What Is IPsec VPN? How It Works & Key Use Cases
Businesses connect branch offices and remote employees over the public internet every day, and that traffic needs a way to stay private and tamper-free as it crosses networks the business doesn't control. IPsec is the standard most business gateways rely on to do this.
An IPsec VPN is a virtual private network built on the IPsec protocol suite, which encrypts and authenticates data at the network layer so that traffic between two locations, or between a remote worker and the office, stays private and unaltered.
This guide explains how IPsec works, explores site-to-site and remote-access use cases, and compares IPsec VPN with SSL VPN so you can choose the approach that fits your network.
What Is IPsec VPN?
IPsec VPN is a VPN built on the IPsec protocol suite that encrypts and authenticates network traffic at the network layer, rather than at the application layer where many other VPN types operate. This network-layer approach protects entire IP packets regardless of which application generated them, providing consistent security across all traffic flowing through the tunnel.
Because IPsec operates below the application layer, it works transparently with existing network traffic. Administrators don't need to configure security individually for email, file sharing, or database traffic. Once the tunnel is established between two endpoints, whether two gateways or a gateway and a remote client, all traffic through that tunnel receives the same encryption and authentication.
IPsec vs. IPsec VPN: What's the Difference?
IPsec and IPsec VPN are related but distinct terms. IPsec is the underlying protocol suite; an IPsec VPN is the specific type of VPN connection built using that suite.
What Is IPsec?
IPsec, or Internet Protocol Security, is a suite of protocols that authenticates and encrypts IP packets to protect data as it travels across a network. IPsec operates at the network layer, working underneath applications rather than inside them.
The protocol suite provides three core functions: authenticating the identity of communicating devices, encrypting data to prevent interception, and verifying data integrity so packets aren't altered in transit. IPsec accomplishes this through a combination of protocols, including Authentication Header (AH), Encapsulating Security Payload (ESP), and Internet Key Exchange (IKE), covered in more detail below.
What Is an IPsec VPN?
Where IPsec provides the underlying security mechanisms, an IPsec VPN is the practical implementation: a secure, encrypted tunnel between two network endpoints that applies those mechanisms to protect traffic.
An IPsec VPN connects two gateways for site-to-site access, or a remote client and a gateway for remote access. Either way, the tunnel encrypts and authenticates all traffic passing between the endpoints.
Why IPsec VPN Matters for Businesses
IPsec VPN gives businesses encrypted branch-to-headquarters connectivity, secure remote access, and data protection as it crosses untrusted networks like the public internet. For businesses operating across multiple locations or supporting remote employees, this means daily operations run more securely.
With an IPsec VPN in place, employees at a branch office can access shared file servers, internal applications, and business systems hosted at headquarters as though they were on the same local network, without exposing those systems directly to the internet. Remote workers can connect to company resources from home or while traveling, through an encrypted tunnel rather than an open connection over public Wi-Fi.
For an IT manager overseeing multiple offices, or an MSP managing several client networks, this translates into fewer exposed entry points and a consistent security posture across every site.
How Does IPsec Work?
IPsec secures a connection through a defined sequence: authenticating the two endpoints, negotiating how traffic will be protected, and then encrypting and verifying data for the life of the connection.
Authentication Header (AH) vs. Encapsulating Security Payload (ESP)
IPsec uses two core protocols to protect traffic, and they provide different levels of protection. Authentication Header (AH) authenticates a packet's source and verifies it wasn't altered in transit, but it does not encrypt the packet's contents. AH is incompatible with NAT, so it is rarely used in commercial gateway deployments. Encapsulating Security Payload (ESP) provides encryption in addition to authentication and integrity checking, making it the more commonly used protocol for modern IPsec VPNs.
Because ESP covers both confidentiality and integrity, most business gateways default to ESP-based configurations, reserving AH for scenarios where encryption isn't required but data integrity still needs verification.
Internet Key Exchange (IKE) and Security Associations (SAs)
Before any data travels through an IPsec tunnel, the two endpoints must agree on how to protect that traffic. Internet Key Exchange (IKE) handles this negotiation, allowing each endpoint to authenticate the other, agree on encryption and authentication settings, and exchange the keying information needed to secure the connection.
Once IKE negotiation completes, the endpoints establish a security association (SA), a set of agreed-upon parameters. Decisions like encryption algorithm, authentication method, and key lifetime govern how traffic is protected for that session. IKE comes in two versions: IKEv1, an older standard, and IKEv2, which offers faster negotiation and better support for mobile and remote connections that may change network paths. Most current business gateways default to IKEv2 for new IPsec VPN configurations.
Encryption and Data Integrity
Once IKE establishes the security association, IPsec applies encryption and integrity algorithms to protect the actual data. Encryption algorithms scramble packet contents, so intercepted traffic is unreadable without the correct key. Integrity algorithms generate a checksum for each packet, allowing the receiving endpoint to confirm the data hasn't been altered in transit.
The specific encryption and integrity algorithms available depend on the gateway and its configuration. Business-grade gateways typically support multiple algorithm options, letting administrators balance security requirements against the processing overhead of stronger encryption.
Here's how an IPsec VPN connection comes together, from initial negotiation to active data transfer:
- IKE negotiation begins. The two endpoints initiate contact and start negotiating how the connection will be secured.
- Endpoints authenticate each other. Using pre-shared keys or certificates, each endpoint confirms the other's identity before proceeding.
- Security parameters are agreed upon. The endpoints settle on encryption algorithms, authentication methods, and key exchange settings for the session.
- A security association is established. This defines the specific rules that will govern how traffic is encrypted and authenticated for the connection.
- Encrypted data transfer begins. Traffic between the endpoints is encrypted and authenticated according to the SA as it passes through the tunnel.
- The tunnel renews or terminates. SAs have a defined lifetime; connections either renegotiate automatically to maintain the tunnel or terminate when no longer needed.
IPsec Modes: Tunnel Mode vs. Transport Mode
IPsec VPN operates in one of two modes: tunnel mode or transport mode. Tunnel mode encrypts the entire original IP packet and wraps it in a new packet, making it the standard choice for gateway-to-gateway connections such as site-to-site VPNs. Transport mode encrypts only the packet payload, leaving the original header intact, which suits direct host-to-host communication where both endpoints are already on the same trusted network path.
The table below compares the IPsec VPN tunnel and transport modes at a glance.
| Factor | Tunnel Mode | Transport Mode |
|---|---|---|
| What's encrypted | Entire original IP packet | Payload only; original header remains visible |
| Typical use | Site-to-site, gateway-to-gateway VPN | Direct host-to-host communication |
| Common deployment | Business gateway to business gateway | Two devices communicating directly, such as server-to-server |
| Endpoint visibility | Original IP addresses hidden inside new packet | Original IP addresses remain visible |
IPsec VPN Business Uses
Businesses primarily use IPsec VPN in two ways: connecting entire networks together, or giving an individual authorized access to business resources from outside the office. Both rely on the same underlying protocol suite but solve different connectivity problems.
Site-to-Site VPN (Branch-to-Headquarters)
A site-to-site VPN uses IPsec to create an encrypted, gateway-to-gateway tunnel between two locations, allowing users at each site to access shared systems and resources as though both locations were part of the same private network.
Consider an MSP managing a client with a headquarters office and a newly opened branch location. Rather than configuring VPN access separately on every employee device at the branch, the MSP configures a single site-to-site IPsec VPN tunnel between the two locations' gateways. Every device at the branch office then has secure, encrypted access to file servers, applications, and other resources at headquarters, without configuring each device individually.
Remote Access VPN (Secure Remote Access)
A remote access VPN uses IPsec to create an encrypted, client-to-site connection between an individual device and the business gateway, enabling secure remote access to approved internal resources from outside the office.
For a small business with employees working from home or traveling for client meetings, instead of exposing internal file servers or applications directly to the internet, the IT manager configures remote access IPsec VPN on the business gateway. Employees connect to company resources securely, whether they're reaching a file server, an in-office printer, or an internal application, without those systems ever being directly reachable from the public internet.
IPsec VPN vs. SSL VPN
IPsec VPN and SSL VPN both create encrypted tunnels, but they operate at different layers of the network and suit different access scenarios. IPsec VPN works at the network layer and typically requires client software or gateway configuration, while SSL VPN operates at a higher layer and often runs through a standard web browser without additional client software.
The table below compares the two approaches across the factors that matter most for deployment decisions.
| Factor | IPsec VPN | SSL VPN |
|---|---|---|
| Layer of operation | Network layer | Application/transport layer |
| Client requirement | Dedicated VPN client or gateway configuration | Often browser-based; client software sometimes optional |
| Typical use case | Site-to-site connections, full network access | Individual remote access to specific applications |
| Access granularity | Broad; connects entire networks or grants full network access | Granular; can restrict access to specific applications or resources |
| Performance | Consistent overhead across all traffic types | Can vary depending on browser and application-layer processing |
Which should you use? Site-to-site connections between offices, where entire networks need to communicate, are typically better served by IPsec VPN. Remote access scenarios where you want to restrict individual users to specific applications, without granting broader network access, often favor SSL VPN. Many business networks use both: IPsec VPN for branch-to-headquarters connectivity, and SSL VPN or IPsec remote access for individual remote workers, depending on the access level each scenario requires.
Advantages and Disadvantages of IPsec VPN
Like any VPN technology, IPsec VPN comes with trade-offs. Weighing the advantages against the disadvantages helps determine whether it fits your network.
Advantages:
- Strong network-layer encryption protects all IP traffic without requiring per-application configuration.
- Application-agnostic design secures any traffic passing through the tunnel, from file transfers to VoIP calls.
- Mature, widely supported standard with broad compatibility across business networking equipment.
Disadvantages:
- Client configuration can be more involved than browser-based VPN alternatives, particularly for remote access deployments.
- NAT traversal and firewall rules sometimes require additional configuration, since IPsec wasn't originally designed with network address translation in mind.
- Encryption and encapsulation add processing overhead, which can affect throughput on lower-powered gateways handling many simultaneous tunnels.
How to Deploy IPsec VPN on an Omada Gateway
Omada ER-series gateways support IPsec VPN for both site-to-site and remote-access connections, centrally managed through the Omada controller.
The ER7206 supports IPsec VPN, L2TP over IPsec VPN, SSL VPN, WireGuard VPN, PPTP, OpenVPN, and GRE VPN, alongside load balancing across up to five WAN ports. Administrators configure and monitor VPN tunnels through the same Omada controller interface used to manage switches and access points, so a site-to-site tunnel to a branch office or a remote-access policy for traveling employees doesn't require separate management tools.
For businesses evaluating gateway options, Omada's wired gateways collection includes multiple models with IPsec VPN support at different WAN port counts and throughput levels, while the broader gateways lineup includes wired, wireless, and multi-WAN options for different deployment sizes.
Once IPsec VPN is configured, it works alongside other Omada SDN capabilities. For businesses running guest Wi-Fi or IoT devices alongside secure remote access, see how BYOD security works with Omada SDN to keep those networks properly segmented.
Frequently Asked Questions
What is the difference between a VPN and an IPsec VPN?
A VPN is the broad category of technology that creates an encrypted, private connection over a public network. An IPsec VPN is one specific type of VPN, distinguished by its use of the IPsec protocol suite to authenticate and encrypt traffic at the network layer. Other VPN types, like SSL VPN or WireGuard, use different protocols to accomplish similar goals.
What are the disadvantages of IPsec VPN?
The main disadvantages of IPsec VPN are more involved client configuration than browser-based alternatives, potential complications with NAT traversal and firewall rules, and processing overhead from encryption and encapsulation that can reduce throughput on lower-powered hardware. These trade-offs are typically manageable on business-grade gateways built to handle VPN traffic.
What is IPsec VPN used for?
IPsec VPN is primarily used for two purposes: site-to-site connectivity that links branch offices to headquarters as though they share the same private network, and remote access that lets authorized employees securely connect to business resources from outside the office. Both use cases rely on IPsec's ability to encrypt and authenticate traffic at the network layer.
Is IPsec VPN secure?
Yes. IPsec VPN is considered a secure, mature standard when properly configured, using strong encryption algorithms and integrity checks to protect data at the network layer. Security depends on configuration choices, including which encryption algorithms are selected and how keys are managed, so using current protocol versions and vetted gateway hardware matters as much as the underlying standard itself.
Choosing the Right VPN Approach for Your Network
IPsec VPN secures traffic at the network layer, making it a proven option for connecting business locations and providing controlled remote access over the public internet. Whether you need to link a branch office to headquarters or give remote employees secure access to internal resources, understanding how IPsec works, its two operating modes, and how it compares to SSL VPN puts you in a better position to choose the right approach for your network.
Explore Omada's gateways collection to find a model that supports the IPsec VPN capabilities your deployment requires.