Connectivity for MPLS VPN Implementations – Best Practice

An access circuit connects the customer’s CE router to the MPLS provider’s PE router.

A MPLS provider can offer a fully managed solution, where they will install and manage a CE router on business premises at additional cost, or an unmanaged solution, where businesses require the fastest router speed from their own CE device. The unmanaged service is the preferred choice. A managed service can be considered if the added value it brings outweighs the additional financial cost.

The access circuit can be any suitable WAN transport option including Gigabit Ethernet, Fast Ethernet, T3, E3 etc. When selecting the access circuit type, consideration must be given to whether it will support multiple VPNs: an Ethernet service is preferred, but a WAN service supporting frame relay is acceptable. In either case, sub-interfaces will be defined with separate VLANs or DLCIs for each VPN to be carried on the same access circuit.

For most MPLS VPN implementations, business will connect a minimum of two separate WAN hub locations to diverse MPLS provider clouds. Remote locations (i.e. any non-WAN hub site) can connect to a single provider cloud (if another WAN connection provides an alternate connection) or to both provider clouds.

