CompTIA Network+ (N10-009)Network OperationsHard

A network engineer is configuring a site-to-site VPN between two offices and must decide how the original IP packet will be protected. The design requires that the entire original IP packet, including its header, be encrypted and encapsulated inside a new IP packet for transport across the internet. Which IPsec mode should be configured?

  1. ATransport mode
  2. BTunnel mode
  3. CMain mode
  4. DAggressive mode
Show answer & explanation

Correct answer: B. Tunnel mode

IPsec tunnel mode encrypts and encapsulates the entire original IP packet (header and payload) inside a new IP packet with new headers, making it ideal for site-to-site VPNs where traffic traverses an untrusted network between gateways. Transport mode only encrypts the payload, leaving the original IP header exposed, which is typically used for host-to-host communication.

Why the other options are wrong

  • A. Transport mode encrypts only the payload and leaves the original IP header visible, unsuitable for full packet protection.
  • C. Main mode is also an IKE Phase 1 negotiation method, not related to packet encapsulation.
  • D. Aggressive mode is an IKE Phase 1 negotiation method, not a data encapsulation mode.

IPsec Tunnel Mode

An IPsec mode that encrypts the entire original IP packet, including its header, and encapsulates it within a new IP packet for secure transport, commonly used in site-to-site VPNs.

  • Encrypts entire original packet including header
  • New outer IP header added for routing between gateways
  • Contrasts with transport mode which only encrypts payload

Memory trick: Tunnel wraps the WHOLE package; Transport just seals the contents.

More Network Operations questions