Home > Networking Tips > Wide Area Networks > VPNs then and now: IPsec and MPLS
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WIDE AREA NETWORKS

VPNs then and now: IPsec and MPLS


Robbie Harrell
03.24.2004
Rating: -4.33- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Virtual Private Networks or VPNs have been around for quite some time. If you are an organization that interconnects remote sites over ATM, Frame-Relay or TDM (time division multiplexing) circuits via a carrier's backbone, then you already have deployed a virtual private network. Carriers' VPN solutions are deployed as partial mesh, full mesh and hub and spoke designs that provide point to point and multipoint connectivity for a multitude of services from multiple providers across the globe. I refer to these types of VPN solutions as private line VPNs, since the carrier provisioned circuit topology and interconnections define the VPN not an overlay technology such as IPSEC or MPLS.

So, if VPN technologies have been around for so long, why all the commotion surrounding alternative forms of VPNs? The answer is two fold. With the advancements in voice and video over IP, consumers realized they could converge real time applications (such as voice and video) and data onto one access circuit, the data circuit, thereby substantially lowering the cost of WAN circuits required for telecommunication. Secondly, carriers realized that with the evolution of convergent technologies, they no longer needed to deploy, maintain and support TDM and IP backbones. However, carriers' IP backbones provided no segmentation of customer traffic or the inherent security associated with that segmentation. Initially, IPSEC became the predominant mechanism for providing the underlying VPN architectures. Customers' traffic was encrypted but not necessarily segmented. By encrypting the traffic, the customer could build VPN networks over the Internet. However, IPSEC in general, is inefficient in that it requires significant overhead to encrypt the traffic. This is acceptable to low speed links but throughput is significantly impacted on high speed links. Most router vendors provide IPSEC capabilities embedded in the operating systems but there is significant performance degradation. Line speed IPSEC processing is still not where most customers would like it top be. MPLS on the other hand provides segmentation of traffic in the same manner as PVC's.

MPLS VPNs provide separation of one customer's traffic from another's by virtue of label switched paths (analogous to PVCs) and separate routing instances per customer. Physically this capability resides on a common platform but logically it is separate. With the advent of MPLS as a viable technology, customers can now build VPNs that support voice, video and data over a common interface. The security and segmentation is inherent to MPLS and there is no performance impact associated with IPSEC encryption. There are tremendous economies of scale associated with MPLS VPNs and as carriers migrate to high speed IP backbones that are capable of supporting real time services over IP, MPLS becomes a very good choice for cost effective VPN solutions.

The tips that I will write moving forward will investigate in detail the comparisons of VPN technology, the design aspects of MPLS, deployment tips for getting the most from an MPLS solution and technical aspects of MPLS architectures. Next tip, IPSEC versus MPLS: a technical discussion.


Robbie Harrell (CCIE#3873) is the National Practice Lead for Advanced Infrastructure Solutions for SBC Communications. He has over 10 years of experience providing strategic, business, and technical consulting services to clients. Robbie resides in Atlanta, and is a graduate of Clemson University. His background includes positions as a Principal Architect at International Network Services, Lucent, Frontway and Callisma.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Virtual Private Networks
Networking Products of the Year 2004
The best of 2004
Preparing an RFP, Part 3 - Measure the results
VPLS, a new Layer 2 MPLS VPN technology
SRLGs solve network reliability problems
Selecting network services
Securing Cisco networks
Sprint makes about-face on VPN technology
Networking Products of the Year
Colligo wraps VPN around apps

Wide Area Networks
Application switch testing: An easy RFP guide
How to calculate network bandwidth requirements
Disabling IPv6 in Windows Vista -- Pros and cons
Advanced OpenVPN configuration
Basic IPsec VPN topologies and configurations - from IPsec Virtual Private Network Fundamentals
Configuring a VRF
Preparing an RFP, Part 3 - Measure the results
VPLS, a new Layer 2 MPLS VPN technology
SRLGs solve network reliability problems
IPsec VPN clients

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts