Network Working Group B. Fox
Request for Comments: 2685 Lucent Technologies
Category: Standards Track B. Gleeson
Nortel Networks
September 1999
Virtual Private Networks Identifier
1. Introduction
As the Public Internet expands and extends its infrastructure globally, the determination to exploit this infrastructure has led to widespread interest in IP based Virtual Private Networks. A VPN emulates a private IP network over public or shared infrastructures. Virtual Private Networks provide advantages to both the Service Provider and its customers. For its customers, a VPN can extend the IP capabilities of a corporate site to remote offices and/or users with intranet, extranet, and dialup services. This connectivity should be achieved at a lower cost to the customer with savings in capital equipment, operations, and services. The Service Provider is able to make better use of its infrastructure and network administration expertise offering IP VPN connectivity and/or services to its customers.
Fox & Gleeson Standards Track [Page 1]
RFC 2685 Virtual Private Networks Identifier September 1999
While the various methods of VPN service implementation are being discussed and debated, there are two points on which there is agreement:
2. Global VPN Identifier
The purpose of a VPN-ID is to identify a VPN. This identifier may be used in various ways depending on the method of VPN service implementation. For example, the VPN-ID may be included:
Fox & Gleeson Standards Track [Page 2]
RFC 2685 Virtual Private Networks Identifier September 1999
There is another very important function that may be served by the VPN identifier. The VPN identifier may be used to define the "VPN authority" who is responsible for coordinating the connectivity and services employed by that VPN. The VPN authority may be the Private Network administrator or the primary Service Provider. The VPN authority will administer and serve as the main point of contact for the VPN. The authority may outsource some functions and connectivity, set up contractual agreements with the different Service Providers involved, and coordinate configuration, performance, and fault management.
3. Global VPN Identifier Format Requirements
The VPN Identifier format should meet the following requirements:
4. Global VPN Identifier Format
The global VPN Identifier format is:
Fox & Gleeson Standards Track [Page 3]
RFC 2685 Virtual Private Networks Identifier September 1999
0 1 2 3 4 5 6 7 8
+-+-+-+-+-+-+-+-+
| VPN OUI (MSB) |
+-+-+-+-+-+-+-+-+
| VPN OUI |
+-+-+-+-+-+-+-+-+
| VPN OUI (LSB) |
+-+-+-+-+-+-+-+-+
|VPN Index (MSB)|
+-+-+-+-+-+-+-+-+
| VPN Index |
+-+-+-+-+-+-+-+-+
| VPN Index |
+-+-+-+-+-+-+-+-+
|VPN Index (LSB)|
+-+-+-+-+-+-+-+-+
The VPN OUI (IEEE 802-1990 Organizationally Unique Identifier) [4] identifies the VPN authority. The VPN authority will serve as the primary VPN administrator. The VPN authority may be the company/organization to which the VPN belongs or a Service Provider that provides the underlying infrastructure using its own and/or other providers' shared networks. The 4 octet VPN Index identifies a particular VPN serviced by the VPN authority.
5. Security Considerations
This document defines the format of the global VPN identifier without specifying usage. However, the association of particular characteristics and capabilities with a VPN identifier necessitates use of standard security procedures with any specified usage. Misconfiguration or deliberate forging of VPN identifier may result different breaches in security including the interconnection of different VPNs.
6. References
[1] Gleeson, Heinanen, Lin, Armitage, Malis, "A Framework for IP
Fox & Gleeson Standards Track [Page 4]
RFC 2685 Virtual Private Networks Identifier September 1999 7. Authors' AddressesBarbara A. Fox Lucent Technologies 300 Baker Ave, Suite 100 Concord, MA 01742-2168
Fox & Gleeson Standards Track [Page 5]
RFC 2685 Virtual Private Networks Identifier September 1999 8. Full Copyright StatementCopyright (C) The Internet Society (1999). All Rights Reserved.