Solved

What is a VPN Encryption Domain?

Posted on 2003-11-09
5
26,403 Views
Last Modified: 2013-05-23
Hello,
  I'm fairly new to VPNs and was wondering if anyone could shine the light on the meaning of an "encryption domain".  All is making sense in regards to tunneling and termination but the materials I've read thus far fail to elaborate on a term often seen in examples of brief setup parameters.  Are there any links you would recommend to better understand VPNs?  Thank You graciously!  Please Advise!

-JS
0
Comment
Question by:jsablan
5 Comments
 
LVL 1

Accepted Solution

by:
Scott_V earned 25 total points
ID: 9712388
0
 
LVL 3

Assisted Solution

by:UkWizard
UkWizard earned 25 total points
ID: 9712997
In summary, an encryption domain is the term referring to ALL the networks behind the firewall, that are routing though the VPN tunnel.

Eg. Encryption domain may be the 192.168.1.x, 192.168.2.x and 192.168.3.x networks. for example.


Simple as that.

Regards,
UkWizard.
0
 

Expert Comment

by:mvselm
ID: 9776919
The encryption domain refers to a concept where your site to site traffic is send over a virtual connection over an other network. Look at this "drawing"

Lets assume IP and Internet transmission

LAN1 ==> Firewall/VPN-router ====> Internet ====> Firewall/VPN-router ==> LAN2
               encryption here            transmission                decryption here

Now an IP packet from LAN1 is encrypted in the Firewall or VPN router. This  packet becomes then the payload of a new IP packet. This is routed over the Internet (or other transmission network). The payload but generally also the IP header is encrypted. One technique is IPsec tunneling. Encryption protocols like 3DES or AES (AES is much better but 3DES is more commonly used). You need to distribute the keys to both sites. You need to configure the tunnel endpoint (this is for the VPN-router where to send the encrypted traffic). All IP traffic can be routed over IPsec tunnels. But because packets are transmitted as the payload of other packets (this is called encapsulation) you add some extra overhead. Another header is added. Also the MTU (maximum transmission unit) reduces because now you have a payload + header + another header. Also remember that when you use protocols that generate small packets, like VoIP, that the extra  overhead more or less doubles the packet size so you  VoIP now needs twice the BW. All major router and FW vendors support this.

Another concept  is ISDN VPN techniques. Here is generally only the B-channel encrypted. So you can dial anywehre (unless the ISDN crypto uses a list of allowed numbers). The signalling is untouched (it can be filtered and/or proxied) but the B-channel is encrypted. There are various commercial ISDN cryptos on the market.

Hope this helps. Marc
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question