Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Getting Started with FortiGate

You're reading from   Getting Started with FortiGate This book will take you from complete novice to expert user in simple, progressive steps. It covers all the concepts you need to administer a FortiGate unit with lots of examples and clear explanations.

Arrow left icon
Product type Paperback
Published in Nov 2013
Publisher Packt
ISBN-13 9781782178200
Length 126 pages
Edition 1st Edition
Concepts
Arrow right icon
Toc

FortiGate IPsec VPN


In the section where we introduced the SSL VPN, we said that looking at the TCP/IP protocol stack, usually the delivery protocol is located on a higher level than the payload protocol. This statement is not valid for the next type of VPN, which will be discussed. An IPsec VPN secures each IP (Internet Protocol) packet with authentication and encryption. IPsec uses two different protocols: AH and ESP, to provide authentication, integrity, and confidentiality of the communication. Basic operations related to IPsec include:

  • Transport mode: Only the payload of the IP datagram is handled by IPsec, which inserts the header between the IP header and the upper levels.

  • Tunnel mode: This is used to protect the entire IP datagram. This is the base of an IPsec VPN that creates a "Layer 3 tunnel". The original packet is encapsulated in a new IP packet (the header of the new packet is IPsec).

In the following diagram we have a schema that shows an original packet compared with the packets...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image