Figure 16.4 Scenario 4
The major difference between bridging and routing is that a routed VPN cannot IP-
broadcast while a bridged VPN can.
16.1.2 Tun and Tap Devices
Whenever you setup a VPN connection your IP packets are transferred over your secured
tunnel. The connection between the client's device and the server's device is called a
tunnel. A tunnel can use a so-called tun or tap device. They are virtual network kernel
drivers which implement the transmission of ethernet frames or ip frames/packets:
tun device
A tun device simulates a point-to-point network (layer 3 packets in the OSI model
such as Ethernet frames). A tun device is used with routing. It works with IP frames.
tap device
A tap device simulates an ethernet device (layer 2 packets in the OSI model such
as IP packets). A tap device is used for creating a network bridge. It works with
Ethernet frames.
146
Security Guide