Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Networking
  4. IPsec and site-to-site VPNs: connecting two networks securely

IPsec and site-to-site VPNs: connecting two networks securely

Applies to General networking concept, VPNAudience Server administrators, network engineersLast reviewed September 2026

Quick answer

IPsec is a standard suite of protocols that encrypts and authenticates traffic between two networks as it crosses the public internet. It's the technology underneath most traditional site-to-site VPNs: a router or firewall at each end builds one permanent encrypted tunnel, and once it's up, anything behind one gateway can reach anything behind the other as if the two networks were joined together. That's a different pattern from Worldstream's mesh VPN, covered in Mesh VPN: connecting your devices with Headscale and Tailscale, which authenticates individual devices onto a shared mesh rather than joining two whole networks through a single tunnel.

On this page
  • What IPsec actually is
  • How a site-to-site tunnel works
  • Site-to-site IPsec vs a mesh VPN
  • Where this fits in the wider network

What IPsec actually is

IPsec, short for IP Security, isn't one protocol but a suite of them working together. It operates at the network layer, below any individual application, so it protects everything running over IP between two points without any application needing to know encryption is happening at all.

Two parts do most of the work. IKE (Internet Key Exchange) is the negotiation phase: the two ends authenticate to each other, usually with a shared pre-shared key or certificates, and agree on the encryption keys they'll use. ESP (Encapsulating Security Payload) is what then encrypts and authenticates the actual data packets, using the keys IKE negotiated. Keys are rotated periodically without tearing the tunnel down, so the connection stays both current and continuous.

How a site-to-site tunnel works

A site-to-site tunnel connects two networks through their edge devices, typically a router or firewall at each location, rather than connecting individual machines. Each side is configured with the other side's public IP, the shared authentication material, and the private address ranges that should travel through the tunnel. Once both ends agree on those parameters, the tunnel comes up and stays up.

From then on, routing does the rest. A server on one side that sends a packet addressed to a private range on the other side has that packet picked up by its local gateway, encrypted, and sent across the tunnel to the remote gateway, which decrypts it and delivers it onto its own local network. No client software runs on the servers themselves, and no individual device authenticates: the gateways do the work, and everything behind them inherits the connection.

That's also the main thing to be aware of with this pattern. Because the tunnel trusts the address ranges, not individual devices, anything reachable behind one gateway is reachable from anything behind the other, by design. Getting the address ranges and any firewall rules on top of the tunnel right matters more than it would in a model where each device is authenticated on its own.

Site-to-site IPsec vs a mesh VPN

Both patterns answer the same underlying question, how do I let two networks or devices reach each other privately without exposing them to the public internet, but they get there differently, and the difference matters when you're choosing between them.

Site-to-site IPsec joins two fixed points. It's built around a pair of gateways, each representing a whole network, with one tunnel between them. A mesh VPN, the kind covered in Mesh VPN: connecting your devices with Headscale and Tailscale, instead authenticates each device individually onto a shared private network. There's no single tunnel between two sites, there's a control server that every laptop, server or firewall connects to on its own, and any two authenticated members can reach each other directly.

AspectSite-to-site IPsecMesh VPN (Headscale/Tailscale)
What it connectsTwo whole networks, through one gateway at each endIndividual devices: laptops, servers, and a firewall as a subnet router
How members authenticateThe two gateways authenticate to each other once, at setupEvery device authenticates to the control server on its own
Adding a new location or deviceConfigure a new tunnel, and usually a new set of routing rulesInstall the client and authorise it, it joins the existing mesh
Typical fitTwo fixed sites that need a permanent link, such as an office and a datacenter rackA distributed set of devices, servers and offices that all need to reach each other

In practice, a classic two-fixed-sites link, joining one office network to one datacenter network, often reaches for site-to-site IPsec because there really are only two ends to configure. A more distributed setup, several offices, a handful of remote laptops and a mix of cloud and on-premises servers that all need mutual reach, tends to fit a mesh model better: adding the tenth member doesn't mean configuring nine new tunnels, it means authorising one more device onto the mesh that already exists.

Where this fits in the wider network

Either pattern sits at the edge of your network, alongside the routing and address planning covered in Worldstream network architecture. Understanding which model you're actually looking at, one tunnel between two gateways, or a mesh of individually-authenticated members, makes it much easier to read a networking diagram or a supplier's VPN documentation correctly, whether it's Worldstream's or anyone else's.

Related articles

  • Mesh VPN: connecting your devices with Headscale and Tailscale
  • Worldstream network architecture
  • Firewall basics in Portal
  • NAT (Network Address Translation) explained
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure