Guest

VPN Services

MPLS VPN Service Overview

SERVICE OVERVIEW
In today's economy, IT managers from businesses of all types and sizes are facing the challenge of supporting an increasingly complex enterprise network while constrained by limited budgets and other resources. Adding to this challenge is a need to integrate data, voice, and video traffic over economical, scalable, and dependable networks. The IP-based VPN has emerged as a viable solution for meeting these challenges, and more IT managers are now looking to service providers for value-added, cost-effective VPN-based services.
To deliver IP VPN services profitably, many service providers worldwide are enhancing core networks by deploying Multiprotocol Label Switching (MPLS) technology. MPLS blends the intelligence of routing with the performance of switching, enabling service providers to extend the capabilities of IP to large-scale VPN implementations.
"Using MPLS, VPNs have become much easier to deploy and scale," says Irwin Lazar of The Burton Group, an enterprise IT research and advisory services firm. "This technology not only creates a more efficient network, it allows service providers to accommodate virtually any customer's requirement for remote access, intranets, extranets, and Internet access."
This document describes the services enabled by MPLS-based IP VPNs that service providers can offer to enterprise customers. It also presents the additional benefits for service providers when these new services are deployed with the comprehensive portfolio of Cisco SystemsÒ MPLS-based IP VPN solutions.

MPLS-BASED IP VPN MARKET OPPORTUNITY

The market opportunity is tremendous for IP VPN services overall. According to a forecast by market researcher IDC, managed IP VPN services will yield US$15.8 billion in revenue worldwide by 2007. Another leading consulting and market research company, Gartner Dataquest, predicts that by 2006, nearly all large U.S. enterprises will use IP VPNs to some extent.
Gartner Dataquest describes several market opportunities and benefits for service providers in deploying MPLS-based IP VPNs:
· Improved customer retention and increased profitability by offering cost-effective and flexible VPN services based on IP and MPLS
· An entry point for selling managed IP services in addition to access, which increases long-term profitability
· The ability to customize VPN services for each business customer, which increases differentiation and adds value through bundled services for data, voice, video, network security, wireless access, and other options
· Improved profitability through reduced costs for VPN service provisioning and network operation, as well as simpler management of a single network
· Flexibility to change the internal network architecture quickly for efficient use of resources
· Support for network scalability to deliver customer-specific, on-demand services
The market opportunity for MPLS-based IP VPNs is also driven from customer interest in out-tasking network functions because of the potential for cost savings. Small and midsize businesses in particular might be more interested in managed VPN services, especially when they are constrained by limited budgets for capital purchases or limited IT resources for network deployment, management, and support.

MARKET SEGMENTATION

The IP VPN services market can be segmented according to company size, a factor that differentiates service requirements and opportunities.
Large enterprises (1000 or more employees) are prominent candidates for IP VPN service offerings. In the face of continually rising IT expenses, many large enterprises see the financial advantages of out-tasking the communications infrastructure. These customers have complex requirements for IP VPN design, including domestic and international connectivity, strong security, and integration with an existing network infrastructure.
A service provider must be able to handle the required network scalability and complexity of a large enterprise, as well as seamless integration of the enterprise's existing network technologies and applications. Certain service-level agreement (SLA) parameters are also critical: service availability, network latency, packet loss, mean time to recovery (MTTR), and jitter.
Midsized businesses (100 to 1000 employees) are also prime candidates for IP VPNs because of their increasingly expanded network use. The requirements of these businesses for IP VPN services include increased bandwidth for remote users, greater geographic coverage, the ability to add new sites and users quickly, stronger security, and service quality backed by SLAs.
Small businesses (20 to 99 employees) face the challenges of rapid growth, lack of in-house technical expertise, and limited ability to keep pace with deployment of networked applications. Because an IP VPN is likely to be the only WAN service deployed by these customers, they require an affordable and bundled solution that encompasses all necessary equipment, accessories, and network services. The bundled solution must be able to reduce costs of dialup access, equipment, and maintenance; increase network uptime; and help ensure quality using SLAs.

MARKET INFLUENCES

Several factors influence the interest of business customers for MPLS-based IP VPN services:
· The growing requirement to connect more geographically dispersed branch offices, teleworkers, business partners, and customers to corporate network resources over flexible connections that are secure, reliable, and economical
· Growth in network traffic as a result of increasing business use of networked applications
· Interest in new networked applications, such as IP telephony and e-collaboration, that can reduce cost, improve productivity, and enable new levels of communication efficiency
Similar to the findings from many leading market research firms, a 2003 Cisco® survey of IT network managers worldwide also found that most of the responding companies across all business segments have either adopted IP VPN or are in the planning or testing stages. Cisco survey results show that IP VPN adoption is gaining momentum based on the motivators to reduce cost, improve network scalability, and replace in-house dialup infrastructures. Small and midsize businesses are also adopting IP VPNs in order to implement stronger, managed network security.

THE ADVANTAGES OF MPLS-BASED VPN

MPLS blends the intelligence of routing with the performance of switching, providing significant benefits to networks with a native IP architecture as well as those with IP, ATM, or a mixture of other Layer 2 technologies. MPLS technology is critical for creating scalable VPNs and delivering end-to-end quality of service (QoS). It enables service providers to make efficient use of existing networks to meet future growth and support rapid fault correction of link and node failures. The inherent MPLS traffic engineering and fast reroute capabilities can significantly improve network service quality by providing the ability to maximize network bandwidth and reroute traffic rapidly in failure conditions within the core network.
MPLS technology helps to deliver highly scalable and differentiated IP services end to end with simpler configuration, management, and provisioning (Figure 1). When deploying MPLS technology, service providers that use Cisco solutions gain immediate benefits, such as the following:
· Highly scalable routing and optimal use of network resources for any-to-any IP connectivity, encompassing multiple customers
· Integration of data, voice, and video networks in one converged infrastructure
· Differentiated, end-to-end IP services that are simpler to configure, manage, and provision and that support SLAs
· A "build once, sell many times" model for delivering network services
· The ability to provide advanced QoS features that help ensure network priority and help provide guaranteed bandwidth for mission-critical traffic
· Centralized service configuration, provisioning, and management

Figure 1

Single MPLS Allows Service Providers to Deliver IP VPN Services to Business Customers
 

 

MPLS-BASED IP VPN SERVICE DESCRIPTION

By deploying MPLS in their core networks, service providers attain a strong, unique position for offering cost-effective and scalable site-to-site and remote-access VPN services to business customers. An MPLS-based VPN can connect a customer's branch offices, mobile workers, business partners, and customers to corporate network resources over the service provider's shared infrastructure. All connections maintain the same security and management policies as private networks.
With an MPLS-based IP VPN, service providers can offer business customers a variety of services, ranging from basic network access, QoS, and SLAs to value-added IP services and service bundles (Table 1).
 

Table 1. MPLS VPNs Communications Services

Basic Services

Value-Added Services

Best-effort service
• Basic SLA
• Managed customer premises equipment (CPE) router
• Intranet and extranet
Business-class service
• Basic SLA
• Basic reporting
• Managed CPE router
• Intranet and extranet
• Web portal
Class of service
• End-to-end SLA
• Customized reporting
• Managed CPE router
• Intranet and extranet
• Web portal enhanced
• Bandwidth on demand
• Alternative access options (Gigabit Ethernet, Frame Relay, ATM, for example)
VPN basic
• Remote access
VPN connect/enhanced
• IP Security (IPSec) secure option
• On-net remote access
• Off-net remote access
• Mobile hot spots
VPN enterprise
• IPSec secure option
• On-net remote access
• Off-net remote access
• Mobile hot spots

MPLS-BASED IP VPN SERVICE FEATURES

As Table 2 shows, an MPLS-based VPN supports a variety of features for new services that attract and retain customers. These features also help service providers reduce operating expenses, increase network efficiency, and improve return on investment (ROI) for MPLS technology deployments.
 

Table 2. Differentiated Service Features of a Managed MPLS VPN

Service Category

Features

Access
• Regional, national, and global access to corporate intranets and extranets
• Any-to-any connectivity
• Choice of bandwidth speeds and access routing protocols
• Option for a bundled service with managed CPE
Quality of Service
• High availability and QoS through SLAs
• Automatic failover features to help ensure high network availability and transparency
• Distinct classes of service for data, voice, video, and storage traffic, each delivered with guaranteed service levels
• IP Multicast for efficient bandwidth utilization when sending information to multiple sites
Security
• Secure data and routing separation between customers
• Resistance to attacks
• Concealment of the service provider's network topology
• Prevention of VPN spoofing
• Optional cryptographic security features
Support
• Detailed reporting and billing
• 24-hour service monitoring and help desk
• Fully managed CPE
Management
• Support for a customer's private IP addressing scheme, including Network Address Translation (NAT) and Dynamic Host Control Protocol (DHCP) services
• Managed Internet access with security and privacy features such as integrated firewall and intrusion detection
• Centralized service configuration, provisioning, and management
Value-Added Services
• A foundation for additional enhanced managed services such as on-net and off-net calling for voice over IP (VoIP), unified communications, content distribution, hosting, and security

CISCO SOLUTIONS FOR MPLS-BASED IP VPN

Cisco is uniquely positioned to help service providers deploy MPLS networks that enable new, profitable revenue opportunities through VPN services. A comprehensive portfolio of Cisco MPLS VPN solutions is available to service providers to offer a full suite of services, including intranet and extranet site-to-site VPN, remote-access VPN, and options for managed CPE. Service providers can use these Cisco solutions to implement the best mix of MPLS VPN services for customer needs, service areas, compatibility with existing services, and other relevant factors.
The Cisco Layer 3 MPLS VPN solution enables service providers to offer scalable intranet and extranet services that link a customer corporate headquarters, branch offices, and business partners over a shared, prioritized network. This site-to-site VPN solution supports a broad range of access technologies and speeds (64 Kbps to STM-1), and options for a bundled service with managed CPE or unbundled service without managed CPE.
· The Cisco Layer 2 MPLS VPN solution enables any existing or emerging Layer 2 transport mechanism to interwork through a common, converged MPLS core network architecture using Any Transport over MPLS (AToM) technology. This solution is designed for service providers with existing Layer 2 ATM and Frame Relay deployments and for providers that want to offer new classes of Layer 2 transport, such as a transparent LAN service, over a common packet backbone.
· The Cisco Remote Access to MPLS VPN solution enables service providers to offer a managed VPN service to remote users over dial, DSL, or cable access technologies. This solution is tailored for efficient on-net remote access.
· The Cisco Network-Based IPSec VPN solution enables a service provider to extend an MPLS VPN access outside of its service areas (off-net) to remote users and branch offices by using the Internet or the networks of partner providers. This solution provides a centrally managed, secure VPN connectivity end to end.
· For VPN network management, the Cisco IP Solution Center (ISC) is a carrier-class solution for managing rapid and cost-effective delivery of IP VPN services. Cisco ISC enables centralized configuration, provisioning, and operation of MPLS VPN services as well as integration with associated Cisco network management products and third-party applications for network management.

SERVICE PROVIDER SUCCESS STORY

Bell Canada's MPLS-based IP VPN service gave a surgeon the means to perform a telerobotics-assisted operation on a patient 250 miles away. The operation took place over Bell Canada's Cisco Powered Network designated service known as Virtual Private Network Enterprise (VPNe). Regarded as one of the most advanced networks of its kind, Bell Canada's VPNe uses Cisco MPLS technology to create VPNs on Bell Canada's national IP backbone and existing infrastructure of Cisco 12000 Series routers and Cisco 7500 Series routers.
Bell Canada was responsible for maintaining the high level of network performance and reliability necessary for real-time remote manipulation of the surgical robot. Bell Canada designed, built, and managed all aspects of the MPLS VPN service that connected the two hospitals in Ontario. Working with Cisco, Bell Canada conducted extensive testing to ensure that the VPN service would deliver the high levels of stability, reliability, and QoS demanded by the surgery.

FOR MORE INFORMATION

A more detailed discussion of the topics in this document is presented in the white paper Implementing Managed IP Virtual Private Network Services, available at: http://www.cisco.com/en/US/netsol/ns341/ns121/ns193/networking_solutions_white_paper0900aecd801ab5d2.shtml
To view an informative E-Tour about opportunities for managed VPN services, visit: http://www.cisco.com/go/managedservicesetour
To learn more about Cisco solutions for MPLS VPNs, contact your Cisco account manager or visit: http://www.cisco.com/go/vpnsolutions