vpn presentation ppt 4703

17
VPN VPN

Upload: fatima-narjis

Post on 11-Mar-2015

118 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: VPN Presentation Ppt 4703

VPNVPN

Page 2: VPN Presentation Ppt 4703

What is VPNWhat is VPN

• An arrangement that provides connections An arrangement that provides connections between: between: – OfficesOffices– remote workers and remote workers and – the Internetthe Internet

• Without requiring a dedicated LineWithout requiring a dedicated Line

• Also known as private networks between sitesAlso known as private networks between sites

Page 3: VPN Presentation Ppt 4703

VPN-Remote Access, and Interoffice VPN-Remote Access, and Interoffice ConnectionsConnections

• Rational for VPN Between OfficesRational for VPN Between Offices

• Productivity Away from the OfficeProductivity Away from the Office

• VPN TechnologyVPN Technology

Page 4: VPN Presentation Ppt 4703

Between OfficesBetween Offices

• Shared circuits within the carrier Shared circuits within the carrier networksnetworks

• Adding capacity to a VPN is:Adding capacity to a VPN is:– Simpler than adding a high-speedSimpler than adding a high-speed– Customer needs only high-speed from Customer needs only high-speed from

its building to the carrier’s networkits building to the carrier’s network

Page 5: VPN Presentation Ppt 4703

Productivity Away from the OfficeProductivity Away from the Office

• Overcomes dial up costs and Overcomes dial up costs and slownessslowness

• Access via a browser to corporate Access via a browser to corporate data bases is the same data bases is the same – at home or at home or – in the officein the office

Page 6: VPN Presentation Ppt 4703

Newer VPN TechnologyNewer VPN Technology

• VPN Site-to-SiteVPN Site-to-Site– MPLSMPLS– IP VPNsIP VPNs

• Secure Access on VPNs for Remote Secure Access on VPNs for Remote AccessAccess– IPSec (Internet protocol security)IPSec (Internet protocol security)– SSL (Secure socket layer) securitySSL (Secure socket layer) security

Page 7: VPN Presentation Ppt 4703

Secure Access on VPNs for Remote Secure Access on VPNs for Remote AccessAccess

– IPSec (Internet protocol security) - requires IPSec (Internet protocol security) - requires client software on computersclient software on computers• Established a secure, encrypted link to a security Established a secure, encrypted link to a security

device at the carrier or the enterprise.device at the carrier or the enterprise.– THIS IS TUNNELINGTHIS IS TUNNELING

– SSL (Secure socket layer) security – is a newer SSL (Secure socket layer) security – is a newer VPN method.VPN method.• Access is embedded in browsers so the organizations Access is embedded in browsers so the organizations

are not required to install special client software in are not required to install special client software in each users computer.each users computer.

Page 8: VPN Presentation Ppt 4703

Rational for VPN Between OfficesRational for VPN Between Offices

• EmployeesEmployees

• Branch OfficesBranch Offices

• Business PartnersBusiness Partners

Page 9: VPN Presentation Ppt 4703

MPLS (Multiprotocol Label MPLS (Multiprotocol Label Switching)Switching)

– VPNs Everyone-to-Everyone LinkVPNs Everyone-to-Everyone Link

– Classes of Service –Prioritize Particular Classes of Service –Prioritize Particular TrafficTraffic

– Electronic Tags on MPLS packetsElectronic Tags on MPLS packets

– Service ComponentsService Components

Page 10: VPN Presentation Ppt 4703

VPNs Everyone-to-Everyone LinkVPNs Everyone-to-Everyone Link

• CustomerCustomer provides to SP provides to SP– A list of IP addresses for each site in the A list of IP addresses for each site in the

VPNVPN

• CarrierCarrier uses the list to define a uses the list to define a closed group of users allowed to closed group of users allowed to communicate with each othercommunicate with each other

Page 11: VPN Presentation Ppt 4703

Classes of Service –Prioritize Particular Classes of Service –Prioritize Particular TrafficTraffic

• Customer chooses 4-5 classes of Customer chooses 4-5 classes of serviceservice– Used to define priorityUsed to define priority– Data, voice, video (low class Data, voice, video (low class high) high)

Page 12: VPN Presentation Ppt 4703

Electronic Tags on MPLS packetsElectronic Tags on MPLS packets

• MPLS attached tags to packetsMPLS attached tags to packets

• Router reads tags and sets priorityRouter reads tags and sets priority

• Bypass the routing table lookupBypass the routing table lookup

• Good VoIP featureGood VoIP feature

Page 13: VPN Presentation Ppt 4703

Service ComponentsService Components

• T1 typical to carrierT1 typical to carrier

• Separate access linesSeparate access lines– MPLS (trusted sources)MPLS (trusted sources)– Internet (high levels of security)Internet (high levels of security)

Page 14: VPN Presentation Ppt 4703

VPNs Everyone-to-Everyone LinkVPNs Everyone-to-Everyone Link

• Mess serviceMess service• MPLS VPN traffic is carried separately from MPLS VPN traffic is carried separately from

public internet traffic to guarantee levels public internet traffic to guarantee levels of service.of service.

• IP VPNs – site-to-site using the public IP VPNs – site-to-site using the public Internet with IPSecInternet with IPSec

• IPSec creates a tunnel for each packetIPSec creates a tunnel for each packet• Tunnel hides the destination IP addressTunnel hides the destination IP address• Scrambles data by encrypting itScrambles data by encrypting it

Page 15: VPN Presentation Ppt 4703

VPNs for International ConnectivityVPNs for International Connectivity

• IPSec VPNs – Public internet-Based IPSec VPNs – Public internet-Based VPNs for Intersite ConnectionsVPNs for Intersite Connections

• Network-Based IPSec VPNs – over Network-Based IPSec VPNs – over carrier private IP Networkscarrier private IP Networks

Page 16: VPN Presentation Ppt 4703

IPSec VPNs – Public internet-Based IPSec VPNs – Public internet-Based VPNs for Intersite ConnectionsVPNs for Intersite Connections

• The VPN provider manages the The VPN provider manages the intercountry portion of the networkintercountry portion of the network

• Carrier’s POP refers to the site where its Carrier’s POP refers to the site where its equipment residesequipment resides

• NTT, BT, AT&T, Infonet, MCI, Sprint, NTT, BT, AT&T, Infonet, MCI, Sprint, Equant all offer intercontinental service.Equant all offer intercontinental service.

Page 17: VPN Presentation Ppt 4703

The EndThe End