This option is much less work because it means you make
changes to only a few routers instead of hundreds or thousands of clients. It provides
protection only between pairs of routers that implement IPsec, but this may
be sufficient for certain applications such as VPNs. The routers can be used to provide
protection for just the portion of the route that datagrams take outside the
organization, thereby leaving connections between routers and local hosts unsecured
(or possibly, secured by other means)