Chapter 34: VPN Technologies
This chapter follows the topics shown in the Networking chapter menu. Work through each section in order, then use the review questions to check recall and troubleshooting reasoning.
34.1 VPN Overview
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.2 Remote-Access VPN
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.3 Site-to-Site VPN
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.4 VPN Tunnel
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.5 IPsec
IPsec protects IP traffic using security associations, authentication and encryption mechanisms. IKE commonly negotiates keys and parameters for IPsec security associations.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.6 IKE
IKE is one of the core topics in VPN Technologies. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place IKE in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.7 UDP 500
UDP 500 identifies transport protocol UDP port 500. Port numbers identify application endpoints; a firewall or capture filter must also consider direction, state, and the complete conversation rather than the number alone.
Example: place UDP 500 in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.8 NAT-T
NAT changes IP address information as traffic crosses a translation boundary. PAT is a many-to-one form that also distinguishes conversations by transport-layer port numbers.
Example: place NAT-T in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.9 UDP 4500
UDP 4500 identifies transport protocol UDP port 4500. Port numbers identify application endpoints; a firewall or capture filter must also consider direction, state, and the complete conversation rather than the number alone.
Example: place UDP 4500 in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.10 ESP
ESP is one of the core topics in VPN Technologies. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place ESP in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.11 AH
AH is one of the core topics in VPN Technologies. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place AH in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.12 Tunnel Mode
Tunnel Mode is one of the core topics in VPN Technologies. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Tunnel Mode in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.13 Transport Mode
Transport Mode is one of the core topics in VPN Technologies. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Transport Mode in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.14 Split Tunneling
Split Tunneling is one of the core topics in VPN Technologies. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Split Tunneling in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.15 Full Tunnel
Full Tunnel is one of the core topics in VPN Technologies. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Full Tunnel in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
34.16 VPN Concentrator
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.17 VPN Authentication
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.18 VPN Routing
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: a router receives a packet for 10.20.30.40 and has several matching routes. It selects the most specific matching prefix, then forwards toward the route's next hop or exit interface if that path is usable.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.19 VPN DNS
DNS translates names into resource records such as IP addresses, aliases, mail-routing information, and service data. Client caching and TTL values affect how quickly changes become visible.
Example: a user can reach 203.0.113.20 but cannot reach server.example by name. That difference points toward name resolution, DNS reachability, record content, cache state, or search-suffix behavior rather than basic IP routing.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
34.20 VPN MTU Troubleshooting
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Confirm the symptom and determine whether the problem affects one host, one segment, one site, or many sites.
- Compare actual configuration and measurements with the intended design, baseline, or documentation.
- Change one variable at a time, verify the result, and document both the cause and the final fix.