1 VLAN-VPN Configuration

z

z

The term switch used throughout this chapter refers to a switching device in a generic sense or the switching engine of a unified switch in the WX3000 series.

The sample output information in this manual was created on the WX3024. The output information on your device may vary.

VLAN-VPN Overview

Introduction to VLAN-VPN

Virtual private network (VPN) is a new technology that emerges with the expansion of the Internet. It can be used for establishing private networks over the public network. With VPN, you can specify to process packets on the client or the access end of the service provider in specific ways, establish dedicated tunnels for user traffic on public network devices, and thus improve data security.

VLAN-VPN feature is a simple yet flexible Layer 2 tunneling technology. It tags private network packets with outer VLAN tags, thus enabling the packets to be transmitted through the service providers’ backbone networks with both inner and outer VLAN tags. In public networks, packets of this type are transmitted by their outer VLAN tags (that is, the VLAN tags of public networks), and the inner VLAN tags are treated as part of the payload.

Figure 1-1 describes the structure of the packets with single-layer VLAN tags.

Figure 1-1Structure of packets with single-layer VLAN tags

0

15

 

 

31

 

Destination MAC address

 

 

 

 

 

 

Source MAC address

VLAN Tag

Data

Figure 1-2 describes the structure of the packets with double-layer VLAN tags.

1-1

Page 598
Image 598
3Com WX3000 operation manual VLAN-VPN Configuration, VLAN-VPN Overview, Introduction to VLAN-VPN