Firewalls and Tunnels
5-20
Hewlett-Packard Company Virtual Private Networking Concepts Guide
Tunnel Modes
Tunnel Modes
Tunnel Modes
Tunnel Modes
VPN tunnels are assigned a mode of either red or black. The
color of the tunnel indicates whether the device on the other end
of the tunnel is trusted; red is trusted and black is untrusted.
When a tunnel starts inside a trusted network, it indicates that
the packets entering or leaving the tunnel are trusted. This is
known as a red tunnel. Conversely, when a tunnel starts outside
the trusted network, it indicates that the data packets are not
trusted. This is known as a black tunnel. In both cases, the data
packets can travel between the two networks safely.
There are three possible ways exist to build a tunnel, depending
on where the two ends terminate:
•
If both ends of the tunnel terminate inside the trusted network,
then the tunnel is called a red-red network. In this case, the two
networks trust each other.
•
If both ends of the tunnel terminate outside the network, the
tunnel is called a black-black network, and neither network
trusts the other completely.
•
Finally, if one end of a tunnel terminates inside a network, while
the other end terminates outside the network, then the tunnel is
called a red-black network or a black-red network. In this case,
one network trusts the other while the trust is not reciprocated.