Transport and Tunnel Modes

IPsec defines two kinds of SAs: transport and tunnel mode SAs. A transport mode SA is an association between two hosts. In transport mode, the IP pay load is protected by IPsec and the original IP header isjeft intact. Additionally, an IPsec header is inserted after the IP header. This is illustrated in Figure 7-2.

Figure 7-2 Transport Mode SA

May be encrypted

Transport mode protects traffic between two IPscc hosts (between a PC and a server, for example) and does not afford any traffic flow confidentiality. That is, the volume of traffic transmittedTrom oneTiost to another can easily be observed, even if encryption is used, because the original source and destination addresses are left intact. An attacker could use this data to determine where servers are located, with the assumption that servers transmit and receive more data than clients.

A tunnel mode SA is an association between two routers (also called security gateways) or between a router and a host. In tunnel mode, the entire IP packet is protected by and becomes the pay load of a new packet. The IPsec header is inserted after the IP header of the new packet. This is illustrated in Figure 7-3.

Figure 7-3 Tunnel Mode SA

IP header

Payload

\

Payload

Protected Packet: [New IP header [ÏPsec header

IP header

Payload v j

May be encrypted

Tunnel mode is the basis for enabling dedicated VPNs between routers, as well as VPDNs that involve remote users terminating their SAs on routers to gain access to hosts within a network. With tunnel mode you do not have to equip every PC and server with IPsec; instead, you can activate IPsec on routers and use the routers to provide IPsec services on behalf of those computers, l or example, you might establish an IPsec peering over the Internet between two branch office routers and use tunnel mode SAs between the routers to protect all interoffice traffic. This is a scenario depicted in Figure 7-1.

The source and destination addresses contained in the new IP header are that of the tunnel mode SA endpoints. Thus, tunnel mode SAs provide a level of traffic flow confidentiality because the IP addresses of the original packet are carried within the secure payload of an IPsec packet (assuming encryption is used).

Continue reading here: Authentication Header and Encapsulating Security Payload

Was this article helpful?

0 0