Understanding Cisco SSL VPN vs IPSec VPN

Поділитися
Вставка
  • Опубліковано 28 гру 2024
  • This video is from the Cisco SIMOS class at Stormwind Live, in this section we explore the differences between the newer SSL VPN and legacy IPsec VPN

КОМЕНТАРІ • 76

  • @PrashantSharma-ql4yb
    @PrashantSharma-ql4yb 9 років тому +37

    Beautiful beautiful video!!!!
    This is what I call real treasure. Pure knowledge.
    Thank you Sir!!
    Please keep on posting.

    • @RyanLindfield
      @RyanLindfield  9 років тому +7

      +Prashant Sharma Thanks for your kind words, happy it was helpful.

  • @ciscoguru2007
    @ciscoguru2007 4 роки тому +1

    Hi Ryan, Great job articulating key difference between SSL and IPSec VPN protocols. Thanks

  • @aironaldana4638
    @aironaldana4638 2 роки тому +1

    This is very CLear! Thank you for this Video

  • @alancisnerosmonreal3119
    @alancisnerosmonreal3119 2 роки тому

    Man you don't know how much you've helped me with this, thank you very much for your knowledge !!

  • @suleimansalau3100
    @suleimansalau3100 8 років тому

    Not only do you know your stuff; you are very good at transferring knowledge; great video. I learned a lot from your videos.

  • @RanaShahid87
    @RanaShahid87 4 роки тому

    Perfectttttttt. I read alot of blogs and thought I knew the answers and you surprised me.

  • @chriscowboyfan
    @chriscowboyfan 8 років тому +2

    Outstanding discussion. Learned a lot. Thank you

  • @laurentpilot
    @laurentpilot 2 роки тому +1

    Many thanks Ryan ! brillant explanations !

  • @fiddycaliber947
    @fiddycaliber947 6 років тому +1

    Needed a quick refresher, very well explained, thanks Ryan!

  • @garv_chawla
    @garv_chawla 5 років тому +2

    This is amazing.
    Beautifully explained.

  • @chandrakantrai
    @chandrakantrai 7 років тому +1

    Excellent explanation. Thanks Ryan

  • @rayang9929
    @rayang9929 5 років тому

    Thank you very much for this video, always helps me revise for situations on demand.

  • @jaski8143
    @jaski8143 3 роки тому

    Gold content right here

  • @mrobjectoriented
    @mrobjectoriented 5 років тому

    Awesome! Very informative and to the point!

  • @vorpalmusic
    @vorpalmusic 9 років тому +2

    Excellent! Extremely helpful overview.

  • @abdultaqi34
    @abdultaqi34 6 років тому +1

    A very beneficial video Must thank you for your knowledge sharing

  • @pragyanidhi2264
    @pragyanidhi2264 5 років тому +1

    Very good explanation.. keep it up

  • @jaggs05
    @jaggs05 8 років тому +1

    You rock mate.... simply the best.

    • @RyanLindfield
      @RyanLindfield  8 років тому

      +Jagdeep Gambhir Thanks for watching glad it helped :)

  • @MrArunbabuc
    @MrArunbabuc 8 років тому

    Thanks a lot for such a session.. very useful indeed

  • @Gabru-RJ
    @Gabru-RJ 4 роки тому +1

    awesome explanation

  • @garyfrazier614
    @garyfrazier614 9 років тому +1

    This was very helpful. I have been unsure about IPsec vs SSL security differences. I have setup a IPsec vpn connection for my office. As I read about the two, it seems SSL is more popular. It makes more sense now that it was broken down into the OSI layers and all. I think I'll stay with my IPsec vpn connections now.

    • @RyanLindfield
      @RyanLindfield  9 років тому +1

      Gary Frazier SSL works more reliably for remote users because when they travel they'll most likely be able to get out over TCP 443 vs UDP 4500 (NAT-T). We can't control the firewalls of remote airports, hotels, conference centers etc, so TCP443 is the way to go :)

  • @scottminnella1880
    @scottminnella1880 7 років тому +1

    Excellent stuff.

  • @phoonjzc
    @phoonjzc 3 роки тому

    Why the esp port number disappeared?

  • @geetanjalisapar2277
    @geetanjalisapar2277 4 роки тому

    Best explanation ever got!!Thank you so much sir...

  • @Arshar
    @Arshar 4 роки тому

    You were going good until 12:35.. the flow broke and I had wo watch again and again, to catch u, 2nd thing I would never have understood what u were saying about tcp retransmissions related to vpn just few secs later if I had not watched TCP- meltdown video by computerphile.. good video btw, pratical examples make it better.. good.. make more. could u do one on ssh tunneling and similar ?

  • @リンゴ酢-b8g
    @リンゴ酢-b8g 2 роки тому

    Als SSL-VPN (englische Schreibweise: SSL VPN ohne durchkoppelnden Bindestrich) bezeichnet man Systeme, die den Transport privater Daten über öffentliche Netzwerke ermöglichen (siehe VPN) und als Verschlüsselungsprotokoll TLS (alte Bezeichnung: SSL) verwenden. Prinzipiell ist SSL als Verschlüsselungsprotokoll für VPN sowohl für Site-to-Site- als auch End-to-Site-VPNs geeignet. In den 1990er-Jahren gab es Systeme, die SSL als Sicherungsschicht für Site-to-Site-VPNs einsetzten. Mit der Entwicklung von IPsec und der zunehmenden Vernetzung über Organisationsgrenzen hinaus hat das standardisierte, interoperable IPsec sich als Alternative etabliert.
    Der entscheidende Vorteil von SSL-VPN gegenüber IPsec ist die Bereitstellung des Netzwerk- und Applikationszugriffs für mobile Anwender, da die Konfiguration der Clients einfacher möglich ist als mit einer Lösung durch IPsec.
    de.wikipedia.org/wiki/SSL-VPN

  • @abdulfattahassad6228
    @abdulfattahassad6228 4 роки тому

    Thanks Ryan for Simplicity and make an unobvious issue to be cleared. But still I have quesiton regards SSL / TLS . SSL is in application layer which use TCP 443 as Transport Layer . so thats mean TLS should in Application layer NOT Transport Layer ? am I right. please explain

    • @RyanLindfield
      @RyanLindfield  4 роки тому

      SSL is in the presentation layer, layer 6, this is where the "work" takes place. As far as allowing SSL VPN traffic, it's Default TCP 443 and there is also a more efficient D-TLS (Datagram) which uses UDP.
      DTLS is efficient however it requires firewall admins to allow their guest networks to pass UDP 443.

  • @LuckyLuke_de
    @LuckyLuke_de 10 років тому +1

    Very detailed good explanation, but I would always prefer a IPSec IKEv2 connection over a SSL one ;-)

  • @andresfx28
    @andresfx28 6 років тому

    Crystal clear. Thank you sir.

  • @muhammad.rafi2012
    @muhammad.rafi2012 9 років тому

    Thanks Rhyan for awesome knowledge transfer, do you have more videos on either security or RS/DC ?

  • @nadzimnor3880
    @nadzimnor3880 10 років тому +1

    Thanks for video upload..clear and simple to understand

  • @ChaoMridu
    @ChaoMridu 4 роки тому +1

    Hi sir..m confused..doesn't esp have a port number, 50.. wat was the need of a udp overhead..plz help

    • @RyanLindfield
      @RyanLindfield  4 роки тому +1

      Protocol numbers are different than port numbers.
      If you look at a picture of an IP header you'll see it has a PROTOCOL field, that field holds a number, like 17 , which would mean UDP.
      When an IP packet is being processed the computer uses the protocol field to know how to decode layer 4.
      This is really confusing at first, hope that helped.

    • @ChaoMridu
      @ChaoMridu 4 роки тому

      @@RyanLindfield Ty Sir.. I will read more on it and then get back to you if I need any further clarification

  • @rubenjaldinsalvatierra6337
    @rubenjaldinsalvatierra6337 9 років тому

    hello ryan i have a good question please help me to figure out. in a sesión SSL is a fact that you have a public key within the digital certificate that the server send you. and the server has the private Key. is a fact that you (the user) encrypt with the public key and the only one who can DesEncrypt is the server. my doubt is somebody inside my swicht with wireshark capture a Packet from the server to the user (first) and me (the second user) with the public key that i got because is a public key can DesEncrypt that Packet ?? and see the data that the server is sending to the First User ??

  • @tjcreek5556
    @tjcreek5556 9 років тому +1

    This is a great video! Thank you.

  • @WoundedEgo
    @WoundedEgo 7 років тому

    Hey, can you please tell me if there is a piece of vpnssl hardware that I can buy that will not require me to subscribe to a monthly service? This is for safe internet browsing, not for corporate connectivity.Thanks.

  • @subhsamal5948
    @subhsamal5948 9 років тому

    why it is not possible to configure site to site vpn using ssl ?

  • @sudiptakp
    @sudiptakp 8 років тому +1

    Very informative...

  • @vishalkalal9657
    @vishalkalal9657 8 років тому

    +Ryan Lindfield
    Hello Ryan, thanks for your efforts, I think this video is continuation of another video. So, can you please provide a link for that video (if at all there is any). Thanks

  • @veerakumardevireddy2884
    @veerakumardevireddy2884 5 років тому +1

    Nice video

  • @zyk_mt
    @zyk_mt 6 років тому

    perfect explaination!! many thanks

  • @jordanaldrich
    @jordanaldrich 6 років тому

    Awesome video

  • @dmezzio
    @dmezzio 3 роки тому

    Geniuss.. thanks man

  • @julianmolina4806
    @julianmolina4806 4 роки тому

    Hola: Tengo el Corporativo y las sucursales unidos por VPN todos, uso escritorio remotos para el RP en todas las sucursales. quiero conectarme al server desde las sucursales usando el Nombre del Servidor y No la dirección ip. En el corporativo si me conecto al Server desde la misma LAN interna usando el nombre del SERVER, pero cuando quiero conectarme desde una sucursal usando el nombre del server no me resuelve, no lo encuentra el escritorio remoto a través de conexión VPN, solamente con la dirección IP funciona. Que se puede hacer para que el nombre del Server este publico a través de las VPN ?? Gracias

  • @NextGennGaming
    @NextGennGaming 8 років тому +1

    Thank you so much

  • @kumarchinthaginjala5610
    @kumarchinthaginjala5610 7 років тому

    Excellent!!!

  • @LayneSadler
    @LayneSadler 10 років тому +1

    wow, thank you so much!

  • @lucaspascual5956
    @lucaspascual5956 6 років тому

    Thank you Sr.

  • @globaleducationnetworklear6000
    @globaleducationnetworklear6000 7 років тому

    Excellent

  • @giovannimercuri5168
    @giovannimercuri5168 7 років тому +1

    Awesome video, thanks Ryan. Also...I just gave this video a thumbs up and it was thumbs up number 443...get it?

  • @RanaShahid87
    @RanaShahid87 4 роки тому +1

    Instructor speaking style is so much similar to Khawar Butt....

  • @Rubded
    @Rubded 5 років тому

    Your videos are A+ quality.

  • @freddiemunoz4443
    @freddiemunoz4443 8 років тому

    Great!!!!!!!!!!!!!

  • @engineermuhammad3936
    @engineermuhammad3936 8 років тому

    its pretty informative....😉

  • @syedmobeen981
    @syedmobeen981 5 років тому +1

    GURU ... GOD BLESS "_)

  • @boydseabiscuit2635
    @boydseabiscuit2635 8 років тому

    that's a quiet class

  • @relikpL
    @relikpL 7 років тому

    Sounds a bit like you're selling Cisco. OpenVPN works everywhere and is faster and much easier to set up. Managing and configuring ASAs is a nightmare.

  • @rudranarayanbiswal9853
    @rudranarayanbiswal9853 2 роки тому +1

    your explanation is not that much clear. new engineer can not understand. only experienced engineer can understand. if some one experienced, then why does he need your video?

  • @Bob_Bikes
    @Bob_Bikes 5 років тому

    Learn to spell, dude.

  • @birolgormez2705
    @birolgormez2705 2 роки тому

    A company wants to implement a large number of WAPs throughout its building and allow
    users to be able to move around the building without dropping their connections Which of the
    following pieces of equipment would be able to handle this requirement?
    (A). A VPN concentrator
    (B). A load balancer
    (C). A wireless controller
    (D). A RADIUS server