Archive for the ‘VPN’ Category

Designing Site-to-Site IPsec VPNs – Part 4

February 5th, 2009 by Marjan Bradesko


The legacy technologies such as leased lines or switched networks (Frame relay, ATM) have long been replaced by public Internet or MPLS. To secure the traffic between the Local Area Networks at remote sites an IPsec is an integral part of today`s solutions. Boštjan Šuštar, the Internetworking Expert at NIL Data ...

Flexible Extranet Implementation

January 5th, 2009 by Marjan Bradesko


Do you need to deploy an extranet? In a simple yet flexible enough way? Getting rid of limitations brought by fixed addressing? MPLS VPN implementation of an extranet brings the flexibility that will make even complex extranets deployment easier. In this IP Corner article, Ivan Pepelnjak, the Chief Technology Officer (CTO) ...

Designing Site-to-Site IPsec VPNs – Part 3

December 1st, 2008 by Marjan Bradesko


Site-to-site VPNs using IPsec can be implemented with the crypto maps or, when routed interface is needed, by GRE-tunnels. Virtual Tunnel Interfaces (VTIs) are a relatively late addition to Cisco IOS and eliminates the need for additional GRE overhead, while still providing the logical interface. Boštjan Šuštar, the Internetworking Expert at ...

Designing Site-to-Site IPsec VPNs – Part 2

October 1st, 2008 by Marjan Bradesko


Crypto maps - used as one of the oldest Cisco IOS implementation options for IPsec – have a downside - they do not provide for a routable logical interface. When migrating from a traditional WAN or upgrading an existing WAN to use cryptography, it may be beneficial to reuse the ...

VPLS: Is it Hot or is it Not?

June 19th, 2008 by Bostjan Sustar


Many people regard Virtual Private LAN Services (VPLS) as the ultimate of MPLS features for providing any-to-any connectivity to VPN sites where minimum signaling is required between customer and provider. I agree that this nifty feature can come in handy in some specific situations, but it is important to define ...