Overview of Layer 2 Services

Layer 2 service types include private circuit constructs Frame Relay ATM and emerging Ethernet. However, the use of XoverMPLS, where X is a Layer 2 construct such as Frame Relay, ATM, or Ethernet that is used to create Layer 2 VPNs for like-to-like or any-to-any implementations, is growing. This section describes various Layer 2 services available to customers. Private circuit mechanisms typically are delivered over SONET SDH and have been popular for the past several years. The reliability...

MPLS QoS

Because MPLS uses an IP network with IP routing protocols, it also uses the same IP QoS models. MPLS QoS does not change the IP DiffServ model of traffic classification, marking, policing, queuing, scheduling, and transmission. However, the IntServ model of IP QoS is different in MPLS networks. MPLS DiffServ is similar to IP DiffServ. In MPLS DiffServ, packets are marked with the EXP field instead of the IP TOS DSCP byte of the IP header. Packets are queued based on the EXP marking, and WRED is...

Security Overview and MPLS

When talking about security concepts, the first question you must answer is, What is meant by the term secure In a normal family house, for example, a good door lock is considered adequate security. In a jeweler's shop, though, a door has to be considerably more robust to be secure, and a bank might have guards in addition to several strong doors. In every scenario, the first step is to define secure only after this is done can the next step of actually securing a network be performed. Early...

Figure 91 Queuing and RED

For MPLS, packer tfassificalion is based on MPLS EXP. Siiicc PrkMitf Sfitieduiis p'Ovides- KHI ' Ubeney s il ptiet 1s vace. * Protocol Type, SA, DAorGlherMalcti Criteria Scheduler Queues can be serviced at a specified rate. If all queues are serviced fairly, this is called weighted fair queuing (WFQ), meaning queues are serviced in a fair manner such that equal amounts of data are transmitted from each queue in one cycle. The queues can be weighted to provide a bias for the high-priority...

Internet Extranet and MPLS Security

The Internet is usually positioned as the insecure part in any network deployment, so threats normally come from the Internet. Although this view is completely correct, it is not complete. In other parts of the Internet, other users require security, and from their point of view, the threat also comes from the Internet, which now includes your own network. For any given service provider networkMPLS or notthis means that a threat is originating in this network toward the Internet. One could...

Figure 74 Summary of Attack Scenarios

In the MPLS VPN environment, the same principles prevail It is best to provide separation against outside networks and control of inbound traffic into a VPN. Where traffic is filtered by a firewall, this filtering is usually independent of the MPLS architecture. However, this assumes correct operation of the MPLS core network. If the engineer of the MPLS service provider misconfigures a PE router, an external site might become a member of the VPN, which enables intrusions from this external...

Remote Access and IPSec Integration with Mpls Vpns

Corporate virtual private networks (VPN) must not only provide secure site-to-site connectivity, but must also integrate remote access technologies for dial, DSL, and cable users of the VPN networks. Enterprise customers cannot just outsource wide-area network (WAN) connectivity to manage only remote access connections for corporate remote users. A decision to outsource for enterprise managers can also mean considering the outsourcing of remote access connectivity, including managing virtual...

Management and Scalability

Network elements must support, at a minimum, manageability with MIBs and applications. The degree of support acceptable is dependent on the provider. ILECs and PTTs require full SNMP support and full MIB support with counter information on packets, bytes, and LSPs including per VPN and per class of service. However, network elements must scale well when the network management (NM) stations poll these devices for statistics. The ability to process NM requests accurately and the ability to inform...

Content Based Services

Other types of VPN services include content-based services and broadband services integrated with the MPLS-based VPNs. In a content-based case, each VPN can represent a content service and subscribers subscribe to this service or VPN. The subscriber traffic is intelligently mapped to a content VPN without compromising the connectivity between the content VPNs themselves. The key here is the ability to map customers to VPNs. Appropriate policy routing with label distribution can help accomplish...

Example 72 Incorrect Configuration Wrong Route Target in the Second VRF

The effect of this simple error is that all the sites of bank B connected to this PE router belong logically to bank A and have full access to the entire VPN of bank A. For routing to work in this scenario, the address spaces of the two now merged banks would have to be unique, which is not necessarily the case in an accidental misconfiguration. Once again, MPLS VPN (BGP-VPN) permits address and data plane separation. With address separation, a service provider or large enterprise deploying...

Figure 12 Service Aware Network Layer Reference Model

Enterprise customers have invested in applications such as enterprise resource planning (ERP), supply chain management (SCM), and customer relationship management (CRM) that facilitate collaborative workplace processes requiring integration to the corporate LAN. ERP is an industry term for the broad s of activities supported by multimodule application software that helps a manufacturer or other business manage the important parts of its business, including product planning, parts purchasing,...