1-2 - VPN Fundamentals Flashcards
Advantages of VPNs
- cost savings
- scalability
- improved security
- better performance
- flexibility and reliability
- greater access to mobile users
provider network
common infrastructure owned by service providers that are used to offer VPN services to customers
customer network
- exclusively under customer control
- consists of routers at various customer sites
- routers that connect the sites of individual customers to the service provider network are called customer edge routers
customer sites
sites that are contiguous parts of the customer network
P device
device on the provider network with no customer connectivity
PE device
device on provider network to which customer devices are connected
PE-CE link
the link between a PE router and a CE router
CE device
device in the customer network that links to the provider network (a.k.a. CPE)
VPN models
overlay: SP provided VCs between customer sites as a replacement for dedicated P2P links
peer-to-peer: SP actively participates in customer routing
Examples of Overlay VPNs (L2 and L3)
L2:
X.25
Frame Relay
ATM
L3:
GRE
DMVPN
IPsec
L2TPv3
SSL VPN
Peer-to-peer VPN examples
- ACLs (shared router)
- split routing (dedicated router)
- GET VPN
- MPLS VPN
Describe MPLS L2VPNs
- Enable the SP to offer P2P or MP2MP L2 connections between distant customer sites
- consolidate L2 traffic such as Ethernet, Frame Relay, ATM, HDLC, and PPP over an IP or MPLS network
- no IP signaling is needed between the customer and provider
Describe MPLS L3VPNs
- customer peers with the service provider at the IP Layer 3 level
- uses private, IP-based service offering from service provider
- they must establish IP routing (static or dynamic) to exchange routing info between customer sites that belong to the same VPN
- VRF instances isolate customer routing information
- MPLS seamlessly provides any-to-any connectivity between sites that belong to the same VPN
Intra-AS VPN
single ASN provides connectivity between sites that belong to a single company
Inter-AS VPN
- allows service providers that run separate networks to jointly offer MPLS VPN services to the same end customer
- can begin at one customer site and traverse multiple service provider backbones before it arrives at another customer site