In tunnel mode, IPsec is used to protect a completely encapsulated IP datagram
after the IP header has already been applied to it. The IPsec headers appear in
front of the original IP header, and then a new IP header is added in front of the
IPsec header. That is to say, the entire original IP datagram is secured and then
encapsulated within another IP datagram. This is shown in Figure 29-5