Establishing an IPSec tunnel between headquarters and branches is a safe and effective connection solution when the dedicated line between branches fails.However,in the actual connection process,some branches can only access the internet through address translation by NAT devices in the network,while IPSec does not allow packet modification.By analyzing the packet encapsulation formats under two working modes of IPSec protocol,the NAT traversal steps and specific examples of IPSec are provided,which has certain reference significance for the application of NAT traversal technology in IPSec.