Layer 2 VPN (L2VPN)

To provide VPN services to multiple clients, ISPs have to implement tunneling so that their customers' VLAN and Layer 2 protocol configurations remain separate from those of other customers. Even though several Cisco devices support tunneling features, only the Catalyst 3550 switch is covered in this chapter because it is the device used in the CCIE Security lab environment. The Catalyst 3550 switch can provide the necessary services through 802.1Q tunneling and Layer 2 protocol tunneling.

802.1Q

If the requirement is to keep all customers' VLANs separated, an ISP would have to provide a unique block of VLAN ranges so that the VLANs belonging to different customers don't overlap. This could lead to certain configuration restrictions ...

Get CCIE Practical Studies: Security (CCIE Self-Study) now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.