| |
| | IPSEC Protocol Overview |
 | | IPSEC is a framework for security that operates at the Network Layer by extending the IP packet header (using additional protocol numbers, not options). |
 | | SAs can operate in transport mode, where the IPSEC data field begins with upper level packet headers (usually TCP, UDP, or ICMP), or in tunnel mode, where the IPSEC data field begins with an entirely new IP packet header, ala RFC 2003. |
 | | IPSEC is well suited for this environment, more so than tunneling PPP over SSL or SSH, since it operates directly on the IP packets and preserves a one-to-one correspondence between packets inside and outside the network. |
| www.freesoft.org /CIE/Topics/141.htm (579 words) |
|