IPsec and site-to-site VPNs: connecting two networks securely
Kort antwoord
IPsec is a standard suite of protocols that encrypts and authenticates traffic between two networks as it crosses the public internet. It's the technology underneath most traditional site-to-site VPNs: a router or firewall at each end builds one permanent encrypted tunnel, and once it's up, anything behind one gateway can reach anything behind the other as if the two networks were joined together. That's a different pattern from Worldstream's mesh VPN, covered in Mesh VPN: connecting your devices with Headscale and Tailscale, which authenticates individual devices onto a shared mesh rather than joining two whole networks through a single tunnel.
What IPsec actually is
IPsec, short for IP Security, isn't one protocol but a suite of them working together. It operates at the network layer, below any individual application, so it protects everything running over IP between two points without any application needing to know encryption is happening at all.
Two parts do most of the work. IKE (Internet Key Exchange) is the negotiation phase: the two ends authenticate to each other, usually with a shared pre-shared key or certificates, and agree on the encryption keys they'll use. ESP (Encapsulating Security Payload) is what then encrypts and authenticates the actual data packets, using the keys IKE negotiated. Keys are rotated periodically without tearing the tunnel down, so the connection stays both current and continuous.
How a site-to-site tunnel works
A site-to-site tunnel connects two networks through their edge devices, typically a router or firewall at each location, rather than connecting individual machines. Each side is configured with the other side's public IP, the shared authentication material, and the private address ranges that should travel through the tunnel. Once both ends agree on those parameters, the tunnel comes up and stays up.
From then on, routing does the rest. A server on one side that sends a packet addressed to a private range on the other side has that packet picked up by its local gateway, encrypted, and sent across the tunnel to the remote gateway, which decrypts it and delivers it onto its own local network. No client software runs on the servers themselves, and no individual device authenticates: the gateways do the work, and everything behind them inherits the connection.
That's also the main thing to be aware of with this pattern. Because the tunnel trusts the address ranges, not individual devices, anything reachable behind one gateway is reachable from anything behind the other, by design. Getting the address ranges and any firewall rules on top of the tunnel right matters more than it would in a model where each device is authenticated on its own.
Site-to-site IPsec vs a mesh VPN
Both patterns answer the same underlying question, how do I let two networks or devices reach each other privately without exposing them to the public internet, but they get there differently, and the difference matters when you're choosing between them.
Site-to-site IPsec joins two fixed points. It's built around a pair of gateways, each representing a whole network, with one tunnel between them. A mesh VPN, the kind covered in Mesh VPN: connecting your devices with Headscale and Tailscale, instead authenticates each device individually onto a shared private network. There's no single tunnel between two sites, there's a control server that every laptop, server or firewall connects to on its own, and any two authenticated members can reach each other directly.
| Aspect | Site-to-site IPsec | Mesh VPN (Headscale/Tailscale) |
|---|---|---|
| What it connects | Two whole networks, through one gateway at each end | Individual devices: laptops, servers, and a firewall as a subnet router |
| How members authenticate | The two gateways authenticate to each other once, at setup | Every device authenticates to the control server on its own |
| Adding a new location or device | Configure a new tunnel, and usually a new set of routing rules | Install the client and authorise it, it joins the existing mesh |
| Typical fit | Two fixed sites that need a permanent link, such as an office and a datacenter rack | A distributed set of devices, servers and offices that all need to reach each other |
In practice, a classic two-fixed-sites link, joining one office network to one datacenter network, often reaches for site-to-site IPsec because there really are only two ends to configure. A more distributed setup, several offices, a handful of remote laptops and a mix of cloud and on-premises servers that all need mutual reach, tends to fit a mesh model better: adding the tenth member doesn't mean configuring nine new tunnels, it means authorising one more device onto the mesh that already exists.
Where this fits in the wider network
Either pattern sits at the edge of your network, alongside the routing and address planning covered in Worldstream network architecture. Understanding which model you're actually looking at, one tunnel between two gateways, or a mesh of individually-authenticated members, makes it much easier to read a networking diagram or a supplier's VPN documentation correctly, whether it's Worldstream's or anyone else's.