1
1

00:00:00,280  -->  00:00:03,150
<v ->Virtual private networks or VPNs.</v>
2

2

00:00:03,150  -->  00:00:04,010
In this lesson,
3

3

00:00:04,010  -->  00:00:06,070
we're going to dive deeper into VPNs
4

4

00:00:06,070  -->  00:00:08,070
known as virtual private networks.
5

5

00:00:08,070  -->  00:00:09,580
And we're going to cover all the things you need to know
6

6

00:00:09,580  -->  00:00:11,820
about a VPN for your exam.
7

7

00:00:11,820  -->  00:00:14,100
First, what is a VPN?
8

8

00:00:14,100  -->  00:00:16,460
Well, a VPN is a virtual private network,
9

9

00:00:16,460  -->  00:00:18,700
and it's going to be used to extend a private network
10

10

00:00:18,700  -->  00:00:20,020
across a public network
11

11

00:00:20,020  -->  00:00:22,000
and enable users to send and receive data
12

12

00:00:22,000  -->  00:00:24,060
across that shared or public network
13

13

00:00:24,060  -->  00:00:26,610
as if their computing devices were directly connected
14

14

00:00:26,610  -->  00:00:28,100
to the private network.
15

15

00:00:28,100  -->  00:00:29,340
Now with a VPN,
16

16

00:00:29,340  -->  00:00:31,544
your users can work in a remote office or work from home
17

17

00:00:31,544  -->  00:00:33,520
and they can telecommute
18

18

00:00:33,520  -->  00:00:36,110
simply by logging into their laptop and establishing
19

19

00:00:36,110  -->  00:00:39,310
a secure VPN tunnel to the organization's network,
20

20

00:00:39,310  -->  00:00:41,710
regardless of where it sits in the world.
21

21

00:00:41,710  -->  00:00:42,543
To do this,
22

22

00:00:42,543  -->  00:00:44,130
they're going to connect to a VPN device
23

23

00:00:44,130  -->  00:00:45,880
sitting at the headquarters data center,
24

24

00:00:45,880  -->  00:00:48,210
and then they're going to establish a secure tunnel
25

25

00:00:48,210  -->  00:00:51,460
using a VPN protocol in order to allow a secure connection
26

26

00:00:51,460  -->  00:00:54,980
for that corporate user over an untrusted or public network,
27

27

00:00:54,980  -->  00:00:56,590
something like the internet.
28

28

00:00:56,590  -->  00:00:58,160
Now, this allows them to then reach
29

29

00:00:58,160  -->  00:00:59,410
into the corporate network
30

30

00:00:59,410  -->  00:01:00,990
and be connected to the internet
31

31

00:01:00,990  -->  00:01:04,751
as if they were sitting right at their desk in their office.
32

32

00:01:04,751  -->  00:01:07,040
VPNs can be configured as a site to site VPN,
33

33

00:01:07,040  -->  00:01:08,250
a client to site VPN,
34

34

00:01:08,250  -->  00:01:09,920
or a clientless VPN.
35

35

00:01:09,920  -->  00:01:11,370
With a site to site VPN,
36

36

00:01:11,370  -->  00:01:13,340
we can connect two offices together.
37

37

00:01:13,340  -->  00:01:14,890
With a client to site VPN,
38

38

00:01:14,890  -->  00:01:17,330
we're more concerned with connecting a single remote user
39

39

00:01:17,330  -->  00:01:19,810
back to a corporate network as I described earlier
40

40

00:01:19,810  -->  00:01:21,570
with the user who needed to telecommute.
41

41

00:01:21,570  -->  00:01:23,350
When we talk about a clientless VPN,
42

42

00:01:23,350  -->  00:01:25,940
these are usually going to be used with web browsing.
43

43

00:01:25,940  -->  00:01:27,650
All right. Let's dive a little bit deeper
44

44

00:01:27,650  -->  00:01:30,030
and talk about a site to site VPN.
45

45

00:01:30,030  -->  00:01:33,200
Now, a site to site VPN is used to interconnect to sites
46

46

00:01:33,200  -->  00:01:34,880
and provide an inexpensive alternative
47

47

00:01:34,880  -->  00:01:36,600
to dedicated lease lines.
48

48

00:01:36,600  -->  00:01:37,470
For example,
49

49

00:01:37,470  -->  00:01:39,700
let's pretend I have a branch office in California
50

50

00:01:39,700  -->  00:01:42,220
and my headquarters is in Washington DC.
51

51

00:01:42,220  -->  00:01:43,310
Now, if I want to be able to connect
52

52

00:01:43,310  -->  00:01:45,240
my remote regional office in California,
53

53

00:01:45,240  -->  00:01:47,600
to my headquarters office in Washington DC,
54

54

00:01:47,600  -->  00:01:49,340
I could buy a dedicated lease line
55

55

00:01:49,340  -->  00:01:51,020
from a telecommunications provider
56

56

00:01:51,020  -->  00:01:52,630
and they would give me a direct connection
57

57

00:01:52,630  -->  00:01:55,120
that covers over 3000 miles in distance
58

58

00:01:55,120  -->  00:01:56,690
between these two sites.
59

59

00:01:56,690  -->  00:01:59,050
Even if I got a low speed T1 connection,
60

60

00:01:59,050  -->  00:02:01,110
this would be very expensive.
61

61

00:02:01,110  -->  00:02:02,270
Now, on the other hand,
62

62

00:02:02,270  -->  00:02:04,620
I could use a site to site VPN and I can save
63

63

00:02:04,620  -->  00:02:05,730
a lot of money.
64

64

00:02:05,730  -->  00:02:07,640
Instead of using that dedicated lease line,
65

65

00:02:07,640  -->  00:02:10,860
I could simply create a VPN tunnel from the regional office
66

66

00:02:10,860  -->  00:02:13,290
back to the headquarters over the public internet,
67

67

00:02:13,290  -->  00:02:14,840
using the internet connectivity
68

68

00:02:14,840  -->  00:02:16,610
that's already in that office.
69

69

00:02:16,610  -->  00:02:19,510
This solution might cost me 50 or $100 per month
70

70

00:02:19,510  -->  00:02:21,990
for a standard cable modem or a fiber modem service
71

71

00:02:21,990  -->  00:02:23,620
from the local ISP.
72

72

00:02:23,620  -->  00:02:25,460
Once that VPN tunnel is established,
73

73

00:02:25,460  -->  00:02:26,630
it's going to take all the traffic
74

74

00:02:26,630  -->  00:02:28,210
from the regional office in California
75

75

00:02:28,210  -->  00:02:31,060
and run it back to the headquarters in Washington DC,
76

76

00:02:31,060  -->  00:02:33,430
over the internet within this secure tunnel.
77

77

00:02:33,430  -->  00:02:35,880
And then, once it gets to Washington DC,
78

78

00:02:35,880  -->  00:02:37,830
it's going to be decrypted and put back
79

79

00:02:37,830  -->  00:02:39,980
inside of my corporate network.
80

80

00:02:39,980  -->  00:02:41,410
Now, when a California user
81

81

00:02:41,410  -->  00:02:43,380
wants to go to Google.com, for instance,
82

82

00:02:43,380  -->  00:02:46,820
that data is going to go from California to Washington DC,
83

83

00:02:46,820  -->  00:02:49,430
out the Washington DC's office internet connection
84

84

00:02:49,430  -->  00:02:50,820
to visit that website,
85

85

00:02:50,820  -->  00:02:51,980
get the information,
86

86

00:02:51,980  -->  00:02:52,813
send it back
87

87

00:02:52,813  -->  00:02:55,010
to the Washington DC's office internet connection,
88

88

00:02:55,010  -->  00:02:58,220
and then back through the VPN to that California user,
89

89

00:02:58,220  -->  00:03:00,740
where they'll be able to view the website they requested.
90

90

00:03:00,740  -->  00:03:02,680
By using this site to site VPN,
91

91

00:03:02,680  -->  00:03:04,410
all the traffic that goes back and forth
92

92

00:03:04,410  -->  00:03:06,180
between California and Washington,
93

93

00:03:06,180  -->  00:03:08,130
is going to be encrypted and secure.
94

94

00:03:08,130  -->  00:03:10,420
So no one can see the internal network traffic
95

95

00:03:10,420  -->  00:03:11,253
that's going
96

96

00:03:11,253  -->  00:03:13,990
through this external public internet connection.
97

97

00:03:13,990  -->  00:03:16,140
Now, when we deal with a client to site VPN
98

98

00:03:16,140  -->  00:03:17,040
on the other hand,
99

99

00:03:17,040  -->  00:03:19,160
we're going to be seeing data from a single host,
100

100

00:03:19,160  -->  00:03:21,840
like a laptop or cell phone or smartphone or tablet,
101

101

00:03:21,840  -->  00:03:24,340
and connecting it back to our headquarters office.
102

102

00:03:24,340  -->  00:03:26,170
This is going to be done instead of going
103

103

00:03:26,170  -->  00:03:27,430
from router to router,
104

104

00:03:27,430  -->  00:03:29,470
we're going from client to router.
105

105

00:03:29,470  -->  00:03:31,410
This allows a remote user to be able to connect
106

106

00:03:31,410  -->  00:03:32,600
back to the head office.
107

107

00:03:32,600  -->  00:03:34,980
And that's why we call it a client to site.
108

108

00:03:34,980  -->  00:03:38,040
Now, in addition to site to site and client to site VPNs,
109

109

00:03:38,040  -->  00:03:39,440
we also have to decide whether or not,
110

110

00:03:39,440  -->  00:03:40,820
we're going to use a full tunnel
111

111

00:03:40,820  -->  00:03:43,230
or a split tunnel VPN configuration.
112

112

00:03:43,230  -->  00:03:45,530
Both full tunnel and split tunnel VPNs
113

113

00:03:45,530  -->  00:03:47,200
can be used with either a site to site
114

114

00:03:47,200  -->  00:03:48,900
or client to site model.
115

115

00:03:48,900  -->  00:03:51,460
Now, a full tunnel VPN is usually used by default
116

116

00:03:51,460  -->  00:03:52,760
in most organizations.
117

117

00:03:52,760  -->  00:03:54,380
And it's what I described earlier.
118

118

00:03:54,380  -->  00:03:55,800
With a full tunnel VPN,
119

119

00:03:55,800  -->  00:03:58,140
we're going to route and encrypt all the traffic requests
120

120

00:03:58,140  -->  00:04:00,760
through the VPN connection, back to the headquarters,
121

121

00:04:00,760  -->  00:04:02,320
regardless of where the destination
122

122

00:04:02,320  -->  00:04:04,000
of that service is located.
123

123

00:04:04,000  -->  00:04:05,449
This is considered more secure,
124

124

00:04:05,449  -->  00:04:08,260
but when we're connected using a full tunnel,
125

125

00:04:08,260  -->  00:04:09,280
the clients are considered
126

126

00:04:09,280  -->  00:04:11,300
to be fully part of the headquarters network
127

127

00:04:11,300  -->  00:04:12,450
when they're connected.
128

128

00:04:12,450  -->  00:04:15,420
This means if you're trying to access a local area resource
129

129

00:04:15,420  -->  00:04:17,360
like a wireless printer in your home office,
130

130

00:04:17,360  -->  00:04:18,700
you're not going to be able to do that
131

131

00:04:18,700  -->  00:04:20,800
because that wireless printer in your home office,
132

132

00:04:20,800  -->  00:04:22,970
is not connected to the headquarters network,
133

133

00:04:22,970  -->  00:04:26,320
like your laptop is, over that client to site VPN.
134

134

00:04:26,320  -->  00:04:27,380
Conversely though,
135

135

00:04:27,380  -->  00:04:28,680
you can still print to the printers
136

136

00:04:28,680  -->  00:04:30,050
in the headquarters office,
137

137

00:04:30,050  -->  00:04:32,750
even if you're connected using a full tunnel VPN,
138

138

00:04:32,750  -->  00:04:34,370
because you could be sitting in a hotel room
139

139

00:04:34,370  -->  00:04:35,450
halfway around the world,
140

140

00:04:35,450  -->  00:04:38,310
but logically, you're still sitting in your office
141

141

00:04:38,310  -->  00:04:40,130
at the corporate headquarters.
142

142

00:04:40,130  -->  00:04:42,230
Now, a split tunnel VPN on the other hand
143

143

00:04:42,230  -->  00:04:44,520
is going to divide your traffic and network requests
144

144

00:04:44,520  -->  00:04:46,670
and then route them to the appropriate connection
145

145

00:04:46,670  -->  00:04:47,590
or network.
146

146

00:04:47,590  -->  00:04:49,050
With a split tunnel VPN,
147

147

00:04:49,050  -->  00:04:50,840
we're going to route and encrypt the traffic
148

148

00:04:50,840  -->  00:04:52,692
bound for the headquarters over the VPN,
149

149

00:04:52,692  -->  00:04:54,610
and we're going to send all the other traffic
150

150

00:04:54,610  -->  00:04:56,150
out the regular internet.
151

151

00:04:56,150  -->  00:04:58,670
So, let's pretend that I'm using a client to site VPN
152

152

00:04:58,670  -->  00:05:01,150
on my laptop with a split tunnel configuration
153

153

00:05:01,150  -->  00:05:02,550
from my home office.
154

154

00:05:02,550  -->  00:05:04,660
The VPN here is going to decide which traffic
155

155

00:05:04,660  -->  00:05:06,290
goes back over the VPN
156

156

00:05:06,290  -->  00:05:08,170
and gets sent over to the headquarters
157

157

00:05:08,170  -->  00:05:10,180
and what traffic goes over the internet.
158

158

00:05:10,180  -->  00:05:12,530
So, if I'm trying to access a file server
159

159

00:05:12,530  -->  00:05:14,450
or a Microsoft exchange mail server,
160

160

00:05:14,450  -->  00:05:16,270
that's back on the headquarters network,
161

161

00:05:16,270  -->  00:05:17,790
those packets will get encrypted
162

162

00:05:17,790  -->  00:05:20,080
and write it over the VPN to the headquarters.
163

163

00:05:20,080  -->  00:05:22,530
But, if I need to attend a Zoom conference
164

164

00:05:22,530  -->  00:05:26,480
or access Office 365 or traffic outbound for the internet,
165

165

00:05:26,480  -->  00:05:29,830
I'm simply going to bypass that encrypted VPN connection
166

166

00:05:29,830  -->  00:05:31,880
and go directly out my internet connection
167

167

00:05:31,880  -->  00:05:33,760
to those public websites.
168

168

00:05:33,760  -->  00:05:35,960
Now, this is why we call it a split tunnel
169

169

00:05:35,960  -->  00:05:37,580
because we have an encrypted VPN tunnel
170

170

00:05:37,580  -->  00:05:39,370
for traffic that needs to go to the headquarters
171

171

00:05:39,370  -->  00:05:41,270
and another un-encrypted tunnel
172

172

00:05:41,270  -->  00:05:45,200
that takes a direct path out to the internet from your ISP.
173

173

00:05:45,200  -->  00:05:46,920
The challenge when using a split tunnel,
174

174

00:05:46,920  -->  00:05:48,610
is that they can be less secure
175

175

00:05:48,610  -->  00:05:49,860
because there is a possibility
176

176

00:05:49,860  -->  00:05:51,720
that an attacker could connect to your device
177

177

00:05:51,720  -->  00:05:53,650
over that un-encrypted internet tunnel,
178

178

00:05:53,650  -->  00:05:56,070
and then they could pivot through your laptop
179

179

00:05:56,070  -->  00:05:59,700
and send out over the VPN back to the headquarters network.
180

180

00:05:59,700  -->  00:06:00,770
For this reason,
181

181

00:06:00,770  -->  00:06:03,560
if you're connecting the VPN over an untrusted network,
182

182

00:06:03,560  -->  00:06:05,990
like Wi-Fi at a hotel or a coffee shop,
183

183

00:06:05,990  -->  00:06:08,000
you should never use a split tunnel.
184

184

00:06:08,000  -->  00:06:10,840
And instead, you should be using a full tunnel.
185

185

00:06:10,840  -->  00:06:13,350
Now, a split tunnel does give you better performance
186

186

00:06:13,350  -->  00:06:15,590
because it's going to route all your internet based traffic
187

187

00:06:15,590  -->  00:06:16,870
directly to those servers
188

188

00:06:16,870  -->  00:06:19,670
and bypass the entire company headquarters network.
189

189

00:06:19,670  -->  00:06:20,920
So, as you see,
190

190

00:06:20,920  -->  00:06:24,110
it becomes a trade off between security and performance.
191

191

00:06:24,110  -->  00:06:25,480
If you want more security,
192

192

00:06:25,480  -->  00:06:27,060
use a full tunnel VPN.
193

193

00:06:27,060  -->  00:06:30,120
If you want better performance, use a split tunnel VPN.
194

194

00:06:30,120  -->  00:06:33,550
So, at this point we've talked about two main types of VPNs,
195

195

00:06:33,550  -->  00:06:36,350
a site to site VPN and a client to site VPN.
196

196

00:06:36,350  -->  00:06:39,340
But, there is one more type of VPN that we need to discuss.
197

197

00:06:39,340  -->  00:06:41,700
And it's known as a clientless VPN.
198

198

00:06:41,700  -->  00:06:43,240
Now, a clientless VPN is used
199

199

00:06:43,240  -->  00:06:45,850
to create a secure remote access VPN tunnel
200

200

00:06:45,850  -->  00:06:48,209
using a web browser without requiring any software
201

201

00:06:48,209  -->  00:06:50,390
or hardware clients to be used.
202

202

00:06:50,390  -->  00:06:52,320
In fact, using this type of VPN,
203

203

00:06:52,320  -->  00:06:53,730
is something you do every day
204

204

00:06:53,730  -->  00:06:55,360
without even knowing it.
205

205

00:06:55,360  -->  00:06:57,830
A clientless VPN is used by your web browser
206

206

00:06:57,830  -->  00:07:00,170
when it makes a secure connection to an e-commerce
207

207

00:07:00,170  -->  00:07:02,303
or other secure website using HTTPS.
208

208

00:07:03,200  -->  00:07:06,260
This can be done using an SSL or TLS tunnel
209

209

00:07:06,260  -->  00:07:07,860
by using those protocols.
210

210

00:07:07,860  -->  00:07:10,230
Now, SSL or the Secure Socket Layer,
211

211

00:07:10,230  -->  00:07:12,630
is going to provide cryptography and reliability
212

212

00:07:12,630  -->  00:07:14,730
using the upper layers of the OSI model,
213

213

00:07:14,730  -->  00:07:17,570
specifically, layers five, six and seven.
214

214

00:07:17,570  -->  00:07:18,620
In recent years,
215

215

00:07:18,620  -->  00:07:21,320
SSL has become a bit outdated and less secure.
216

216

00:07:21,320  -->  00:07:24,610
So, most clientless VPNs are now using TLS,
217

217

00:07:24,610  -->  00:07:26,360
which is Transport Layer Security,
218

218

00:07:26,360  -->  00:07:29,470
to provide secure web browsing over HTTPS.
219

219

00:07:29,470  -->  00:07:32,620
So, when you logged into this website to watch this video,
220

220

00:07:32,620  -->  00:07:34,550
you had to enter your username and password,
221

221

00:07:34,550  -->  00:07:36,210
and you saw that little green padlock
222

222

00:07:36,210  -->  00:07:38,250
in the upper left corner of the address bar.
223

223

00:07:38,250  -->  00:07:41,870
That's how you knew you had a secure connection using HTTPS.
224

224

00:07:41,870  -->  00:07:44,900
That means you're using either SSL or TLS
225

225

00:07:44,900  -->  00:07:47,570
to create that secure clientless VPN tunnel
226

226

00:07:47,570  -->  00:07:50,720
from your web browser in your computer to my servers,
227

227

00:07:50,720  -->  00:07:52,640
so you can pull these videos.
228

228

00:07:52,640  -->  00:07:54,240
Now, SSL and TLS,
229

229

00:07:54,240  -->  00:07:57,410
both use TCP to establish their secure connections
230

230

00:07:57,410  -->  00:07:59,020
between a client and a server.
231

231

00:07:59,020  -->  00:08:00,990
But, this can slow down your connection
232

232

00:08:00,990  -->  00:08:03,210
because TCP has a lot more overhead
233

233

00:08:03,210  -->  00:08:04,870
than a UDP connection does.
234

234

00:08:04,870  -->  00:08:06,330
So, if you want,
235

235

00:08:06,330  -->  00:08:08,750
you can instead opt to use DTLS
236

236

00:08:08,750  -->  00:08:11,000
or the Datagram Transport Layer Security,
237

237

00:08:11,000  -->  00:08:13,130
which is essentially a UDP based version
238

238

00:08:13,130  -->  00:08:14,850
of the TLS protocol.
239

239

00:08:14,850  -->  00:08:17,360
This provides the same level of security as TLS,
240

240

00:08:17,360  -->  00:08:19,310
but it does operate a bit faster
241

241

00:08:19,310  -->  00:08:22,590
because there's less overhead inside the UDP protocol.
242

242

00:08:22,590  -->  00:08:25,030
Now, DTLS is an excellent choice to use
243

243

00:08:25,030  -->  00:08:27,090
when you're wanting to do things like video streaming
244

244

00:08:27,090  -->  00:08:28,920
and things like Voice over IP
245

245

00:08:28,920  -->  00:08:31,000
over secure and encrypted tunnels.
246

246

00:08:31,000  -->  00:08:33,740
This provides the end-user with security over UDP
247

247

00:08:33,740  -->  00:08:36,830
and prevents eavesdropping, tampering and message forgery
248

248

00:08:36,830  -->  00:08:39,390
inside that clientless VPN connection.
249

249

00:08:39,390  -->  00:08:41,480
Now, there are a few older VPN protocols
250

250

00:08:41,480  -->  00:08:42,940
you need to be aware of as well.
251

251

00:08:42,940  -->  00:08:47,480
This includes things like L2TP, L2F and PPTP.
252

252

00:08:47,480  -->  00:08:50,490
L2TP is the Layer 2 Tunneling Protocol.
253

253

00:08:50,490  -->  00:08:52,650
L2TP was a very early VPN.
254

254

00:08:52,650  -->  00:08:55,430
It was invented all the way back in the 80s and 90s.
255

255

00:08:55,430  -->  00:08:56,420
Unfortunately,
256

256

00:08:56,420  -->  00:09:00,540
L2TP lacks security features like encryption by default.
257

257

00:09:00,540  -->  00:09:02,550
So, if you're going to use L2TP,
258

258

00:09:02,550  -->  00:09:04,490
you have to combine it with another protocol
259

259

00:09:04,490  -->  00:09:06,720
to provide encryption for your VPN tunnel
260

260

00:09:06,720  -->  00:09:08,850
when you're using L2TP.
261

261

00:09:08,850  -->  00:09:10,330
Even though it's an older protocol,
262

262

00:09:10,330  -->  00:09:12,580
it's still used by a lot of modern networks
263

263

00:09:12,580  -->  00:09:14,390
by combining it with that extra encryption layer
264

264

00:09:14,390  -->  00:09:15,370
for protection.
265

265

00:09:15,370  -->  00:09:18,510
L2F or Layer 2 Forwarding is a VPN protocol
266

266

00:09:18,510  -->  00:09:19,890
that was originally developed by Cisco
267

267

00:09:19,890  -->  00:09:21,310
to provide a tunneling protocol
268

268

00:09:21,310  -->  00:09:24,050
for the point to point protocol or PPP.
269

269

00:09:24,050  -->  00:09:26,500
Unfortunately, it also lacks the native security
270

270

00:09:26,500  -->  00:09:27,530
and encryption features
271

271

00:09:27,530  -->  00:09:29,470
just like the Layer 2 Tunneling Protocol.
272

272

00:09:29,470  -->  00:09:30,580
For this reason,
273

273

00:09:30,580  -->  00:09:32,630
LTF has lost most of its popularity,
274

274

00:09:32,630  -->  00:09:35,230
and it's not used in most modern networks.
275

275

00:09:35,230  -->  00:09:37,920
PPTP or the Point-to-Point Tunneling Protocol
276

276

00:09:37,920  -->  00:09:40,520
is an older version of the VPN protocol as well.
277

277

00:09:40,520  -->  00:09:42,560
And it was used for dial up networks.
278

278

00:09:42,560  -->  00:09:45,480
PPTP also lacks the native security features,
279

279

00:09:45,480  -->  00:09:48,450
but Microsoft Windows has added security features
280

280

00:09:48,450  -->  00:09:51,100
to their implementation of PPTP.
281

281

00:09:51,100  -->  00:09:54,480
Therefore, if you're using a VPN through Windows with PPTP,
282

282

00:09:54,480  -->  00:09:57,160
you can still consider this to be pretty secure.
283

283

00:09:57,160  -->  00:09:59,710
All these VPN types can still be used today.
284

284

00:09:59,710  -->  00:10:01,040
It's just a matter of how secure
285

285

00:10:01,040  -->  00:10:02,650
you need your implementation to be,
286

286

00:10:02,650  -->  00:10:04,703
and if you need to add an additional layer of encryption,
287

287

00:10:04,703  -->  00:10:06,920
provide a more secure tunnel.
288

288

00:10:06,920  -->  00:10:08,850
But in most modern VPNs,
289

289

00:10:08,850  -->  00:10:11,800
you're going to see overwhelmingly that IPsec
290

290

00:10:11,800  -->  00:10:14,120
or IP Security is being used.
291

291

00:10:14,120  -->  00:10:16,670
Now, IPsec is used in virtual private networks
292

292

00:10:16,670  -->  00:10:19,270
to provide authentication and encryption of packets
293

293

00:10:19,270  -->  00:10:21,530
to create a secure encrypted communication path
294

294

00:10:21,530  -->  00:10:22,770
between two computers
295

295

00:10:22,770  -->  00:10:24,880
over an internet protocol based network.
296

296

00:10:24,880  -->  00:10:27,550
We're going to talk more about IPsec in a separate lesson,
297

297

00:10:27,550  -->  00:10:30,040
because there's a lot to cover in terms of IPsec
298

298

00:10:30,040  -->  00:10:31,290
and how it operates.
299

299

00:10:31,290  -->  00:10:34,200
For now, remember there are three main types of VPNs,
300

300

00:10:34,200  -->  00:10:35,890
site to site, client to site,
301

301

00:10:35,890  -->  00:10:37,040
and clientless.
302

302

00:10:37,040  -->  00:10:39,480
Also, remember there are two methods of communication
303

303

00:10:39,480  -->  00:10:40,620
using a VPN.
304

304

00:10:40,620  -->  00:10:43,100
You can use full tunnel or split tunnel.
305

305

00:10:43,100  -->  00:10:45,880
Finally, remember there are several VPN protocols
306

306

00:10:45,880  -->  00:10:48,200
you can use to establish those VPNs.
307

307

00:10:48,200  -->  00:10:50,030
You can use the L2TP,
308

308

00:10:50,030  -->  00:10:51,080
L2F,
309

309

00:10:51,080  -->  00:10:52,080
PPTP
310

310

00:10:52,080  -->  00:10:53,303
and IPsec.
