Zum Hauptinhalt springen
Support
0
Kontaktieren Sie uns
English
Nederlands
Español
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareers
Cloud Compute

Mit Cloud Compute haben Sie jederzeit und überall Zugriff auf ein Portal, über das Sie Ihre gesamte IT-Umgebung konfigurieren können – egal wo auf der Welt Sie sich befinden.

Cloud-Speicher

Zuverlässiger Zugriff auf Ihre Dateien, Infrastruktur und Anwendungen zu jeder Zeit – ganz ohne Unterbrechungen oder Verzögerungen. Bei Worldstream bieten wir eine Vielzahl von Speicherlösungen an.

Flexible cloud icon
Flexible Cloud
Private cloud icon
Private Cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Objektspeicher
Hollow cube icon
Dateiablage
Block storage icon
Blockspeicher
Backup storage icon
Sicherungsspeicher
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Dedicated Server

Wählen Sie jetzt Ihren Dedicated Server. Individuelle oder Instant Delivery. Leistungsstarke Server, die perfekt zu Ihrem Anwendungsfall passen.

Use Cases

Ganz gleich, welcher Use Case – wir helfen Ihnen, die ideale Lösung zu finden.

Deal servers icon
Deals
AMD servers icon
AMD-Prozessoren
AI servers icon
Intel-Prozessoren
Hollow cube icon
Virtualisierung, Containerisierung & Orchestrierung
Hollow cube icon
Websites & Applications
Hollow cube icon
Gaming & Streaming Infrastruktur
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Smartes Outsourcing

Bestimmte IT-Lösungen generieren Mehrwert, andere erfüllen eher eine unterstützende Funktion. Denken Sie beim Outsourcing daran.

Kosteneffizienz

IT-Komplettpakete mögen erstmal wie eine sichere Option erscheinen, doch wenn man sich die Kosten genau anschaut, sind andere Lösungen oft sinnvoller.

IT-Flexibilität und Kontrolle

Outsourcing heißt nicht, dass man die Kontrolle verliert; man bekommt sogar mehr Flexibilität und Kontrolle.

Cloud-Repatriierung

Die Cloud ist kein Endziel: Sie sollten Ihre Cloud-Umgebung kontinuierlich prüfen und an die sich ändernden Anforderungen anpassen.

Finanzdienstleistungen
Logistik und Transport
Einzelhandel und E-commerce
Medien und Unterhaltung
Technik und Softwareentwicklung
Sicherheit
Managed Service Provider
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Chatten Sie mit unsKontaktieren Sie uns
Über WorldstreamÜber die TechnologieKundenfälleWissensdatenbank
Über unsLernen Sie unser Team kennenJobsWerden Sie WiederverkäuferZertifizierungenUnsere RechenzentrenUnser NetzwerkDDoS-SchutzAMD EPYC-ServerTechnologiepartnerBetriebssystemeAlle KundenfälleEasyTerraDutch Drone CompanyPerfGridArtikelFAQNachrichten und BlogbeiträgeProdukte und Services
Kontaktieren Sie uns

Rufen Sie an unter +31 (0) 174 – 712 117 Industriestraat 53, Naaldwijk

English
Nederlands
Español
0
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareersÜber WorldstreamÜber die TechnologieKundenfälleWissensdatenbankMy Worldstream
Contact
Support
EnglishNederlandsEspañol
  1. HomeHome
  2. Knowledge Base
  3. Networking
  4. IPsec and site-to-site VPNs: connecting two networks securely

IPsec and site-to-site VPNs: connecting two networks securely

Gilt für General networking concept, VPNZielgruppe Server administrators, network engineersZuletzt geprüft September 2026

Kort antwoord

IPsec is a standard suite of protocols that encrypts and authenticates traffic between two networks as it crosses the public internet. It's the technology underneath most traditional site-to-site VPNs: a router or firewall at each end builds one permanent encrypted tunnel, and once it's up, anything behind one gateway can reach anything behind the other as if the two networks were joined together. That's a different pattern from Worldstream's mesh VPN, covered in Mesh VPN: connecting your devices with Headscale and Tailscale, which authenticates individual devices onto a shared mesh rather than joining two whole networks through a single tunnel.

Auf dieser Seite
  • What IPsec actually is
  • How a site-to-site tunnel works
  • Site-to-site IPsec vs a mesh VPN
  • Where this fits in the wider network

What IPsec actually is

IPsec, short for IP Security, isn't one protocol but a suite of them working together. It operates at the network layer, below any individual application, so it protects everything running over IP between two points without any application needing to know encryption is happening at all.

Two parts do most of the work. IKE (Internet Key Exchange) is the negotiation phase: the two ends authenticate to each other, usually with a shared pre-shared key or certificates, and agree on the encryption keys they'll use. ESP (Encapsulating Security Payload) is what then encrypts and authenticates the actual data packets, using the keys IKE negotiated. Keys are rotated periodically without tearing the tunnel down, so the connection stays both current and continuous.

How a site-to-site tunnel works

A site-to-site tunnel connects two networks through their edge devices, typically a router or firewall at each location, rather than connecting individual machines. Each side is configured with the other side's public IP, the shared authentication material, and the private address ranges that should travel through the tunnel. Once both ends agree on those parameters, the tunnel comes up and stays up.

From then on, routing does the rest. A server on one side that sends a packet addressed to a private range on the other side has that packet picked up by its local gateway, encrypted, and sent across the tunnel to the remote gateway, which decrypts it and delivers it onto its own local network. No client software runs on the servers themselves, and no individual device authenticates: the gateways do the work, and everything behind them inherits the connection.

That's also the main thing to be aware of with this pattern. Because the tunnel trusts the address ranges, not individual devices, anything reachable behind one gateway is reachable from anything behind the other, by design. Getting the address ranges and any firewall rules on top of the tunnel right matters more than it would in a model where each device is authenticated on its own.

Site-to-site IPsec vs a mesh VPN

Both patterns answer the same underlying question, how do I let two networks or devices reach each other privately without exposing them to the public internet, but they get there differently, and the difference matters when you're choosing between them.

Site-to-site IPsec joins two fixed points. It's built around a pair of gateways, each representing a whole network, with one tunnel between them. A mesh VPN, the kind covered in Mesh VPN: connecting your devices with Headscale and Tailscale, instead authenticates each device individually onto a shared private network. There's no single tunnel between two sites, there's a control server that every laptop, server or firewall connects to on its own, and any two authenticated members can reach each other directly.

AspectSite-to-site IPsecMesh VPN (Headscale/Tailscale)
What it connectsTwo whole networks, through one gateway at each endIndividual devices: laptops, servers, and a firewall as a subnet router
How members authenticateThe two gateways authenticate to each other once, at setupEvery device authenticates to the control server on its own
Adding a new location or deviceConfigure a new tunnel, and usually a new set of routing rulesInstall the client and authorise it, it joins the existing mesh
Typical fitTwo fixed sites that need a permanent link, such as an office and a datacenter rackA distributed set of devices, servers and offices that all need to reach each other

In practice, a classic two-fixed-sites link, joining one office network to one datacenter network, often reaches for site-to-site IPsec because there really are only two ends to configure. A more distributed setup, several offices, a handful of remote laptops and a mix of cloud and on-premises servers that all need mutual reach, tends to fit a mesh model better: adding the tenth member doesn't mean configuring nine new tunnels, it means authorising one more device onto the mesh that already exists.

Where this fits in the wider network

Either pattern sits at the edge of your network, alongside the routing and address planning covered in Worldstream network architecture. Understanding which model you're actually looking at, one tunnel between two gateways, or a mesh of individually-authenticated members, makes it much easier to read a networking diagram or a supplier's VPN documentation correctly, whether it's Worldstream's or anyone else's.

Related articles

  • Mesh VPN: connecting your devices with Headscale and Tailscale
  • Worldstream network architecture
  • Firewall basics in Portal
  • NAT (Network Address Translation) explained
War dieser Artikel hilfreich?

Solide IT. Keine Überraschungen

Sparringspartner für IT-Reife
Wir räumen die Hindernisse aus dem Weg, damit Sie freie Bahn haben
Vorhersehbare und transparente Kosten

Kontakt

  • Industriestraat 53, Naaldwijk
  • Zahlungsmöglichkeiten
  • Missbrauch
  • Ressourcen für Entwickler
  • Network Operations Center
  • Über uns
  • Lernen Sie unser Team kennen
  • Jobs
  • Werden Sie Wiederverkäufer
  • Zertifizierungen
  • Unsere Rechenzentren
  • Unser Netzwerk
  • DDoS-Schutz
  • AMD EPYC-Server
  • Technologiepartner
  • Betriebssysteme
  • Übersicht
  • FAQ
  • Kundenfälle
  • Nachrichten und Blogbeiträge
  • Use Cases
English
Nederlands
Español
English
Nederlands
Español
  • Rechtliches
  • Transparenzhinweis