5.7 Summary

In this chapter, we discussed the following:

  • Business customers want new approaches to wide area networking that preserve the benefits of low-cost, easy-to-deploy IP-based intranet applications and deliver them to mobile users and branch offices. IVPN solutions are emerging as a viable solution that provides the connectivity, transparency, security, and flexibility required by intranet and extranet applications over public wide area backbones such as the Internet.

  • The availability of advanced outsourced IP networking services will give small and medium-sized businesses the ability to deploy global networks at a manageable price, in order to stay competitive against large corporations.

  • The groundswell of demand for IVPN services is forcing service providers to plan and implement the deployment of highly scalable IVPNs, preserving the current economic benefits for subscribers while also adding new capabilities and services.

  • Layer 2 tunneling protocols such as L2TP and PPTP are a good way of providing cost-effective remote access in mixed-protocol environments; however, they offer no privacy (well, PPTP has extensions for encryption and authentication). Without the complementary use of strong, scalable, security techniques (as provided by IPSec), a Layer 2 tunnel alone does not provide adequate security for today's e-commerce applications.

  • An advantage of tunneling protocols such as L2TP and GRE is that providers can offer finer-grained QoS than with IPsec solutions alone (since routers have visibility into IP header information necessary for application-level QoS). In an IPSec packet, the payload protocol and user data are encrypted, obfuscating all of the useful data required to prioritize applications. The disadvantage of a pure encapsulation solution is that by definition it is not secure.

  • L2TP enables remote users to connect to a local ISP and tunnel through the Internet to a home network, avoiding long-distance charges. L2TP has emerged as the open standard protocol for multiprotocol Layer 2 tunneling. L2TP should be used over IPSec for true VPN provisioning.

  • IPSec is becoming the standard for IP-based VPN applications. IPSec is now a powerful and mature standard with excellent support for authentication, confidentiality, and key management (via IKE). Since IPSec works at the Network Layer, it is totally transparent to applications. While the combination of the IPSec protocols in theory leads to a large number of possibilities, in practice only a few are commonly used.


