Skip to content
arrow_back
search
ISM-0494 policy ASD Information Security Manual (ISM)

Use of IPsec Tunnel and Transport Modes

IPsec connections should use tunnel mode; if using transport mode, ensure an IP tunnel is used.

record_voice_over

Plain language

This control is about using a specific method to secure information when it's sent over the internet—like putting it in a secure envelope. Tunnel mode is preferred because it wraps everything up securely. If you don't use it, private information could be exposed, leading to data leaks or breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel is used.
policy ASD Information Security Manual (ISM) ISM-0494
priority_high

Why it matters

Using IPsec transport mode without an IP tunnel can expose payload data and leak endpoints, increasing interception risk and causing compliance issues.

settings

Operational notes

Confirm IPsec uses tunnel mode by default; if transport mode is required, ensure an IP tunnel is configured and periodically validate settings in change reviews.

Mapping detail

Mapping

Direction

Controls