Skip to main content

IPsec: Tunnel Mode and Transport Mode

IPsec is a suite of protocols that protects IP traffic under a security policy.

What is IPsec: Tunnel Mode and Transport Mode?

IPsec is a suite of protocols that protects IP traffic under a security policy. ESP can provide confidentiality, integrity, data-origin authentication, and anti-replay protection. AH provides integrity and data-origin authentication but not confidentiality. In transport mode, IPsec primarily protects the upper-layer payload of an IP packet. In tunnel mode, it protects an inner IP packet carried inside a new outer IP packet. Tunnel mode is common with security gateways, but it is not limited to network-to-network use.

Why it matters

IPsec can protect IP packets across an untrusted network without changing each application protocol. The selected mode determines which part of the packet is protected and which addresses remain visible for routing.

How it works

  1. Security policy selects traffic, and the peers establish security associations, algorithms, keys, and sequence state.
  2. Transport mode protects the upper-layer payload, while tunnel mode encapsulates and protects an inner IP packet inside a new outer packet.
  3. The receiver selects the security association, checks anti-replay and integrity data, decrypts ESP data when used, and delivers the accepted packet.

Example

Two security gateways use ESP tunnel mode across the internet. A packet from an office host becomes the protected inner packet, while a new outer packet carries it between the gateways.

Pomerium boundary

Pomerium does not create IPsec tunnels. It can instead expose named TCP and UDP services through HTTPS-based routes that use user identity and route policy. Choose the control that matches the required network or application access scope.

Limits and non-claims

  • IPsec protects traffic between its endpoints but not traffic before entry or after exit from the protected path.
  • Peer, key, policy, NAT, and maximum-transmission-unit configuration can make a deployment complex.
  • A valid tunnel does not by itself authorize a human user or an application operation inside the remote network.

Evaluation checklist

  • Which hosts or gateways authenticate, and which traffic selectors define protected packets?
  • Do mode, key exchange, algorithms, rekey, and anti-replay settings match the intended boundary?
  • Can traffic bypass the tunnel, and which application permissions remain after network reachability?

Sources and further reading

Keep learning

Network and Infrastructure

Virtual Private Network (VPN)

A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks.

Learn this term
Security Operations and RiskStandards and Protocols

Encryption

Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.

Learn this term
Network and Infrastructure

North-South Traffic

North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo