1-4 - Peer-to-Peer MPLS VPNs Flashcards
What are the characteristics of a peer-to-peer VPN?
- overcomes the scalability issue of P2P overlay VPNs
- service providers actively participate in customer routing
What are the characteristics of this type of peer-to-peer VPN: ACLs (shared router)
- two or more customers share a PE router
- ISP uses ACLs to filter traffic on the shared PE to isolate on customer’s traffic from anothers’
- ISP allocates a portion of its address space to each customer
What are the characteristics of this type of peer-to-peer VPN: split routing (dedicated router)
- each customer has their own dedicated PE router at the POPs
- each PE router only contains routes to that specific customer’s networks
- P routers contain all customer routes
- PEs have route filters applied to only accept routes for that particular customer’s networks
What are the characteristics of this type of peer-to-peer VPN: GET VPN
- tunnel-less
- preserves original source and destination IP addresses in header of encrypted packet
- uses Group Domain of Interpretation (GDOI) as the keying protocol and IPsec for encryption
What are the characteristics of this type of peer-to-peer VPN: MPLS (L3) VPNs
- implements best features of the overlay and point-to-point models
- uses MPLS labels
- PEs exchange routing info with CEs
- uses MP-BGP (e.g. VPNv4 address-family)
- P routers don’t carry customer routing information. Just the PEs do.
Customer Network
customer controlled domain with devices or routers that span multiple sites
CE routers
routers in customer network that interface with the service provider network
provider network
provider controlled domain with PE and P routers that connect sites that belong to the customer on a shared infrastructure
PE routers
routers in the provider network that connect to CE routers in the customer network
provider routers
routers in the core of the provider network that interface with either other provider core router or PE routers
Forward Equivalence Class (FEC)
represents a group of packets to be treated in the same way by the network