Tunnel Mode

Mode wherein user creates VPN session from a remote location. During tunnel mode, AH and ESP are both encrypted.

Requires pre-shared keys and certificates through Kerberos.

Always-on Mode

Applied to establish long-term connections between two sites.

  • AH and ESP are always encrypted

Transport Mode

Used during creating of IPSec tunnel.

  • Only ESP in encrypted.