CompTIA Network+ (N10-009)Network OperationsHard
A network engineer is configuring a site-to-site VPN between two offices and must decide how the original IP packet will be protected. The design requires that the entire original IP packet, including its header, be encrypted and encapsulated inside a new IP packet for transport across the internet. Which IPsec mode should be configured?
- ATransport mode
- BTunnel mode
- CMain mode
- DAggressive mode
Show answer & explanationAnswer & explanation
Correct answer: B. Tunnel mode
IPsec tunnel mode encrypts and encapsulates the entire original IP packet (header and payload) inside a new IP packet with new headers, making it ideal for site-to-site VPNs where traffic traverses an untrusted network between gateways. Transport mode only encrypts the payload, leaving the original IP header exposed, which is typically used for host-to-host communication.
Why the other options are wrong
- A. Transport mode encrypts only the payload and leaves the original IP header visible, unsuitable for full packet protection.
- C. Main mode is also an IKE Phase 1 negotiation method, not related to packet encapsulation.
- D. Aggressive mode is an IKE Phase 1 negotiation method, not a data encapsulation mode.
IPsec Tunnel Mode
An IPsec mode that encrypts the entire original IP packet, including its header, and encapsulates it within a new IP packet for secure transport, commonly used in site-to-site VPNs.
- Encrypts entire original packet including header
- New outer IP header added for routing between gateways
- Contrasts with transport mode which only encrypts payload
Memory trick: Tunnel wraps the WHOLE package; Transport just seals the contents.