
Concentric Network Corporation White Paper, Outsourcing Remote Access Services
10/1/1998 9
Virtual Private Network Technology: An Overview
One of the hottest topics in the networking industry is switched access to Virtual Private
Networks (VPNs). Driven by the boom in Internet usage, as well as a sharp increase in the
number of workers that dial in to their own corporate networks, the use of generically
encapsulated “tunnels” is already making switched access to these network resources more
efficient and practical for customers, service providers, and the telephone companies that
provide the physical infrastructure for all of these networks.
Concentric’s solution for providing switched connectivity to VPNs is based upon Bay Network’s
Baystream DVS™. This technology provides a set of capabilities that runs across Bay Networks
remote access server and router platforms. It is available now as a fully functional end-to-end
solution that has many capabilities unique in the industry today. Concentric’s testing indicates
that this technology is interoperable with any standards-based client PPP software, any
standards-based Frame Relay router, and any existing Frame Relay service.
Recently, the IETF decided that the "standard" Layer-3 tunneling solution would be based on
Mobile IP. Today, Concentric RemoteLink(tm) is 80%-85% compliant with the Mobile IP
specification. In addition to the Layer-3 tunneling approach currently offered, Concentric
Network will implement Layer 2 Tunneling Protocol (L2TP) as the standard evolves and is
finalized.
The goal of RemoteLink™ is to allow remote devices simple and secure access to a
corporation’s LAN. RemoteLink™ is based on the concept of encapsulating multiprotocol data in
IP “tunnels” that exist between a RAS (Remote Access Server) and a gateway router using GRE.
RemoteLink dynamically establishes and tears down “tunnels” over an IP routed backbone in
order to facilitate the connection between the remote user and his/her “home” network. In
addition to GRE, this technology borrows heavily from IETF working groups, draft specifications,
and standards such as IP Mobility, RADIUS, and IP Security (IPSEC) in addition to IP routing,
Frame Relay, and Point-to-Point Protocol (PPP).
Some Benefits of a Dial VPN Service
Corporate customers no longer need to invest in massive banks of modem racks or ISDN
equipment to terminate subscriber calls at their premises since the RAS is placed in Concentric
Network SuperPOP sites. Additionally, corporate IS staffs are no longer required to deal with the
many headaches associated with remote network connectivity or performance issues because
these calls can be deflected to Concentric Network’s customer service organization.
Finally, corporate customers will save money on toll, calling card, 1-800, and 950 charges while
giving end users more convenient access to their home networks.
How It Works
The Concentric RemoteLink™ service incorporates a technique known as Layer 3 Forwarding.
With Layer 3 Forwarding, the incoming call to the network is terminated at the Remote Access
Server (RAS) and the Layer 2 protocol header, usually a PPP header, is stripped off leaving only
the Layer 3 (Network Layer) payload. The payload is then encapsulated with a GRE header and
an IP header in which the source IP address is the tunnel initiation point and the destination IP
address is the tunnel termination point.
Comentarios a estos manuales