MicroNugget: IPsec Site to Site VPN Tunnels Explained | CBT Nuggets

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 ก.ย. 2012
  • Start learning cybersecurity with CBT Nuggets. courses.cbt.gg/security
    In this video, CBT Nuggets trainer Keith Barker takes a look at the concepts behind how IPsec site-to-site VPNs work. Keith uses a protocol analyzer to show you the before and after picture of a packet that's been encrypted and transmitted.
    Sending packets in the wild can be dangerous. The Big Bad Internet is just waiting for you to send sensitive or important information so it can be sniffed out and exploited. So any time you send a packet out there, it's a good idea to give it some protection. IPSec lets you do that
    Imagine a company with two geographically separated offices. They want full data networking between the two sites. All the servers and resources of both should be shared fully between the two.
    With high-speed connectivity at both sites, the impulse might be to just send it all over the internet. But that can pose a security risk.
    An IPsec VPN site-to-site tunnel can provide a number of things. First, confidentiality thanks to encryption. Also, integrity - IPsec can confirm that no bits were manipulated in transit. It can even provide authentication and anti-replay support.
    See the benefits of IPsec VPN tunnels and what the packets themselves look like before and after transmission.
    0:25: When you might need a VPN tunnel
    1:00: The risk of using the Internet
    1:45: What are IPsec’s claims to fame?
    2:40: How does it do it?
    3:55: Two perspectives of what the VPN looks like
    5:10: Side-by-side comparison of the encrypted packet
    6:40: Overview
    🌐 Download the Free Ultimate Networking Cert Guide: blog.cbt.gg/i297
    ⬇️ 13-Week Study Plan: CCNA (200-301): blog.cbt.gg/on5i
    Start learning with CBT Nuggets:
    • Intro to Networking | courses.cbt.gg/tuv
    • MPLS Fundamentals | courses.cbt.gg/u7u

ความคิดเห็น • 159

  • @bohemians77
    @bohemians77 10 ปีที่แล้ว +96

    You have a remarkable gift for teaching in plain language; I have watched a few of your videos on YT and gained in understanding, even though I am not an IT novice - I sense you enjoy what you do: thanks for taking the time to assist others.

  • @BijouBakson
    @BijouBakson 4 ปีที่แล้ว +1

    This stuff was pure gibberish before I started studying Cisco; now it's pure gold. Thank you very much CBT Nuggets.

  • @OsvaldoMaria
    @OsvaldoMaria 4 ปีที่แล้ว +7

    Your enthusiasm made this much easier to understand

  • @ShivamMiglani
    @ShivamMiglani 3 ปีที่แล้ว +13

    You teach amazingly well. I can see the hard work you put into first explain the theory and then back it up with a practical example.

  • @AfricanAstro
    @AfricanAstro 5 ปีที่แล้ว +1

    This was incredible. Simple, clear, well-paced, sticks to the subject, practical use-case. Just very well done.

  • @KeithBarker
    @KeithBarker 11 ปีที่แล้ว +1

    You are very welcome Samer!
    Best wishes,
    Keith

  • @KeithBarker
    @KeithBarker 10 ปีที่แล้ว +11

    Hello Ashwin-
    Yes, you've got it. The outside IP header will have the source IP of the VPN gateway sending the packet, with a destination IP header of the remote VPN gateway who will be receiving the packet over the internet. When the receiving router gets the packet, it will de-encapsulate and throw away the old outside header, decrypt the contents (which include the initial IP header addresses the client was using) and continue to route the packet.
    Keith

  • @chickenman1176
    @chickenman1176 2 ปีที่แล้ว +1

    Thank you for not having a monotone voice!

  • @felipegrings9357
    @felipegrings9357 2 ปีที่แล้ว +2

    Simple. Easy to Understand. Straight to the point. Awesome!

  • @jairusan
    @jairusan 5 ปีที่แล้ว

    Best of the best! Super simplified nugget, this is the best explanation of IPsec I have seen, very informative and useful. Thank you so much, Keith!

  • @guerrillafocus
    @guerrillafocus ปีที่แล้ว +1

    AH would've been good to mention as well. You do teach very well Keith!

  • @ArindamChattopadhya
    @ArindamChattopadhya 4 ปีที่แล้ว

    Your style of explaining is second to none. 👍🙏🙏🙏

  • @ksbpsb
    @ksbpsb 11 ปีที่แล้ว +3

    great job by keith barker and one of the best trainer on the internet

  • @elpidiagomez3701
    @elpidiagomez3701 5 ปีที่แล้ว

    Thanks for the vid Mr. Barker...you take complicated topics and explain them so i can understand, keep up the great work!!

  • @AshwinRamdin
    @AshwinRamdin 10 ปีที่แล้ว

    Hi Keith, thank you for taking the time and answering my question. Great video!

  • @agustinothadeus
    @agustinothadeus 5 ปีที่แล้ว

    The way you explain it makes it seem so easy to the point where it becomes funny!!, thank you

  • @KasunMadurasinghe
    @KasunMadurasinghe ปีที่แล้ว

    This is one of the coolest explanations I've seen ..You've got talent.. Kudos

  • @MojoTojoChannel
    @MojoTojoChannel 11 ปีที่แล้ว

    Man you're way of teaching is just awesome.. pls keep on doing what you're doing..

  • @paulykamau
    @paulykamau 4 ปีที่แล้ว +3

    Amazing! I'm blown away. Thank you for the intelligent explanation.

  • @myretarnation
    @myretarnation 9 ปีที่แล้ว

    Great description and even I got. :)
    Very good voice to match the video tutorial. Thanks Keith!!

  • @anastasijat.4138
    @anastasijat.4138 9 ปีที่แล้ว +13

    Awesome video, love your enthusiasm! :)

  • @SarabjitMadan
    @SarabjitMadan 8 ปีที่แล้ว +1

    This was so well illustrated and explained. Thanks

  • @microsoftsarker
    @microsoftsarker ปีที่แล้ว

    This series is awesome.

  • @ManishYadav0719
    @ManishYadav0719 2 ปีที่แล้ว

    You Deserved 5 star ⭐ believe me

  • @Leo-uy4qv
    @Leo-uy4qv ปีที่แล้ว

    Excellent, learned something new. thanks for showing packet tracer working in the background

  • @MrGvui
    @MrGvui 9 ปีที่แล้ว +1

    Thanks so much, really simple and clear explanation.

  • @annehipolito7305
    @annehipolito7305 2 ปีที่แล้ว

    Thanks. Been doing site to site VPN for years now. Still is reliable for small and medium sized businesses :)

  • @thebluegoonie
    @thebluegoonie 3 ปีที่แล้ว +1

    I hadn't realised how old this vid is until I saw the Windows XP Start button! Still good, though, thanks.

  • @YosiFeig
    @YosiFeig 11 ปีที่แล้ว

    Excellent. You did a great job. Simple to understand. Thanks!

  • @manjunathnarendra3854
    @manjunathnarendra3854 7 ปีที่แล้ว

    Thank you sir...You know exactly how to teach things..wonderful video

  • @iMPRE7ed
    @iMPRE7ed 11 ปีที่แล้ว

    Made it so clear and easy! Great job!

  • @tariksotalei4808
    @tariksotalei4808 2 ปีที่แล้ว

    Brilliant video...simple and practical example ...loved it.

  • @pimguilherme
    @pimguilherme 4 ปีที่แล้ว +6

    This is just so fun, thanks man!!

  • @coveysax
    @coveysax 8 ปีที่แล้ว +1

    Subscribed thanks to this video. You sound so happy talking about this lol. Thanks for the vid!

  • @AlexKontent
    @AlexKontent 5 ปีที่แล้ว

    Great tutorial man! Great work, Great examples!

  • @proplemsolver5995
    @proplemsolver5995 11 ปีที่แล้ว

    شكرا للدكتور هيازع البارقي خبير امن نظم المعلومات

  • @ketansanil6046
    @ketansanil6046 10 ปีที่แล้ว

    Great Explanation in Simple Language

  • @vaihi1
    @vaihi1 5 ปีที่แล้ว

    Bro I loved this video. Thank you so much haha you have a gift at teaching simply

  • @MrUglyDave
    @MrUglyDave 4 ปีที่แล้ว

    Thank you so much, so well explained

  • @abhijeetagrawal5817
    @abhijeetagrawal5817 ปีที่แล้ว

    Brilliant.. Thanks a lot for simplifying it.

  • @alitajvidi5610
    @alitajvidi5610 5 ปีที่แล้ว

    Excellent teacher!!! Thanks.

  • @HongeraGideon
    @HongeraGideon 5 ปีที่แล้ว

    How can someone thumb down this video, fantastic explanation.

  • @snehanaik4304
    @snehanaik4304 2 ปีที่แล้ว

    thanks for this detailed explanation with the actual ping request!

  • @johnconnor9787
    @johnconnor9787 5 ปีที่แล้ว

    Great explanation! Thank you!!!

  • @sobc2737
    @sobc2737 3 ปีที่แล้ว

    Thank you for such a great explanation.

  • @GL455_
    @GL455_ 2 ปีที่แล้ว

    Man! You mad helpful! So glad I found ya!

  • @shai2009
    @shai2009 8 ปีที่แล้ว

    very professional video. thanks!

  • @newkool100
    @newkool100 9 ปีที่แล้ว

    thanks. good one. well explained. short and to the point.

  • @johnson554671
    @johnson554671 4 ปีที่แล้ว

    Good Job Keith!

  • @Zehle325
    @Zehle325 10 ปีที่แล้ว +1

    This was great! :D

  • @ahmedabduljabar6269
    @ahmedabduljabar6269 9 ปีที่แล้ว +3

    Keith that was amazing .. many thanks :)

    • @KeithBarker
      @KeithBarker 9 ปีที่แล้ว +3

      Ahmed Abduljabar Thanks for the feedback! It is appreciated.
      -Keith

    • @SuperKirkb
      @SuperKirkb 9 ปีที่แล้ว +2

      Keith Barker
      My best instructor

  • @IkramKhan-gk3wl
    @IkramKhan-gk3wl 7 ปีที่แล้ว

    Dear Sir, you teach very very nice "super nice" than the other

  • @haimbendanan
    @haimbendanan 8 ปีที่แล้ว

    Thank for this video!

  • @techtejas804
    @techtejas804 3 ปีที่แล้ว

    Superb! Got it exact

  • @virajayachit5702
    @virajayachit5702 9 ปีที่แล้ว +1

    Thank you. Awesome work

    • @davidnadon6879
      @davidnadon6879 6 ปีที่แล้ว

      viraj ayachit 🎒😈🍯👨‍👦👚👨‍👦‍👦♥️U.K.

  • @ryutkin
    @ryutkin 8 ปีที่แล้ว +6

    You are amazing! I've never heard someone explain something so well! Brilliant!

  • @fightbackmatix
    @fightbackmatix 11 ปีที่แล้ว

    Great video :) Thanks again!

  • @chechobarbery
    @chechobarbery 10 ปีที่แล้ว +1

    Excelente !!!!!!!!!!! Congrats!!!!!!!!!!!

  • @BJ24hk
    @BJ24hk 11 ปีที่แล้ว

    awesome video thank u so much !

  • @senyk1
    @senyk1 2 ปีที่แล้ว

    Thanks for the video, what did you use to draw on the screen? Is that a pad you can hook up to a computer?

  • @nikl0618
    @nikl0618 10 ปีที่แล้ว +2

    Awesome video, thank you so much!

  • @OnsDlaili1
    @OnsDlaili1 8 ปีที่แล้ว

    so helpful thx !

  • @andrejss
    @andrejss 3 ปีที่แล้ว

    Amazing! Thank you!

    • @cbtnuggets
      @cbtnuggets  3 ปีที่แล้ว

      Our pleasure! Glad you were able to find value in this video! :)

  • @happyshay1977
    @happyshay1977 4 ปีที่แล้ว

    Great facilitated! thanks

  • @markarca6360
    @markarca6360 8 ปีที่แล้ว

    To check the data integrity of the packets as they are sent means they undergo tests like CRC (cyclic redundacy checking).

  • @ryanbarrera2595
    @ryanbarrera2595 5 ปีที่แล้ว

    Hi Keith..What tool are you using in creating your topology? and also the tool you use to capture the packet

  • @jaafarali1417
    @jaafarali1417 11 ปีที่แล้ว

    great and simplified vedio

  • @kingofhavila9850
    @kingofhavila9850 2 ปีที่แล้ว

    Your channel enlighten some dark spots i had in networking, I'd like to thank you I have my network security exam at the end of this month.
    Otherwise, would you tell me what software are you using for the facilitation of the course?

  • @cesarausan
    @cesarausan 10 ปีที่แล้ว

    Muchas Gracias! implementar una VPN.

  • @kracherjon3938
    @kracherjon3938 3 ปีที่แล้ว

    Danke Bre

  • @RaphaelMeyer
    @RaphaelMeyer 8 ปีที่แล้ว

    awesome dude. thx

  • @amankinson7384
    @amankinson7384 10 ปีที่แล้ว

    Great Stuff!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

  • @ashishsontakke
    @ashishsontakke 3 ปีที่แล้ว

    The VPN client installed in our home machines will do the ESP encapsulation at machine itself before it sends to our ISP ? Is that right ? In this example you said Router R1(ISP's router) is doing it.

  • @pablocaiza.
    @pablocaiza. 3 ปีที่แล้ว

    thank you

  • @MaHutchy
    @MaHutchy 7 ปีที่แล้ว +1

    IPSec or OpenVPN, which would you suggest in terms of security?

  • @nemanjajovic2854
    @nemanjajovic2854 8 ปีที่แล้ว

    Very nice !

  • @mitpatel4268
    @mitpatel4268 4 ปีที่แล้ว

    Hi Keith,
    I have a short question. Why do we not use SSL universally/predominantly for VPNs but use IPSec? One good reason to use SSL as opposed to IPSec is the popularity of port on which it works (443). The positive is that it's open everywhere! Am I missing something?? Maybe one similar question should be - What prevents us from using SSL instead of IPSEC protocol suite in Site-to-site tunnels?

  • @KeithBarker
    @KeithBarker 10 ปีที่แล้ว

    The the crypto ACL says any-any, there are 2 challenges. The two peers will need to agree on that to bring up a tunnel, and then secondly, all traffic leaving the VPN peers would be sent to the peer on the other side. There may be some corner cases where something similar to that would work, but for general site to site VPNs it would be a configuration/design error.

  • @josecarlosglz.barron9314
    @josecarlosglz.barron9314 9 ปีที่แล้ว

    good job!

  • @AshwinRamdin
    @AshwinRamdin 10 ปีที่แล้ว

    Hi Keith,
    At around 3:05 you say the packet is going to be encapsulated. Does this mean that the Packet basically has 2 Destination and 2 Source IP adresses, from which only 1 Destination and 1 Source Address are visable when the packet is send over the Internet?

  • @KeithBarker
    @KeithBarker 11 ปีที่แล้ว

    My pleasure! Glad you liked the video.
    Keth

  • @ibarrax3872
    @ibarrax3872 6 ปีที่แล้ว

    THANK YOU !!!!!!!!!!!!!!!!!!!!!!!

  • @erikvandervelden4566
    @erikvandervelden4566 ปีที่แล้ว

    Nice explanation. What i'm missing is: Who to do this? How do i create R1 and R2?
    After all, it's about. How to get this to work.

  • @Jdiddy1792
    @Jdiddy1792 9 ปีที่แล้ว

    How were you able to capture the packets sent from machine to router? Then router to web?

  • @poligon333
    @poligon333 11 ปีที่แล้ว

    Thanks

  • @IQ88612
    @IQ88612 5 ปีที่แล้ว

    hi , thanks for your nice video but, software did you use??

  • @HylianEvil
    @HylianEvil 11 ปีที่แล้ว

    You're awesome.

  • @issiagadiallo3684
    @issiagadiallo3684 9 ปีที่แล้ว

    Hello CBT, This was quit a great one. Could you please share a simulated one with packet tracer or GNS3 what ever ... Please. it will be very helpfull begginers as me :D

  • @AWSwithChetan
    @AWSwithChetan 2 ปีที่แล้ว

    Great video on VPN tunnels. I was trying to setup S2S VPN in AWS and what I did not understand is role of Inside IPv4 addresses (typically 169.254.0.0/16 range). It would be great if you could help me understand what these inside IPs are, why they are used, are these actual IPs?

    • @psyedd
      @psyedd 9 หลายเดือนก่อน

      This is a year late but that looks to be APIPA range. Just google that and I think you'll be good to go

  • @SwooshxWu
    @SwooshxWu 11 ปีที่แล้ว

    That is awesome.

  • @ashleighholmes6670
    @ashleighholmes6670 3 ปีที่แล้ว

    good god this was helpful

    • @cbtnuggets
      @cbtnuggets  3 ปีที่แล้ว

      We're so glad to hear that, Ashleigh! Thank you for learning with us.

  • @Shake_Well_Before_Use
    @Shake_Well_Before_Use 9 วันที่ผ่านมา

    Hi Keith,
    Can u help with something. I have this network that I'm working on packet tracer. I have two sites site A and B. Site A is ASN 10 and B is ASN 20. In the middle is an ISP router on the ASN 50. I use OSPF for the interior routing on my two sites and bgp has been configured successfully on all three routers and I managed to get IP connectivity from hosts on site A to B and vice versa. The thing is when I implemented the IPsec VPN tunnel, the hosts on site A can reach until the router that connects the destination hosts but never reached them. The thing is the pings from a host in A reaches all networks inside site B except the network of the destination host. Like if 192.168.1.0 / 24 is the source network in site A and 192.168.2.0 / 24 is the destination network on B, the hosts on A can reach all networks except the network on which my destination hosts live. Pls help me understand what could have gone wrong

  • @yiannisserpico2646
    @yiannisserpico2646 4 ปีที่แล้ว

    Hi dear teacher. As always, an amazing teaching video, and thank you! Beginning VPN self-studying, why so many companies selling VPN connections? Can't we set up VPNs from both sites using just internet connections of two routers? Thank you!

  • @MrJinsilverx
    @MrJinsilverx 10 ปีที่แล้ว

    Hi, I just wanna ask. What will happen if I use an access-list with permit ip any any in Ipsec VPN? Will the network be able to browse the internet?

  • @semitangent
    @semitangent 3 ปีที่แล้ว

    What I never understood is why a VPN is necessary at all - why not send a regular IP packet with encrypted payload?
    But I am getting the feeling that this is *exactly* what VPN (or rather IPsec) is doing. It always seemed to me that the encapsulation part, which was always presented as one of the two critical components of a VPN (the other being encryption), was a VPN-exclusive thing, but I guess when two PCs in their respective local networks talk to each other, encapsulation is *always* present - is that correct?

  • @metalliciano
    @metalliciano 8 ปีที่แล้ว

    if I get the videos on your CBT Nuggets, would subtitles in my language?

  • @abhyudaychattopadhyay8632
    @abhyudaychattopadhyay8632 8 ปีที่แล้ว

    So.. the routing table of R1 is supposed to contain the entire range of IPs of PCs under R2, or else how does it understand which of the requests are to be encrypted and sent to R2's IP ???? (and vice versa)

  • @MARINADELY777
    @MARINADELY777 11 ปีที่แล้ว

    thanks

  • @viclam1633
    @viclam1633 3 ปีที่แล้ว

    Does Ipsec add latency to voip calls because it has to encrypt the message? When would I turn on or off ipsec? Any help would be appreciated.

  • @hosseinsabouri3121
    @hosseinsabouri3121 4 ปีที่แล้ว

    Thanks. But how do you connect two routers with each other? Do you use Public IP addres forwarding to each Router? For Example....How can i RDP from 172.16.0.2 to 192.168.0.20 ?