The Scope of IPSec
Both authentication and encryption are generally desired,
- (1) assure that unauthorized users do not penetrate the virtual private network
- (2) assure that eavesdroppers on the Internet cannot read messages sent over the virtual private network.
Because both features are generally desirable, most implementations are likely to use ESP rather than AH.