Ethernet VPN
André Perez · Network Security · 2014
Ethernet technology is employed in Local Area Networks (LANs) and Wide Area Network (WAN) aggregation networks. In LAN, two types of equipment can be deployed: hubs and switches. Q-virtual LAN (VLAN) marking is used to isolate flows inside the LAN network to make up a Virtual Private Network (VPN). The Tag Protocol Identification (TPID) field is used to indicate that S-TAG marking has been added. VPLS technology is deployed in the core network. H-VPLS architecture makes it possible to extend MPLS technology to the aggregation network. The connection establishment begins with a three-exchange handshake including the remote router responding with a Start-Control-Connection-Reply (SCCRP) message containing its own capacities. The authentication and integrity checking of control messages are optional functionalities. An association created between an Ethernet port or Ethernet VLAN, on the one hand and a Pseudo-Wire (PW) pseudo-link, on the other hand, initializes the establishment of a session.