Understanding AH vs ESP and ISKAKMP vs IPSec in VPN tunnels

Поделиться
HTML-код
  • Опубликовано: 15 окт 2024
  • This is a sniplet from the Cisco SIMOS course, where we discuss the logical constructs behind a site-to-site IPSec VPN. I hope that this content helps you understand what's happening behind the scenes of your VPN's.

Комментарии • 269

  • @K2dawilla
    @K2dawilla 7 месяцев назад +5

    9 years later and still this is gold. The underlying principles never change that fast. It is the decor on top! Thanks so much Ryan.

  • @brandonunger1689
    @brandonunger1689 7 месяцев назад +1

    Amazing refreshing of IPSec IKEv1 and Phase 1, Phase 2, and breakdowns of what is going on. Truly a masterful teaching lesson. Thank you.

  • @ankitwadhwa89
    @ankitwadhwa89 7 лет назад +44

    When you say " How you guys doing so far" . It really feels like we are in class.
    Keep up good work.

    • @andaluspc
      @andaluspc 5 лет назад +1

      He was already in a class by the way :)

  • @zhangstones
    @zhangstones 8 лет назад +101

    This is the most clearly clips i've ever seen to introduce IPSec, plain to text. Thank you.

    • @RyanLindfield
      @RyanLindfield  8 лет назад +4

      +张磊 Thank for your kind words, I hope it helps.

  • @darylallen2485
    @darylallen2485 4 года назад +2

    I have literally been coming back to this video every 6 months for about 2-3 years. Every time i watch it again, I feel I have learned something I didn't pick up on the previous viewings. I found myself yelling "ip" at the screen for 13:34. Its never been more clear to me.

    • @RyanLindfield
      @RyanLindfield  4 года назад

      I think learning happens in layers, as the concepts go by we only capture so much of it. Glad that you've found it useful.
      Glad to hear I'm not the only one talking to the computer screen and an empty room :)

  • @rutwijkulkarni443
    @rutwijkulkarni443 7 лет назад +8

    Explanation is extremely in a simple jargon, sometimes the books don't help you but at the same time we have people like you. You nailed it . Thanks

  • @swajalsarkar6122
    @swajalsarkar6122 4 года назад +1

    This video cleared my basic concept of IPSec, as I was previously thinking IPSec is a tunnel inside a tunnel of ISAKMP/IKE.

    • @RyanLindfield
      @RyanLindfield  4 года назад

      Awesome, I'm glad that helped :)
      You may already be familiar, but there are some neat reasons to put a tunnel in a tunnel. GRE inside of IPSec for example. It let's you take traffic that IPSec doesn't support (anything other than unicast IP) and do what you like with it.
      Protocols that would normally not leave a broadcast domain (ARP, LLMNR, STP, CDP, IGP's etc) can be collected and passed anywhere then dropped off anywhere you like, any number of hops, networks, devices, and they come off the other side like nothing happened.

    • @swajalsarkar6122
      @swajalsarkar6122 4 года назад

      @@RyanLindfield Thank you 🙂

  • @ClovisdeCruz
    @ClovisdeCruz 7 лет назад +28

    It takes a lifetime to understand IPSec... this helps.

  • @stevanwpierce
    @stevanwpierce 9 лет назад +21

    This is by far the best tutorial I've seen to date on explaining AH v. EDP and ISAKMP in IPSec tunnels. Your whiteboard examples leave nothing to question or wonder about. Combine this with a Cisco LAN to LAN VPN config guide for ASA or router and you have a winning combination. Thanks!

  • @scott2495
    @scott2495 4 года назад +6

    This guy is so clear and understandable when it comes to explaining/teaching. His knowledge is so impressive

  • @daniel.m2808
    @daniel.m2808 3 года назад +1

    The best explanation detail oriented. Thank you

  • @venkcut
    @venkcut 2 года назад

    8 years and still this the best explanation ever for ISAKMP/IPsec

  • @user-vv9fw7ok9d
    @user-vv9fw7ok9d 3 года назад +10

    I wish every professor could explain this stuff like you do.

  • @kubic22562
    @kubic22562 3 года назад +1

    Whoa, that was what I was looking for! No bullshiting about VPN providers but rather providing actuall knowledge :D

  • @anthonymoscon18
    @anthonymoscon18 6 лет назад +3

    Probably the best overall demonstrator out there, you offer a very visual approach that is made easy to comprehend.

  • @mikespilligan7840
    @mikespilligan7840 Год назад +1

    Absolutely superb thank you loads a true expert makes the difficult, easy (relatively) to understand.

  • @katakberjarisepuluh5949
    @katakberjarisepuluh5949 3 года назад +1

    after study ipsec for a couple hour, and now I understand in a minutes. Thanks man.

  • @vishwaskaupvijayananda3900
    @vishwaskaupvijayananda3900 4 года назад +1

    The best explanation of AH, ESP, IPSec, ISAKMP and how VPN works.

  • @christophergriffin4330
    @christophergriffin4330 2 года назад

    OMG. Ryan has updated my resume with a new skill in less than 20 minutes. What took me so long to find this video. Top Notch lesson! Thank you.

  • @noone019
    @noone019 4 года назад +1

    You explained this 50x clearer and better than my uni professor ever could.
    Thanks so much, keep up the great work!

    • @RyanLindfield
      @RyanLindfield  4 года назад

      Awesome to hear, I 'm glad that it was helpful :)

  • @alexandermarohnic7563
    @alexandermarohnic7563 10 месяцев назад

    Just found this after trying to understand it by reading multiple online sources and the SVPN official cert guide material. Thanks, Ryan. Your videos are awesome.

  • @joelvictores3540
    @joelvictores3540 4 года назад +1

    Excellent video. The best explanation I have ever seen for this topic. Technical and at the same time simple. Kuddos!!

    • @RyanLindfield
      @RyanLindfield  4 года назад

      Glad it was helpful!

    • @hurricaneharveyh7848
      @hurricaneharveyh7848 4 года назад

      @@RyanLindfield what are the biggest things that have happened over the past 6 years in this space?

  • @Julio2Tube
    @Julio2Tube Год назад +1

    Great video. One thing to mention is that both ESP and AH have protocol numbers. 50 and 51, respectively.

  • @faaez27
    @faaez27 7 лет назад +3

    This is the best explanation to IPsec tunnels I have seen so far. It covers all the key points to give an idea on how IPsec works. Thank you.

  • @jakebenstade
    @jakebenstade 2 года назад

    one of the great way to explain the things, love the way he explain the concept.

  • @muneer84
    @muneer84 4 года назад +1

    Tx for this ...Studying for my CISSP ...This clarifies my doubts

    • @RyanLindfield
      @RyanLindfield  4 года назад +1

      Great certification to go after, enjoy the journey :)

  • @jonmcfarland3832
    @jonmcfarland3832 Год назад +1

    great explanation, easy to understand since you explain it well.

    • @RyanLindfield
      @RyanLindfield  Год назад

      Delighted to hear you found it helpful, thanks a lot for letting me know!

  • @rickysandhu3916
    @rickysandhu3916 4 года назад +1

    I have to say this video is what finally nailed it for me! I've been trying to dive deep into the inner workings of IPSec for weeks and more I studied more I got confused. But this video finally cleared it all up! Thank You @RyanLindfield!

    • @RyanLindfield
      @RyanLindfield  4 года назад +1

      I think part of the learning process is hearing it explained multiple times by different people, then finally p00f you own it :) Happy that helped!
      IPSec should serve you well for many years to come!

  • @Vrikancs
    @Vrikancs 9 лет назад +4

    Dude, you're awesome! I tried to study IPsec several times and never managed to understand it so far but this vid just opened my eyes so I wanted to say: Thank you!
    Great work :)

  • @dineshkumar-qv4df
    @dineshkumar-qv4df 3 года назад +1

    Awesome content thanks Ryan for your wonderful video.

  • @diyegr
    @diyegr 8 лет назад

    This is the clearest, most concise explanation of VPN tunnel establishment I've ever seen. Thank you!

  • @pakutharivalar
    @pakutharivalar 5 лет назад +1

    Ryan, this video is the best one out there in youtube explaining site-to-site VPN's IPSec phases.
    Feel free to do DMPVN phases as well.
    Thanks a lot Ryan Lindfield

  • @biteme949
    @biteme949 4 года назад +1

    Excellent intro! Very helpful for an Application Solution Architect who is working with his Infrastructure colleagues to allow remote access via IPSec VPN tunnels to understand what this is all about :-)

  • @mihirpatel197
    @mihirpatel197 3 года назад +1

    Thank you so much for your video, this helped me clear up most of my IPSEC VPN concept....

    • @RyanLindfield
      @RyanLindfield  3 года назад

      Hi Mihir, I'm happy that you found my tutorial!

  • @darion2272
    @darion2272 5 лет назад +1

    Same as many, this is the clearest explanation I've seen on this topic. Excellent work

  • @darkcatapulter
    @darkcatapulter 4 года назад +2

    This was such an amazing explanation! I thought I understood Phase1 but not Phase2, but it seems like I actually had understood it wrong all together. Seeing the two different uses and purposes of the ISAKMP SA contrary to the IPsec SA (or Crypto SA) has cleared my mind.

    • @roytmanpiccoli
      @roytmanpiccoli 2 года назад

      First Phase1 is Policy Set exchange, Phase2 is How will be used Security Transfer data between them.

  • @christoal6125
    @christoal6125 6 лет назад +1

    Best video I've seen on site to site VPN. So easy to understand. Please keep up good work m8

  • @aminabensalem5202
    @aminabensalem5202 4 года назад

    Words don't do this extraordinary work justice! I knew I found the right video when he explained AH vs ESP at 4:18 . Thank you for this.

    • @RyanLindfield
      @RyanLindfield  4 года назад +1

      Really happy it was useful, enjoy the journey :)

  • @ankitkhandelwal9273
    @ankitkhandelwal9273 5 лет назад +1

    very well explained the most sorted explanation . thumbs Up Ryann ,, hats off to u .

  • @pqr2726
    @pqr2726 5 лет назад +2

    If I can begin to understand IPsec, IKE SAs, etc after this video then anyone can. I'd give him an Oscar if I could.

  • @marcinwee5278
    @marcinwee5278 Год назад

    I truly regret Ryan stopped adding videos , one of the best networking lecturer , this lesson here , best explanation of differences between ESP and AH , take care Ryan

    • @RyanLindfield
      @RyanLindfield  Год назад

      Thanks so much for your kind words, I'm glad you found the video helpful, it's a tricky thing to explain with words alone..
      I promise to release more content in 2023 :).

  • @NetworkBook6
    @NetworkBook6 4 года назад +1

    This is the best ipsec tutorial which i have seen in my lifetime .. wonderful work .. cheers !

    • @RyanLindfield
      @RyanLindfield  4 года назад

      Really kind of you to say, thanks Azhar!

  • @aminegh8725
    @aminegh8725 4 месяца назад

    Best teacher giving the why of concepts , thank you very much.

    • @RyanLindfield
      @RyanLindfield  4 месяца назад

      You're too generous, thanks for the kind words!

  • @nonsochinonso864
    @nonsochinonso864 6 лет назад +1

    One of the best clips on youtube on how VPN tunnels work.

  • @al-kurdiahmed8081
    @al-kurdiahmed8081 6 лет назад

    Ryan i would like to thank you for this awesome explanation. its a crystal clear . the only part missing is the practical side. thanks again

  • @g_pazzini
    @g_pazzini 8 лет назад +2

    A very good explanation on how the ipsec vpn connection established... Phase by phase.. Thanks a lot!

  • @maheshmuttath534
    @maheshmuttath534 4 года назад +1

    Woawww. Crystal Clear about the topic ... What a presentation!!! . We feel as if we are in the class . Subscribed for all Videos .

  • @brianh2447
    @brianh2447 7 лет назад +1

    I'm fairly new to networking and I've been struggling with learning the concepts between IPSec for a bit. You just cleared everything up! thanks

  • @marrywhowanna
    @marrywhowanna 7 лет назад +1

    By far the best IPSec explanation. Thanks!

  • @TheAnkurj
    @TheAnkurj 8 лет назад +2

    Yes, this is easily the best explanation of IPSec so far.

  • @hottroddinn
    @hottroddinn 9 лет назад +1

    Comprehensive information in 18:29 minutes told in a simple manner. Thanks for the great video!

  • @ml20101993
    @ml20101993 8 лет назад +2

    Smooth, clear and concise !
    Thanks for the video Ryan

  • @piotrjasinski
    @piotrjasinski 9 лет назад +1

    I'm preparing for 300-101. I was looking for a quick repeat of ipsec. Well explained. Thanks.

  • @Telancer
    @Telancer 4 года назад +2

    I would agree with the comments below great refresher for myself and great explanation.
    Thanks

  • @sa3657
    @sa3657 6 лет назад +1

    Really a very usefull to understand the basic IPSEC parameter ...excellent explained

  • @charleszuo2946
    @charleszuo2946 6 лет назад +1

    This is the best video I've watched that goes into detail regarding the IPsec process, and I've used other resources like INE Udemy, and CIsco library. Thank you

  • @kishor.rautela
    @kishor.rautela 4 года назад +1

    Thanks Ryan, the video is so understandable. I am looking for the answer of one question, during this process when it use UDP 500 and when it is use UDP 4500 ? . I mean the difference between 500 and 4500 in prospective of tunnel formation. Once again thanks.

    • @RyanLindfield
      @RyanLindfield  4 года назад

      You'll use UDP 500 always because that's how you agree upon how to do crypto (build your IPSec SA's ).
      Once IPSec SA's are built ESP is used at layer 4.
      If your VPN is across a firewall that uses PAT, ESP has no port numbers. So, unless your firewall can PAT ESP (Cisco firewall will if you ask it nicely) you'll drop those messages. It can be frustrating because the VPN client says connected but you'll see packets sent but non received.
      To get them to pass through the firewall you can "wrap" them in UDP and pass that over 4500, this is known as NAT-Traversal (NAT-T)

    • @kishor.rautela
      @kishor.rautela 4 года назад

      @@RyanLindfield You are awesome.....thankyou so much.

  • @newkool100
    @newkool100 9 лет назад +1

    Thanks a lot, one of the best videos for IPSec. Short and to the point.

  • @hdhillon774
    @hdhillon774 2 года назад

    amazing, thanks for explaining this topic in most simplistic way possible......

  • @asahelsanchez3928
    @asahelsanchez3928 9 лет назад +1

    So far the best explanation i have ever seeing!!! Great

    • @RyanLindfield
      @RyanLindfield  9 лет назад

      Asahel Sanchez Very kind of you thanks!

  • @CiscoFernandez
    @CiscoFernandez 8 лет назад +1

    This is an excellent quality tutorial. Your teaching style is very effective. Thanks for posting this.

  • @JonathanAnon
    @JonathanAnon 6 лет назад +2

    You are a really good teacher. Well done.

  • @MissLOHMORE
    @MissLOHMORE 5 лет назад +1

    this is very helpful, thank you! Clearly defines difference between ESP and AH for me!

  • @gajendrabora130
    @gajendrabora130 7 лет назад

    Ryan Lindfield, you are a rock star. Great tutorial

  • @daviddunn5877
    @daviddunn5877 9 лет назад +1

    Very helpful. Most interesting 20 mins I've had today. Thanks for doing this video.

  • @ahmetgazi3896
    @ahmetgazi3896 2 года назад

    Best IPSEC tutorial I have seen.

  • @deathByStupid
    @deathByStupid Год назад +1

    I usually watch these at 1.5 times, happy to say it's one of the first videos that made me do a spit take and slow it down to 1.0 times haha. Good content.

  • @eddieotero77
    @eddieotero77 5 лет назад +1

    Thanks for this Ryan. Really helping me along with my CCNA Security studies. You're an awesome instructor.

  • @KishoreDasLearner
    @KishoreDasLearner 9 лет назад +1

    Liked the video... very compact with all required information. Thanks for sharing.

  • @caleb_gonsalves
    @caleb_gonsalves 3 года назад

    I keep coming back for this video, better explanation on the Internet!

  • @abdeljaouadouahid4235
    @abdeljaouadouahid4235 4 года назад +1

    this is a very cool video that explains clearly IPSec, Thank you

  • @azatkhan4714
    @azatkhan4714 3 года назад +1

    Thanks for your time.

  • @rbora7671
    @rbora7671 4 года назад +1

    seen a very good explanation in a long time.

  • @wowsankar
    @wowsankar 8 лет назад +1

    Thank you Ryan!! An awesome video and its very crisp to the point on IPSec.

  • @michaeldawson6309
    @michaeldawson6309 3 года назад

    I had a problem pinging site to site this week over an IPSEC that was up but not passing my traffic. I learned through testing that the IPSEC Phase 2 did not identify the networks I was trying to ping. Hence my traffic was not allowed to use the IPSEC tunnel even though the route in the routing table showed the destination via the IPSEC. So once I added the source + destination and crypto into my Phase 2 configs for these networks i wanted to reach bingo it all started working. BTW this was between a Meraki - Fortigate device using IKEv2
    Hope this helps :-)

  • @alozborne
    @alozborne 8 лет назад

    Thanks for such a clear and concise explanation! Going to be watching more of your videos soon, as you clearly are a subject matter expert.

  • @SnehalChorge
    @SnehalChorge 4 года назад

    Finally, I found the best IPsec VPN video! Very helpful! Thank you.

  • @Daniel_CLopes
    @Daniel_CLopes 5 лет назад

    My God! Never thought I would see such a great explanation of IPSec!

    • @RyanLindfield
      @RyanLindfield  5 лет назад

      Really kind of you thanks Daniel, glad to hear it was useful :)

  • @kreep182
    @kreep182 5 лет назад

    this video is absolutely perfect for what I am trying to study right now. could you please do a similar video about ipsec in transport mode, and how routing works after the client establishes thw ipsec tunnel with the server? I cannot seem to find this anywhere. Thank you

  • @sudiptakp
    @sudiptakp 7 лет назад +1

    Excellent!! very nicely put through.

  • @contactsahan
    @contactsahan 9 лет назад +3

    Wow..... Awesome..... You helped me brush up my VPN knowledge in 19Mins......!!!!!

    • @RyanLindfield
      @RyanLindfield  9 лет назад

      sahan marapana Glad it helped thanks for watching :)

  • @VijayaBaskarvvk
    @VijayaBaskarvvk 4 года назад

    Just one word.. "Excellent.." Could you explain what is exactly happening if use ipv6 address for the same scenario.. how AH, ESP extension header is used..

  • @romesan2011
    @romesan2011 9 лет назад +1

    Very lucid and precise -Thank You

  • @joe1z392
    @joe1z392 7 лет назад +1

    really good video. clear my confusions my understanding about IKE1 and 2. Thank you!

  • @bikerbob182
    @bikerbob182 5 лет назад +1

    Great video. Seriously, thanks.

  • @Jay-jr1fx
    @Jay-jr1fx 4 года назад +1

    Very well explained! I just new IPsec now. haha

  • @cwlancaster979
    @cwlancaster979 8 лет назад +1

    Thanks for this explanation! Very helpful video and commentary! :)

  • @tanmoymallick8244
    @tanmoymallick8244 4 года назад

    Hi Rayan, this is clear understanding.. Thanks.. Could you please share the next vedio..

  • @jacoba8851
    @jacoba8851 7 лет назад +1

    Ryan Lindfield I finally fully understand IPsec. Thank you! Please make more videos. Do you have any other paid or free video courses/resources other than RUclips?

    • @RyanLindfield
      @RyanLindfield  7 лет назад +1

      I work full time for Stormwind Studios, but I'll definitely release more content to youtube, very glad you found it useful, thanks for watching!

  • @xdx8457
    @xdx8457 8 лет назад +1

    Thank you so much for this great IPSec video!

  • @max200970
    @max200970 9 лет назад +1

    Its was an awesome explanation ... cleared several doubts .Thank You

  • @Foodieninja
    @Foodieninja 7 лет назад

    Great video man helped with my recap. However, there was no mention of the two types of modes that phase 1 can do? (Main more or aggressive mode) is there a reason for this?

  • @gabirican4813
    @gabirican4813 4 года назад +1

    Great presentation, thank you.

    • @RyanLindfield
      @RyanLindfield  4 года назад

      Thanks Gabi, glad to see you've got the enthusiasm to spend your Saturday learning the guts of crypto! Enjoy the journey :)

    • @gabirican4813
      @gabirican4813 4 года назад

      @@RyanLindfield Thank you, and I wish you all the best as well! 😊

  • @Daniel_CLopes
    @Daniel_CLopes 5 лет назад +1

    Hi Ryan, congratulations for this AMAZING video. I have one question, though:
    In a network with a DMZ, what would be the best location for a VPN concentrator, and why?
    Thank you in advance

    • @RyanLindfield
      @RyanLindfield  5 лет назад +1

      Regarding VPN concentor placement, easy answer and typical answer which is , "It Depends" :)
      What's in the DMZ, who's accessing it, what are your business needs etc.
      Imagine my DMZ is in a colocation with redundant heating/cooling /power / security, and this hosts customer facing apps, but in the office we have resources used by my employees in the office or remote. Printers (paper & 3D), conferencing equipment, cameras, maybe even robotics and lab gear. I may place the VPN at HQ so employees can work remote and interact with people in the office. This is especially true if you're using on-prem collaboration platform.
      You may have a high speed interconnect between the data center & HQ, then it comes down to what apps are hosted where, and security model. If you may have filtering appliances that you want to pass traffic through, that may be in one location or another.. It really depends how you want to pass / isolate traffic which will be unique based on customer.

    • @Daniel_CLopes
      @Daniel_CLopes 5 лет назад +1

      @@RyanLindfield Thank you Ryan! Thank you for dedicating a bit of your time to answer my question! You were the only one who was able to answer it for me.

  • @GamjaField
    @GamjaField 5 лет назад

    Great explanation on IPsec. But 1:56 and 4:39 can you elaborate??

    • @GamjaField
      @GamjaField 5 лет назад +1

      Just finished watching the video, now I understand. Thank you sir :)

  • @ashutoshchauhan1824
    @ashutoshchauhan1824 4 года назад

    Wow. I had been seeking for this kind of instructor for almost 9 years for Security related stuffs. I had a good instructor for the network but for security i never had one.

  • @h22charles
    @h22charles 9 лет назад +1

    Very good teaching technique.

  • @twdk01
    @twdk01 8 лет назад +2

    Brilliantly explained; keep up the good work!

  • @JigarShah8568
    @JigarShah8568 7 лет назад +1

    Brilliant!! Short and Simple

  • @giulioambrogi5413
    @giulioambrogi5413 9 лет назад

    Great video and great teaching skills!
    I'm studying ESP, AH and IKEv2 from RFCs but I have some doubts:
    1) If an IPsec system is behind a NAT, in Tunnel Mode, is UDP necessary because there is no Port-Number in the ESP (or AH) header ?
    2) About IP fragmentation, in Transport Mode the RFC says "AH/ESP must be applied only to whole IP datagram" and in Tunnel Mode it says "AH/ESP can be applied to packets that can be fragment [...]". Can you explain why ?
    Thank you,
    Giulio

    • @devashishsingh1
      @devashishsingh1 9 лет назад

      +Giulio Ambrogi Correct UDP 4500 hundred is required to be filled in along with new IP header, however it would only be done in case the NAT device is doing PAT and not one to one.