Secure Extension of L3 VPN's over IP-Based Wide Area Networks
Craig A. Hill · 2014
This paper examines how recent network-based virtualization technology innovation can be used to simplify Layer 3 (L3) Virtual Private Network (VPN) deployment and operations within secure government, commercial, and enterprise networks. The key innovations addressed in this paper are Multiprotocol Label Switching (MPLS) over multipoint GRE (mGRE), combined with Group Encrypted Transport (GET) Virtual Private Network (VPN) technology while utilizing Next Generation Encryption ([NGE], which is a superset of suite B 1 ). These technologies, when combined as an architectural framework, address some of the major scaling, deployment, and operational challenges common in secure Wide Area Networks (WANs) today when Layer 3 network segmentation is required. This paper compares the use of MPLS VPN over the WAN with other network virtualization technologies typically deployed today. It also highlights the advantages of Cisco GET VPN over multipoint IP tunnel-based overlay networks, and how it simplifies operations and deployment. Finally, this paper describes and compares NGE to legacy cipher solutions, offering cryptographic algorithms designed to meet large-scale security requirements for decades to come.