Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A network engineer is configuring a site-to-site IPsec VPN tunnel between two Cisco routers. The engineer wants to ensure that the integrity of the data is maintained and that the data is encrypted during transit. Which two components are essential to achieve these goals within the IPsec transform set?
- AAuthentication algorithm and encryption algorithm
- BAuthentication Header (AH) and Internet Key Exchange (IKE)
- CPre-shared key and Diffie-Hellman group
- DSecurity Association (SA) and Security Policy Database (SPD)
Show answer & explanationAnswer & explanation
Correct answer: A. Authentication algorithm and encryption algorithm
Within an IPsec transform set, an authentication algorithm (e.g., HMAC-SHA, HMAC-MD5) is used to ensure data integrity and authenticity, while an encryption algorithm (e.g., AES, 3DES) is used to provide confidentiality and encrypt the data.
Why the other options are wrong
- B. AH provides integrity but not encryption. IKE is a protocol for key management, not part of the transform set itself.
- C. Pre-shared key is for authentication during IKE Phase 1, and Diffie-Hellman is for key exchange. Neither is part of the transform set for data integrity/encryption.
- D. SA and SPD are concepts related to IPsec operation, but they are not components configured within a transform set itself.
IPsec Transform Set Components
An IPsec transform set defines how IPsec protects a particular data flow. It combines an authentication algorithm (for integrity/authenticity) and an encryption algorithm (for confidentiality) to be applied to the data.
- Specifies the combination of security protocols (ESP/AH) and algorithms.
- Authentication algorithm ensures data integrity and origin authenticity.
- Encryption algorithm ensures data confidentiality.
Memory trick: Transformations need Algorithms for Authenticity and Encryption!