VPNs tunnel traffic as follows from one customer site to another customer site, using a public network as a transit network, when certain requirements are met:
The CE devices require only a BGP connection to the PE routers.
The provider network must be running either OSPF or IS-IS as an IGP, as well as IBGP sessions through either a full mesh or route reflector. IBGP is required so that the PE routers can exchange route information for routes that originate or terminate in the VPN.
Either LDP or RSVP must be configured to dynamically set up LSPs through the provider network.
Because the tunnel information is maintained at both PE routers, neither the provider core routers nor the CE devices need to maintain any VPN information in their configuration databases.