Multi-Domain Virtual Private Network service : une infrastructure sans couture pour les réseaux régionaux et les NREN
Xavier Jeannin, Sébastien Boggia, Jean Benoit, Benjamin Collet, Christophe Palanche, Alain Bidaud · HAL (Le Centre pour la Communication Scientifique Directe) · 2015
Research and education network operators offer layer 2 and layer 3 VPN services. These services are difficult to implement, as the service must extend beyond a regional or national network (NREN). This is the type of problem that the new network service Multi-domain Virtual Private Network (MD-VPN) resolves.MD-VPN is a seamless multi-domain infrastructure capable of delivering a variety of network services: point-to-point and multipoint L3VPN (IPv4, IPv6) and L2VPN. MD-VPN is a very flexible service: it allows for quick release of VPNs; only one local configuration at the ends is necessary (in the regional network); no configuration was necessary in the networks crossed (RENATER, GEANT, other NRENs). As of 1st March 2015, MD-VPN is used in 15 countries in Europe. This already means excellent connection possibilities between 457 access points in Europe potentially to be used for our users’ projects. Additionally, in the event that the service is not locally available, it is still possible to connect via a VPN-Proxy.MD-VPN is an excellent tool to develop French regional networks, OSIRIS and SYRHANO being pioneers of this domain (institutes spread throughout France, shared hosting of large equipment, computing tables, cloud, etc.). International VPNs aim to provide technological support to international partnerships, which are now very common in the scientific world.Based on proven standards and technologies (RFC 4364, 3107), MD-VPN is supported on many routers. Its roll-out requires no investment cost, and operating costs, for their part, are significantly reduced.