Frame Relay Vs. IP Vpns
Total Page:16
File Type:pdf, Size:1020Kb
Contents: The Case for Frame Relay The Case for IP VPNs Conclusion Frame Relay vs. IP VPNs 2002 02089 9/02 Contents: Table of Contents Introduction 2 Definition of Terms 2 “Virtual” Privacy and 3 the Value of Shared Networks The Three Definitions 3 or Distinctions of VPN The Case for Frame Relay 4 The Case for IP Virtual Private Networks 6 Conclusion 8 1 02089 9/02 Introduction: Introduction Definition of Terms Welcome to one in a series of white papers The following definitions will be used in this brought to you by Sprint. We believe it is white paper: important to inform you on issues in the industry and to keep you updated on our VPN — Virtual Private Network is a private current endeavors. communications network that uses a shared network as its Wide Area Network (WAN) A major challenge in today’s data transport backbone, thereby offering the appearance market is that businesses wanting to and functionality of a dedicated private implement a Virtual Private Network (VPN) network at a reduced price. are faced with a dizzying array of options and have few guidelines from which to make IP VPN — An IP Security (IPSec)-based VPN an educated decision. The sheer breadth of that uses encryption and authentication to available VPN offerings can be overwhelming, offer the appearance and functionality of a especially for those unfamiliar with the relative private data network over a shared IP network merits and capabilities of all the alternatives. such as the Internet. In this paper, IP VPN will be discussed in terms of both Sprint CPE- To answer this challenge, Sprint has based IP VPNs and Network-based IP VPNs. It developed this series of VPN white papers will not be discussed in relation to IP-enabled designed to help customers and prospects frame relay or MPLS VPNs. navigate the VPN decision-making process. Each paper in the series compares and QoS — Quality of Service refers to the contrasts different types of VPN solutions consistent performance of a network as and highlights the various communications supported by the network Service Level needs they can — and cannot — address. Agreements (SLAs). This white paper not only identifies the communications needs that can be solved CoS — Class of Service refers to traffic by VPNs, but also examines the relative differentiation. CoS provides the ability to capabilities of frame relay and IP VPNs in treat packets differently based on the packet’s delivering solutions. importance. Sprint has extensive knowledge and experience in this industry category. In fact, Sprint and Cisco are currently working together to develop, market and deliver nationwide IP and broadband solutions. The joint effort combines Cisco Systems’ best-in-class networking technology and equipment with Sprint state-of-the art network infrastructure and customer service capability. The companies are initially focused on dedicated Internet access, IP VPN, IP Telephony solutions, content delivery networks and metro Ethernet solutions. By joining forces on this project, Sprint and Cisco intend to define and establish IP industry standards. 2 02089 9/02 Virtual Definitions: “Virtual” Privacy and the Value of The Three Definitions or Shared Networks Distinctions of VPNs It wasn’t long ago that dedicated leased At the most basic level, all VPNs serve the lines were the only viable option for same purpose — they permit organizations to businesses requiring secure data transmission securely share data with key stakeholders. among multiple remote locations. At the This includes: time, this solution addressed most organizations’ • Sharing a particular subset of data with all communications needs; but the associated costs and complexities could be considerable stakeholders — especially for businesses with geographically • Sharing all data with a particular subset of dispersed employees or a large number of stakeholders branch offices. •Sharing a particular subset of data with a With the advent of Layer 21 technologies particular subset of stakeholders like frame relay, more cost-effective shared networking solutions became available. The following table shows which stakeholder Such solutions were seen as breakthroughs groups are served by each of the three because they allowed businesses to leverage fundamental types of VPNs. a service provider’s shared network resources • Intranet — employees at fixed locations to build “virtually” private networks. These (HQs, branch offices, small offices/home networks could mimic the appearance and offices, etc.) functionality of leased line services at a fraction of the cost. • Remote Access — employees “on the go” (telecommuters, mobile users, business Currently, most companies run at least a travelers, etc.) portion of their WAN over shared facilities. The key advantage is seen in the potential • Extranet — key business partners cost savings. With the rise of Internet and (suppliers, distributors, resellers, etc.) IP usage for business applications, the role of shared networks has accelerated in today’s corporate data networking environment. 3 02089 9/02 The Case for Frame Relay: The Case for Frame Relay Frame relay networks are considered private because each customer’s individual traffic is 1 Frame relay is a Layer 2 communications separated into a predetermined path, the PVC. protocol that enables the establishment of Unintended recipients cannot view traffic multiple independent circuits, or data links, that is not deliberately sent to them. In fact, over a single physical connection. The there is no way to misdirect traffic without protocol accomplishes this by packaging physical access to network facilities. In order data into variable length frames at their to intercept or corrupt traffic traveling on a source location, and then merging these frame network, an individual would need to frames into a single data stream for physically tap into the transport medium in transmission over a shared network resource. question — an intrusion that is easily detected This merging process, called statistical using widely available monitoring tools. multiplexing, ensures efficient use of capacity on the shared facilities and minimizes the Key Strengths end-to-end delay of frame delivery. Ability to support multiple Layer 3 In a frame relay network, each individual protocols. Frame relay is a Layer 2, or data logical connection is called a Permanent link, technology, and thus can support any Virtual Circuit (PVC). Beyond cost savings, Layer 3 protocol. Businesses running PVCs have two distinct advantages over applications based on non-IP protocols, such leased lines: as IPX, SNA or AppleTalk, should strongly consider implementing — or sticking with — • PVCs are software defined, so they can be a frame relay network. For companies created, altered or dismantled in a matter of running purely IP-based applications, this hours. This represents a tremendous time isn’t a key decision factor. savings over leased lines, which require Ability to address Internet security days, weeks or even months to deploy the concerns with a single firewall. Many physical components. corporate frame relay networks are built in a hub-and-spoke arrangement with a single Internet connection at the hub site. This • Every PVC has an associated Committed architecture requires all remote (spoke) offices Information Rate (CIR) that defines the to access the Internet via the central (hub) amount of bandwidth a customer is site. In this scenario, the company can protect provided on the shared network facility. their entire network from unauthorized access However, customers have the ability to via the Internet by using only one firewall transmit data on their PVC at rates up located at the hub site. The upside to such to the full port speed. This means a configuration is the need to pay for and customers can “burst” above standard manage no more than one firewall, which can be a significant benefit for customers capacity as needed for certain bandwidth- looking to save money and headaches on intensive applications. Sprint is one of Internet security. However, businesses whose the service providers that offers 0-CIR employees send and receive a considerable PVCs, which provide SLA guarantees on all traffic transmitted. 4 02089 9/02 The Case for Frame Relay: amount of Internet traffic should think twice question. For businesses with many sites, a about this type of configuration. The inefficient large number of PVCs can be required to use of bandwidth as Internet traffic traverses achieve this type of meshed configuration. the frame network to and from the hub site Since more PVCs translate to additional cost could end up costing more than deploying and complexity, companies interested in Internet connections and firewalls at each enabling direct communications between remote location. multiple locations should consider alternatives to frame relay networking. Ability to provide predictable performance for delay-sensitive traffic. Since the frames Potentially high network delay. Depending that carry data in frame relay networks are on the topology of a customer’s frame relay variable in length, network congestion network, packets traveling over a frame problems can arise when larger data blocks relay network may experience high latency queue up ahead of delay-sensitive traffic, relative to IP networks with any-to-any such as voice. To help alleviate this problem, connectivity. For example, in a hub-and- the Frame Relay Forum has ratified spoke configuration, traffic must first travel procedures to break down larger frames into to a hub site before reaching its final a series of smaller ones. While such methods destination. This added distance can slow are not official CoS protocols, they can the delivery of data. Once again, customers provide predictable delay patterns and looking for fast, direct connections among therefore maintain the integrity of many remote locations may be better served delay-sensitive traffic. Companies concerned by solutions other than frame relay. about the quality of any delay-sensitive traffic sent over their network may feel more Limited interoperability. Frame relay comfortable with a frame relay (as opposed backbones in existence today are managed to IP) solution.