- Gateway: The gateway is usually your firewall, but this can be any host within your network.
Often the gateway is also able to serve a small network with DHCP and DNS.
In the image above the hosts moon and sun serve as gateways for the internal hosts alice and bob,
- Remote access / Roadwarrior clients: Usually, roadwarriors are laptops and other mobile devices
connecting from remote to your network using the gateway. In the image above carol represents a
roadwarrior who wants to access either of the two networks behind the two gateways.
- Remote hosts / Host-to-Host: This can be a remote web server or a backup system. This is illustrated
in the image by host winnetou and either of the gateways. The connection between the two hosts can
usually be initiated by either one of them.
- Remote sites / Site-to-Site: Hosts in two or more subnets at different locations should be able to access
each other. Again referring to the image above, the two subnets 10.1.0.0/24 and 10.2.0.0/24 behind
gateways moon and sun, respectively, might be connected, so that the hosts alice and bob may securely
communicate with one another.
transport mode 端到端(Remote access / Roadwarrior)的情况，比如client -> server直连（server不能作代理）
tunnel mode 非端到端情况，如Host-to-Host、 Site-to-Site。
我们常见的拓扑结构可能是这样： pc -> router(nat) -> vpn server
tunnel mode nat-t