Please advise when is host to gateway being used in IPSEC? Thank You.

Transport mode
encrypts only the data portion (payload) at each packet but leave the header untouched. This mode is designed peer to peer.

Secure Mode encrypts both the header and payload. On the receiving side, an IPSec compliant device decrypts each packet. This mode is designed gateway to gateway.


  • if you want to hide your ip address then you should use tunnel mode (secure mode).
    otherwise - transport mode.
    Just know the difference between Xport and Tunnel mode and why you would use them.
