Step 1 Specify Interesting Traffic

Interesting traffic is better thought of as traffic that must be protected by the IPsec VPN. When an IPsec VPN tunnel exists between two sites, traffic that is considered "interesting" is sent securely through the VPN to the remote location. Once inside the VPN, the data is safe until it reaches the other end of the tunnel. The traffic cannot be modified without detection, nor can it be read by anyone in the middle (if ESP is employed).
In fact, such traffic can only travel to the other end of the VPN tunnel. It cannot "escape" from the VPN tunnel and travel to some unintended destination. Only the predetermined VPN endpoint has the capability to validate and decrypt such packets.
This concept of interesting traffic also implies that packets that are not interesting do not enjoy the benefits of the IPsec VPN. They are not encrypted or protected in any way. They may travel to any destination, including the remote destination where the VPN tunnel terminates.
An extended access control list (ACL) is used to specify interesting traffic. Traffic that is permitted by this ACL has the appropriate security policy applied to it and the packets then enter the IPsec VPN tunnel. However, if the tunnel does not yet exist, then the arrival of the first interesting packet triggers the events needed to create the tunnel.
The five steps in the lifecycle of an IPsec VPN (explained here) assume that the tunnel does not yet exist and must be built upon the receipt of interesting traffic. It takes only one interesting packet to trigger the IPsec VPN tunnel process. If the IPsec tunnel already exists, then the traffic that is considered interesting (Step 1) is sent through the tunnel (Step 4).
Continue reading here: Step 3 IKE Phase
Was this article helpful?