About IPsec modes: tunnel and transport
This solution uses two types of VPN:
The following figure shows the protocol stacks for the tunnel mode VPN and the transport
mode VPN for the connection type PPPoA.
In this How To Note, branch office 1 uses PPPoA. The other offices in this How To Note use
different connection types and therefore have different stacks below IP. Branch office 2 uses
PPP over virtual Ethernet over ATM, and headquarters simply uses IP over an actual Ethernet
WAN connection.
Page 3 | AlliedWare™ OS How To Note: VPNs for Corporate Networks
IPsec tunnel mode, for the headquarters office to branch office VPNs. These are site-to-
site (router-to-router) VPNs.
IPsec transport mode with L2TP, for the roaming Windows VPN clients.
IP
IPsec
encrypted
by IPsec
IP
PPP
ATM
ADSL
Tunnel mode - for site-to-site VPNs
IPsec payload
tunnel mode:
policy "hq"
statically-defined
interface ppp0
IP
IPsec payload (dynamic
PPP
PPP using template)
using L2TP server
L2TP
definition
transport mode:
IPsec
policy "roaming"
IP
statically-defined
PPP
interface ppp0
ATM
ADSL
Transport mode - for roaming clients
vpn-protocol-stack.eps