Vous êtes sur la page 1sur 1

5/29/2017 ESPTunnelmodeandESPtransportmodeIPSecthroughFirewallVPNtutorial

TunnelmodeandTransportmode
WhenusingESPyoucanspecifyoneoftwomodes,inwhichESPoperatesin.Tunnel
modeencryptsthewholepacket.TunnelmodeisusedforsitetositeVPN,when
securingcommunicationbetweensecuritygateways,concentrators,firewalls,etc.Tunnel
modeprovidessecurityfortheentireoriginalIPpacket,thatistheheadersandthe
payload.

TheothermodeESPcanoperateinisTransportmode,whichisnotassecureasitonly
encryptsthedataportionandnotthewholepacketunliketuneltunnelmode.

Transportmodeencryptsthedataportionofthepacket.Itworksbetweentwodifferent
workstationsrunningsomekindofVPNsoftware.Transportmodeprotectspayloadof
packetandthehighlayerprotocols.TransportmodeleavestheoriginalIPaddressesin
opencleartext.Usingtransportmodethefinaldestinationisnotagatewayorrouter,
generallythehostitself.Transportmodeprovidessecuritytothehigherlayerprotocols
only.

http://www.internetcomputersecurity.com/VPNGuide/Tunnelmode.html 1/1

Vous aimerez peut-être aussi