Network Data Encryption

To safeguard your network data, Cisco provides network data encryption and route authentication services in Cisco IOS Software. This section briefly discusses how route authentication in OSPF is done and how it can benefit your network.

Network data encryption is provided at the IP packet level. IP packet encryption prevents eavesdroppers from reading the data that is being transmitted. When IP packet encryption is used, IP packets can be seen during transmission, but the IP packet contents (payload) cannot be read. Specifically, the IP header and upper-layer protocol (TCP or UDP) headers are not encrypted, but all payload data within the TCP or UDP packet is encrypted and therefore is not readable during transmission.

The actual encryption and decryption of IP packets occurs only at routers that you configure for network data Intermediate routers do not participate in encryption/decryption.

Typically, when an IP packet is initially generated at a host, it is unencrypted (cleartext). This occurs on a secured (internal) portion of your network. Then when the transmitted IP packet passes through an encrypting router, the router determines if the packet should be encrypted. If the packet is encrypted, the encrypted packet travels through the unsecured

network portion (usually an external network such as the Internet) until it reaches the remote peer-encrypting router. At this point, the encrypted IP packet is decrypted and forwarded to the destination host as cleartext. Further discussion on the proper techniques and process involved in deploying data encryption in your network is beyond the scope of this book.

NOTE By requiring the routers to encrypt data, you are adding overhead to the routers' processing load.

You should first test this to ensure that the routers in your network can handle the added load.

Router authentication enables peer-encrypting routers to positively identify the source of incoming encrypted data. This means that attackers cannot forge transmitted data or tamper with transmitted data without detection. Router authentication occurs between peer routers each time a new encrypted session is established. An encrypted session is established each time an encrypting router receives an IP packet that should be encrypted (unless an encrypted session is already occurring at that time).

TIP Encryption is applied to your data only after it leaves the router because that is the device that applies the encryption. This is important because the data travels from the host to the router in an unsecured format. Of course the depends rule hits again here as it certainly is possible in today's processing environment that the host will do its own encryption.

To provide IP packet encryption with router authentication, Cisco implements the following standards: the Digital Signature Standard (DSS), the Diffie-Hellman (DH) public key algorithm, and the DES. DSS is used in router authentication. The DH algorithm and DES are used to initiate and conduct encrypted communication sessions between participating routers.

Continue reading here: OSPF Authentication

Was this article helpful?

0 0

Readers' Questions

  • terzo
    Which protocol is used to encrypt data as it travels a network?
    8 months ago
  • Secure Socket Layer (SSL) or its successor, Transport Layer Security (TLS) are the most commonly used protocols for encrypting data as it travels a network.