Home > Ask the Networking Experts > VPNs with Lisa Phifer Questions & Answers > What is the difference between an IPsec tunnel and a normal tunnel, and what is the bandwidth of each?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

What is the difference between an IPsec tunnel and a normal tunnel, and what is the bandwidth of each?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 April 2004
I have a Fast Ethernet connection to my ISP that I've configured to support three IPsec tunnels and three normal tunnels. What is the bandwidth of each tunnel? Can I configure the bandwidth for each tunnel? What is the difference between an IPsec tunnel and a normal tunnel?

>
EXPERT RESPONSE
Methods commonly used to tunnel traffic include IP-in-IP and the Generic Routing Encapsulation (GRE). I suspect that your "normal tunnels" are using one of these methods to carry IP packets from one network to another without regard to the network topology that lies between them. These methods simply wrap an inner IP packet inside an outer IP packet. Routers encountered between the tunnel endpoints look only at the outer IP packet header to determine whether and how to forward the packet towards the outer destination. The inner IP headers are only used once the packet reaches the outer destination IP. There, the outer headers are stripped before the packet is forwarded towards the inner destination. For example, inner IP headers may contain private (non-routable) addresses like 192.168.0.x or 10.x.x.x. Tunneling lets a privately-addressed packet to traverse a public network like the Internet or your ISP's backbone network.

Psec can be used in tunnel mode or transport mode, but most VPNs use IPsec in tunnel mode. IPsec in tunnel mode works just like I've described with respect to encapsulation and traversing intervening networks. But IPsec ALSO uses security measures to protect the inner IP packet from eavesdropping, replay, insertion, or modification. For example, IPsec ESP in tunnel mode encrypts the entire inner packet (including the inner packet's IP header) so that nobody in between can see the ultimate source or destination, type of application, or data payload. IPsec ESP and AH in tunnel mode use a hashed message authentication code to detect any change to the inner IP packet. Your "normal tunnels" probably do not have this type of cryptographic protection, which means that someone could inject modified packets or intercept your data in transit. If you are sending confidential information and need to be sure that no one (including your ISP) can tamper with that information, you should use IPsec tunnels.

Bandwidth management is independent of tunneling method. Products without bandwidth management features don't allocate any specific bandwidth to each tunnel -- all tunnels share the aggregate bandwidth of the data link, first-come first-serve. On the other hand, if your firewall or router provides bandwidth management, it may do so in a wide variety of ways. It might let you prioritize tunnels so that one tunnel gets "first dibs" on available bandwidth (i.e., packets for that tunnel get processed first). Or it might let you assign a maximum throughput to each tunnel, or possibly burstable throughputs. For example, if your link supports 100 Mbps, you might configure a 10 Mbps limit for each of your 6 tunnels. Depending on the product, the tunnels might share any unused capacity on a FCFS or priority basis, or spare capacity might go unused if 10 Mbps is treated as an absolute upper bound. Because bandwidth management features vary widely and are product specific, you'll need to consult your firewall or router's documentation to learn about bandwidth controls (if any) applied to your tunnels.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
VPN Troubleshooting
Problem connecting to virtual private network (VPN) through Linksys router
How to maintain corporate VPN connection while printing to a private network
Can I set up a VPN on my wireless router?
How can I get our VPN to work on Windows Vista?
To set up a VPN server, do you need two NIC cards?
How do I connect to our VPN with authentication ID?
What causes my overseas VPN connection to slow during the day?
Why has the terminal server ended my connection?
How can I access each device from my network while keeping the companies' networks secure?
VPN operating system interoperability -- Configure VPNs with Windows, Checkpoint

VPNs with Lisa Phifer
Would you consider a Microsoft VPN tunnel through a WEP encrypted access point to be secure?
I've heard rumors that some service providers can see unencrypted VPN traffic of their customers. Is this true?
I need to select a Cisco ADSL router which is capable of acting as a VPN server for Microsoft VPN clients that come through the Internet.
I am having issues with the IKE communication between the two Cisco VPN concentrators.
What about using SSL VPN with e-mail clients?
Can you have two VPN connections to the same machine simultaneously?
Why can't I access my folders on the server through the VPN?
I need a very basic VPN solution to connect two offices to allow two servers to talk to one another.
Can one use VPN over a peer-to-peer network within a home?
After setting up my wireless router, I can no longer get on the VPN.

Remote Access VPNs
Problem connecting to virtual private network (VPN) through Linksys router
Direct transport VPN configuration
Cisco Virtual Office gives remote workers simple and secure access
Split-tunnel Cisco IPsec VPN gateway with software client
Full-crypto Cisco IPsec VPN gateway with software client
IPsec VPN router configuration: The ISAKMP policy
IPsec VPN authentication: Generating and exchanging pre-shared keys
VPN gateway router configuration using transform sets
VPN gateway router configuration using static and dynamic crypto maps
IPsec protocol details for implementing VPNs
Remote Access VPNs Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
virtual systems management  (SearchNetworking.com)
VPN appliance  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts