Q70Security Fundamentals
When a site-to-site VPN is configured, which IPsec mode encapsulates and encrypts the entire original IP packet?
← → navigate · a answer
Community votes
Discussion · 2
D 27
Selected Answer: D
Authentication Header (AH)
Encapsulating Security Payload (ESP)
D 6
Selected Answer: D
When a site-to-site VPN is set up, IPsec tunnel mode with ESP (Encapsulating Security Payload) gives encapsulation and encryption of the whole original IP packet. In this mode, the full IP packet, including the original IP header and payload, is encapsulated inside a new IP packet with a new IP header added by the VPN gateway. The original packet is encrypted, providing confidentiality, and the new IP header lets the encrypted packet be routed over the public internet securely to the other VPN gateway, where it is decrypted and sent on to its final destination.