Broadband Network Architecture



Similar documents
OS3 Fiber Day Broadband networks - Network Architecture. May 20, 2016 / Jan Martijn Metselaar Vodafone

WAN Topologies MPLS. 2006, Cisco Systems, Inc. All rights reserved. Presentation_ID.scr Cisco Systems, Inc. All rights reserved.

How Routers Forward Packets

Development of the FITELnet-G20 Metro Edge Router

ICTTEN6172A Design and configure an IP- MPLS network with virtual private network tunnelling

Introducing Basic MPLS Concepts

ISTANBUL. 1.1 MPLS overview. Alcatel Certified Business Network Specialist Part 2

How To Make A Network Secure

Designing and Developing Scalable IP Networks

MPLS Concepts. Overview. Objectives

Data Networking and Architecture. Delegates should have some basic knowledge of Internet Protocol and Data Networking principles.

Introduction to IP v6

SSVVP SIP School VVoIP Professional Certification

MPLS VPN Services. PW, VPLS and BGP MPLS/IP VPNs

- Multiprotocol Label Switching -

ICTTEN4215A Install and configure internet protocol TV in a service provider network

Enterprise Network Simulation Using MPLS- BGP

Networking 4 Voice and Video over IP (VVoIP)

MikroTik RouterOS Introduction to MPLS. Prague MUM Czech Republic 2009

Introduction to MPLS-based VPNs

INDIAN INSTITUTE OF TECHNOLOGY BOMBAY MATERIALS MANAGEMENT DIVISION : (+91 22) (DR)

How To Understand The Benefits Of An Mpls Network

Residential IPv6 IPv6 a t at S wisscom Swisscom a, n an overview overview Martin Gysi

November Defining the Value of MPLS VPNs

APPLICATION NOTE 211 MPLS BASICS AND TESTING NEEDS. Label Switching vs. Traditional Routing

IP/MPLS-Based VPNs Layer-3 vs. Layer-2

Computer Network Architectures and Multimedia. Guy Leduc. Chapter 2 MPLS networks. Chapter 2: MPLS

CS419: Computer Networks. Lecture 9: Mar 30, 2005 VPNs

Security Technology White Paper

IPv6 Migration Challenges for Large Service Providers

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

Multi Protocol Label Switching (MPLS) is a core networking technology that

IPV6 DEPLOYMENT GUIDELINES FOR. ARRIS Group, Inc.

Bandwidth Management in MPLS Networks

Internetworking. Problem: There is more than one network (heterogeneity & scale)

Deploying IPv6 for Service Providers. Benoit Lourdelet IPv6 Product Manager, NSSTG

IPv6 Co-existence & Integration

Master Course Computer Networks IN2097

Fast Reroute for Triple Play Networks

Course Contents CCNP (CISco certified network professional)

Addressing Inter Provider Connections With MPLS-ICI

Cisco Certified Network Associate Exam. Operation of IP Data Networks. LAN Switching Technologies. IP addressing (IPv4 / IPv6)

AT&T Managed IP Network Service (MIPNS) MPLS Private Network Transport Technical Configuration Guide Version 1.0

Project Report on Traffic Engineering and QoS with MPLS and its applications

VLAN und MPLS, Firewall und NAT,

Network Virtualization with the Cisco Catalyst 6500/6800 Supervisor Engine 2T

IPv6 Fundamentals, Design, and Deployment

Industry s First QoS- Enhanced MPLS TE Solution

Demonstrating the high performance and feature richness of the compact MX Series

MPLS/IP VPN Services Market Update, United States

Guide to Network Defense and Countermeasures Third Edition. Chapter 2 TCP/IP

CLOUD NETWORKING FOR ENTERPRISE CAMPUS APPLICATION NOTE

Campus LAN at NKN Member Institutions

Implementation IPV6 in Mikrotik RouterOS. by Teddy Yuliswar

SBSCET, Firozpur (Punjab), India

MPLS in Private Networks Is It a Good Idea?

Configuring the Transparent or Routed Firewall

IPv6 Deployment Strategies

Guide to TCP/IP, Third Edition. Chapter 3: Data Link and Network Layer TCP/IP Protocols

MPLS Quality of Service What Is It? Carsten Rossenhövel EANTC (European Advanced Networking Test Center)

: Interconnecting Cisco Networking Devices Part 2 v1.1

Internetworking II: VPNs, MPLS, and Traffic Engineering

Virtual Leased Lines - Martini

Cisco Configuring Basic MPLS Using OSPF

VLAN and QinQ Technology White Paper

IPv6 Opportunity and challenge

DD2491 p MPLS/BGP VPNs. Olof Hagsand KTH CSC

Optimizing Enterprise Network Bandwidth For Security Applications. Improving Performance Using Antaira s Management Features

How To Make A Network Cable Reliable And Secure

IMPLEMENTING CISCO MPLS V3.0 (MPLS)

VPN taxonomy. János Mohácsi NIIF/HUNGARNET tf-ngn meeting April 2005

Internet Protocol: IP packet headers. vendredi 18 octobre 13

Applications that Benefit from IPv6

Extending Networking to Fit the Cloud

Multi-Protocol Label Switching To Support Quality of Service Needs

Mobile IP. Bheemarjuna Reddy Tamma IIT Hyderabad. Source: Slides of Charlie Perkins and Geert Heijenk on Mobile IP

"Charting the Course...

Transport and Network Layer

DCS C Fast Ethernet Intelligent Access Switch Datasheet

MPLS is the enabling technology for the New Broadband (IP) Public Network

MPLS Layer 2 VPNs Functional and Performance Testing Sample Test Plans

ProCurve Networking IPv6 The Next Generation of Networking

VXLAN: Scaling Data Center Capacity. White Paper

20 GE + 4 GE Combo SFP G Slots L3 Managed Stackable Switch

Interconnecting Cisco Networking Devices Part 2

The Essential Guide to Deploying MPLS for Enterprise Networks

White paper. Reliable and Scalable TETRA networks

WHITE PAPER. Addressing Inter Provider Connections with MPLS-ICI CONTENTS: Introduction. IP/MPLS Forum White Paper. January Introduction...

Broadband Networks. Prof. Karandikar. Department of Electrical Engineering. Indian Institute of Technology, Bombay. Lecture - 26

MPLS Basics. For details about MPLS architecture, refer to RFC 3031 Multiprotocol Label Switching Architecture.

MPLS. A Tutorial. Paresh Khatri. paresh.khatri@alcatel-lucent.com.au

Best Effort gets Better with MPLS. Superior network flexibility and resiliency at a lower cost with support for voice, video and future applications

How To Learn Cisco Cisco Ios And Cisco Vlan

MPLS-based Virtual Private Network (MPLS VPN) The VPN usually belongs to one company and has several sites interconnected across the common service

CCT vs. CCENT Skill Set Comparison

QoS Implementation For MPLS Based Wireless Networks

IPv4/IPv6 Transition Mechanisms. Luka Koršič, Matjaž Straus Istenič

IP Switching: Issues and Alternatives

SSVP SIP School VoIP Professional Certification

Course Description. Students Will Learn

Transcription:

Broadband Network Architecture Jan Martijn Metselaar May 24, 2012 Winitu Consulting Klipperaak 2d 2411 ND Bodegraven The Netherlands slide

Broadband Services! Dual play, Triple play, Multi play! But what does the end-user care?! Nice those triple play services, but how do you get the content to the subscribers?! Smart network architecture and a lot of IP packets slide 2

Current broadband services over FTTH networks! Internet access! Unicast IP (Duh )! Television! IP unicast for video-on-demand! IP multicast for broadcast television (the default package of 50 channels)! Telephony! SIP signaling, RTP for transport slide 3

Network Architecture Layered model! Access! Lots of individual connections! Focus on physical aggregation of lines! Security! Distribution! Connection towards access layer! Focus on logical aggregation of connections! Route summarization! Core! Connection towards the distribution layer! Focus on traffic volume! No identification of individual connections slide 4

Network Architecture Layered model Service provider 1 Service provider 2 Core netwerk core metro access slide 5

Discussion! The how and why of current broadband networks! Protocols?! Speeds?! Possibilities?! Restrictions? slide 6

Network Architecture Ethernet as uniform transport protocol Leased line ATM Frame Relay X.25 PPP Ethernet Packet over Sonet (POS) Ethernet SONET SDH STM-1, 4, 16 slide 7

Network structure Domain separation Access Distributie / Core Core CPE backbone ISP 1 ISP 2 WWW ISP 3 PSTN/ISDN subscriber domain Operator domain service provider domain Wholesale model: operator delivers network facilities to different content and service providers. slide 8

Network Architecture Access: connection model How is the connection between subscriber and network realized? Point-to-Point Protocol (PPP)! IP over PPP over Ethernet! PPP session from the modem into the distribution layer! IP address assignment in PPP session setup via RADIUS! connection oriented! Multiple PPP sessions for QoS Ethernet Bridging DHCP model! IP over Ethernet! IP address assigment through DHCP! connection less! QoS via Ethernet Class of service guarantees slide 9

Network Architecture Core: MPLS VPN Ethernet Bridging MPLS VPN CPE VPN ISP 1 Distributie / Core apparatuur VPN ISP 2 backbone VPN ISP 3 City PoP ISP 1 ISP 2 ISP 3 subscriber domain Operator domain service provider domain slide 10

Network Architecture Core Network MPLS (Multi Protocol Label Switching)! Support for VPNs! Traffic Engineering (used for fast reroute and ip multicast traffic)! Ethernet transport over MPLS IP Routing! IGP! For distributing next-hop routing information! OSPF or IS-IS! M-BGP! For distributing IPv4 prefixes slide 11

Network Architecture MPLS primer: labels IP packet L1 IP packet L2 IP packet L3 IP packet IP packet Label Switched Router (LSR) MPLS enabled router Forwarding based on Labels, forwarding control separated from forwarding plane Labels are distributed via Label Distributie Protocol (LDP) LDP hello packets are UDP and transported via broadcast of multicast Multiple labels (stack) per packet possible (note that MTU must be large enough!) slide 12

Network Architecture MPLS primer: forwarding Control plane inside a node IP rou>ng protocols Routing information exchange with other routers IP rou>ng table Label informa>on Base (LIB) MPLS IP rou>ng control Label binding exchange with different routers Data plane inside a node Forwarding Informa>on Base (FIB) Label Forwarding informa>on Base (LFIB) slide 13

Network Architecture Increasing complexity Complexiteit Triple play Single play Dual play Multiplay slide 14

Quizzz! What about Quality of Service?! What about Security? slide 15

Network Architecture Quality of Service Core network! QoS only relevant if congestion can occur! Used to be irrelevant in broadband networks as bandwidth was plenty. FTTH and Docsis3 has changed this.! QoS policy of most providers was: upgrade capacity. Currently large providers are running into technological limits: 10GE is not fast enough and 100GE is not yet there!! Cost for service providers is increasing rapidly! Traffic is becoming more symmetrical slide 16

Network Architecture Quality of Service Access networks! Multi-play services all use the same connection! Voice traffic needs to be protected! Video needs to get enough bandwidth (otherwise you ll see blocks)! Video and voice need protection from general internet traffic (especially P2P and news traffic) slide 17

Network Architecture Quality of Service QoS enforcement downstream traffic QoS parameters On incoming traffic CPE backbone ISP 2 QoS parameters upstream traffic QoS transparent IP QoS: precedence bits, diffserv Ethernet QoS: Class of Service (priority bit in vlan header) MPLS QoS: Exp. bits slide 18

Network Architecture Security slide 19

Network Architecture Security! Network! Access to network elements! Access to network management systems! Protocols! Security by obscurity! Control plane protection! Services platform! Policy: every service is responsible for it s own platform! Where possible network security can provide additional protection! Separate users! Spoofing filters! User isolation! Protocol filters (note that new OS like Windows Vista and 7 bring new challenges, like IPv6 default enabled). slide 20

Network Architecture Security Attack Vectors! ARP flood attack, plus spoofing! DHCP flood attack! MAC flood attack, plus spoofing! IGMP flood attack! IPv4 broadcast flood attacks! IPv4 unicast flood attack! TTL=1 attack! IP options attack! IPv6 MLD! some others. Focused on the control plane of the routers and switches in the network. Most are denial of service attacks, but some can be used for a man-in-the-middle attack. slide 21

Network Architecture Security (DHCP) Spoofing filters Arp filtering Security by obscurity (that which is not reachable is secure) CPE backbone ISP 2 CPE configuration Security force configuration from a central server Private vlan s vlan filtering Reverse path check slide 22

Network Architecture FTTH networks Security toolbox DHCP snooping Dynamic Arp Inspection Private VLAN PFC based special case Hardware limiters VACL Layer-2 filtering: - Allow ethertypes 0x800 and 0x806 - Broadcast ARP filtering - Multicast filtering - Broadcast redirection Multicast route limit STP filtering ARP rate-limiting DHCP rate-limiting IGMP group filtering IGMP group limiting UUFB UMFB Port-security IPSG Storm-control Ethertype filtering: - 0x800 0x806 (IP & ARP) Control plane policing urpf Ip local proxy-arp PIM neighbor filtering slide 23

Network Architecture IPv6 adressing! IPv4: adress 32-bit! 10.100.34.123! IPv6: adress 64-bit! 2031:0000:130F:0000:0000:09C0:876A:130B! IPv6 display! 2031:0:130F::9C0:876A:130B! Leading 0 in a segment is optional! Use double colon :: to summarise two segments with 0 s allowed only once in an address. slide 24

Network Architecture IPv6 adressing! Adress scopes:! Unicast single host or interface! Anycast group of hosts or interfaces! Multicast group of receivers! There are no IPv6 broadcast adresses (!)! Adress types:! Link-local adres, starts with FE80:: /10! Site-local adres, stars with FEC0:: /10! Global aggregate adress, worldwide unique slide 25

Network Architecture IPv6 adressing! Growth of connected networks and hosts exhausts the available IPv4 addresses solution is IPv6! Support for IPv6 is low! Most equipment is IPv6 ready but not full IPv6! Performance often only about 50% compared to IPv4 performance! (Legacy) applications usually not IPv6 ready! Migration to IPv6 will take a long time! IPv6 is incompatible with IPv4 (there is no implicit migration path in the IPv6 protocol design) Bron: http://ran.psg.com/~randy/070722.v6-op-reality.pdf slide 26

Network Architecture IPv6 migration scenarios! Dual-Stack both IPv4 and IPv6 running on one system! Investments in the whole end-to-end network! All components must support IPv6! Best route to IPv6 only! Carrier grade NAT! Scalability issues! Tunneling IPv6 in IPv4! Schalability, and what does it solve?! ISP world embraces Dual-Stack! DNS is a challenge (what first? v4 of v6) slide 27

Network Architecture IPv6 Dual-Stack (DHCP) Spoofing filters IPv6 Arp filtering IPv6 IPv6 backbone IPv6 Internet CPE IPv4 backbone IPv4 Internet CPE configuration security configuration envoforcement from central provisioning system also IPv6 slide 28

Quizzz! Netwerk management?! Why does that seem to be so difficult for most Service Providers? slide 29

Network IT - Provisioning! We like zero touch, flow through provisioning. Service providers would like to focus on exception management only! Bullshit or? slide 30

Network IT Provisioning! The success of network provisioning and order management is correct and complete information:! Orders! Subscriber connections! Automation is the key, every manual action increases the chance of mistakes slide 31

Network and IT Systems slide 32

That s all for now! Questions? Don t hesitate to send an email to: janmartijn @ winitu.com slide 33