Internet Protocol Security (IPsec)

IPsec secures IP communications through authentication and encryption at the network layer, widely deployed in VPNs and site-to-site tunnels. The surface it presents to an adversary is proportional to its complexity: key negotiation steps, cryptographic mode selection, identity verification, and implementation variation all create points where the security model can be degraded, abused, or circumvented rather than broken outright.