs under R2, or else how does it understand which of the requests are to be encrypted and sent to R2's IP ???? (and vice versa)
@YosiFeig
@YosiFeig 11 жыл бұрын
Excellent. You did a great job. Simple to understand. Thanks!
@atlantis7896
@atlantis7896 4 жыл бұрын
ipsec uses 2 protocols ESP for encryption and AH for authentication . using sha1 sha2 or md5 and using aes for authentication
@hosseinsabouri3121
@hosseinsabouri3121 4 жыл бұрын
Thanks. But how do you connect two routers with each other? Do you use Public IP addres forwarding to each Router? For Example....How can i RDP from 172.16.0.2 to 192.168.0.20 ?
@viclam1633
@viclam1633 4 жыл бұрын
Does Ipsec add latency to voip calls because it has to encrypt the message? When would I turn on or off ipsec? Any help would be appreciated.
@ericlaforge9445
@ericlaforge9445 2 жыл бұрын
Is the data bridge trottled
@manjunathnarendra3854
@manjunathnarendra3854 8 жыл бұрын
Thank you sir...You know exactly how to teach things..wonderful video
@MrJinsilverx
@MrJinsilverx 11 жыл бұрын
Hi, I just wanna ask. What will happen if I use an access-list with permit ip any any in Ipsec VPN? Will the network be able to browse the internet?
@sobc2737
@sobc2737 3 жыл бұрын
Thank you for such a great explanation.
@AWSwithChetan
@AWSwithChetan 2 жыл бұрын
Great video on VPN tunnels. I was trying to setup S2S VPN in AWS and what I did not understand is role of Inside IPv4 addresses (typically 169.254.0.0/16 range). It would be great if you could help me understand what these inside IPs are, why they are used, are these actual IPs?
@psyedd
@psyedd Жыл бұрын
This is a year late but that looks to be APIPA range. Just google that and I think you'll be good to go
@babouras84
@babouras84 12 жыл бұрын
I don't get it with the source ip adresses. The router would change the source private ip address anyway if it is ipsec or not if it goes through the internet. It also encapsulates the whole packet with HDLC or whatever protocol the router is using to connect to the ISP router. No one could ever see the private ip address even if ipsec is not used. Could you please elaborate on that one?I really don't get it
@metalliciano
@metalliciano 9 жыл бұрын
if I get the videos on your CBT Nuggets, would subtitles in my language?
@alokgupta6152
@alokgupta6152 8 жыл бұрын
Great explanantion. Am new to networks and have a (stupid) question. Doesn't HTTPS communication provide this (Encryption/Security) already ? If so then why do we need a tunnel? why don't we just use SSL protocol for communication.
@andrewk3218
@andrewk3218 8 жыл бұрын
+Alok Gupta If your doing it from your work pc to say VPN to your home pc as you cannot establish a connection from your pc directly that approach would work. If you are however wanting to connection two different offices together the proper way to do it is via a LAN LAN or DMVPN as it gives flexibility that is simply not available if things are being routed via a https connection
@vaihi1
@vaihi1 6 жыл бұрын
Bro I loved this video. Thank you so much haha you have a gift at teaching simply
@newkool100
@newkool100 9 жыл бұрын
thanks. good one. well explained. short and to the point.
@brianhm7706
@brianhm7706 9 жыл бұрын
in order to decrypt the data in the other router, does the other router need to install ipsec too or it will automatically decrypt it?
@ciscojunipergns3760
@ciscojunipergns3760 9 жыл бұрын
both routers need to have same configuration on both sides in order to transmit traffic first part: IKE negotiation 1 second part : ipsec IKE negotiation 2
@brianhm7706
@brianhm7706 9 жыл бұрын
CISCO | JUNIPER | GNS3 okay thanks
@svmayol
@svmayol 11 жыл бұрын
hi sir keith, what is the difference between ipsec and ssl vpn? thanks
@liamhatch3073
@liamhatch3073 6 жыл бұрын
SSL is clientless uses a browser and does not require any network information to create a secure tunnel IPsec is client based and requires networking information (ip addresses) to create a tunnel
@MrGvui
@MrGvui 10 жыл бұрын
Thanks so much, really simple and clear explanation.
@shernaj255
@shernaj255 6 жыл бұрын
what ports? and IPsec uses what kind of routing paths? bgp? and how do they open sessions with eachother? sorry
@kricsek
@kricsek 4 жыл бұрын
What if both PCs had the same IP address like 192.168.1.123 before setting up the VPN? Do the subnets have to be different at each site?
@gambettonsa4528
@gambettonsa4528 4 жыл бұрын
When PC1 pings 192.168.0.20, how does router 1 know that private IP is at site 2 rather than any other company using the same private address for a host? I mean it's on the internet right? it could go anywhere, that has me confused. Can you please explain?
@chechobarbery
@chechobarbery 11 жыл бұрын
Excelente !!!!!!!!!!! Congrats!!!!!!!!!!!
@KeithBarker
@KeithBarker 12 жыл бұрын
CBT Nuggets licenses access to it directly from their web site. Keith
@iMPRE7ed
@iMPRE7ed 11 жыл бұрын
Made it so clear and easy! Great job!
@roseandmose
@roseandmose Жыл бұрын
What this tracer called ?
@ivandrofly
@ivandrofly 10 жыл бұрын
What app you used to trace ping packages:
@rahatpansat3312
@rahatpansat3312 10 жыл бұрын
MS Network Monitor 3.4
@10201578
@10201578 10 жыл бұрын
wireshark
@MrUglyDave
@MrUglyDave 5 жыл бұрын
Thank you so much, so well explained
@virajayachit5702
@virajayachit5702 9 жыл бұрын
Thank you. Awesome work
@davidnadon6879
@davidnadon6879 7 жыл бұрын
viraj ayachit 🎒😈🍯👨‍👦👚👨‍👦‍👦♥️U.K.
@johnconnor9787
@johnconnor9787 6 жыл бұрын
Great explanation! Thank you!!!
@HAPPYSLAPS1
@HAPPYSLAPS1 2 жыл бұрын
Can we use black or dark mode in you videos please instead of bright white backgrounds please???
@SuuhDude-Menace
@SuuhDude-Menace 2 жыл бұрын
Does a vpn tunnel have to go through an isp to even be called a vpn tunnel?
@shai2009
@shai2009 9 жыл бұрын
very professional video. thanks!
@khushitshah2215
@khushitshah2215 5 жыл бұрын
HOW ENCRYPTION DECRYPTION WORKS, WHERE ARE KEYS PRESENT?
@ksbpsb
@ksbpsb 12 жыл бұрын
right on one can see your private ip address and what about your data is your data is secure on the network ipsec does it for vpn
@fightbackmatix
@fightbackmatix 11 жыл бұрын
Great video :) Thanks again!
@kracherjon3938
@kracherjon3938 3 жыл бұрын
Danke Bre
@zehle
@zehle 11 жыл бұрын
This was great! :D
@happyshay1977
@happyshay1977 4 жыл бұрын
Great facilitated! thanks
@cbtnuggets
@cbtnuggets 4 жыл бұрын
Glad it helped!
@haimbendanan
@haimbendanan 9 жыл бұрын
Thank for this video!
@avinashshankarpalli2130
@avinashshankarpalli2130 8 жыл бұрын
What happens if the customer using the same address range as ours at pc1 and pc2?I mean the private address range
@TehDraconas
@TehDraconas 8 жыл бұрын
You have to NAT the traffic or change one of the subnets. Having identical ranges on both ends is a bad idea.
@vincentmuyo
@vincentmuyo 8 жыл бұрын
There may be address conflicts if two different machines use the same IP. So you NAT or change the private network. If you want, you can have different subnets sharing address parts and supernet the two different private networks, like 192.168.0.0/24 and 192.168.1.0/24 being supernetted into one 192.168.0.0/16 net.
IP Sec VPN Fundamentals
14:55
LearnCantrill
Рет қаралды 193 М.
MicroNugget: What is Multi-Protocol Label Switching (MPLS)?
6:58
CBT Nuggets
Рет қаралды 164 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН
The evil clown plays a prank on the angel
00:39
超人夫妇
Рет қаралды 53 МЛН
Understanding AH vs ESP and ISKAKMP vs IPSec in VPN tunnels
18:30
Ryan Lindfield
Рет қаралды 316 М.
MicroNugget: BGP Configuration Explained | CBT Nuggets
7:19
CBT Nuggets
Рет қаралды 190 М.
What is IPSec?
9:44
Palo Alto Networks LIVEcommunity
Рет қаралды 176 М.
Cisco CCNA | Career Advice | How to Get Started in Networking
26:44
VPN Types Options and Protocols Explained
10:24
CBT Nuggets
Рет қаралды 28 М.
Fortinet: IPsec Site-to-Site VPN Setup on FortiGate Firewall
5:00
ToThePoint Fortinet
Рет қаралды 88 М.
IPSec Site to Site VPN tunnels
18:44
Keith Barker - The OG of IT
Рет қаралды 497 М.
IPsec  - IKE Phase 1 | IKE Phase 2
13:47
Networking Newbies
Рет қаралды 91 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН