F10 MitigatingEthernetSecurityRisks
F10 MitigatingEthernetSecurityRisks
[ PA G E
O F
2 ]
SONET/SDH channel. EPL services provide the high availability, reliability, QoS and security that enterprise IT managers have become accustomed to with their TDM private line services, but with Ethernets flexibility to meet growing bandwidth demands within their OpEx budgets. Its no wonder that EPL services have been, by far, the most popular Ethernet service offering worldwide for many years. Now, a relatively new type of Ethernet service, referred to as an Ethernet Private LAN (EP-LAN) service, is emerging. EP-LAN provides the same benefits of EPL services (including secure delivery over dedicated SONET/SDH channels), and also enables multi-site connectivity. EP-LAN services provide an Ethernet UNI to connect the enterprise locations to three or more sites, extending the enterprise LAN over a metro or wide area network with the same availability, reliability, QoS and security of SONET/SDH transport networks. Many assume that multi-point E-LAN services can only be offered via IP/MPLS (VPLS) or switched Ethernet transport networks, but EP-LAN services can be very efficiently and costeffectively delivered via carrier Ethernet equipment supporting next-generation SONET/SDH transport. By using Ethernet-over-SONET/SDH technologies, service providers can utilize dedicated and diversely routed channels for transporting point-to-point EPL services or multi-point EP-LAN services across the public MAN and
WAN infrastructure with the highest possible level of security. Next-generation SONET/SDH networking equipment encapsulates the enterprises Ethernet frames using GFP and diversely routes them across non-contiguous SONET/SDH channels using VCAT. GMPLS enables the dynamic assignment of SONET/SDH channels as new services are activated. These technologies effectively scramble the enterprises Ethernet frames across the SONET/SDH network, making it impossible to eavesdrop, reassemble or redirect themeven if monitoring test equipment is placed in the SONET/SDH optical path, only Ethernet service frame fragments can be recovered. Ethernet service bandwidth can easily and efficiently be added using the SONET/SDH Link Capacity Adjustment Scheme (LCAS). LCAS enables the service provider to dynamically increase or decrease bandwidth to an existing Ethernet service without any service disruptions. This capability enables Ethernet service providers to achieve maximum network bandwidth efficiencies on par with any packet switched networking technology.
Figure 1. Ethernet Private Line (EPL) and Ethernet Private LAN (EP-LAN) Services
Force10 Networks, Inc. 350 Holger Way San Jose, CA 95134 USA www.force10networks.com 408-571-3500 408-571-3550
PHONE FACSIMILE
2009 Force10 Networks, Inc. All rights reserved. Force10 Networks and E-Series are registered trademarks, and Force10, the Force10 logo, Force10 Reliable Networking, C-Series, EtherScale, ExaScale, FlexMedia, FTMS, FTOS, Hot Lock, PowerSmart, P-Series, Reliable Business Networking, SFTOS, S-Series, StarSupport, TeraScale, VirtualControl, VirtualScale, and VirtualView are trademarks of Force10 Networks, Inc. All other company names are trademarks of their respective holders. Information in this document is subject to change without notice. Certain features may not yet be generally available. Force10 Networks, Inc. assumes no responsibility for any errors that may appear in this document.
WP35 309 v1.0
[ PA G E
O F
2 ]