In this mode, the original IP datagram is taken and the AH header
is inserted right after the IP header. If the datagram already has an
IPSec header, then the AH header is inserted before any of those.
Transport mode is used by hosts, not by gateways. In fact, gateways
are not required to support transport mode.
The advantage of the transport mode is it requires less processing
overhead. The disadvantage is that the mutable fields are not
authenticated.
Figure 1
