1
00:00:00,120 --> 00:00:01,620
In this lesson, we're going to cover

2
00:00:01,620 --> 00:00:04,860
some of the methods used in securing network communications.

3
00:00:04,860 --> 00:00:07,080
Now, as cyber threats continue to evolve,

4
00:00:07,080 --> 00:00:08,460
it's always important that you learn

5
00:00:08,460 --> 00:00:10,500
about the different tools and protocols that are used

6
00:00:10,500 --> 00:00:13,530
to protect our data as it's transiting across the Internet

7
00:00:13,530 --> 00:00:15,420
and other insecure networks.

8
00:00:15,420 --> 00:00:17,520
As we attempt to secure our data in transit,

9
00:00:17,520 --> 00:00:20,100
we have to protect it against any potential eavesdroppers

10
00:00:20,100 --> 00:00:22,800
or malicious actors so that our data communications

11
00:00:22,800 --> 00:00:25,200
remain confidential and trustworthy.

12
00:00:25,200 --> 00:00:27,540
To achieve this kind of data in transit security,

13
00:00:27,540 --> 00:00:30,480
we usually are going to rely on three main technologies.

14
00:00:30,480 --> 00:00:33,240
These are Virtual Private Networks known as VPNs,

15
00:00:33,240 --> 00:00:35,550
Transport Layer Security known as TLS,

16
00:00:35,550 --> 00:00:38,880
and Internet Protocol Security known as IPSec.

17
00:00:38,880 --> 00:00:40,440
Let's take a look at each of these.

18
00:00:40,440 --> 00:00:42,930
First, we have virtual private networks.

19
00:00:42,930 --> 00:00:45,870
Now, a virtual private network or VPN is going to be used

20
00:00:45,870 --> 00:00:48,450
to extend a private network across a public network

21
00:00:48,450 --> 00:00:51,210
to allow users to send and receive data across a shared

22
00:00:51,210 --> 00:00:53,850
or public network as if they're computing devices

23
00:00:53,850 --> 00:00:55,830
were directly connected to your organization's

24
00:00:55,830 --> 00:00:57,300
own private network.

25
00:00:57,300 --> 00:01:00,120
With a VPN, your users can work in a remote office

26
00:01:00,120 --> 00:01:01,410
or work from home

27
00:01:01,410 --> 00:01:04,050
and telecommute simply by logging into their laptop

28
00:01:04,050 --> 00:01:06,180
and establishing a secure VPN tunnel

29
00:01:06,180 --> 00:01:07,920
within their organization's network

30
00:01:07,920 --> 00:01:10,020
regardless of where it is in the world.

31
00:01:10,020 --> 00:01:12,900
Now, to do this, users are going to connect to a VPN device

32
00:01:12,900 --> 00:01:14,910
sitting at the headquarters' data center,

33
00:01:14,910 --> 00:01:17,040
and then they'll establish a secure tunnel

34
00:01:17,040 --> 00:01:20,220
using a VPN protocol in order to allow a secure connection

35
00:01:20,220 --> 00:01:21,870
from the corporate user's device

36
00:01:21,870 --> 00:01:23,820
over that untrusted or public network

37
00:01:23,820 --> 00:01:26,460
such as the Internet back into the trusted network

38
00:01:26,460 --> 00:01:29,310
that is contained inside of your headquarters' data center.

39
00:01:29,310 --> 00:01:32,580
These VPNs can be configured as a site-to-site VPN,

40
00:01:32,580 --> 00:01:35,790
a client-to-site VPN or a clientless VPN.

41
00:01:35,790 --> 00:01:37,950
Now, a site-to-site VPN is going to be used

42
00:01:37,950 --> 00:01:39,060
to interconnect two sites

43
00:01:39,060 --> 00:01:40,950
and provide an inexpensive alternative

44
00:01:40,950 --> 00:01:42,690
to a dedicated leased line.

45
00:01:42,690 --> 00:01:45,000
For example, let's pretend that I have a branch office

46
00:01:45,000 --> 00:01:48,480
in California and my headquarters sits in Washington DC.

47
00:01:48,480 --> 00:01:50,670
If I want to be able to connect my remote regional office

48
00:01:50,670 --> 00:01:53,070
in California all the way back to my head office

49
00:01:53,070 --> 00:01:56,700
in Washington DC, I could buy a dedicated leased fiber line

50
00:01:56,700 --> 00:01:58,410
from a telecommunications provider

51
00:01:58,410 --> 00:01:59,610
that gives me a direct connection

52
00:01:59,610 --> 00:02:03,360
that covers over 3,000 miles between these two sites.

53
00:02:03,360 --> 00:02:05,820
Now, even if I got a low speed T1 connection,

54
00:02:05,820 --> 00:02:08,370
this would be very expensive for me to use,

55
00:02:08,370 --> 00:02:11,460
so I can actually use a site-to-site VPN instead

56
00:02:11,460 --> 00:02:13,380
and I'll be able to save a lot of money.

57
00:02:13,380 --> 00:02:15,390
Instead of using a dedicated leased line,

58
00:02:15,390 --> 00:02:18,600
I can simply create a VPN tunnel from the regional office

59
00:02:18,600 --> 00:02:21,300
all the way back to my headquarters over the public Internet

60
00:02:21,300 --> 00:02:22,620
using the Internet connectivity

61
00:02:22,620 --> 00:02:25,620
that I already have in place at both of those offices.

62
00:02:25,620 --> 00:02:29,070
This solution might only cost me $50 or $100 per month

63
00:02:29,070 --> 00:02:31,830
using a standard cable modem or fiber optic modem

64
00:02:31,830 --> 00:02:35,040
from your local service provider at each of those locations.

65
00:02:35,040 --> 00:02:37,260
Now, once the VPN tunnel is established,

66
00:02:37,260 --> 00:02:39,540
it's going to take all the traffic from my regional office

67
00:02:39,540 --> 00:02:42,150
over in California and route it back to the headquarters

68
00:02:42,150 --> 00:02:44,190
in Washington DC over the Internet

69
00:02:44,190 --> 00:02:46,380
within this securely encrypted tunnel.

70
00:02:46,380 --> 00:02:48,450
And then once it reaches back to my network

71
00:02:48,450 --> 00:02:51,060
in Washington DC, I can decrypt that data

72
00:02:51,060 --> 00:02:52,980
and use it as if somebody was sitting right there

73
00:02:52,980 --> 00:02:55,410
inside the Washington DC office.

74
00:02:55,410 --> 00:02:57,150
Now, whenever a California user though

75
00:02:57,150 --> 00:02:58,830
wants to go to google.com,

76
00:02:58,830 --> 00:03:00,210
their data is actually going to go

77
00:03:00,210 --> 00:03:02,580
from California to Washington DC

78
00:03:02,580 --> 00:03:05,700
and then out the Washington DC office's Internet connection

79
00:03:05,700 --> 00:03:08,610
to visit that website, in this case google.com,

80
00:03:08,610 --> 00:03:10,470
and then it returns that response back

81
00:03:10,470 --> 00:03:12,240
to the Washington DC office,

82
00:03:12,240 --> 00:03:14,580
and then it goes back through the VPN connection

83
00:03:14,580 --> 00:03:16,710
over to the user in California.

84
00:03:16,710 --> 00:03:18,930
This way, we're actually funneling everything

85
00:03:18,930 --> 00:03:20,640
through that headquarters' network.

86
00:03:20,640 --> 00:03:21,630
Now, this gives us an ability

87
00:03:21,630 --> 00:03:23,130
to have a lot of security there,

88
00:03:23,130 --> 00:03:26,580
but it also does slow down things for that California user

89
00:03:26,580 --> 00:03:29,070
because they have all this extra data transit happening

90
00:03:29,070 --> 00:03:30,930
going from the West Coast to the East Coast,

91
00:03:30,930 --> 00:03:33,210
out to the website, and then back from the East Coast

92
00:03:33,210 --> 00:03:35,190
over to our user on the West Coast.

93
00:03:35,190 --> 00:03:36,360
Under this kind of a setup,

94
00:03:36,360 --> 00:03:38,580
we're really using a site-to-site VPN,

95
00:03:38,580 --> 00:03:40,530
and all of our traffic from California

96
00:03:40,530 --> 00:03:42,690
is going over to Washington DC first

97
00:03:42,690 --> 00:03:45,210
before it goes out into the public Internet.

98
00:03:45,210 --> 00:03:47,790
By doing this, all the traffic between those two sites

99
00:03:47,790 --> 00:03:49,530
is going to be encrypted and secure

100
00:03:49,530 --> 00:03:52,110
so that nobody can see our internal network traffic,

101
00:03:52,110 --> 00:03:53,430
even though we're doing all this

102
00:03:53,430 --> 00:03:56,130
over an external public Internet connection.

103
00:03:56,130 --> 00:03:58,200
Now, when we deal with a client-to-site VPN,

104
00:03:58,200 --> 00:03:59,130
on the other hand,

105
00:03:59,130 --> 00:04:01,050
we're going to be sending data from a single host

106
00:04:01,050 --> 00:04:04,470
like a laptop, a cellphone, a smartphone, or a tablet,

107
00:04:04,470 --> 00:04:07,410
and connecting it directly back to our headquarters office.

108
00:04:07,410 --> 00:04:09,630
This way, instead of going from a site's router

109
00:04:09,630 --> 00:04:10,950
to the headquarters' router,

110
00:04:10,950 --> 00:04:14,100
we're just going from our device back to the headquarters.

111
00:04:14,100 --> 00:04:15,930
This allows the remote user to be able to connect

112
00:04:15,930 --> 00:04:17,190
back to the head office

113
00:04:17,190 --> 00:04:20,100
and that's why we call this a client-to-site VPN.

114
00:04:20,100 --> 00:04:22,170
For example, let me show you how easy it is

115
00:04:22,170 --> 00:04:24,690
for a user to configure a client-to-site VPN

116
00:04:24,690 --> 00:04:27,570
from their Windows laptop back to their corporate network

117
00:04:27,570 --> 00:04:29,610
using their wireless connection.

118
00:04:29,610 --> 00:04:31,890
In this demonstration, I'm going to show you how to create

119
00:04:31,890 --> 00:04:34,260
a VPN connection on a Windows machine.

120
00:04:34,260 --> 00:04:36,900
Now for this example, I'm going to use a Windows 7 machine,

121
00:04:36,900 --> 00:04:38,610
but it's pretty much the same process

122
00:04:38,610 --> 00:04:40,380
in any version of Windows.

123
00:04:40,380 --> 00:04:41,460
What we're going to do is I'm going to click

124
00:04:41,460 --> 00:04:43,800
on this wireless network that's currently connected,

125
00:04:43,800 --> 00:04:46,800
and I'm going to go to Open Network and Sharing Center.

126
00:04:46,800 --> 00:04:48,300
Now, from here, we're going to go to set up

127
00:04:48,300 --> 00:04:50,010
a new connection or network,

128
00:04:50,010 --> 00:04:53,040
and this will bring up our dialog box to create our VPN.

129
00:04:53,040 --> 00:04:54,810
We want to use connect to a workplace,

130
00:04:54,810 --> 00:04:57,540
which is going to set up our dial up or VPN connection.

131
00:04:57,540 --> 00:04:59,760
We'll then hit Next, and then from here,

132
00:04:59,760 --> 00:05:01,470
we're going to either use it over the Internet

133
00:05:01,470 --> 00:05:02,970
or a direct dial.

134
00:05:02,970 --> 00:05:05,640
In our case, we're going to create a secure VPN tunnel

135
00:05:05,640 --> 00:05:06,990
over the Internet.

136
00:05:06,990 --> 00:05:08,400
And then we'll give it our IP address.

137
00:05:08,400 --> 00:05:12,240
In my case, it's 198.10.20.12,

138
00:05:12,240 --> 00:05:13,470
and I'll give it a name.

139
00:05:13,470 --> 00:05:15,363
Let's call it the Corporate VPN.

140
00:05:16,800 --> 00:05:18,750
And then from there, we're going to hit Next.

141
00:05:18,750 --> 00:05:21,300
We have to put in our username and our password.

142
00:05:21,300 --> 00:05:25,953
So let's say it was Jason Dion and my password of password,

143
00:05:27,060 --> 00:05:28,833
and then we can hit Connect.

144
00:05:32,940 --> 00:05:35,880
And there you go, you're now connected to the VPN,

145
00:05:35,880 --> 00:05:38,310
and you can see that we have an access

146
00:05:38,310 --> 00:05:39,870
over our VPN connection

147
00:05:39,870 --> 00:05:42,990
and we have our wireless connectivity on top of that.

148
00:05:42,990 --> 00:05:45,150
And that's going to make that secure tunnel

149
00:05:45,150 --> 00:05:48,090
so that nobody can see anything that we're transmitting

150
00:05:48,090 --> 00:05:52,500
from our laptop over the Internet back into our VPN network.

151
00:05:52,500 --> 00:05:54,780
Now, once you've decided to use either a site-to-site

152
00:05:54,780 --> 00:05:58,380
or a client-to-site VPN, you need to decide one more thing,

153
00:05:58,380 --> 00:06:00,360
and that's whether you're going to use a full tunnel

154
00:06:00,360 --> 00:06:02,760
or a split tunnel VPN configuration.

155
00:06:02,760 --> 00:06:05,550
Now, both full tunnel and split tunnel VPNs can be used

156
00:06:05,550 --> 00:06:08,400
with either a site-to-site or a client-to-site VPN,

157
00:06:08,400 --> 00:06:10,530
and each one gives you different abilities.

158
00:06:10,530 --> 00:06:13,050
Now, a full tunnel VPN is usually what's going to be used

159
00:06:13,050 --> 00:06:15,210
by most organizations by default,

160
00:06:15,210 --> 00:06:16,740
and it's what I described earlier.

161
00:06:16,740 --> 00:06:18,090
With a full tunnel VPN,

162
00:06:18,090 --> 00:06:20,400
we're going to route and encrypt all of our network requests

163
00:06:20,400 --> 00:06:22,680
through the VPN connection back to the headquarters

164
00:06:22,680 --> 00:06:24,270
regardless of where that destination

165
00:06:24,270 --> 00:06:26,610
or the service is actually going to be located.

166
00:06:26,610 --> 00:06:28,320
This is considered to be more secure,

167
00:06:28,320 --> 00:06:30,720
but when you're connected using a full tunnel,

168
00:06:30,720 --> 00:06:32,700
all of your clients are considered to be fully

169
00:06:32,700 --> 00:06:34,170
a part of your headquarters network

170
00:06:34,170 --> 00:06:35,550
whenever they're connected.

171
00:06:35,550 --> 00:06:37,200
This means that if you're trying to access

172
00:06:37,200 --> 00:06:38,880
a local area network resource

173
00:06:38,880 --> 00:06:40,830
like a wireless printer in your home office,

174
00:06:40,830 --> 00:06:42,210
you're not going to be able to do that

175
00:06:42,210 --> 00:06:44,130
because that wireless printer in your home office

176
00:06:44,130 --> 00:06:46,650
is not connected back to your headquarters network

177
00:06:46,650 --> 00:06:48,480
like your laptop is because you're using

178
00:06:48,480 --> 00:06:50,580
that client-to-site VPN connection.

179
00:06:50,580 --> 00:06:52,290
Conversely though, you could still print

180
00:06:52,290 --> 00:06:53,880
to the printer in your headquarters office

181
00:06:53,880 --> 00:06:56,220
when you're connected using that full tunnel VPN

182
00:06:56,220 --> 00:06:57,960
because all of your headquarters' resources

183
00:06:57,960 --> 00:07:00,120
are still virtually connected to you,

184
00:07:00,120 --> 00:07:01,710
even if you're sitting in a hotel room

185
00:07:01,710 --> 00:07:03,270
halfway around the world.

186
00:07:03,270 --> 00:07:05,280
Now, a split tunnel VPN, on the other hand,

187
00:07:05,280 --> 00:07:07,500
is going to divide your traffic and network requests

188
00:07:07,500 --> 00:07:08,370
and then route them

189
00:07:08,370 --> 00:07:10,590
to the appropriate connection or network.

190
00:07:10,590 --> 00:07:12,810
A split tunnel VPN will route and encrypt

191
00:07:12,810 --> 00:07:14,070
only the traffic that's bound

192
00:07:14,070 --> 00:07:16,320
for your headquarters' network over your VPN

193
00:07:16,320 --> 00:07:18,900
and everything else will be sent out a split tunnel

194
00:07:18,900 --> 00:07:22,200
to the rest of the Internet directly from your location.

195
00:07:22,200 --> 00:07:25,380
For example, if I'm using a client-to-site VPN on my laptop

196
00:07:25,380 --> 00:07:27,660
using a split tunnel from my home office,

197
00:07:27,660 --> 00:07:29,430
I actually have a VPN that's going to decide

198
00:07:29,430 --> 00:07:31,800
which traffic will be routed over the VPN

199
00:07:31,800 --> 00:07:34,230
and which traffic will go directly over to a website

200
00:07:34,230 --> 00:07:36,150
that's located directly on the Internet.

201
00:07:36,150 --> 00:07:38,250
So if I'm trying to access a file server

202
00:07:38,250 --> 00:07:39,960
or a Microsoft Exchange mail server

203
00:07:39,960 --> 00:07:42,810
for my corporate network, I'm going to go through the VPN

204
00:07:42,810 --> 00:07:44,460
and all those packets will get encrypted

205
00:07:44,460 --> 00:07:46,800
and routed back to the headquarters network.

206
00:07:46,800 --> 00:07:48,840
But if I'm going to attend a Zoom conference

207
00:07:48,840 --> 00:07:52,590
or access Office 365, that traffic that's bound for those

208
00:07:52,590 --> 00:07:54,090
will go directly to those sites

209
00:07:54,090 --> 00:07:56,130
by going directly through my Internet connection

210
00:07:56,130 --> 00:07:58,920
and bypassing the headquarters' network completely.

211
00:07:58,920 --> 00:08:01,650
And this is why we call this a split tunnel configuration

212
00:08:01,650 --> 00:08:03,870
because we have both an encrypted VPN tunnel

213
00:08:03,870 --> 00:08:05,790
for the traffic that needs to go to the headquarters

214
00:08:05,790 --> 00:08:08,730
and an unencrypted direct Internet path or tunnel

215
00:08:08,730 --> 00:08:10,800
for everything else that's available openly

216
00:08:10,800 --> 00:08:12,990
and online in the public Internet.

217
00:08:12,990 --> 00:08:15,330
Now, the big challenge when you're using a split tunnel

218
00:08:15,330 --> 00:08:16,800
is that these can be less secure

219
00:08:16,800 --> 00:08:18,510
because now we have a possibility

220
00:08:18,510 --> 00:08:20,070
that an attacker could connect to your device

221
00:08:20,070 --> 00:08:22,080
over your unencrypted Internet tunnel

222
00:08:22,080 --> 00:08:23,730
and then pivot through your laptop

223
00:08:23,730 --> 00:08:25,470
and send out that out back through the VPN

224
00:08:25,470 --> 00:08:27,270
over to the headquarters' network.

225
00:08:27,270 --> 00:08:29,760
For this reason, if you're connecting to the VPN

226
00:08:29,760 --> 00:08:31,200
from an untrusted network

227
00:08:31,200 --> 00:08:33,809
like using Wi-Fi at a hotel or a coffee shop,

228
00:08:33,809 --> 00:08:36,120
you should always use a full tunnel VPN

229
00:08:36,120 --> 00:08:38,100
and not a split tunnel VPN

230
00:08:38,100 --> 00:08:40,409
because this gives you higher levels of security.

231
00:08:40,409 --> 00:08:41,460
That being said,

232
00:08:41,460 --> 00:08:43,620
a split tunnel will give you better performance

233
00:08:43,620 --> 00:08:45,720
because it's routing all Internet-based traffic

234
00:08:45,720 --> 00:08:47,490
directly to those Internet servers

235
00:08:47,490 --> 00:08:50,160
and bypassing your entire headquarters' network.

236
00:08:50,160 --> 00:08:53,490
So as you can see, once again, we have to make a decision

237
00:08:53,490 --> 00:08:56,430
and weigh the trade-offs between security and performance

238
00:08:56,430 --> 00:08:58,440
when we're choosing which type of VPN tunneling

239
00:08:58,440 --> 00:08:59,640
we want to use.

240
00:08:59,640 --> 00:09:02,490
For more security, you're going to use a full tunnel VPN.

241
00:09:02,490 --> 00:09:05,880
For better performance, you're going to use a split tunnel VPN.

242
00:09:05,880 --> 00:09:08,670
So now that we've talked about two main types of VPNs,

243
00:09:08,670 --> 00:09:11,400
a site-to-site VPN and a client-to-site VPN,

244
00:09:11,400 --> 00:09:13,200
we need to talk about the third type

245
00:09:13,200 --> 00:09:16,140
and the third type is known as a clientless VPN.

246
00:09:16,140 --> 00:09:17,970
Now, a clientless VPN is going to be used

247
00:09:17,970 --> 00:09:21,390
to secure remote access VPN tunnels using a web browser,

248
00:09:21,390 --> 00:09:23,100
and it doesn't require any software

249
00:09:23,100 --> 00:09:25,170
or hardware clients to be configured.

250
00:09:25,170 --> 00:09:27,780
In fact, you use this VPN every single day

251
00:09:27,780 --> 00:09:29,190
without even knowing it.

252
00:09:29,190 --> 00:09:31,680
A clientless VPN is going to be used by your web browser

253
00:09:31,680 --> 00:09:33,900
when it makes a secure connection to an e-commerce

254
00:09:33,900 --> 00:09:37,170
or other secure website using the HTTPS connection

255
00:09:37,170 --> 00:09:38,640
over port 443

256
00:09:38,640 --> 00:09:41,370
and it uses a TLS protocol to encrypt the data

257
00:09:41,370 --> 00:09:43,500
being sent to and from that website.

258
00:09:43,500 --> 00:09:46,530
Now, TLS or the Transport Layer Security protocol

259
00:09:46,530 --> 00:09:48,810
is going to provide cryptographic and reliability

260
00:09:48,810 --> 00:09:51,000
using the upper layers of the OSI model,

261
00:09:51,000 --> 00:09:53,670
specifically Layers 5, 6, and 7.

262
00:09:53,670 --> 00:09:56,160
So if you logged into this website to watch the video,

263
00:09:56,160 --> 00:09:58,380
you had to actually enter your username and password.

264
00:09:58,380 --> 00:10:00,270
And when you did that, you looked up to verify

265
00:10:00,270 --> 00:10:01,500
there was that little green lock

266
00:10:01,500 --> 00:10:03,600
in the upper left corner of the address bar.

267
00:10:03,600 --> 00:10:07,137
If you saw that, you knew you had a secure HTTPS connection

268
00:10:07,137 --> 00:10:08,953
and that you're using TLS to create a secure

269
00:10:08,953 --> 00:10:11,940
clientless VPN tunnel through your web browser

270
00:10:11,940 --> 00:10:13,956
from your computer over to my server

271
00:10:13,956 --> 00:10:15,180
to be able to log in securely

272
00:10:15,180 --> 00:10:16,530
without your username and password

273
00:10:16,530 --> 00:10:18,210
being sent directly over the Internet

274
00:10:18,210 --> 00:10:19,980
without being first encrypted.

275
00:10:19,980 --> 00:10:22,107
This now allows you to watch these videos over the secure

276
00:10:22,107 --> 00:10:25,740
and encrypted tunnel between your system and my system.

277
00:10:25,740 --> 00:10:28,290
TLS uses the Transmission Control Protocol,

278
00:10:28,290 --> 00:10:29,700
which is known as TCP,

279
00:10:29,700 --> 00:10:31,890
for us to be able to establish our secure connections

280
00:10:31,890 --> 00:10:33,570
between a client and a server.

281
00:10:33,570 --> 00:10:35,340
But this can slow down your connection

282
00:10:35,340 --> 00:10:37,440
because TCP has a lot more overhead

283
00:10:37,440 --> 00:10:39,330
than a UDP connection does.

284
00:10:39,330 --> 00:10:43,110
So your systems can also opt to use DTLS instead.

285
00:10:43,110 --> 00:10:46,830
And DTLS is the Datagram Transport Layer Security protocol,

286
00:10:46,830 --> 00:10:50,190
which is a UDP-based version of the TLS protocol.

287
00:10:50,190 --> 00:10:53,820
DTLS does provide the same level of security as TLS,

288
00:10:53,820 --> 00:10:55,560
but it operates a bit faster

289
00:10:55,560 --> 00:10:59,010
because it has less overhead in the UDP protocol itself.

290
00:10:59,010 --> 00:11:02,010
Now, DTLS is considered to be an excellent choice to use

291
00:11:02,010 --> 00:11:03,630
when you're wanting to provide video streaming

292
00:11:03,630 --> 00:11:06,630
and things like that over a secure and encrypted tunnel.

293
00:11:06,630 --> 00:11:08,310
This provides the end user with security

294
00:11:08,310 --> 00:11:11,070
over a UDP connection and prevents eavesdropping,

295
00:11:11,070 --> 00:11:12,840
tampering, and message forgery

296
00:11:12,840 --> 00:11:15,450
inside of our clientless VPN connections.

297
00:11:15,450 --> 00:11:18,030
Now, in most modern VPNs that rely on site-to-site

298
00:11:18,030 --> 00:11:19,710
or client-to-site connections though,

299
00:11:19,710 --> 00:11:21,000
you're going to see that we're going to use

300
00:11:21,000 --> 00:11:22,980
the Internet Protocol Security Suite,

301
00:11:22,980 --> 00:11:25,140
which is more commonly called IPSec,

302
00:11:25,140 --> 00:11:28,170
instead of using a clientless TLS encrypted tunnel.

303
00:11:28,170 --> 00:11:31,470
In fact, IPSec is the most popular protocol in use today

304
00:11:31,470 --> 00:11:33,570
for the creation and operation of VPNs

305
00:11:33,570 --> 00:11:36,240
because it provides us with confidentiality, integrity,

306
00:11:36,240 --> 00:11:39,000
authentication, and anti-replay protections

307
00:11:39,000 --> 00:11:40,740
when we're using our VPN connections

308
00:11:40,740 --> 00:11:43,800
for both site-to-site and client-to-site VPNs.

309
00:11:43,800 --> 00:11:46,530
IPSec is a secure network protocol suite

310
00:11:46,530 --> 00:11:47,700
that provides authentication

311
00:11:47,700 --> 00:11:49,470
and encryption of our data packets

312
00:11:49,470 --> 00:11:51,600
to create a secure encrypted communication path

313
00:11:51,600 --> 00:11:54,720
between two computers over an Internet protocol network.

314
00:11:54,720 --> 00:11:58,320
IPSec provides confidentiality by using data encryption.

315
00:11:58,320 --> 00:12:01,140
IPSec will also provide us with the integrity that we want

316
00:12:01,140 --> 00:12:03,720
by ensuring that our data was not modified in transit

317
00:12:03,720 --> 00:12:06,330
by checking its hash digest just before it's transmitted

318
00:12:06,330 --> 00:12:08,280
and then again once it's been received

319
00:12:08,280 --> 00:12:09,660
to ensure they match.

320
00:12:09,660 --> 00:12:11,400
Authentication is going to be provided

321
00:12:11,400 --> 00:12:14,250
by having each party verify they are who they claim to be.

322
00:12:14,250 --> 00:12:17,250
And IPSec will also provide you with anti-replaying

323
00:12:17,250 --> 00:12:18,660
by checking the sequence of numbers

324
00:12:18,660 --> 00:12:20,910
on all of the packets before they're sent.

325
00:12:20,910 --> 00:12:23,370
This prevents the transmission of any duplicate packets,

326
00:12:23,370 --> 00:12:25,530
and it prevents an attacker from being able to capture

327
00:12:25,530 --> 00:12:28,380
and resend packets later as part of an attack.

328
00:12:28,380 --> 00:12:30,390
Now, there are five main steps in the process

329
00:12:30,390 --> 00:12:32,940
of establishing and using a secure VPN tunnel

330
00:12:32,940 --> 00:12:34,770
when you're using IPSec.

331
00:12:34,770 --> 00:12:37,380
First, there's a request to start a key exchange.

332
00:12:37,380 --> 00:12:40,410
Second, IKE Phase 1 is going to authenticate the parties

333
00:12:40,410 --> 00:12:42,990
and establish a secure channel for negotiation.

334
00:12:42,990 --> 00:12:45,630
Third, IKE Phase 2 is going to negotiate

335
00:12:45,630 --> 00:12:47,370
the security association parameters

336
00:12:47,370 --> 00:12:49,530
and fully establish the secure tunnel.

337
00:12:49,530 --> 00:12:51,330
Fourth, we're going to have data transfer,

338
00:12:51,330 --> 00:12:52,890
and this is then going to allow data transfer

339
00:12:52,890 --> 00:12:55,920
between the two parties to occur over the secure tunnel

340
00:12:55,920 --> 00:12:57,990
using the IPSec parameters and keys

341
00:12:57,990 --> 00:12:59,940
that we stored from the security associations

342
00:12:59,940 --> 00:13:02,190
that were negotiated back in step three.

343
00:13:02,190 --> 00:13:05,370
And fifth, IPSec tunnel termination is going to occur,

344
00:13:05,370 --> 00:13:07,260
and this happens when the security associations

345
00:13:07,260 --> 00:13:08,310
are going to be terminated

346
00:13:08,310 --> 00:13:10,260
through either a mutual agreement and deletion

347
00:13:10,260 --> 00:13:12,540
or due to the timing out of the tunnel

348
00:13:12,540 --> 00:13:15,000
because one party became non-responsive.

349
00:13:15,000 --> 00:13:16,800
Now, let's take a look at these five steps

350
00:13:16,800 --> 00:13:18,570
and how they work in the real world.

351
00:13:18,570 --> 00:13:20,220
First, I have PC1

352
00:13:20,220 --> 00:13:22,950
and they want to be able to send some traffic over to PC2.

353
00:13:22,950 --> 00:13:25,110
To do this, router one is going to create

354
00:13:25,110 --> 00:13:27,540
an initiation of an IPSec tunnel.

355
00:13:27,540 --> 00:13:30,330
Second, we're going to see router one and router two,

356
00:13:30,330 --> 00:13:31,470
and they're going to start negotiating

357
00:13:31,470 --> 00:13:32,760
the security associations

358
00:13:32,760 --> 00:13:35,400
to form the IPSec IKE Phase 1 tunnel.

359
00:13:35,400 --> 00:13:39,570
This is known as our ISAKMP tunnel or I-S-A-K-M-P.

360
00:13:39,570 --> 00:13:42,660
Now in step three, IKE Phase 2 is going to create this tunnel

361
00:13:42,660 --> 00:13:45,810
inside of a tunnel when it's negotiated and set up.

362
00:13:45,810 --> 00:13:47,700
Now, once the second tunnel is established,

363
00:13:47,700 --> 00:13:50,610
we can then begin to conduct data transfer in step four

364
00:13:50,610 --> 00:13:52,050
and the information will start flowing

365
00:13:52,050 --> 00:13:54,750
between PC1 and PC2 securely.

366
00:13:54,750 --> 00:13:55,860
When they're all done with that,

367
00:13:55,860 --> 00:13:58,380
we reach step five and the tunnel will be torn down

368
00:13:58,380 --> 00:14:01,830
and the IPSec security associations are going to be deleted.

369
00:14:01,830 --> 00:14:04,260
Now, if you want to be able to create another VPN,

370
00:14:04,260 --> 00:14:06,300
you can do that by starting this whole process

371
00:14:06,300 --> 00:14:07,500
over again from the beginning

372
00:14:07,500 --> 00:14:09,960
and going through those five steps once more.

373
00:14:09,960 --> 00:14:13,080
Now, to allow the data transfer to happen inside of IPSec,

374
00:14:13,080 --> 00:14:14,700
we do this during step four,

375
00:14:14,700 --> 00:14:16,800
and we're going to do this using one of two modes.

376
00:14:16,800 --> 00:14:20,340
These modes are known as transport mode or tunneling mode.

377
00:14:20,340 --> 00:14:21,990
First, we have transport mode.

378
00:14:21,990 --> 00:14:23,790
And transport mode is going to use the packet's

379
00:14:23,790 --> 00:14:24,623
original IP header

380
00:14:24,623 --> 00:14:27,360
and it's going to be used for client-to-site VPNs.

381
00:14:27,360 --> 00:14:29,430
The transport mode approach works really well

382
00:14:29,430 --> 00:14:31,500
if you have problems increasing your packet size

383
00:14:31,500 --> 00:14:34,290
because you may go over your maximum transmission unit size

384
00:14:34,290 --> 00:14:36,600
or MTU inside of your network.

385
00:14:36,600 --> 00:14:38,910
Remember, by default in most networks,

386
00:14:38,910 --> 00:14:41,550
the MTU or maximum transmission unit size

387
00:14:41,550 --> 00:14:45,300
is going to be set at 1,500 bytes in most of our networks.

388
00:14:45,300 --> 00:14:46,980
If you go over 1,500 bytes,

389
00:14:46,980 --> 00:14:48,750
that packet will become fragmented,

390
00:14:48,750 --> 00:14:51,810
and this can cause issues with your VPN's functionality.

391
00:14:51,810 --> 00:14:53,820
If you're using a client-to-site VPN,

392
00:14:53,820 --> 00:14:55,800
I highly recommend that use a transport mode

393
00:14:55,800 --> 00:14:58,260
as your IPSec method because it doesn't add

394
00:14:58,260 --> 00:15:00,060
any additional padding to your packet

395
00:15:00,060 --> 00:15:02,160
and it doesn't increase its size.

396
00:15:02,160 --> 00:15:02,993
Now, on the other hand,

397
00:15:02,993 --> 00:15:05,040
if you're setting up a site-to-site VPN,

398
00:15:05,040 --> 00:15:06,210
like having a regional office

399
00:15:06,210 --> 00:15:08,010
connecting back to your main office,

400
00:15:08,010 --> 00:15:09,630
then I would use tunneling.

401
00:15:09,630 --> 00:15:11,100
Now, tunneling mode is going to be used

402
00:15:11,100 --> 00:15:12,900
to encapsulate the entire packet

403
00:15:12,900 --> 00:15:14,970
and put another header on top of it.

404
00:15:14,970 --> 00:15:16,737
This will increase the size of the packet,

405
00:15:16,737 --> 00:15:17,927
and this could cause you to go over

406
00:15:17,927 --> 00:15:20,880
that 1,500 bytes of your MTU

407
00:15:20,880 --> 00:15:23,370
or maximum transmission unit size.

408
00:15:23,370 --> 00:15:24,840
Now, when you think about tunneling mode,

409
00:15:24,840 --> 00:15:26,580
I want you to think about it this way.

410
00:15:26,580 --> 00:15:28,500
Let's say you have a letter that you want to deliver

411
00:15:28,500 --> 00:15:29,910
and you put it in an envelope.

412
00:15:29,910 --> 00:15:31,890
Inside of that envelope, you're going to put down the address

413
00:15:31,890 --> 00:15:33,390
of who you want to send it to.

414
00:15:33,390 --> 00:15:36,000
Now, before you send it out, you're actually going to tunnel it

415
00:15:36,000 --> 00:15:37,560
by putting it into a second envelope

416
00:15:37,560 --> 00:15:39,630
and putting a different address on it.

417
00:15:39,630 --> 00:15:41,640
Now, when you put that second address on it,

418
00:15:41,640 --> 00:15:43,110
this is going to be a new header,

419
00:15:43,110 --> 00:15:44,760
and this new header has the new source

420
00:15:44,760 --> 00:15:47,250
and destination of the VPN terminating device

421
00:15:47,250 --> 00:15:50,070
at the different site that you want this letter to go to.

422
00:15:50,070 --> 00:15:51,450
When it gets to the other side,

423
00:15:51,450 --> 00:15:54,180
your VPN concentrator will remove the outer envelope,

424
00:15:54,180 --> 00:15:55,680
which is that outer header,

425
00:15:55,680 --> 00:15:58,170
and inside of that will be the network packet

426
00:15:58,170 --> 00:15:59,190
that can be decrypted

427
00:15:59,190 --> 00:16:01,980
and then routed across their private local area network

428
00:16:01,980 --> 00:16:05,160
just as if it came from an internally connected client.

429
00:16:05,160 --> 00:16:06,600
When you're using this tunneling mode,

430
00:16:06,600 --> 00:16:08,790
you're actually encapsulating the entire packet

431
00:16:08,790 --> 00:16:10,080
into a new packet

432
00:16:10,080 --> 00:16:12,210
so you can send it over the public Internet.

433
00:16:12,210 --> 00:16:14,520
This is going to increase the size of your overall packet,

434
00:16:14,520 --> 00:16:18,150
and it could go above the MTU default size of 1,500 bytes.

435
00:16:18,150 --> 00:16:20,700
So if you're going to be using a site-to-site VPN,

436
00:16:20,700 --> 00:16:22,650
you may need to allow jumbo frames

437
00:16:22,650 --> 00:16:25,050
or frames that are bigger than 1,500 bytes

438
00:16:25,050 --> 00:16:26,250
inside of your network

439
00:16:26,250 --> 00:16:29,070
to be able to access this type of tunneling mode.

440
00:16:29,070 --> 00:16:31,770
This way, it'll be able to properly support these packets

441
00:16:31,770 --> 00:16:33,900
that are larger than 1,500 bytes.

442
00:16:33,900 --> 00:16:36,000
Now, if you can't set up jumbo mode,

443
00:16:36,000 --> 00:16:37,260
another way you can do this

444
00:16:37,260 --> 00:16:40,050
is by actually dropping the maximum MTU size

445
00:16:40,050 --> 00:16:42,990
on your inner router to something like 1,400 bytes

446
00:16:42,990 --> 00:16:45,060
and then connecting to the VPN.

447
00:16:45,060 --> 00:16:47,580
This way, you've got an extra 100 bytes of room

448
00:16:47,580 --> 00:16:49,980
between 1,400 and 1,500 bytes

449
00:16:49,980 --> 00:16:51,870
to be able to add that extra encapsulation

450
00:16:51,870 --> 00:16:53,190
and the new packet header

451
00:16:53,190 --> 00:16:55,290
before it's transmitted over the public Internet

452
00:16:55,290 --> 00:16:57,150
inside of your VPN tunnel.

453
00:16:57,150 --> 00:16:59,130
If you control your entire network though,

454
00:16:59,130 --> 00:17:01,140
you can again just use jumbo frames

455
00:17:01,140 --> 00:17:03,630
and actually go up to a size of up to 9,000 bytes

456
00:17:03,630 --> 00:17:06,030
if you wanted to, but this should only be done

457
00:17:06,030 --> 00:17:07,829
on your own local area networks

458
00:17:07,829 --> 00:17:10,170
because 9,000 byte packets will have trouble

459
00:17:10,170 --> 00:17:12,450
traversing the entire Internet.

460
00:17:12,450 --> 00:17:14,550
Now, the final thing we need to discuss in this lesson

461
00:17:14,550 --> 00:17:17,880
is the concept of an AH or Authentication Header,

462
00:17:17,880 --> 00:17:21,150
as well as an Encapsulating Security Payload or ESP

463
00:17:21,150 --> 00:17:23,760
that is used within your IPSec protocol.

464
00:17:23,760 --> 00:17:26,550
Now, the AH or Authentication Header is going to be used

465
00:17:26,550 --> 00:17:28,500
to provide connectionless data integrity

466
00:17:28,500 --> 00:17:31,590
and data origin authentication for IP datagrams,

467
00:17:31,590 --> 00:17:34,260
and it provides protection against replay attacks.

468
00:17:34,260 --> 00:17:36,300
Be aware though that the authentication header

469
00:17:36,300 --> 00:17:38,430
does not provide any kind of confidentiality

470
00:17:38,430 --> 00:17:39,870
of the data itself.

471
00:17:39,870 --> 00:17:41,640
Instead, the authentication header

472
00:17:41,640 --> 00:17:43,830
contains a cryptographic hash of the data,

473
00:17:43,830 --> 00:17:46,560
and this will simply act as identification information

474
00:17:46,560 --> 00:17:48,480
to provide the integrity between the sender

475
00:17:48,480 --> 00:17:51,420
and the receiver of each packet that's being transmitted.

476
00:17:51,420 --> 00:17:54,060
Now, the Encapsulating Security Payload or ESP,

477
00:17:54,060 --> 00:17:55,920
on the other hand, is going to be used to provide

478
00:17:55,920 --> 00:17:58,530
authentication, integrity, replay protection,

479
00:17:58,530 --> 00:18:00,750
and confidentiality of your data.

480
00:18:00,750 --> 00:18:03,030
By using ESP within IPSec,

481
00:18:03,030 --> 00:18:05,070
you can actually rewrite the payload of the packet

482
00:18:05,070 --> 00:18:07,080
inside of an encrypted format.

483
00:18:07,080 --> 00:18:08,460
Now, when we're using ESP,

484
00:18:08,460 --> 00:18:10,950
we're only protecting the confidentiality of the payload

485
00:18:10,950 --> 00:18:12,570
that's contained within the packet,

486
00:18:12,570 --> 00:18:14,160
not the headers themself.

487
00:18:14,160 --> 00:18:16,200
So if you're using transport mode,

488
00:18:16,200 --> 00:18:18,120
such as in a client-to-site VPN,

489
00:18:18,120 --> 00:18:19,710
you can use authentication headers

490
00:18:19,710 --> 00:18:22,050
to provide integrity for your TCP header,

491
00:18:22,050 --> 00:18:23,580
and then you can add ESP

492
00:18:23,580 --> 00:18:25,680
or the Encapsulating Security Payload

493
00:18:25,680 --> 00:18:27,510
to be able to encrypt the TCP header

494
00:18:27,510 --> 00:18:29,760
and the data inside the payload.

495
00:18:29,760 --> 00:18:31,950
This does not encrypt the end-to-end header

496
00:18:31,950 --> 00:18:33,900
so people outside your organization though

497
00:18:33,900 --> 00:18:35,880
will be able to see where the data's coming from

498
00:18:35,880 --> 00:18:37,110
and where it's going to,

499
00:18:37,110 --> 00:18:39,420
but they won't be able to read the data inside.

500
00:18:39,420 --> 00:18:41,040
It's just like if I went to your mailbox

501
00:18:41,040 --> 00:18:42,330
and looked at a letter in there.

502
00:18:42,330 --> 00:18:43,680
I could see who sent you the letter

503
00:18:43,680 --> 00:18:45,180
and I could see that it was sent to you,

504
00:18:45,180 --> 00:18:46,710
but I don't know what's inside that letter

505
00:18:46,710 --> 00:18:48,990
because I haven't opened up the envelope.

506
00:18:48,990 --> 00:18:50,520
Now, if you're using the tunneling mode,

507
00:18:50,520 --> 00:18:52,410
such as in a site-to-site VPN,

508
00:18:52,410 --> 00:18:54,537
you can instead use both the authentication header

509
00:18:54,537 --> 00:18:56,520
and the encapsulated security payload

510
00:18:56,520 --> 00:18:59,070
to provide integrity and encryption of that payload,

511
00:18:59,070 --> 00:19:00,840
including the end-to-end header.

512
00:19:00,840 --> 00:19:03,300
In this case, a new IP header is going to be added

513
00:19:03,300 --> 00:19:05,250
to the front of the packet to cover the hops

514
00:19:05,250 --> 00:19:07,350
to the other end of the secure connection.

515
00:19:07,350 --> 00:19:09,000
This means that nobody on the Internet

516
00:19:09,000 --> 00:19:11,460
will be able to see the source or destination of the traffic

517
00:19:11,460 --> 00:19:13,530
within your organization's internal networks

518
00:19:13,530 --> 00:19:15,870
on either side of that VPN connection.

519
00:19:15,870 --> 00:19:17,250
So remember, when it comes

520
00:19:17,250 --> 00:19:18,930
to securing network communications,

521
00:19:18,930 --> 00:19:22,440
we usually rely on a VPN, TLS, or IPSec

522
00:19:22,440 --> 00:19:24,900
to ensure the data remains safe from prying eyes

523
00:19:24,900 --> 00:19:27,630
as it traverses over an untrusted or insecure network

524
00:19:27,630 --> 00:19:28,890
like the Internet.

525
00:19:28,890 --> 00:19:30,960
A VPN or Virtual Private Network

526
00:19:30,960 --> 00:19:32,370
is a secure and encrypted connection

527
00:19:32,370 --> 00:19:34,770
between a user's device and a remote server

528
00:19:34,770 --> 00:19:35,700
that allows for private

529
00:19:35,700 --> 00:19:37,740
and anonymous access to the Internet.

530
00:19:37,740 --> 00:19:40,320
A client-to-site VPN will allow individual users

531
00:19:40,320 --> 00:19:42,060
to remotely connect to a secure network,

532
00:19:42,060 --> 00:19:44,970
while a site-to-site VPN establishes a secure connection

533
00:19:44,970 --> 00:19:47,190
between two separate network locations.

534
00:19:47,190 --> 00:19:49,770
A clientless VPN is a remote access solution

535
00:19:49,770 --> 00:19:51,750
that's going to allow users to securely access

536
00:19:51,750 --> 00:19:54,000
network resources using a web browser

537
00:19:54,000 --> 00:19:56,970
without the need for a dedicated piece of client software

538
00:19:56,970 --> 00:19:59,700
that's going to rely on the Transport Layer Security protocol

539
00:19:59,700 --> 00:20:01,080
for its encryption.

540
00:20:01,080 --> 00:20:03,750
IPSec or the Internet Protocol Security Suite

541
00:20:03,750 --> 00:20:05,250
is a suite of protocols that's used

542
00:20:05,250 --> 00:20:08,100
to secure Internet protocol communications by authenticating

543
00:20:08,100 --> 00:20:11,040
and encrypting each IP packet in the data stream.

544
00:20:11,040 --> 00:20:12,450
IPSec can be configured

545
00:20:12,450 --> 00:20:14,730
to use either transport mode or tunneling mode.

546
00:20:14,730 --> 00:20:16,350
Transport mode is normally going to be used

547
00:20:16,350 --> 00:20:18,000
for client-to-site VPNs,

548
00:20:18,000 --> 00:20:19,710
while tunneling mode is normally going to be used

549
00:20:19,710 --> 00:20:21,450
for site-to-site VPNs.

550
00:20:21,450 --> 00:20:23,610
These different tools and protocols are going to be used

551
00:20:23,610 --> 00:20:24,810
to help encrypt our data

552
00:20:24,810 --> 00:20:27,030
and to protect it against any potential eavesdropping

553
00:20:27,030 --> 00:20:29,790
or modifications as it transits across the Internet

554
00:20:29,790 --> 00:20:31,413
and other insecure networks.

