Which protocol provides data confidentiality, integrity, and origin authentication for IP packets in a VPN tunnel?
Trap 1: AH (Authentication Header)
AH provides authentication and integrity for the packet, but it lacks encryption functionality. Because it does not provide data confidentiality, it is rarely used in modern VPN implementations, as traffic remains visible to anyone capturing the packets on the transit path.
Trap 2: GRE (Generic Routing Encapsulation)
GRE is a tunneling protocol used to wrap various layer-3 protocols, but it provides no inherent security, encryption, or authentication. When used for VPNs, it must be combined with IPsec to provide the necessary security features that ESP provides natively.
Trap 3: L2TP (Layer 2 Tunneling Protocol)
L2TP is a tunneling protocol used for remote access, but it does not provide encryption on its own. It is typically paired with IPsec to secure the tunnel, making it a transport mechanism rather than the security protocol itself.
- A
AH (Authentication Header)
Why it fails: AH provides authentication and integrity for the packet, but it lacks encryption functionality. Because it does not provide data confidentiality, it is rarely used in modern VPN implementations, as traffic remains visible to anyone capturing the packets on the transit path.
- B
IKE (Internet Key Exchange)
ESP is the primary protocol that actually carries the encapsulated, encrypted payload. While IKE negotiates the keys, ESP is the protocol that performs the actual encryption, authentication, and integrity checking of the user data packets as they transit the VPN tunnel.
- C
GRE (Generic Routing Encapsulation)
Why it fails: GRE is a tunneling protocol used to wrap various layer-3 protocols, but it provides no inherent security, encryption, or authentication. When used for VPNs, it must be combined with IPsec to provide the necessary security features that ESP provides natively.
- D
L2TP (Layer 2 Tunneling Protocol)
Why it fails: L2TP is a tunneling protocol used for remote access, but it does not provide encryption on its own. It is typically paired with IPsec to secure the tunnel, making it a transport mechanism rather than the security protocol itself.