When sending encrypted traffic from firewall/IPsec gateway to firewall/IPsec gateway,
Why does there need to be an extra IP header? Why can’t the sending firewall/IPsec
Gateway simply encrypt the packet, leaving the source and destination addresses in the
New outer IP header the same as those in the original (now inside) IP header source and
Destination addresses?
