RE: Draft charter for L3VPN: Internet transparency
"Paul Knight" <[email protected]>
| Newsgroups | gmane.ietf.ppvpn |
|---|---|
| Message-ID | <6204FDDE129D364D8040A98BCCB290EF05C2D8C4@zbl6c004.corpeast.baynetworks.com> |
I definitely have to agree with Jeremy (and Mark Duffy) here: CE-based IPsec VPNs are not only viable, but there are hundreds, if not thousands, of sizable examples. Currently, these are mostly user-managed, but the provider-provisioned numbers are growing faster. These are NOT simply residence-to-backbone replacements for dial-up, but are often replacing frame relay, ATM, and leased lines between sites of all sizes, across the enterprise. Enterprises of all sizes are installing CE-based IPsec VPNs. While it's clear that QOS and SLAs will typically not be guaranteed, several years of experience shows that adequate sizing of the access link (site to ISP) usually gives perfectly acceptable performance. Traffic prioritization at the VPN gateway device and high encryption rates help ensure that even delay-sensitive traffic performs acceptably. I don't really understand how the "viability" can be questioned, unless we envision a future where the Internet no longer provides reasonable performance for best-effort traffic. Regards, Paul > -----Original Message----- > From: [email protected] > [mailto:[email protected]] > Sent: Wednesday, May 14, 2003 3:59 AM > To: Alex Zinin > Cc: [email protected]; Eric Rosen > Subject: Re: Draft charter for L3VPN: Internet transparency > > > Alex, Eric, > > > > I think this applies to all the schemes. Even the CE-based > > > schemes aren't viable, in my opinion, over the public Internet > > > because issues of QoS, SLA, and accountability really prevent a > > > company from using the public Internet as the backbone for its > > > intranet. > > > > I understand your position. I'd like to see more opinions here. > > It is clear that using CE-based VPNs over the public Internet > will have different QoS properties, different SLAs and > different accounting frameworks. It's the applicability > statement document's task to clearly formulate that. And it's > the SLA that will also reflect this from a service > perspective (a VPN scheme shouldn't promise what it can't > accomplish). But I don't think this means that it's "not viable". > > Jeremy. > >