SlideShare a Scribd company logo
1 of 2
Download to read offline
Site-to-site connectivity: MPLS vs. IPSec
by David Davis, CCIE, MCSE
When it comes to connecting multiple sites with WAN links, there are now a variety of viable choices.
Naturally, the solution that is right for your business will vary depending on the size of your company, the
type of traffic you need to transmit, and your preferences for security, latency, and reliability.
In the not-too-distant past, a business could choose from dial-up circuits, dedicated point-to-point circuits,
and ultra-expensive ATM. In the late 1990s, frame relay generally replaced dedicated point-to-point
circuits as the top choice because of its ability to create a fully or partially meshed network that provided
better fault tolerance. However, with the popular spread of the Internet and the increasingly low cost of
connecting to it, encrypted site-to-site VPN tunnels have taken the top spot from frame relay.
The drawbacks to encrypted VPN tunnels are that there is overhead (latency) associated with the
encryption, security is of much greater concern, and reliability can be decreased due to the complexities
of the Internet. For example, some companies even choose DSL Internet circuits to run site-to-site VPN
tunnels over. While DSL Internet circuits may be a good fit for a small company or a telecommuter, they
are usually inadequate for a business to depend on for critical data, due to their poor SLAs and low
priority for repair by telecom companies. All of these options have their negatives. I know about these
negatives because my company (a 70-location retail company) has made this progression from dedicated
point-to-point, to frame-relay, and to IPSec VPN over DSL Internet and dedicated Internet T1 circuits.
Now, my company is about to make the transition to Multiprotocol Label Switching (MPLS).
MPLS is usually done by giving the customer a dedicated IP circuit with private IP addressing on it. Any
traffic sent from the customer to the carrier, on that circuit, is labeled. That labeled packet is sent across a
labeled switch path (LSP) to a label switch router (LSR). That router routes the packet to its label edge
router (LER), where the label is removed and the packet is delivered to the customer’s destination router.
What this does for the customer is create a private network without any encryption required. For the
customer’s router to know what networks are available, it runs a routing protocol like OSPF or BGP and
receives routes from routers in the MPLS cloud (or the provider can do static routing).
One of the top benefits of MPLS is that it creates a fully meshed network by default. So by being
connected to your MPLS network, you have a direct connection to all your remote locations without any of
the additional cost or configuration you would need with frame-relay or IPSec VPN tunnels. An application
that most benefits from this "any-to-any" connectivity is Voice-over-IP (VoIP). VoIP is challenging to
implement over IPSec site-to-site VPN tunnels because the encryption and going through multiple
Internet carriers can cause too much latency. Of course, an infinite number of applications might benefit
from the built-in any-to-any connectivity of MPLS. The other main benefit of MPLS is the quality of service
(QoS). Either the carrier will offer QoS in its standard offering or it will be an add-on feature. With the QoS
of MPLS, you can prioritize certain traffic all the way through the carrier’s network.
To help you size up the similarities, differences, and pros and cons of MPLS and IPSec VPN, I've put
together the comparison chart on page 2.
Author's note
For the purposes of this article, when I say “IPSec VPN,” I'm talking about “IPSec site-to-site VPN
tunneling.” That would be using VPN concentrators/routers to encrypt traffic over the Internet to connect
multiple remote LANs. Undoubtedly, standard IPSec VPN servers are great for allowing remote access
to individual users, but we aren't comparing that here.
Feature MPLS VPN IPSec site-to-site VPN
Reliability You will have to receive all MPLS circuits
through a single carrier, which helps with
reliability. However, some carriers offer
MPLS using DSL as the local loop, and
choosing this can result in less reliability.
In general, MPLS will be more reliable
than IPSec VPNs because there is less
complication in the tunneling and firewall
configuration.
Receiving all your IPSec VPN circuits
through the same carrier will increase
reliability (but decrease fault tolerance)
over using multiple Internet carriers. But
due to the multiple VPN concentrators and
the encryption configuration, an IPSec
VPN can be less reliable than MPLS.
Cost The cost for the local loops for each
choice will be the same. The MPLS
tunneling, through the carrier, will have a
price tag associated with it, but it shouldn’t
be more than a managed IPSec VPN
service from a carrier or more than the
staff required to manage and troubleshoot
an IPSec VPN.
Unlike MPLS, IPSec VPN requires VPN
concentrators, which will boost the upfront
cost. Once you have the hardware, the
staff required to maintain and troubleshoot
the IPSec VPN tunnels may be the same
as, or more than, the MPLS service from
the carrier.
Security MPLS should be more secure than IPSec
VPN tunnels, if you don’t allow your MPLS
circuits to connect directly to the Internet,
which some carriers offer through the
carrier’s MPLS cloud. For the best
security, use MPLS as a private network
only. Used as a private network, MPLS
offers the same security as a frame relay
network. However, keep in mind that as
with frame relay, data sent over an MPLS
network is not encrypted.
Network intrusions are a greater concern
with IPSec VPN tunnels since you are
running them through an Internet circuit.
That Internet circuit is open to connections
from around the world. A misconfigured
firewall can open your IPSec VPN network
to the Internet. Security is of even higher
concern if you use split tunneling on your
VPN concentrators. However, IPSec VPN
tunnels beat out MPLS when it comes to
protecting the data that is traversing the
WAN, because the IPSec VPN data will be
encrypted with IPSec. The MPLS data is
not encrypted, only tunneled.
QoS QoS may be included with the carrier’s
MPLS offering or it may cost extra. Either
way, with MPLS QoS, you can prioritize
certain traffic all the way through the
carrier’s network. This is great for latency-
sensitive applications, like VoIP.
QoS features are limited. Once you send
your encrypted data over the Internet, little
can be done to prioritize it.
To get more details on the various MPLS options, check out shopforbandwidth.com.

More Related Content

What's hot

12 Understanding V P Ns
12  Understanding  V P Ns12  Understanding  V P Ns
12 Understanding V P NsAamirAziz
 
PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...
PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...
PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...PROIDEA
 
PLNOG 5: Rafał Szarecki - SEAMLESS MPLS
PLNOG 5: Rafał Szarecki - SEAMLESS MPLSPLNOG 5: Rafał Szarecki - SEAMLESS MPLS
PLNOG 5: Rafał Szarecki - SEAMLESS MPLSPROIDEA
 
Velocloud introduction for wakamonog
Velocloud introduction for wakamonogVelocloud introduction for wakamonog
Velocloud introduction for wakamonogakira suzuki
 
VPN as the Key for a Successful MSP Business
VPN as the Key for a Successful MSP BusinessVPN as the Key for a Successful MSP Business
VPN as the Key for a Successful MSP BusinessSafar Safarov
 
China Telecom Americas: SD-WAN Overview
China Telecom Americas:  SD-WAN OverviewChina Telecom Americas:  SD-WAN Overview
China Telecom Americas: SD-WAN OverviewVlad Sinayuk
 
Chapter9ccna
Chapter9ccnaChapter9ccna
Chapter9ccnarobertoxe
 
MathWork Network Architecture
MathWork Network ArchitectureMathWork Network Architecture
MathWork Network ArchitectureRobert Muliero
 
China Telecom Americas Overview
China Telecom Americas OverviewChina Telecom Americas Overview
China Telecom Americas OverviewVlad Sinayuk
 
Automate programmable fabric in seconds with an open standards based solution
Automate programmable fabric in seconds with an open standards based solutionAutomate programmable fabric in seconds with an open standards based solution
Automate programmable fabric in seconds with an open standards based solutionTony Antony
 
Evolution of Network Virtualization
Evolution of Network VirtualizationEvolution of Network Virtualization
Evolution of Network VirtualizationPavan Hasabnis
 

What's hot (19)

12 Understanding V P Ns
12  Understanding  V P Ns12  Understanding  V P Ns
12 Understanding V P Ns
 
V P N
V P NV P N
V P N
 
Fusion MPLS
Fusion MPLSFusion MPLS
Fusion MPLS
 
Vivpn pp tfinal
Vivpn pp tfinalVivpn pp tfinal
Vivpn pp tfinal
 
PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...
PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...
PLNOG16: Jak zbudować Punkt Wymiany Ruchu używając urządzeń Junipera, Aleksan...
 
PLNOG 5: Rafał Szarecki - SEAMLESS MPLS
PLNOG 5: Rafał Szarecki - SEAMLESS MPLSPLNOG 5: Rafał Szarecki - SEAMLESS MPLS
PLNOG 5: Rafał Szarecki - SEAMLESS MPLS
 
Velocloud introduction for wakamonog
Velocloud introduction for wakamonogVelocloud introduction for wakamonog
Velocloud introduction for wakamonog
 
What is VPN?
What is VPN?What is VPN?
What is VPN?
 
VPN as the Key for a Successful MSP Business
VPN as the Key for a Successful MSP BusinessVPN as the Key for a Successful MSP Business
VPN as the Key for a Successful MSP Business
 
China Telecom Americas: SD-WAN Overview
China Telecom Americas:  SD-WAN OverviewChina Telecom Americas:  SD-WAN Overview
China Telecom Americas: SD-WAN Overview
 
Network Virtualization
Network VirtualizationNetwork Virtualization
Network Virtualization
 
Vpn presentation
Vpn presentationVpn presentation
Vpn presentation
 
Chapter9ccna
Chapter9ccnaChapter9ccna
Chapter9ccna
 
Vpn security
Vpn security Vpn security
Vpn security
 
MathWork Network Architecture
MathWork Network ArchitectureMathWork Network Architecture
MathWork Network Architecture
 
Ip tunneling and vpns
Ip tunneling and vpnsIp tunneling and vpns
Ip tunneling and vpns
 
China Telecom Americas Overview
China Telecom Americas OverviewChina Telecom Americas Overview
China Telecom Americas Overview
 
Automate programmable fabric in seconds with an open standards based solution
Automate programmable fabric in seconds with an open standards based solutionAutomate programmable fabric in seconds with an open standards based solution
Automate programmable fabric in seconds with an open standards based solution
 
Evolution of Network Virtualization
Evolution of Network VirtualizationEvolution of Network Virtualization
Evolution of Network Virtualization
 

Viewers also liked

Cardiovascular System
Cardiovascular SystemCardiovascular System
Cardiovascular SystemCloe Reichelt
 
SFO15-TR7: OSS License Compliance
 SFO15-TR7: OSS License Compliance SFO15-TR7: OSS License Compliance
SFO15-TR7: OSS License ComplianceLinaro
 
Appreciation Letter 2011.PDF
Appreciation Letter 2011.PDFAppreciation Letter 2011.PDF
Appreciation Letter 2011.PDFLa Shawnda Noble
 
Cancer pulmonar
Cancer pulmonarCancer pulmonar
Cancer pulmonarvepc1234
 
Guion científico de Fisiología animal.
Guion científico de Fisiología animal. Guion científico de Fisiología animal.
Guion científico de Fisiología animal. genesis Melendez
 
Un caso de enfisema subcutáneo en un canino
Un caso de enfisema subcutáneo en un caninoUn caso de enfisema subcutáneo en un canino
Un caso de enfisema subcutáneo en un caninoCarlos Morales Mendoza
 
1. aseo enfermo encamado
1. aseo enfermo encamado1. aseo enfermo encamado
1. aseo enfermo encamadoCAEDTBE
 
Enfermedad cerebro vascular
Enfermedad cerebro vascularEnfermedad cerebro vascular
Enfermedad cerebro vascularjoel cordova
 
Documentación de software
Documentación de softwareDocumentación de software
Documentación de softwareMaestros Online
 
Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez
Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez
Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez SOSTelemedicina UCV
 
Cap 01 Anatomia Renal Comprehensive Clinical Nephrology
Cap 01 Anatomia Renal Comprehensive Clinical NephrologyCap 01 Anatomia Renal Comprehensive Clinical Nephrology
Cap 01 Anatomia Renal Comprehensive Clinical NephrologyAllan Tapia Castro
 
Fitness Buffet
Fitness Buffet Fitness Buffet
Fitness Buffet Maddalungu
 

Viewers also liked (20)

Unidad herramientas de la stps
Unidad herramientas de la stpsUnidad herramientas de la stps
Unidad herramientas de la stps
 
Cardiovascular System
Cardiovascular SystemCardiovascular System
Cardiovascular System
 
SFO15-TR7: OSS License Compliance
 SFO15-TR7: OSS License Compliance SFO15-TR7: OSS License Compliance
SFO15-TR7: OSS License Compliance
 
Guia avanzada de_gestion_de_riesgos
Guia avanzada de_gestion_de_riesgosGuia avanzada de_gestion_de_riesgos
Guia avanzada de_gestion_de_riesgos
 
Appreciation Letter 2011.PDF
Appreciation Letter 2011.PDFAppreciation Letter 2011.PDF
Appreciation Letter 2011.PDF
 
Cancer pulmonar
Cancer pulmonarCancer pulmonar
Cancer pulmonar
 
Guion científico de Fisiología animal.
Guion científico de Fisiología animal. Guion científico de Fisiología animal.
Guion científico de Fisiología animal.
 
Un caso de enfisema subcutáneo en un canino
Un caso de enfisema subcutáneo en un caninoUn caso de enfisema subcutáneo en un canino
Un caso de enfisema subcutáneo en un canino
 
1. aseo enfermo encamado
1. aseo enfermo encamado1. aseo enfermo encamado
1. aseo enfermo encamado
 
Enfermedad cerebro vascular
Enfermedad cerebro vascularEnfermedad cerebro vascular
Enfermedad cerebro vascular
 
Documentación de software
Documentación de softwareDocumentación de software
Documentación de software
 
Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez
Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez
Infección con VPH y su prevención por vacuna. Dr. Alejandro Rísquez
 
Cap 01 Anatomia Renal Comprehensive Clinical Nephrology
Cap 01 Anatomia Renal Comprehensive Clinical NephrologyCap 01 Anatomia Renal Comprehensive Clinical Nephrology
Cap 01 Anatomia Renal Comprehensive Clinical Nephrology
 
CARCINOMA BASOCELULAR
CARCINOMA BASOCELULARCARCINOMA BASOCELULAR
CARCINOMA BASOCELULAR
 
Si semana01
Si semana01Si semana01
Si semana01
 
Dolor abdominal final
Dolor abdominal finalDolor abdominal final
Dolor abdominal final
 
Sindrome Ascitico Edematoso
Sindrome Ascitico EdematosoSindrome Ascitico Edematoso
Sindrome Ascitico Edematoso
 
Analisis seguro de trabajo
Analisis seguro de trabajoAnalisis seguro de trabajo
Analisis seguro de trabajo
 
Crisis hipertensiva
Crisis hipertensivaCrisis hipertensiva
Crisis hipertensiva
 
Fitness Buffet
Fitness Buffet Fitness Buffet
Fitness Buffet
 

Similar to Mpls vs ip_sec VPN's

How to Re-evaluate Your MPLS Service Provider
How to Re-evaluate Your MPLS Service ProviderHow to Re-evaluate Your MPLS Service Provider
How to Re-evaluate Your MPLS Service ProviderIdan Hershkovich
 
SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?Phani Kumar
 
hSo Guide To MPLS
hSo Guide To MPLShSo Guide To MPLS
hSo Guide To MPLShSo
 
SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?Haris Chughtai
 
International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)IJERD Editor
 
VPN (virtual private network)
VPN (virtual private network) VPN (virtual private network)
VPN (virtual private network) Netwax Lab
 
Vpls%20backgrounder
Vpls%20backgrounderVpls%20backgrounder
Vpls%20backgrounderPHIL110
 
VPN Using MPLS Technique
VPN Using MPLS TechniqueVPN Using MPLS Technique
VPN Using MPLS TechniqueAhmad Atta
 
Auto-Bandwidth Allocation in Multicast Aware VPLS Netowrks
Auto-Bandwidth Allocation in Multicast Aware VPLS NetowrksAuto-Bandwidth Allocation in Multicast Aware VPLS Netowrks
Auto-Bandwidth Allocation in Multicast Aware VPLS NetowrksAllan Kweli
 
Internet Leased Line Connection Service - Linkup Networks/
Internet Leased Line Connection Service - Linkup Networks/Internet Leased Line Connection Service - Linkup Networks/
Internet Leased Line Connection Service - Linkup Networks/LINKUPNETWORKS
 
design of leased line network using vmux
 design of leased line network using vmux design of leased line network using vmux
design of leased line network using vmuxXhitesh Thakur
 
csevpnppt-170905123948 (1).pdf
csevpnppt-170905123948 (1).pdfcsevpnppt-170905123948 (1).pdf
csevpnppt-170905123948 (1).pdfHirazNor
 
Virtual Private LAN Service (VPLS)
Virtual Private LAN Service (VPLS)Virtual Private LAN Service (VPLS)
Virtual Private LAN Service (VPLS)Johnson Liu
 
1Running Head Network Design3Network DesignUn.docx
1Running Head Network Design3Network DesignUn.docx1Running Head Network Design3Network DesignUn.docx
1Running Head Network Design3Network DesignUn.docxeugeniadean34240
 

Similar to Mpls vs ip_sec VPN's (20)

How to Re-evaluate Your MPLS Service Provider
How to Re-evaluate Your MPLS Service ProviderHow to Re-evaluate Your MPLS Service Provider
How to Re-evaluate Your MPLS Service Provider
 
SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?SD WAN VS MPLS – Which is better for your Business?
SD WAN VS MPLS – Which is better for your Business?
 
hSo Guide To MPLS
hSo Guide To MPLShSo Guide To MPLS
hSo Guide To MPLS
 
SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?SDWAN vs MPLS: What Enterprises need?
SDWAN vs MPLS: What Enterprises need?
 
Mpls
MplsMpls
Mpls
 
International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)
 
VPN (virtual private network)
VPN (virtual private network) VPN (virtual private network)
VPN (virtual private network)
 
Leased line
Leased lineLeased line
Leased line
 
Vpls%20backgrounder
Vpls%20backgrounderVpls%20backgrounder
Vpls%20backgrounder
 
Ip virtual leased line
Ip virtual leased lineIp virtual leased line
Ip virtual leased line
 
VPN Using MPLS Technique
VPN Using MPLS TechniqueVPN Using MPLS Technique
VPN Using MPLS Technique
 
Vp ns
Vp nsVp ns
Vp ns
 
Auto-Bandwidth Allocation in Multicast Aware VPLS Netowrks
Auto-Bandwidth Allocation in Multicast Aware VPLS NetowrksAuto-Bandwidth Allocation in Multicast Aware VPLS Netowrks
Auto-Bandwidth Allocation in Multicast Aware VPLS Netowrks
 
Internet Leased Line Connection Service - Linkup Networks/
Internet Leased Line Connection Service - Linkup Networks/Internet Leased Line Connection Service - Linkup Networks/
Internet Leased Line Connection Service - Linkup Networks/
 
design of leased line network using vmux
 design of leased line network using vmux design of leased line network using vmux
design of leased line network using vmux
 
Wan networks
Wan networksWan networks
Wan networks
 
csevpnppt-170905123948 (1).pdf
csevpnppt-170905123948 (1).pdfcsevpnppt-170905123948 (1).pdf
csevpnppt-170905123948 (1).pdf
 
Virtual Private Networks (VPN) ppt
Virtual Private Networks (VPN) pptVirtual Private Networks (VPN) ppt
Virtual Private Networks (VPN) ppt
 
Virtual Private LAN Service (VPLS)
Virtual Private LAN Service (VPLS)Virtual Private LAN Service (VPLS)
Virtual Private LAN Service (VPLS)
 
1Running Head Network Design3Network DesignUn.docx
1Running Head Network Design3Network DesignUn.docx1Running Head Network Design3Network DesignUn.docx
1Running Head Network Design3Network DesignUn.docx
 

Recently uploaded

Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 

Recently uploaded (20)

Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 

Mpls vs ip_sec VPN's

  • 1. Site-to-site connectivity: MPLS vs. IPSec by David Davis, CCIE, MCSE When it comes to connecting multiple sites with WAN links, there are now a variety of viable choices. Naturally, the solution that is right for your business will vary depending on the size of your company, the type of traffic you need to transmit, and your preferences for security, latency, and reliability. In the not-too-distant past, a business could choose from dial-up circuits, dedicated point-to-point circuits, and ultra-expensive ATM. In the late 1990s, frame relay generally replaced dedicated point-to-point circuits as the top choice because of its ability to create a fully or partially meshed network that provided better fault tolerance. However, with the popular spread of the Internet and the increasingly low cost of connecting to it, encrypted site-to-site VPN tunnels have taken the top spot from frame relay. The drawbacks to encrypted VPN tunnels are that there is overhead (latency) associated with the encryption, security is of much greater concern, and reliability can be decreased due to the complexities of the Internet. For example, some companies even choose DSL Internet circuits to run site-to-site VPN tunnels over. While DSL Internet circuits may be a good fit for a small company or a telecommuter, they are usually inadequate for a business to depend on for critical data, due to their poor SLAs and low priority for repair by telecom companies. All of these options have their negatives. I know about these negatives because my company (a 70-location retail company) has made this progression from dedicated point-to-point, to frame-relay, and to IPSec VPN over DSL Internet and dedicated Internet T1 circuits. Now, my company is about to make the transition to Multiprotocol Label Switching (MPLS). MPLS is usually done by giving the customer a dedicated IP circuit with private IP addressing on it. Any traffic sent from the customer to the carrier, on that circuit, is labeled. That labeled packet is sent across a labeled switch path (LSP) to a label switch router (LSR). That router routes the packet to its label edge router (LER), where the label is removed and the packet is delivered to the customer’s destination router. What this does for the customer is create a private network without any encryption required. For the customer’s router to know what networks are available, it runs a routing protocol like OSPF or BGP and receives routes from routers in the MPLS cloud (or the provider can do static routing). One of the top benefits of MPLS is that it creates a fully meshed network by default. So by being connected to your MPLS network, you have a direct connection to all your remote locations without any of the additional cost or configuration you would need with frame-relay or IPSec VPN tunnels. An application that most benefits from this "any-to-any" connectivity is Voice-over-IP (VoIP). VoIP is challenging to implement over IPSec site-to-site VPN tunnels because the encryption and going through multiple Internet carriers can cause too much latency. Of course, an infinite number of applications might benefit from the built-in any-to-any connectivity of MPLS. The other main benefit of MPLS is the quality of service (QoS). Either the carrier will offer QoS in its standard offering or it will be an add-on feature. With the QoS of MPLS, you can prioritize certain traffic all the way through the carrier’s network. To help you size up the similarities, differences, and pros and cons of MPLS and IPSec VPN, I've put together the comparison chart on page 2.
  • 2. Author's note For the purposes of this article, when I say “IPSec VPN,” I'm talking about “IPSec site-to-site VPN tunneling.” That would be using VPN concentrators/routers to encrypt traffic over the Internet to connect multiple remote LANs. Undoubtedly, standard IPSec VPN servers are great for allowing remote access to individual users, but we aren't comparing that here. Feature MPLS VPN IPSec site-to-site VPN Reliability You will have to receive all MPLS circuits through a single carrier, which helps with reliability. However, some carriers offer MPLS using DSL as the local loop, and choosing this can result in less reliability. In general, MPLS will be more reliable than IPSec VPNs because there is less complication in the tunneling and firewall configuration. Receiving all your IPSec VPN circuits through the same carrier will increase reliability (but decrease fault tolerance) over using multiple Internet carriers. But due to the multiple VPN concentrators and the encryption configuration, an IPSec VPN can be less reliable than MPLS. Cost The cost for the local loops for each choice will be the same. The MPLS tunneling, through the carrier, will have a price tag associated with it, but it shouldn’t be more than a managed IPSec VPN service from a carrier or more than the staff required to manage and troubleshoot an IPSec VPN. Unlike MPLS, IPSec VPN requires VPN concentrators, which will boost the upfront cost. Once you have the hardware, the staff required to maintain and troubleshoot the IPSec VPN tunnels may be the same as, or more than, the MPLS service from the carrier. Security MPLS should be more secure than IPSec VPN tunnels, if you don’t allow your MPLS circuits to connect directly to the Internet, which some carriers offer through the carrier’s MPLS cloud. For the best security, use MPLS as a private network only. Used as a private network, MPLS offers the same security as a frame relay network. However, keep in mind that as with frame relay, data sent over an MPLS network is not encrypted. Network intrusions are a greater concern with IPSec VPN tunnels since you are running them through an Internet circuit. That Internet circuit is open to connections from around the world. A misconfigured firewall can open your IPSec VPN network to the Internet. Security is of even higher concern if you use split tunneling on your VPN concentrators. However, IPSec VPN tunnels beat out MPLS when it comes to protecting the data that is traversing the WAN, because the IPSec VPN data will be encrypted with IPSec. The MPLS data is not encrypted, only tunneled. QoS QoS may be included with the carrier’s MPLS offering or it may cost extra. Either way, with MPLS QoS, you can prioritize certain traffic all the way through the carrier’s network. This is great for latency- sensitive applications, like VoIP. QoS features are limited. Once you send your encrypted data over the Internet, little can be done to prioritize it. To get more details on the various MPLS options, check out shopforbandwidth.com.