Sunteți pe pagina 1din 2

Site-to-site connectivity: MPLS vs.

IPSec

by David Davis, CCIE, MCSE


When it comes to connecting multiple sites with WAN links, there are now a variety of viable choices.
Naturally, the solution that is right for your business will vary depending on the size of your company, the
type of traffic you need to transmit, and your preferences for security, latency, and reliability.

In the not-too-distant past, a business could choose from dial-up circuits, dedicated point-to-point circuits,
and ultra-expensive ATM. In the late 1990s, frame relay generally replaced dedicated point-to-point
circuits as the top choice because of its ability to create a fully or partially meshed network that provided
better fault tolerance. However, with the popular spread of the Internet and the increasingly low cost of
connecting to it, encrypted site-to-site VPN tunnels have taken the top spot from frame relay.

The drawbacks to encrypted VPN tunnels are that there is overhead (latency) associated with the
encryption, security is of much greater concern, and reliability can be decreased due to the complexities
of the Internet. For example, some companies even choose DSL Internet circuits to run site-to-site VPN
tunnels over. While DSL Internet circuits may be a good fit for a small company or a telecommuter, they
are usually inadequate for a business to depend on for critical data, due to their poor SLAs and low
priority for repair by telecom companies. All of these options have their negatives. I know about these
negatives because my company (a 70-location retail company) has made this progression from dedicated
point-to-point, to frame-relay, and to IPSec VPN over DSL Internet and dedicated Internet T1 circuits.
Now, my company is about to make the transition to Multiprotocol Label Switching (MPLS).

MPLS is usually done by giving the customer a dedicated IP circuit with private IP addressing on it. Any
traffic sent from the customer to the carrier, on that circuit, is labeled. That labeled packet is sent across a
labeled switch path (LSP) to a label switch router (LSR). That router routes the packet to its label edge
router (LER), where the label is removed and the packet is delivered to the customer’s destination router.
What this does for the customer is create a private network without any encryption required. For the
customer’s router to know what networks are available, it runs a routing protocol like OSPF or BGP and
receives routes from routers in the MPLS cloud (or the provider can do static routing).

One of the top benefits of MPLS is that it creates a fully meshed network by default. So by being
connected to your MPLS network, you have a direct connection to all your remote locations without any of
the additional cost or configuration you would need with frame-relay or IPSec VPN tunnels. An application
that most benefits from this "any-to-any" connectivity is Voice-over-IP (VoIP). VoIP is challenging to
implement over IPSec site-to-site VPN tunnels because the encryption and going through multiple
Internet carriers can cause too much latency. Of course, an infinite number of applications might benefit
from the built-in any-to-any connectivity of MPLS. The other main benefit of MPLS is the quality of service
(QoS). Either the carrier will offer QoS in its standard offering or it will be an add-on feature. With the QoS
of MPLS, you can prioritize certain traffic all the way through the carrier’s network.

To help you size up the similarities, differences, and pros and cons of MPLS and IPSec VPN, I've put
together the comparison chart on page 2.
Author's note
For the purposes of this article, when I say “IPSec VPN,” I'm talking about “IPSec site-to-site VPN
tunneling.” That would be using VPN concentrators/routers to encrypt traffic over the Internet to connect
multiple remote LANs. Undoubtedly, standard IPSec VPN servers are great for allowing remote access
to individual users, but we aren't comparing that here.

Feature MPLS VPN IPSec site-to-site VPN

Reliability You will have to receive all MPLS circuits Receiving all your IPSec VPN circuits
through a single carrier, which helps with through the same carrier will increase
reliability. However, some carriers offer reliability (but decrease fault tolerance)
MPLS using DSL as the local loop, and over using multiple Internet carriers. But
choosing this can result in less reliability. due to the multiple VPN concentrators and
In general, MPLS will be more reliable the encryption configuration, an IPSec
than IPSec VPNs because there is less VPN can be less reliable than MPLS.
complication in the tunneling and firewall
configuration.

Cost The cost for the local loops for each Unlike MPLS, IPSec VPN requires VPN
choice will be the same. The MPLS concentrators, which will boost the upfront
tunneling, through the carrier, will have a cost. Once you have the hardware, the
price tag associated with it, but it shouldn’t staff required to maintain and troubleshoot
be more than a managed IPSec VPN the IPSec VPN tunnels may be the same
service from a carrier or more than the as, or more than, the MPLS service from
staff required to manage and troubleshoot the carrier.
an IPSec VPN.

Security MPLS should be more secure than IPSec Network intrusions are a greater concern
VPN tunnels, if you don’t allow your MPLS with IPSec VPN tunnels since you are
circuits to connect directly to the Internet, running them through an Internet circuit.
which some carriers offer through the That Internet circuit is open to connections
carrier’s MPLS cloud. For the best from around the world. A misconfigured
security, use MPLS as a private network firewall can open your IPSec VPN network
only. Used as a private network, MPLS to the Internet. Security is of even higher
offers the same security as a frame relay concern if you use split tunneling on your
network. However, keep in mind that as VPN concentrators. However, IPSec VPN
with frame relay, data sent over an MPLS tunnels beat out MPLS when it comes to
network is not encrypted. protecting the data that is traversing the
WAN, because the IPSec VPN data will be
encrypted with IPSec. The MPLS data is
not encrypted, only tunneled.

QoS QoS may be included with the carrier’s QoS features are limited. Once you send
MPLS offering or it may cost extra. Either your encrypted data over the Internet, little
way, with MPLS QoS, you can prioritize can be done to prioritize it.
certain traffic all the way through the
carrier’s network. This is great for latency-
sensitive applications, like VoIP.

To get more details on the various MPLS options, check out shopforbandwidth.com.

S-ar putea să vă placă și