IP Sec VPN provides a Private and Secure IP communication over a Public Network Infrastructure. With this technology, different sites or users in different geographical areas can communicate over a network and this provides a very good resource utilization. Here, we will learn tjheorical parts of IP Sec, you can check IP Sec configuration lesson also to learn how to configure IPSec on Huawei Routers.
IP Sec provide data confidentiality and integrity with its Security mechanisms.What are these mechanisms? Mainly these security mechanism are :
- Authentication
- Integrity Check
- Encryption
If you would like to view all HCIA Lessons, you can check HCIA Training Page.
IPSec Protocols
There are two main IP Sec Protocols. These protocols are :- AH (Authentication Header)
- ESP (Encapsulation Security Protocol)
- MD5
- SHA-1
- SHA-2

- DES
- 3DES
- AES


Transport Mode and Tunnel Mode
Both ESP and AH can work in two different modes. These Modes are “Transport Mode” and “Tunnel Mode”. In Trasport Mode, original IP packet is used with ESP and AH Headers and then, the original IP Header is reused in front of the ESP and AH Headers.

Security Associations (SA)
To use IPSec between different nodes, some of the certain parameters must be negotiated between these two nodes. This negotiation is about how to use IPSec security services. Security Associations are the policies that provide this negotiations. Each device has a Security Policy Database (SPD) and a local database, that is called SA Database (SADB). SPD stores the policies that is related to the whole IP traffic. It defines which Sas will be used on the IP traffic. Each device has its own Security Policy Database (SPD). SADB is the Security Association Table. This table contains the parameters related with Security Associations. Every device has its own SA Database (SADB). Each Security Association (SA) is unidirectional. It defines the IPSec parameters in only one direction. So, we need at least two Security Associations (SAs) for IP Sec communciation. Every Security Association(SA) has a 32 bit unique SPI (Security Parameter Index). SPI allows the destination to select the correct Security Association (SA). What information a Security Association (SA) keep? Here is a list:- Source IP
- Destination IP
- IPSec Protocols
- Encryption Algorithm
- Authentication Algorithm
- Tunel/Tranport Mode
- SPI
- Key Lifetime
Let’s check SPD and SADB for both Transport and Tunnel Modes.
Below, you can find the SPD and SADB tables of both end devices for Transport Mode.

Again, you can find the Tunnel Mode SPD and SADB tables of both end devices below.



IPSec VPN Types
There different types of IPSec VPNs. These are :- Site-to-Site VPN
- Hub-and-Spoke VPN
- Remote Access VPN
Site-to-Site VPN is a VPN type that securely connects two different sites of a company.
Hub-and-Spoke VPN is a VPN type that securely connects different branch offices of a company to the main office. Hub is the central office and spokes are the branches.
Remote Access VPN is a VPN type that provide access to the company network remotely. This is used by remote users and on site workers. They connect to the corporate network via such VPN.
[sc name=”ContentRMessage”]