vpn tunnel mode versus transport mode

Posted on 2014-03-15
Last Modified: 2014-04-03
I am looking at a IPSec site-to-site VPN connection routers configuration and I see that one router has the transform set mode tunnel and the other side has transform set mode transport. Will this be a problem? The tunnel is up and running. But I am not sure if there are any errors in the background. Thanks
Question by:leblanc
  • 3
  • 2
LVL 11

Accepted Solution

naderz earned 333 total points
ID: 39931905
For a site-to-site tunnel you should be using the tunnel mode. I would make sure they match on both ends.

Author Comment

ID: 39932088
what if they don't match. What command can I use to see what mode they are using on both end. Thanks
LVL 17

Assisted Solution

lruiz52 earned 167 total points
ID: 39932095
Agree with naderz, both sides should be the same,

On router to router vpn you should use tunnel mode on both sides, check the link below for a good explanation of both modes and when to use;
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

LVL 11

Assisted Solution

naderz earned 333 total points
ID: 39933017
I am not sure what devices you are using. Here is the command for a Cisco device

show crypto ipsec sa

Here is another link that also explains the different modes and their intent:

Author Comment

ID: 39933171
We are all Cisco gear
LVL 11

Expert Comment

ID: 39935985
Try the command above and the links provided for more information.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Hybrid WAN vs SD WAN 4 51
Filter IP range with PowerShell 1 41
eigrp routing loop 5 42
How do I allow multiple VLANs internet access on a Cisco ASA 5505? 8 13
Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question