Soru

Zorluk: OrtaRemote Access and Site-to-Site VPN Concepts

Match each VPN operational feature or protocol component on the left with its corresponding functional description on the right.

  • Dead Peer Detection (DPD)Monitors the liveness of an established IPsec tunnel by sending periodic keepalive messages to detect gateway failure.
  • Split TunnelingDirects remote client traffic destined for internal corporate networks through the encrypted tunnel while sending internet-bound traffic directly through the local ISP.
  • Authentication Header (AH)Provides connectionless data integrity and origin authentication for IP packets, but explicitly lacks data confidentiality through encryption.
  • Dynamic Multipoint VPN (DMVPN)Combines GRE, NHRP, and IPsec to dynamically build on-demand spoke-to-spoke IPsec tunnels across an enterprise WAN.

Cevap

Dead Peer Detection matches with monitoring tunnel liveness via keepalives; Split Tunneling matches with selectively routing corporate traffic through the tunnel while internet traffic bypasses it; Authentication Header matches with providing integrity and authentication without data encryption; Dynamic Multipoint VPN matches with leveraging GRE, NHRP, and IPsec to dynamically establish spoke-to-spoke tunnels.
Each feature corresponds to its specific technical function in VPN architecture: Dead Peer Detection detects dead VPN peers via keepalives; Split Tunneling optimizes bandwidth by routing only targeted subnets over the VPN; Authentication Header provides integrity without encryption; Dynamic Multipoint VPN uses mGRE and NHRP for dynamic spoke-to-spoke WAN connectivity.

Adım Adım Çözüm

1
Analyze Dead Peer Detection (DPD)
Identify that DPD handles connection liveness monitoring using hello/keepalive messages between IPsec peers.
VPN gateways need a mechanism to reclaim security association resources when a peer unexpectedly crashes or loses power.
2
Analyze Split Tunneling
Identify that split tunneling separates corporate-bound traffic (sent inside the VPN) from general internet traffic (sent outside the VPN).
This conserves central corporate internet bandwidth while maintaining secure access to private enterprise resources.
3
Analyze Authentication Header (AH)
Identify that AH provides integrity and authentication for the whole packet, but does not provide encryption (confidentiality).
AH (IP protocol 51) computes a hashed MAC over packet headers and payload, whereas ESP (IP protocol 50) is required for encryption.
4
Analyze Dynamic Multipoint VPN (DMVPN)
Identify that DMVPN combines mGRE, NHRP, and IPsec to form on-demand site-to-site tunnels dynamically.
DMVPN scales enterprise WAN topologies by allowing spokes to communicate directly without hair-pinning traffic through the hub.

Anahtar Kavram

Remote Access and Site-to-Site VPN Components & Operation
Bu soruyu puanla