Using the technology implemented in their networks, service providers can provide VPNs for the enterprises. A service provider segregates customer traffic as it crosses a shared infrastructure. While traffic physically crosses shared infrastructure, there is no mixing of traffic. One customer cannot see another customer’s traffic. When using MPLS, service providers can create Layer 2 MPLS VPNs or Layer 3 MPLS VPNs.
服務提供者可利用其網路中已部署的技術,為企業提供 VPN。服務提供者會在共用基礎設施上區隔各客戶的流量。雖然流量實際上會經過共用基礎設施,但不同客戶的流量並不會混合,一個客戶無法看到另一個客戶的流量。使用 MPLS 時,服務提供者可以建立第 2 層 MPLS VPN 或第 3 層 MPLS VPN。
A Layer 2 MPLS VPN is useful for customers who run their own Layer 3 infrastructure and require only Layer 2 connectivity from the service provider. In this case, the customer manages its own routing information. One advantage that Layer 2 VPN has over its Layer 3 counterpart is that some applications do not work if nodes are not in the same Layer 2 network.
第 2 層 MPLS VPN 適用於自行維運第 3 層基礎設施、只需要服務提供者提供第 2 層連線的客戶。在這種情況下,客戶自行管理其路由資訊。第 2 層 VPN 相較於第 3 層 VPN 的優勢之一,是部分應用程式在節點不在同一個第 2 層網路中時將無法運作。
Some typical examples of Layer 2 VPN are VPLS and Virtual Private Wire Service (VPWS). If you look from the customer perspective, with Layer 2 MPLS VPN, you can imagine a whole service provider network as one big virtual switch.
第 2 層 VPN 的典型範例有 VPLS 與虛擬私有線路服務(Virtual Private Wire Service,VPWS)。從客戶角度來看,使用第 2 層 MPLS VPN 時,可以把整個服務提供者網路想像成一台巨大的虛擬交換器。
A Layer 3 MPLS VPN provides a Layer 3 service across the backbone. A separate IP subnet is used on each customer site. When you deploy a routing protocol over this VPN, the service provider needs to participate in the exchange of routes. Neighbor adjacency is established between your CE router and the PE router (which the service provider owns). Within the service provider network, there are many P routers (service provider core routers). The job of P routers is to provide connectivity between PE routers. What this situation means is that the service provider becomes the backbone of your (customer) network.
第 3 層 MPLS VPN 會跨骨幹網路提供第 3 層服務,每個客戶站點會使用獨立的 IP 子網路。當你在此 VPN 上部署路由協定時,服務提供者需要參與路由交換。你的 CE 路由器與服務提供者所擁有的 PE 路由器之間會建立鄰居關係。在服務提供者網路內,有許多 P 路由器(服務提供者核心路由器),其作用是提供 PE 路由器之間的連線。也就是說,服務提供者實際上成為你(客戶)網路的骨幹。
Layer 3 VPN is appropriate for customers who prefer to outsource their routing to a service provider. The service provider maintains and manages routing for the customer sites. If you look from the customer perspective, with Layer 3 MPLS VPN, you can imagine the whole service provider network as one big virtual router.
第 3 層 VPN 適合希望將路由外包給服務提供者的客戶,由服務提供者負責維護與管理各客戶站點的路由。從客戶角度來看,使用第 3 層 MPLS VPN 時,可以把整個服務提供者網路想像成一台巨大的虛擬路由器。
