IPSec
In short: Internet Protocol Security — a protocol suite that authenticates and encrypts IP packets at the network level, independently of the application above.
In more detail: Because IPSec operates directly at layer 3, it’s transparent to all applications — they notice nothing of the encryption. The most common use: setting up site-to-site or client VPN connections between networks.
In Depth
IPSec consists of several interacting sub-protocols rather than a single one: IKE (Internet Key Exchange) negotiates the cryptographic keys between the two sides at the beginning (comparable to a handshake), AH (Authentication Header) ensures integrity and authenticity (without encrypting the data), and ESP (Encapsulating Security Payload) handles the actual encryption of the payload — in practice ESP is almost always used, since it can do both at once.
A central architectural feature is that it operates at layer 3 (network layer) instead of further up like TLS (which typically operates at the application level, see HTTPS):
TLS: the application notices encryption and has to use it explicitly (https:// instead of http://)
IPSec: the application notices NOTHING, every IP packet is automatically protected
This transparency is IPSec’s biggest advantage for corporate networks: a site-to-site VPN between two company locations automatically encrypts ALL data traffic between the networks, without individual applications having to be adapted for it — from the point of view of an employee at location A, accessing a server at location B feels just like in the local network. The drawback: configuration is more complex than with application-specific solutions, and IPSec can cause problems with NAT routers (since it wasn’t originally designed for networks with address translation), which makes additional workarounds such as NAT traversal necessary.
See also: VPN, Encryption