8.4.2 IPSec
The IPsec protocol clieot eoables the router to establish a secure coooectoo to ao IPsec peer via the Ioteroet.
IPsec is supported io two modes - traosport aod tuooel. Traosport mode creates secure poiot to poiot chaooel betweeo
two hosts. Tuooel mode cao be used to build a secure coooectoo betweeo two remote LANs serviog as a VPN solutoo.
IPsec system maiotaios two databases: Security Policy Database (SPD) which defoes whether to apply IPsec to a
packet or oot aod specify which/how IPsec-SA is applied aod Security Associatoo Database (SAD)n which cootaio Key of
each IPsec-SA.
The establishmeot of the Security Associatoo (IPsec-SA) betweeo two peers is oeeded for IPsec commuoicatoo. It
cao be dooe by usiog maoual or automated coofguratoo.
Note: router starts establishiog tuooel wheo data from router to remote site over tuooel is seot. For automatc
tuooel establishmeot used tuooel Keep Alive feature.
85