IPSEC, MPLS and Ethernet WAN

From IPSEC to MPLS and Ethernet WAN

How companies modernize their network

Many company networks have grown historically and are now slowed down by high latency and complex management. SAVECALL accompanies the migration to modern solutions with a clear structure and greater efficiency. An IP VPN is a virtual private network that is based on a shared IP Backbone of a telecommunications provider. It uses MPLS technology and enables companies to achieve secure and cost-efficient Site Connectivity without their own physical lines.

In a nutshell:

  • From IPSEC to MPLS: one carrier instead of many, less effort, more security
  • From MPLS to Ethernet: Layer 2 design for lower costs and more control
  • Advantages: Simplification, optimized SLAs, cost savings, flexible scaling
  • Decision: MPLS for managed networks, Ethernet for in-house IT expertise

The solution: SAVECALL plans and implements corporate networks that reduce costs, increase performance and remain globally scalable.

What this article covers: This article shows the typical migration paths from IPSec via MPLS to Ethernet WAN, including prototype example networks. The core question: Which migration path suits the requirements of your company network?










Why companies migrate their WAN

IPSec, MPLS and Ethernet WAN are three approaches to site connectivity that companies choose between when modernizing their network.

Customers very often contact us because their existing IP-Sec or MPLS network no longer optimally meets their requirements. We are commissioned with the redesign and migration. This often results in a migration path from IPSEC to MPLS and MPLS to Ethernet. In today’s guest article, we discuss this topic with Marc Gebhardt, Product Expert at 1&1 Versatel, and present prototype example networks.

How MPLS differs from the alternative SD-WAN is something we cover in detail on our WAN pages.

From IPSec to MPLS

Many smaller company networks have grown historically and are often still based on IPSec connections. Low QoS and unfulfillable SLAs, high latencies, complex firewall management and the tedious management of many local carriers lead to dissatisfaction. In the video we show you a more complex IPSec VPN, which is considerably simplified by an MPLS with a one-carrier strategy. The result: cost savings, reduction of internal support effort, higher security.

From MPLS to Ethernet WAN

Even though MPLS is a simple and secure way to network a company, many customers contact us for whom Layer 2-based Ethernet Site Connectivity is more suitable. In the video we show you a more complex MPLS network that is being converted to a Layer 2 Ethernet network. It has been simplified to minimize costs and IT management effort.




How SAVECALL supports your WAN migration

SAVECALL analyzes your existing network and plans the right migration path, independent of technology and provider, across more than 80 carriers. Savecall’s experts will be happy to help you analyze, plan and implement your perfect corporate network with a focus on manageability, cost optimization and the best possible SLAs and QoS for any business situation. Feel free to contact us without obligation!

Conclusion: MPLS or Ethernet WAN?

Whether an MPLS or Ethernet WAN is the better solution for your Site Connectivity depends entirely on your particular situation. In addition to the number of locations, countries, bandwidth and flexibility requirements, the network management skills available in the company also play a role. If you prefer the network to be fully managed, foreign locations do not require too much bandwidth and latency times are not extremely critical, an MPLS can be a good all-round solution. If you have a strong IT department, high bandwidth requirements, latency-critical applications and would like to manage both the network and, if necessary, more than one carrier abroad yourself, an Ethernet network may be recommended.

Frank Frommknecht, Key Account Consultant bei SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for over 20 years in selecting and optimizing their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and strategically finding the right solution.

Sources

  • IETF, RFC 4364 “BGP/MPLS IP Virtual Private Networks (VPNs)”, rfc-editor.org
  • MEF Forum, “Carrier Ethernet”, mef.net
  • SAVECALL, “Enterprise WAN: SD-WAN, MPLS & Ethernet”, savecall.de/en/wan

Frequently asked questions about IPSec, MPLS and Ethernet WAN

What is the difference between IPSec, MPLS and Ethernet WAN?

IPSec, MPLS and Ethernet WAN are three approaches to site connectivity. IPSec sets up encrypted tunnels over the public Internet and is inexpensive but latency-prone and demanding to manage. MPLS is a carrier-managed private network with guaranteed SLAs and classes of service. Ethernet WAN connects sites at Layer 2 and gives the company more control at high bandwidths. Which approach fits depends on the number of sites, bandwidth, latency needs and in-house IT expertise.

When is it worth migrating from IPSec to MPLS?

Migrating from IPSec to MPLS pays off when a historically grown network is slowed down by low QoS, unfulfillable SLAs, high latencies and complex firewall management. Instead of managing many local carriers individually, a one-carrier strategy consolidates the network and simplifies operations considerably. The result is cost savings, less internal support effort and higher security. For companies without a large in-house network team, a managed MPLS is often the more sensible foundation.

When is Ethernet WAN better than MPLS?

Ethernet WAN is usually the better choice when a company has a strong in-house IT department, high bandwidth requirements and latency-critical applications. The Layer 2 design lowers costs and gives more control over the network. Companies that want to manage the network and possibly several carriers abroad themselves benefit from the flexibility. MPLS, by contrast, remains the good all-round solution when the network should be fully managed and bandwidth and latency are less critical.

What is an IP VPN?

An IP VPN is a virtual private network based on a shared IP backbone of a telecommunications provider. It typically uses MPLS technology and enables companies to achieve secure and cost-efficient site connectivity without their own physical lines. Traffic remains logically separated from other customers and can be prioritized using classes of service. This lets an IP VPN connect multiple sites predictably and securely, without the company having to operate its own lines.

What are the benefits of switching to a single carrier?

A one-carrier strategy reduces complexity considerably. Instead of coordinating many local providers with different SLAs and contacts, everything runs through one partner with consistent service levels. This lowers internal support effort, improves SLA enforceability and increases security through a consistent design. Billing and monitoring also become easier. SAVECALL compares more than 80 carriers neutrally to find the combination with the best price-performance ratio.

MPLS or Ethernet WAN: which fits my company?

It depends on the number of sites, countries, bandwidth and flexibility needs and your in-house network expertise. If the network should be fully managed, foreign sites do not need very high bandwidth and latency is uncritical, MPLS is a good all-round solution. With strong in-house IT, high bandwidth and latency-critical applications, Ethernet WAN is the better fit. SAVECALL assesses your situation neutrally and plans the right migration path with a focus on manageability, cost and SLAs.

You might also be interested in


Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

What drives you forward – & what drives

Book a free expert consultation