
Explore IPsec and IKEv2 internals, learning how the Internet key exchange enables mutual authentication and security associations, with coding exercises to implement IKEv2 features in code.
Explain how IPsec provides a transparent security layer between transport and applications, enabling site-to-site encryption, while IKE authenticates and negotiates security associations for encryption.
Understand how IPsec secures the network layer by delivering confidentiality, integrity, authentication, and anti-replay, using AH and ESP, with ESP adding encryption for data confidentiality.
Compare IKEv2 transport and tunnel modes in IPsec: transport mode preserves IP header while encapsulating payload; tunnel mode encapsulates IP packet with a new IP header and IPsec header.
Compare AH and ESP modes in IPsec, outlining how AH provides authenticity and integrity without encryption, while ESP offers encryption plus authentication in transport and tunnel modes.
Master how security associations and a security policy database govern IPsec packet flow, selecting encryption and authentication per source and destination, with SA and SPD databases determining parameters and processing.
Build an IPv6 IPsec simulator that models a single connection end, implementing a four-state IKEv2 state machine with init, timeout, data, and established states, plus a 1000-packet queue.
Develop a two-dimensional finite state machine for an IPSec IKEv2 simulator, queuing events in a film queue and driving transitions with a PRISM program structure.
https://github.com/aseemsethi/ipsec
Develop a simple finite state machine that processes events from a prism-like state-event queue in a separate thread, driving an IPSec IKEv2 negotiation through a physical routine.
Shows committing a sim.c file to a GitHub repository for the ipsec ikev2 internals course, performing the first commit and push, and previewing IPC data structures initialization.
Introduce the internal IP stack and the first three functions: get self IP address, initiate data socket, and receive packets for a virtual machine setup.
Learn to implement a get self ip address function using a linux socket and the ifr structure to retrieve and print the ip address of the enp0s3 interface.
initialize a data socket, bind it to the interface, configure its address and mac details, and enable promiscuous mode for complete packet capture.
Learn to create and bind a data socket, use promiscuous mode, and validate self and peer IP addresses while preparing the receiver routine.
Learn how pf_packet raw sockets bypass the kernel ip stack to deliver ethernet frames directly to user space, enabling simulation of many IPsec peers and MAC address handling.
Implement a receive function that waits on the data socket using select, collects partial packets into buffers, tracks counts, and assembles complete Ike packets for processing.
Implement a complete receive function that collects data packets in a loop, assembling buffers into IKEv2 packets by parsing lengths, skipping IP/UDP headers, and driving a finite state machine.
Run the IPsec ikev2 internals sim by wiring three files, defining a state machine, and using a data socket and receiver to capture udp packets and begin v2 parsing.
Describe the four-message IKEv2 phase 1 exchange, where the first pair negotiates cryptographic algorithms and derives a secret key, and the second pair authenticates with a secret or certificate.
The lecture covers the initial IKEv2 SA exchange, where the initiator and responder negotiate algorithms and DH values with nonces, then derive the shared SA key to encrypt subsequent messages.
Explain the IKEv2 auth exchange with four messages: initiator identity with auth protection, responder identity with certificates and trust anchors, and the response; cover diffie-hellman group negotiation and traffic selectors.
Explore how the security association payload carries proposals, each with a protocol and transforms for encryption, integrity, Diffie-Hellman group, and the peer algorithm.
Create the ike start module, include the header, set up ipsec config, and implement a hex dump for debugging, then initialize ike variables for proposals and sha1 96.
Define and assemble the IKE header for SA INIT by building the IKEv2 header, payload header, and transforms, while managing the buffer, message I.D., and initiator flags.
Completes the SA init for IKEv2 by assembling the initial identity, building the proposal with encryption and integrity transforms, and executing the key-exchange payload, buffering and signing data for transmission.
Install strongSwan on a Linux VM and configure IKEv2 with IPsec. Test with a simulator and a responder, troubleshoot 'no proposal is chosen' by aligning proposals.
Learn to configure strongSwan for ipsec, defining left and right, traffic selectors, and ipsec.conf setup, using pre-shared keys and ipsec secrets, with proposals for encryption and integrity.
Configure strongSwan's ipsec.conf with an accepted proposal, restart strongSwan, and observe the SA INIT exchange, peer acceptance, and connection status through counters and logs.
Prepare to receive ike sa init response from strongSwan, parse the data event, verify message id and exchange type, and move toward sending the auth in the next ikev2 phase.
Parse the IKEv2 SA init response, save payload pointers for the SA, key exchange, and ID payloads, and prepare key derivation after processing.
Process the IKEv2 SA init receive routine by evaluating the SA payload and transforms for encryption (CBC), integrity, and DH, then derive keys in a hardcoded simulator.
Analyze the sa init response to derive encryption and authentication keys from the sdk seed and nonces using the pr function, and assemble key material from a large buffer.
Learn how to build and send IKEv2 SA authentication messages by crafting headers, protecting payloads with keys, signing data, and exchanging IKE SA and child SA payloads.
Test the SA authentication with strongSwan and confirm a SA between the simulator and strongSwan, then debug child SA formation using status and ESP parameters.
Verify an IKEv2 SA authentication with the strongSwan simulator, confirming receipt of the init, auth response, and a four-packet handshake that establishes the SA, including authentication and lifetime payloads.
Students will learn how to implement the IKv2 protocol as per RFC 5996 in C language and build a simple simulator that can be used to test another IPSec implementation. Students will also learn on how test the simulator with strongSwan open source implementation and see messages in wireshark tool. The course primarliy works on 4 initial messages of IKEv2 exchange, i.e. SA INIT and SA AUTH messages.