Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Apple tops the $100B+ tech club
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Microsoft details Windows 8 for ARM devices
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
/


Feature /

How it works: Layer 2 VPNs


VPN UpdateWith Multi-protocol Label Switching Layer 2 VPNs based on the Martini approach, a customer's Layer 2 traffic is encapsulated when it reaches the edge of the service provider network, mapped onto a label-switched path, and carried across a network.

This Layer 2 VPN technique takes advantage of MPLS label stacking, whereby more than one label is used to forward traffic across an MPLS infrastructure. Specifically, two labels are used to support MPLS Layer 2 VPNs: One label represents a point-to-point virtual circuit, while a second label represents the tunnel across the network.

The current Martini drafts define encapsulations for Ethernet (port-based and virtual LANs [VLAN]), ATM (ATM Adoption Layer Type 5 and cell formats), Frame Relay, Point-to-Point Protocol and High-level Data Link Control.

Other drafts are being developed that fine-tune support for specific traffic types. The Fischer draft (which vendors such as Alcatel and Nortel support) provides an alternative encapsulation for ATM.

Once traffic is encapsulated, the ingress Label Switch Router (LSR) assigns it a virtual circuit label. This label identifies the VPN, VLAN or connection end point (equivalent to a Frame Relay Data Link Connection Identifier, for example); the egress LSR uses the virtual circuit label to determine how to process the frame. Control protocols, including the MPLS Label Distribution Protocol and Border Gateway Protocol, are used to set up the emulated virtual circuits.

For its part, the tunnel label determines the path a packet takes through the network -- that is, LSRs in the network core use the tunnel label for packet forwarding. Numerous emulated virtual circuits can be carried in a single tunnel, which aids in scalability.

Vendors are supporting a variety of MPLS protocols, including Label Distribution Protocol and Resource Reservation Protocol-Tunneling Extension, for tunnel setup.

Back to main story: The promised LAN

Related Links

Variations on a VPN theme
A new breed of VPN based on Multi-protocol Label Switching is emerging as an alternative to traditional VPNs based on IP Security. Network World, 04/08/02.

VPN audio primer
. In this 6-minute primer you'll learn how VPNs work as well as if they are right for your remote access needs. Network World Fusion.

VPN e-mail newsletter
A twice-weekly look at VPN technologies and trends. Network World Fusion.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.