
208 Chapter 6: How IPsec Complements MPLS
for applications such as the Hypertext Transport Protocol (HTTP), which is located on top
of the TCP layer. However, other protocols have to be mapped onto SSL. Figure 6-9 depicts
both protocols and their locations in the stack.
Figure 6-9 IPsec and SSL
SSL has found application in VPN gateways where limited application support is required,
such as when the VPN access is only used to access web pages. The advantage in those
scenarios is that SSL does not require a client on the PC.
In MPLS VPN environments, SSL is not used for CE-CE or PE-PE security, but it may be
used as a remote access technology.