par De Clercq, Jeremy;Paridaens, Olivier
Référence IEEE communications magazine, 40, 5, page (151-157)
Publication Publié, 2002
Article révisé par les pairs
Résumé : This article gives an overview of the most promising technologies for service providers to offer virtual private network services. The focus of this article is on the analysis of the scalability implications of these virtual private network mechanisms on existing service provider backbone networks. Very often, when deploying VPN services, service providers will be confronted with a trade-off between scalability and security. VPNs that require site-to-site interconnectivity without strong (cryptographic) security can be deployed in a scalable way based on the network-based VPN model, as long as the interaction between the customer and provider routing dynamics are controlled. VPNs that require strong (end-to-end) cryptographic security should be deployed according to the CPE-based VPN model, using the available IPsec protocol suite.