Linux
Technology
IPSEC
Protocols
Domains
100

This command shows the current working directory.

What is pwd?

100

What is our Load Balancer Platform?

f5

100

This IPsec protocol provides encryption and confidentiality for data as it travels across a network.

What is ESP (Encapsulating Security Payload)?

100

This protocol maps IPs to MACs

ARP

100

This domain is the general enterprise domain

c00 or CORP

200

This command is used to list files and directories in Linux.

What is ls?

200

What is our CORP EDR?

CrowdStrike

200

This IPsec mode encrypts only the original IP packet payload, leaving the original IP header intact.

What is Transport Mode?

200

This protocol maps names to IPs

DNS

200

This domain is the Generation domain

 c07 

300

This file contains user account information, including usernames, UIDs, and home directories.

What is /etc/passwd?

300

What is our OT AV?

Defender

300

This key exchange protocol is commonly used with IPsec VPNs to negotiate security associations and cryptographic keys.

What is IKE (Internet Key Exchange)?

300

This protocol operates over UDP 500 and 4500, and is used to establish secure tunnels

IPSEC

300

This domain is the scci domain

corpd OR s00 - S04

400

This command displays active processes running on a Linux system.

What is ps?

400

What is our OT SIEM?

Splunk

400

In IKEv2, these Security Associations carry protected user traffic and can be rekeyed independently of the IKE SA that manages them.

What are Child SAs?

400

This protocol uses port 20000 by default, and is very common in energy industry tools

DNP

Distributed Network Protocol

400

This domain is the SCADA domain

prd

500

This command changes file permissions and can be used with values like 755 or 644.

What is chmod?

500

What is the name of our cloud hosted VPN Solution

Prisma Access

500

A tunnel appears up, Phase 1/IKE SA is established, and no packets are encrypted. Packet captures show traffic bypassing the VPN entirely. An engineer should first verify these rules that determine whether traffic is considered "interesting" enough to trigger or use IPsec.

What are the security policies or crypto ACLs?

500

This protocol is the S in HTTPS

SSL

500

This domain is the DMZ

c06

M
e
n
u