<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSEC transport mode and GET VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-transport-mode-and-get-vpn/m-p/1248859#M969917</link>
    <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am about to implement GET VPN while read the following from Cisco's website:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPsec transport mode suffers from fragmentation and reassembly limitations and must not be used in&lt;/P&gt;&lt;P&gt;deployments where encrypted or clear packets might require fragmentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just do not understand why transport mode will suffer fragmentation and reassembly while it had less overhead than tunnel mode.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:46:39 GMT</pubDate>
    <dc:creator>yuhuiyao</dc:creator>
    <dc:date>2020-02-21T11:46:39Z</dc:date>
    <item>
      <title>IPSEC transport mode and GET VPN</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-transport-mode-and-get-vpn/m-p/1248859#M969917</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am about to implement GET VPN while read the following from Cisco's website:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPsec transport mode suffers from fragmentation and reassembly limitations and must not be used in&lt;/P&gt;&lt;P&gt;deployments where encrypted or clear packets might require fragmentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just do not understand why transport mode will suffer fragmentation and reassembly while it had less overhead than tunnel mode.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-transport-mode-and-get-vpn/m-p/1248859#M969917</guid>
      <dc:creator>yuhuiyao</dc:creator>
      <dc:date>2020-02-21T11:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC transport mode and GET VPN</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-transport-mode-and-get-vpn/m-p/1248860#M969918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One thing to understand about Tran sport mode vs Tunnel mode (ipsec) is thst Transport is used between acyual source and destination of the ip protocol &lt;PAYLOAD&gt; &lt;/PAYLOAD&gt;&lt;/P&gt;&lt;P&gt;Tunnel mode actually not only authenticates but also encrypts at the higher layers of the pckt &lt;/P&gt;&lt;P&gt;Pix &lt;/P&gt;&lt;P&gt;VPN &lt;/P&gt;&lt;P&gt;IP layers &lt;/P&gt;&lt;P&gt;Tunnel actual source and destination is encrypted at the upper layers and therefor when the packet gets to the IP Layer, it really doesnt know about or care about the iCV signature already withinh the upper PIX layer.&lt;/P&gt;&lt;P&gt;Also from a security standpoint because of the fact that tunnel mode encrpyts and authenticated the ip infoemation whereas transport only authenticates packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 07:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-transport-mode-and-get-vpn/m-p/1248860#M969918</guid>
      <dc:creator>sdoremus33</dc:creator>
      <dc:date>2009-11-05T07:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC transport mode and GET VPN</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-transport-mode-and-get-vpn/m-p/1248861#M969919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would strongly suggest you spend some time on the differece on esp, ah and transport mode, tunnel mode. You seemed to be confused with that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 13:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-transport-mode-and-get-vpn/m-p/1248861#M969919</guid>
      <dc:creator>yuhuiyao</dc:creator>
      <dc:date>2009-11-05T13:31:51Z</dc:date>
    </item>
  </channel>
</rss>

