An exemplary system and method for using a network access system, such as
a virtual private network (VPN), are provided. A user device may have a
user session with a home agent. Additionally, an initiating security
gateway may be in communication with the home agent, and a terminating
security gateway may be in communication with the initiating security
gateway via a tunnel (e.g., Internet Protocol in Internet Protocol
(IP-in-IP) or Internet Protocol security (IPsec) tunnel). Further, a
virtual local area network (VLAN) tag associated with the user session
may map to a selector operable in a security policy database. The
selector may be used to find a security policy defining an IPsec
procedure, and the security policy may be applied to the tunnel. Also,
the initiating security gateway may also include a Quality of Service
(QoS) module that determines QoS markings for a packet traveling along
the tunnel.