You are on page 1of 7

CSCN

Project

IPsec VPN topologies

2016
IPsec VPN - Topology 1.1
.1 CH .1
CNW
(Hub)
.2 .6
6.1.4.0/24 6.1.1.0/24
5.1.2.0/30 5.1.2.4/30
● IPsec VPN topology: .1 .5 ● Protocols:
1.1: Hub-and-spoke. - All interfaces are (Fast) Ethernet.
.5 .6
PE1 PE2 - OSPF in SP network (PE routers).
5.1.1.4/30 - Static routes in customer routers.
● Methods: .1 .9 - IPsec SAs using IKE(v1) and ESP.
1.1.a: IPsec tunnels.
1.1.b: IPsec in GRE tunnels. 5.1.1.0/30
Service 5.1.1.8/30
Provider ● Notation:
PE: Provider Edge router
.2 .10 CNW: Customer North-West router
PE3 .13 .14 PE4 CSW: Customer South-West router
CNE: Customer North-East router
5.1.1.12/30
.13 .9 CSE: Customer South-East router

5.1.2.12/30 5.1.2.8/30

.14 .10
.1 .1
CSW CSE

6.1.3.0/24 6.1.2.0/24

© Octavian Catrina 2
IPsec VPN - Topology 1.2
.1 .1
CNW CNE
.14 .2
6.2.3.0/24 6.2.4.0/24
5.2.2.12/30 5.2.2.0/30
● IPsec VPN topology: .13 .1 ● Protocols:
1.2: Full mesh. - All interfaces are (Fast) Ethernet.
.9 .10
PE2 PE3 - OSPF in SP network (PE routers).
5.2.1.8/30 - Static routes in customer routers.
● Methods: .1 .5 - IPsec SAs using IKE(v1) and ESP.
1.2.a: IPsec tunnels.
1.2.b: IPsec in GRE tunnels. 5.2.1.0/30
Service 5.2.1.4/30
Provider ● Notation:
PE: Provider Edge router
.2 .6 CNW: Customer North-West router
PE1 .13 .14 PE4 CSW: Customer South-West router
CNE: Customer North-East router
5.2.1.12/30
.5 .9 CSE: Customer South-East router

5.2.2.4/30 5.2.2.8/30

.6 .10
.1 .1
CSW CSE

6.2.1.0/24 6.2.2.0/24

© Octavian Catrina 3
IPsec VPN - Topology 2.1
.1 .1
CH CNE
(Hub)
.14 .18
2.3.1.0/24 2.3.2.0/24
1.3.1.12/30 1.3.1.16/30
● IPsec VPN topology: .13 .17 ● Protocols:
2.1: Hub and spoke. 1.3.1.0/30 - All interfaces are (Fast) Ethernet.
.1 .2
PE1 PE2 - OSPF in SP network (PE routers).
- Static routes in customer routers.
● Methods: .5 .10 - IPsec SAs using IKE(v1) and ESP.
2.1.a: IPsec tunnels.
2.1.b: IPsec in GRE tunnels. 1.3.1.4/30 1.3.1.8/30

.6 Service
Provider
PE3 .9

.21 .25

1.3.1.20/30 1.3.1.24/30
● Notation:
.22 .26 PE: Provider Edge router
CH: Customer Hub
.1 .1
CSW: Customer South-West router
CSW: Customer South-Center router
CSW CSC CNE: Customer North-East router
2.3.3.0/24 2.3.4.0/24

© Octavian Catrina 4
IPsec VPN - Topology 2.2
.1 .1
CNW CNE
.14 .10
2.4.1.0/24 2.4.2.0/24
1.4.2.12/30 1.4.2.8/30
● IPsec VPN topology: .13 .9 ● Protocols:
2.2: Full mesh. 1.4.1.8/30 .10 - All interfaces are (Fast) Ethernet.
.9
PE2 PE1 - OSPF in SP network (PE routers).
- Static routes in customer routers.
● Methods: .5 .2 - IPsec SAs using IKE(v1) and ESP.
2.2.a: IPsec tunnels.
2.2.b: IPsec in GRE tunnels. 1.4.1.4/30 1.4.1.0/30

.6 Service
Provider
PE3 .1

.1 .5

1.4.2.0/30 1.4.2.4/30
● Notation:
.2 .6 PE: Provider Edge router
CH: Customer Hub
.1 .1
CSW: Customer South-West router
CSW: Customer South-Center router
CSW CSC CNE: Customer North-East router
2.4.3.0/24 2.4.4.0/24

© Octavian Catrina 5
IPsec VPN - Topology 3.1
.1 CH .1
(Hub)
.14 .22
CNW
3.3.1.0/24 3.3.2.0/24
2.3.1.12/30 2.3.1.20/30
● IPsec VPN topology: .13 .21 ● Protocols:
3.1: Hub-and-spoke. - All interfaces are (Fast) Ethernet.
PE3 - OSPF in SP network (PE routers).
- Static routes in customer routers.
● Methods: .5 .9 - IPsec SAs using IKE(v1) and ESP.
3.1.a: IPsec tunnels.
3.1.b: IPsec in GRE tunnels. 2.3.1.4/30 2.3.1.8/30
Service
Provider
PE2 PE1
.6 .10
.1 .2
2.3.1.0/30
.17 .25

2.3.1.16/30 2.3.1.24/30

.18 .26
● Notation:
.1 .1 PE: Provider Edge router
CNW: Customer North-West router
CSW CSE CSW: Customer South-West router
3.3.4.0/24 3.3.3.0/24 CNE: Customer North-East router
CSE: Customer South-East router

© Octavian Catrina 6
IPsec VPN - Topology 3.2
.1 .1

.14 .2
CNW CNE
3.4.1.0/24 3.4.2.0/24
2.4.2.12/30 2.4.2.0/30
● IPsec VPN topology: .13 .1 ● Protocols:
3.2: Full mesh. - All interfaces are (Fast) Ethernet.
PE1 - OSPF in SP network (PE routers).
- Static routes in customer routers.
● Methods: .5 .9 - IPsec SAs using IKE(v1) and ESP.
3.2.a: IPsec tunnels.
3.2.b: IPsec in GRE tunnels. 2.4.1.4/30 2.4.1.8/30
Service
Provider
PE2 PE3
.6 .10
.1 .2
2.4.1.0/30
.9 .5

2.4.2.8/30 2.4.2.4/30

.10 .6
● Notation:
.1 .1 PE: Provider Edge router
CNW: Customer North-West router
CSW CSE CSW: Customer South-West router
3.4.3.0/24 3.4.4.0/24 CNE: Customer North-East router
CSE: Customer South-East router

© Octavian Catrina 7

You might also like