Tunnel Mode
With tunnel mode, a number of hosts on networks behind firewalls may engage in secure communications without implementing IPSec.
The unprotected packets generated by such hosts are tunneled through external networks
These paths use SAs set up by the IPSec process in the firewall or secure router at the boundary of the local network