---
title: "L3 private core"
canonical: "https://docs.aryaka.com/space/KNOW/1284571184/L3%20private%20core"
format: markdown
---
The VPN Path Aryaka network comprises a set of encrypted tunnels that connect a site's ANAP or CPE to an Aryaka point of presence (POP). Aryaka has developed a global private network by connecting each POP to the rest of the POPs using layer 2 core links that provide high performance network connectivity across the globe. All applications traversing these links enjoy increased application performance by leveraging data deduplication, compression, TCP optimization, and application acceleration using CIFS, SSL, and so on. Aryaka recently introduced an L3 private core that connects the Aryaka POPs with each other using layer 3 core links. These links are purchased from tier 1 ISPs and provide the optimum path between the POPs over the internet. While there is no optimization or compression available for any traffic traversing these links, the traffic always uses encrypted tunnels between your sites. Additionally, using tier 1 ISPs ensures that the path taken between the POPs experiences lower latency and can use higher bandwidths to avoid congestion as compared to the lower tier ISPs.    Contact Aryaka Support  to enable the L3 private core for all your sites. Route traffic to a specific core With the L3 private core enabled, a site can be configured to use either only the L3 core or combination of L2 and L3 cores. When a site is configured to use both cores, you can route the traffic over either core by configuring a local rule as described in  Create site-level WAN Routing rules  and  Create customer-level WAN Routing rules .  Note that at a rule level, only one core can be enabled for a specific match rule and not both. Therefore, if the rule is configured for a specific match rule to send the traffic over the L3 core and it is down, traffic does  not  failover to the L2 core.  These rules can only be configured on sites with an Aryaka-provided ANAP. Sites without an ANAP  cannot  initiate the traffic destined over the L3 private core.  Bandwidth settings When a site is configured, Aryaka provides the subscribed bandwidth that you contracted. When L3 private core is enabled, and a site is configured to use both L3 and L2 cores, additional bandwidth attributes are available to define how much bandwidth should be used by the L3 core versus the L2 core. These bandwidth attributes are described in the sections that follow. Total site bandwidth (TSB)  TSB is the maximum bandwidth a site's ANAP (or CPE) can use to send traffic to the Aryaka POP in either direction. This includes both L3 private core and L2 private core.  By default, TSB is calculated as subscribed bandwidth times burst factor and can not be changed.  L2 private core limit (L2 limit) L2 limit is the maximum bandwidth that the L2 private core traffic can use. This is equal to the TSB and can not be changed.  This ensures that when L3 traffic does not exist on the link, the L2 core can utilize the complete TSB. L2 private core reserve (L2 reserve) L2 reserve is the minimum guaranteed bandwidth that the L2 private core traffic can use when TSB is completely used and some L3 private core traffic exists. By configuring the L2 reserve, the L3 private core traffic gets dropped until the guaranteed bandwidth is available to be used by L2 traffic.  When a site is configured for both L2 and L3, this is equal to TSB by default and can be reduced if desired.  If a site is configured to use only L3, then this is equal to zero (0) and can not be changed.  L3 private core limit (L3 limit) L3 limit is the maximum bandwidth that the L3 private core traffic can use. This is equal to TSB and can not be changed.  This ensures that when L2 traffic does not exist on the link, L3 core can utilize the complete TSB. L3 private core reserve (L3 reserve) L3 reserve is the minimum guaranteed bandwidth that the L3 private core traffic can use when TSB is completely used and some L2 private core traffic exists. By configuring the L3 reserve, the L2 private core traffic gets dropped until the guaranteed bandwidth is available to be used by L2 traffic.  By default, L3 reserve is equal to TSB minus the L2 reserve and can be changed by modifying the L2 reserve.  Note: The sum of L3 private core reserve and the L2 private core reserve always equals the total site bandwidth.  None of the bandwidth settings are available for configuration if the site is configured to use VPN Path Internet only.  Related topics Create site-level WAN Routing rules Create customer-level WAN Routing rules