In the enterprise scenario, IPsec is mainly used to interconnect IPsec VPNs between enterprises or allow mobile office employees to remotely access an enterprise network. The typical applications are the site-to-site VPN and GRE over IPsec. IPsec networking modes in the enterprise scenario are diversified.
The IPsec over L2TP mechanism encapsulates packets using IPsec and then L2TP. In this way, the IPsec over L2TP mechanism implements user authentication and address allocation based on L2TP, and ensures security using IPsec.
As shown in Figure 3, Device A, serving as an access server, initiates a PPP session in PPP dial-up mode to trigger the establishment of an L2TP tunnel. After the L2TP tunnel is established, the LNS generates a route to Device A. Device A obtains an IP address and initiates the IPsec tunnel creation.
In this networking, you can configure IPsec, or GRE over IPsec based on actual requirements.
Branch networks do not communicate with each other.
Branch networks need to communicate with each other.
In the site-to-site or Hub-Spoke VPN networking, users of the branch networks can access the Internet in following modes:
The users of the branch networks access the Internet through the HQ network.
The users of the branch networks access the Internet through their own gateways.