Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


vpn tunnel mode versus transport mode

Posted on 2014-03-15
Medium Priority
Last Modified: 2014-04-03
I am looking at a IPSec site-to-site VPN connection routers configuration and I see that one router has the transform set mode tunnel and the other side has transform set mode transport. Will this be a problem? The tunnel is up and running. But I am not sure if there are any errors in the background. Thanks
Question by:leblanc
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 11

Accepted Solution

naderz earned 1332 total points
ID: 39931905
For a site-to-site tunnel you should be using the tunnel mode. I would make sure they match on both ends.

Author Comment

ID: 39932088
what if they don't match. What command can I use to see what mode they are using on both end. Thanks
LVL 17

Assisted Solution

lruiz52 earned 668 total points
ID: 39932095
Agree with naderz, both sides should be the same,

On router to router vpn you should use tunnel mode on both sides, check the link below for a good explanation of both modes and when to use;

Plesk WordPress Toolkit

Plesk's WordPress Toolkit allows server administrators, resellers and customers to manage their WordPress instances, enabling a variety of development workflows for WordPress admins of all skill levels, from beginners to pros.

See why 2/3 of Plesk servers use it.

LVL 11

Assisted Solution

naderz earned 1332 total points
ID: 39933017
I am not sure what devices you are using. Here is the command for a Cisco device

show crypto ipsec sa

Here is another link that also explains the different modes and their intent:


Author Comment

ID: 39933171
We are all Cisco gear
LVL 11

Expert Comment

ID: 39935985
Try the command above and the links provided for more information.

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question