Académique Documents
Professionnel Documents
Culture Documents
TunnelmodeandTransportmode
WhenusingESPyoucanspecifyoneoftwomodes,inwhichESPoperatesin.Tunnel
modeencryptsthewholepacket.TunnelmodeisusedforsitetositeVPN,when
securingcommunicationbetweensecuritygateways,concentrators,firewalls,etc.Tunnel
modeprovidessecurityfortheentireoriginalIPpacket,thatistheheadersandthe
payload.
TheothermodeESPcanoperateinisTransportmode,whichisnotassecureasitonly
encryptsthedataportionandnotthewholepacketunliketuneltunnelmode.
Transportmodeencryptsthedataportionofthepacket.Itworksbetweentwodifferent
workstationsrunningsomekindofVPNsoftware.Transportmodeprotectspayloadof
packetandthehighlayerprotocols.TransportmodeleavestheoriginalIPaddressesin
opencleartext.Usingtransportmodethefinaldestinationisnotagatewayorrouter,
generallythehostitself.Transportmodeprovidessecuritytothehigherlayerprotocols
only.
http://www.internetcomputersecurity.com/VPNGuide/Tunnelmode.html 1/1