Home > Ask the Networking Experts > VPNs with Lisa Phifer Questions & Answers > I've heard rumors that some service providers can see unencrypted VPN traffic of their customers. Is this true?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

I've heard rumors that some service providers can see unencrypted VPN traffic of their customers. Is this true?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 12 April 2005
I've heard rumors that some service providers can see unencrypted VPN traffic of their customers. Is this true?

>
EXPERT RESPONSE
There are many definitions of "virtual private network," and not all VPNs use end-to-end encryption. For example:

  • VPNs based on Multi-Protocol Label Switching (MPLS) carve virtual switched paths out of the provider's network to carry customer traffic between edge routers. MPLS does not provide data encryption, but can be used in conjunction with IPsec when encryption is required.

  • VPNs based on the Layer Two Tunneling Protocol (L2TP) relay dial-up (PPP) sessions terminated by an ISP's Network Access Server to an L2TP Gateway at the customer's network. L2TP does not provide data encryption, but is commonly used over IPsec transport mode to provide confidentiality (for example, within Windows XP/2000).

  • Network-based IPsec VPN services often use a carrier-class VPN switch at the provider's point of presence (POP) to initiate and terminate VPN tunnels across the provider's backbone. The "tail circuit" between the customer's premises and the provider's POP (for example, a dedicated T1 link or a Frame Relay PVC) may or may not be encrypted.

    If you require end-to-end confidentiality from your VPN service -- that is, encryption from customer premises to customer premises, without any point in the middle at which your data is cleartext -- then it's important to explicitly look for a secure VPN service that provides this. For example, most managed IPsec VPN services can deliver end-to-end encryption. But whether or not they actually do encrypt end-to-end is determined by the VPN's security policy configuration.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    VPNs with Lisa Phifer
    Would you consider a Microsoft VPN tunnel through a WEP encrypted access point to be secure?
    I need to select a Cisco ADSL router which is capable of acting as a VPN server for Microsoft VPN clients that come through the Internet.
    I am having issues with the IKE communication between the two Cisco VPN concentrators.
    What about using SSL VPN with e-mail clients?
    Can you have two VPN connections to the same machine simultaneously?
    Why can't I access my folders on the server through the VPN?
    I need a very basic VPN solution to connect two offices to allow two servers to talk to one another.
    After setting up my wireless router, I can no longer get on the VPN.
    Can one use VPN over a peer-to-peer network within a home?
    Why can't I access my company's VPN?

    VPN Products and Services
    To simulate voice over IPSec VPNs which simulators work?
    Creating Remote Access and Site-to-Site VPNs with ISA Firewalls: from 'The Best Damn Firewall Book Period, Second Edition'
    How can I get our VPN to work on Windows Vista?
    To set up a VPN server, do you need two NIC cards?
    How do I connect to our VPN with authentication ID?
    SonicWall acquisition could hurt Aventail users
    What equipment do I use to connect two LANs in different cities? What are the steps?
    Remote access keeps physicians connected
    Security Spotlight: SSL VPN appliances simplify secure access
    MPLS transport options

    VPN Troubleshooting
    How to maintain corporate VPN connection while printing to a private network.
    Can I set up a VPN on my wireless router?
    How can I get our VPN to work on Windows Vista?
    To set up a VPN server, do you need two NIC cards?
    How do I connect to our VPN with authentication ID?
    What causes my overseas VPN connection to slow during the day?
    Why has the terminal server ended my connection?
    How can I access each device from my network while keeping the companies' networks secure?
    VPN operating system interoperability -- Configure VPNs with Windows, Checkpoint
    VPN operating system interoperability -- configure VPNs with Unix

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    extranet  (SearchNetworking.com)
    hardware VPN  (SearchNetworking.com)
    IPLC  (SearchNetworking.com)
    virtual network adapter  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Expert networking advice and tips for IT professionals
    Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts