VIRTUAL PRIVATE NETWORKS (VPN)

33

description

VIRTUAL PRIVATE NETWORKS (VPN). WAN Technology Comparison. long-distance dial-up connection. WAN technology - PSTN. Figure 7-9 A WAN using frame relay. WAN technology – X.25 and Frame Relay. A BRI link. A PRI link. WAN technology - ISDN. CSU/DSU. point-to-point T-carrier connection. - PowerPoint PPT Presentation

Transcript of VIRTUAL PRIVATE NETWORKS (VPN)

Page 1: VIRTUAL PRIVATE NETWORKS (VPN)
Page 2: VIRTUAL PRIVATE NETWORKS (VPN)
Page 3: VIRTUAL PRIVATE NETWORKS (VPN)

3

long-distance dial-up connection

Page 4: VIRTUAL PRIVATE NETWORKS (VPN)

4

Figure 7-9 A WAN using frame relay

Page 5: VIRTUAL PRIVATE NETWORKS (VPN)

5

A BRI link

A PRI link

Page 6: VIRTUAL PRIVATE NETWORKS (VPN)

6T-carrier connecting to a LAN through a router

point-to-point T-carrier connection

CSU/DSU

Page 7: VIRTUAL PRIVATE NETWORKS (VPN)

7

DSL connection

Page 8: VIRTUAL PRIVATE NETWORKS (VPN)

8

SONET ring

Page 9: VIRTUAL PRIVATE NETWORKS (VPN)

Virtual Private Network is a type of private network that uses public telecommunication, such as the Internet, instead of leased lines to communicate.

Became popular as more employees worked in remote locations.

Page 10: VIRTUAL PRIVATE NETWORKS (VPN)

(From Gartner Consulting)

Page 11: VIRTUAL PRIVATE NETWORKS (VPN)

Secure VPNs use cryptographic tunneling protocols.◦ IPsec, SSL/TLS, OpenVPN, PPTP, L2TP, L2TPv3,

VPN-Q and MPVPN Trusted VPNs rely on the security of a single

provider’s network to protect the traffic.◦ MPLS and L2F

Page 12: VIRTUAL PRIVATE NETWORKS (VPN)

A virtual point-to-point connectionmade through a public network. It transportsencapsulated datagrams.

Encrypted Inner Datagram

Datagram Header Outer Datagram Data Area

Original Datagram

Data Encapsulation [From Comer]

Two types of end points: Remote Access Site-to-Site

Page 13: VIRTUAL PRIVATE NETWORKS (VPN)
Page 14: VIRTUAL PRIVATE NETWORKS (VPN)

Figure 1

Page 15: VIRTUAL PRIVATE NETWORKS (VPN)
Page 16: VIRTUAL PRIVATE NETWORKS (VPN)
Page 17: VIRTUAL PRIVATE NETWORKS (VPN)

Authentication – validates that the data was sent from the sender.

Access control – limiting unauthorized users from accessing the network.

Confidentiality – preventing the data to be read or copied as the data is being transported.

Data Integrity – ensuring that the data has not been altered

Cryptography Technic Encryption -- is a method of “scrambling” data before

transmitting it onto the Internet.

Public Key Encryption Technique

Digital signature – for authentication

Page 18: VIRTUAL PRIVATE NETWORKS (VPN)

VPN can be deployed in three ways : Host to host Site-to-Site Host-to-Site

Page 19: VIRTUAL PRIVATE NETWORKS (VPN)
Page 20: VIRTUAL PRIVATE NETWORKS (VPN)

Remote access VPN Intranet VPN Extranet VPN

Page 21: VIRTUAL PRIVATE NETWORKS (VPN)
Page 22: VIRTUAL PRIVATE NETWORKS (VPN)
Page 23: VIRTUAL PRIVATE NETWORKS (VPN)
Page 24: VIRTUAL PRIVATE NETWORKS (VPN)
Page 25: VIRTUAL PRIVATE NETWORKS (VPN)
Page 26: VIRTUAL PRIVATE NETWORKS (VPN)
Page 27: VIRTUAL PRIVATE NETWORKS (VPN)
Page 28: VIRTUAL PRIVATE NETWORKS (VPN)
Page 29: VIRTUAL PRIVATE NETWORKS (VPN)

MPLS = Multi Protocol Label Switching Suatu metode forwarding (meneruskan data/paket

melalui suatu jaringan dengan menggunakan informasi label yang dilekatkan pada I

Memungkinkan router meneruskan paket dengan hanya melihat label yang melekat pada paket tersebut, sehinggap tidak perlu lagi melihat alamat IP tujuan)

Page 30: VIRTUAL PRIVATE NETWORKS (VPN)

Back

Page 31: VIRTUAL PRIVATE NETWORKS (VPN)

Perpaduan mekanisme Label Swapping (Layer 2) dan Routing (Layer 3)

Terdiri atas LSR yang saling terhubung, membentuk suatu LSP

LSR pertama disebut ingress LSR terakhir disebut egress Bagian tepi dari jaringan LSR disebut LER

Back

Page 32: VIRTUAL PRIVATE NETWORKS (VPN)

LSR = Label Switched Router LSP = Label Switched Path LER = Label Edge Router TTL = Time to Live

Back

Page 33: VIRTUAL PRIVATE NETWORKS (VPN)

Pembuatan label dan distribusi Pembuatan label dalam tiap router Pembuatan jalur label yang terhubung Pemasukan label Forwarding paket

Back