SP-面试---MPLSVPN

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

VPNCategoriesQ.WhatisthemajorpartsofanoverallVPNsolutionŸProvidernetwork(P-network):ThecommoninfrastructurethattheserviceproviderusestoofferVPNservicestocustomersŸCustomernetwork(C-network):ThepartoftheoverallcustomernetworkthatisstillexclusivelyundercustomercontrolŸCustomersites:ContiguouspartsoftheC-networkQ.WhatAretheVPNtwomajormodels•OverlayVPNs,inwhichtheserviceproviderprovidesvirtualpoint-to-pointlinksbetweencustomersites•Peer-to-peerVPNs,inwhichtheserviceproviderparticipatesinthecustomerroutingQ.WhatAretheOverlayVPNImplementationTechniques?•IntheLayer1overlayVPNimplementation,theserviceprovidersellsLayer1circuits(bitpipes)implementedwithtechnologiessuchasISDN,digitalservicezero(DS0),E1,T1,SynchronousDigitalHierarchy(SDH),orSONET.ThecustomerisresponsibleforLayer2encapsulationbetweencustomerdevicesandthetransportofIPdataacrosstheinfrastructure.•ALayer2VPNimplementationisthetraditionalswitchedWANmodel,implementedwithtechnologiessuchasX.25,FrameRelay,ATM,andSwitchedMultimegabitDataService(SMDS).TheserviceproviderisresponsiblefortransportofLayer2framesbetweencustomersites,andthecustomerisresponsibleforallhigherlayers.•WiththesuccessofIPandassociatedtechnologies,someserviceprovidersstartedtoimplementpureIPbackbonestoofferVPNservicesbasedonIP.Inothercases,customerswantedtotakeadvantageofthelowcostanduniversalavailabilityoftheInternettobuildlowcostprivatenetworksoverit.Q.WhatAretheImplementationTechniquesforPeer-to-PeerVPNs?theserviceprovideractivelyparticipatesincustomerrouting,acceptingcustomerroutes,transportingthosecustomerroutesacrosstheserviceproviderbackbone,andfinallypropagatingthemtoothercustomersites.Themorecommonpeer-to-peerVPNimplementationallowedaPEroutertobesharedbetweentwoormorecustomers.PacketfilterswereusedonthesharedPErouterstoisolatethecustomers.Inthisimplementation,itwascommonfortheserviceprovidertoallocateaportionofitsaddressspacetoeachcustomerandmanagethepacketfiltersonthePErouterstoensurefullreachabilitybetweensitesofasinglecustomerandisolationbetweenseparatecustomers.Q.WhatAretheBenefitsofVPNImplementations?overlayVPNshavethefollowingadvantages:ŸOverlayVPNsarewell-knownandeasytoimplementfrombothcustomerandserviceproviderperspectives.ŸTheserviceproviderdoesnotparticipateincustomerrouting,makingthedemarcationpointbetweenserviceproviderandcustomereasiertomanage.Ontheotherhand,peer-to-peerVPNsprovidethefollowing:ŸOptimumroutingbetweencustomersiteswithoutanyspecialdesignorconfigurationeffortŸEasyprovisioningofadditionalVPNsorcustomersites,becausetheserviceproviderprovisionsonlyindividualsites,notthelinksbetweenindividualcustomersitesQ.WhatAretheDrawbacksofVPNImplementations?ØOverlayVPNshavethefollowingdisadvantages:ŸOverlayVPNsrequireafullmeshofvirtualcircuitsbetweencustomersitestoprovideoptimumintersiterouting.ŸAllvirtualcircuitsbetweencustomersiteshavetobeprovisionedmanually,andthebandwidthmustbeprovisionedonasite-to-sitebasis(whichisnotalwayseasytoachieve).ŸTheIP-basedoverlayVPNimplementations(withIPSecorGRE)incurhighencapsulationoverhead—rangingfrom20bytes(B)to80Bpertransporteddatagram.ØThemajordrawbacksofpeer-to-peerVPNsarisefromserviceproviderinvolvementincustomerrouting,suchasthefollowing:ŸTheserviceproviderbecomesresponsibleforcorrectcustomerroutingandforfastconvergenceoftheC-networkfollowingalinkfailure.ŸTheserviceproviderPEroutershavetocarryallcustomerroutesthatwerehiddenfromtheserviceproviderintheoverlayVPNmodel.ŸTheserviceproviderneedsdetailedIProutingknowledge,whichisnotreadilyavailableintraditionalserviceproviderteams.Q.WhatAretheDrawbacksofTraditionalPeer-to-PeerVPNs?•SharedPErouter:–Allcustomerssharethesame(provider-assignedorpublic)addressspace.–Highmaintenancecostsareassociatedwithpacketfilters.–Performanceislower—eachpackethastopassapacketfilter.•DedicatedPErouter:–Allcustomerssharethesameaddressspace.–EachcustomerrequiresadedicatedrouterateachPOP.Q.OverlayVPNsarecategorizedbasedonthetopologyofthevirtualcircuits:•(Redundant)hub-and-spoke•Partialmesh•Fullmesh•Multilevel—combinesseverallevelsofoverlayVPNtopologiesQ.WhatAretheVPNBusinessCategories?•IntranetVPNconnectssiteswithinanorganization.•ExtranetVPNconnectsdifferentorganizationsinasecureway.•AccessVPN(VPDN)providesdialupaccessintoacustomernetwork.Q.WhatIstheVPNConnectivityCategory?•SimpleVPN:Everysitecancommunicatewitheveryothersite.•OverlappingVPNs:SomesitesparticipateinmorethanonesimpleVPN.•CentralservicesVPN:Allsitescancommunicatewithcentralserversbutnotwitheachother.•Managednetwork:AdedicatedVPNisestablishedtomanageCErouters.MPLSVPNArchitectureQ.WhatIstheMPLSVPNArchitecture?AnMPLSVPNcombinesthebestfeaturesofanoverlayVPNandapeer-to-peerVPN:ŸPEroutersparticipateincustomerrouting,guaranteeingoptimumroutingbetweencustomersites.ŸPErouterscarryaseparatesetofroutesforeachcustomer,resultinginperfectisolationbetweencustomers.ŸCustomerscanuseoverlappingaddresses.Q.WhatIstheArchitectureofaPERouterinanMPLSVPN?ThearchitectureofaPErouterinanMPLSVPNisverysimilartothearchitectureofaPOPinthededicatedPErouterpeer-to

1 / 54
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功