Documente Academic
Documente Profesional
Documente Cultură
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 2
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Agenda
What Is Metro Ethernet
and Why Is It Relevant to
Enterprise Customers
Evolution of
Ethernet with Introduction What Services to
Support for LMI Expect from a
and OAM Metro Ethernet
Signaling; What Advanced SP, P2P, MP2MP,
Standards Bodies Topics Services
MPLS VPN, CPE
Are Involved Considerations
Agenda
What Is Metro Ethernet
and Why Is It Relevant to
Enterprise Customers
Introduction
Advanced
Topics Services
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 4
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
What is Metro Ethernet?
SONET/SDH
RPR Remote
Regional Office 1
Headquarters DWDM/CWDM
Ethernet
MPLS/IP
Ethernet-
Ethernet-
Connected
Connected
10 Mbps Branch
Branch
Ethernet
SP Remote
100 Mbps Metro Ethernet Office 2
Ethernet Network
10 Mbps
Ethernet
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 5
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet:
Revolution or Evolution?
Questions:
How does Metro Ethernet change the way
enterprises design and deploy networks?
What enterprise requirements are addressed
by Metro Ethernet?
Answers:
Nothing should change; the same principles of
structure and hierarchy still hold true
Enterprise applications drive BW requirements
Service type will dictate design considerations
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 7
Transparent
LAN interconnect Services
Service aggregation High Availability
Interconnect
data centers High Bandwidth
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Agenda
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 9
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 10
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
L2VPN versus L3VPN
VPN A
VPN C
VPN B
MPLS VPN
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 11
VPN A
VPN A
VPN B
VPN C VPN C
VPN B
VPN A
FR, ATM, Ethernet
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Layer 3 and Layer 2 VPN Characteristics
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet Services Evolution
Meeting Carrier Class
Technology Mainstream Smart
Niche Spark in the Making Metro Pipes
Needs
High-Speed
High-Speed Emergence
Emergence of
of
Connectivity
Connectivity at
at Ethernet
Ethernet
Any
Any Cost
Cost Service
Service
Providers
Providers
TLS
TLS Service
Service
W/
W/ ATM
ATM Lane
Lane Optical
Optical
or
or ATM
ATM RFC1483
RFC1483 Emergence
Emergence
Ethernet
Ethernet
Dominance
Dominance
IP
IP Prevalence
Prevalence
Velocity
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 15
High-Speed
High-Speed Emergence
Emergence of
of Fusion
Fusion of
of
Connectivity
Connectivity at
at Ethernet
Ethernet Technology
Technology
Any
Any Cost
Cost Service
Service and
and Systems
Systems
Providers
Providers
TLS
TLS Service
Service Incumbent
Incumbent
W/
W/ ATM
ATM Lane
Lane Optical
Optical Carrier
Carrier Adoption
Adoption
or
or ATM
ATM RFC1483
RFC1483 Emergence
Emergence
Ethernet
Ethernet
Dominance
Dominance
IP
IP Prevalence
Prevalence Dependability
Optimization
Richness
Scale
Velocity
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 16
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet Services Evolution
Meeting Carrier Class
Technology Mainstream Smart
Niche Spark in the Making Metro Pipes
Needs
High-Speed
High-Speed Emergence
Emergence of
of Fusion
Fusion of
of Large
Large Scale
Scale Ethernet
Ethernet
Connectivity
Connectivity at
at Ethernet
Ethernet Technology
Technology System
System Utility
Utility Service
Service
Any
Any Cost
Cost Service
Service and
and Systems
Systems Deployments
Deployments
Providers
Providers
TLS
TLS Service
Service Incumbent
Incumbent Service
Service
W/
W/ ATM
ATM Lane
Lane Optical
Optical Carrier
Carrier Adoption
Adoption Inter
Inter-Working
-Working
or
or ATM
ATM RFC1483
RFC1483 Emergence
Emergence
Revenue
Revenue
Ethernet
Ethernet Expansion
Expansion
Dominance
Dominance Utility Service
Transparency/Interworking
IP
IP Prevalence
Prevalence Dependability
Optimization
Richness
Scale
Velocity
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 17
Ethernet Services
Definition Framework
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Private Line (EPL)
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 19
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Relay Service (ERS)
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 21
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Wire Service (EWS)
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 23
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Multipoint Service (EMS)
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 25
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Relay Multipoint Service (ERMS)
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 27
OPT-2045
Routers can safely connect to an ERMS UNI
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 28
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Summary of Ethernet-Based Services
Ethernet-Based Services
Point-to-Point Multipoint
Ethernet
Ethernet Ethernet Ethernet Ethernet
Relay MPLS
Private Relay Wire Multipoint
Multipoint VPN
Line Service Service Service
Service
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 29
Over-- subscription
Over Yes Yes Yes No Yes
Layer 2 PDU Discard CDP, Discard CDP, Tunnel CDP, Tunnel CDP, Tunnel CDP,
Transparency VTP, STP* VTP, STP* VTP, STP* VTP, STP* VTP, STP*
CPE Type Router*** Router*** Router or Switch Router or Switch Router or Switch
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Layer 2 Ethernet Services Comparison
P2P and MP2MP compared as the Enterprise
Network grows
Point-to-Point (ERS and Multipoint (EMS and
EWS) ERMS)
Models ATM/Frame Relay New WAN broadcast model
Complex configuration Simple configuration
Predictable traffic patterns Unpredictable traffic
patterns
Simple QoS and security
policy definition Complex QoS and security
policy definition
Simple IGP peering
Complex IGP peering
Simple IP multicast
behaviour Complex IP multicast
behaviour
Simple troubleshooting
Complex troubleshooting
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 31
CPE Considerations
Questions:
Can I connect switches to an ERS service?
Can I connect routers to an EWS service?
Do I need to worry about the STP protocol I am
running on my switches?
What are the valid CPE combinations?
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 32
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
CPE Considerations
ERS and L2 Switches
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 33
CPE Considerations
ERS Valid Combinations
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 34
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
CPE Considerations
EWS Valid Combinations
3
/ &3 (
9 73 97
External loops can / &3 (
%3'
8
be detected by the
end devices
Both L2 and L3
CPEs can be / &3 (
/ 3 ' 8 V%3 ' 8 &' 3
973 W UDQVSDUHQF\
/ &3 (
connected to an
EWS UNI
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 35
CPE Considerations
CPE STP Protocol
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Agenda
Introduction
Advanced
Topics Services
Ethernet to ATM/FR
L2 Service Inter -Working:
IP Multicast
Inter-Working Bridged versus
Routed, CPE
Considerations
Quality
Security
of Service
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 37
Remote
Regional Office 1
Headquarters
TODAY 256 Kb
Frame Relay-
Connected
Branches
Service
Provider Remote
512 Kb Frame Relay Network Office 2
256 Kb
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet to Frame/ATM Inter-Working
Remote
Regional Office 1
Headquarters
TOMORROW 256 Kb
Frame Relay-
Connected
Branches
Service
Provider Remote
100 Mbps Metro Ethernet Network Office 2
256 Kb
Ethernet
SIW Device
10
10 Mbps
Mbps
Ethernet
Ethernet
Provides end-to-end L2 transport
services between two CEs with Remote
disparate interfaces Office 3
Ethernet-
Ethernet-
Extends service footprint Connected
Connected
Branch
Branch
OPT-2045
BUT It Is Not Trivial !!!
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 39
Layer 2 Service
Inter-Working Complexities
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Layer 2 Protocols Frame Formats
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 41
Layer 2 Service
Inter-Working Complexities
Each Layer 2 protocol has different address
resolution processes
Ethernet uses IP ARP
The target Layer 3 address is known but not the Layer 2 address
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Pseudowire Reference Model
Approach to SIW:
Local-AC-Termination
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
SIW Example for Metro Ethernet
Layer 2 Service
Inter-Working Features
Cisco Any Transport Over MPLS (ATOM) and L2TPv3 any-to-any
Cisco also supports complimentary Layer 2 Service Inter-
Working features
Integrated Routing and Bridging (IRB)used at CPE for bridged SIW
Route Bridge Encapsulation (RBE)used at CPE for bridged SIW
Bridge Route Encapsulation (BRE)used at PE for routed SIW (no-IP/MPLS)
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Bridged
Service Inter-Working
MPLS or IP Core CE 2
CE 1
Ethernet Pseudowire CE2
CE 1
PE 1 PE 2
ATM header
Tunnel label
LLC (AA-AA)
IRB / RBE LLC (03) OUI(00) VC label
OUI (80-C2)
PID (00 -07)
Control word
PAD (00- 00)
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 48
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet to AAL5 Bridged SIW
Configuration
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 49
Ethernet Ethernet
Any
Frame Relay -2- Frame Relay
Any
PPP/HDLC PPP/HDLC
ATM ATM
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 50
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet to ATM AAL5 Routed SIW
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 52
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Bridge Route Encapsulation (BRE) Cont.
BRE Sample
Configuration
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 53
Bridged: Routed:
Native service: Ethernet Native service: IP
Pro: ARP resolution done Pro: no configuration
by both end CPEs changes at ATM/FR CPE
Pro: implicit support for Cons: ARP
any L3 Network protocols resolution/spoofing done at
ATM-attached PE
Cons: ATM/FR CPE has to
(e.g. via BRE)
run in bridging mode, i.e.:
IRB for Frame Relay VC Cons: supports one L3
attachment circuits Network Protocol (IP)
RBE or IRB for ATM VC
attachment circuit
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 54
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Agenda
Introduction
Advanced
Topics Services
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
Why Is QoS Relevant
in Metro Ethernet;
What SLAs to Expect
from an SP
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 55
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
What Is an SLA?
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 58
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet End-to-End QoS
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 59
Classification Policing
Policer
Drops
OPT-2045
SP EDGE
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 60
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet End-to-End QoS
Queue Shaped
Drops Scheduling
OPT-2045
SP EDGE
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 61
SP Network
UNI UNI
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet End-to-End QoS
SP Network
VoIP
UNI UNI
signaling traffic
Voice Ctrl 10%
10%
Signaling and
Queue 4
Management
33 60% WRED
Threshold for 33
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 63
SP Network
Critical
UNI UNI
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet End-to-End QoS
SP Network
UNI UNI
Best
Effort
Management
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 65
UNI UNI
Example: SP WRR
Management Voice
PQ
PQ
Queue 1
traffic
10%
10%
Minimum BW Best Effort
Queue 2
management 77
Voice Ctrl 10%
10%
and
Queue 4
Management
95% WRED
Threshold for 77
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 66
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet End-to-End QoS
SNMP
SP Network Alarms VoIP
Critical
UNI UNI
Best
Effort
WRR
55 PQ
PQ
Voice
Queue 1 WRED WRED
Threshold for 11 Threshold for 22
00
10%
10% 40% 90%.
Best Effort
Queue 2
11
80%
80%
CIR and PIR
Queue 3
22
Voice Ctrl 10%
10%
77 and
Queue 4
Management
33 95% WRED
Threshold for 77
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 67
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Agenda
Introduction
Advanced
Topics Services
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
How to Secure an
Enterprise Network
Connected to a Metro
Ethernet Provider
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 69
Ethernet Security
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 70
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security
Attacks such as dSniff exploit Ethernet weaknesses
http://naughty.monkey.org/~dugsong/dsniff/
dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy
arpspoof, dnsspoof, and macof
sshmitm and webmitm
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 71
Ethernet Security:
An Example of What Can Go Wrong
Lets Look at Trust Me Mistakes:
Edge switches physical security
questionable
Password recovery is enabled
No central system monitoring for
Time to configuration changes
Work!! All customer VLANs are allowed
everywhere
Switch X
Trust Me Time to
Telecom Work!!!
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 72
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
An Example of What Can Go Wrong
1. Use Password
Recovery and
Reconfigure My
Port to a Trunk
What a Nice
Day!!!
Spoofed
VLAN Trunk
Switch X
Trust Me What a Nice
2. Launch MACOF Attack Day!!!
Telecom
480,000 MAC/min
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 73
Ethernet Security:
An Example of What Can Go Wrong
3. Wow, CAM Tables Are 3. Wow, CAM Tables Are
Full; Ill Flood All New Full; Ill Flood All New
Sessions as I Cant Learn Sessions as I Cant Learn
New MAC addresses! New MAC addresses!
Switch X
Trust Me What a Nice
Telecom Day!!!
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
An Example of What Can Go Wrong
5. Username: Stevep
Password: 3bmChtr
Thanks
Stevep!!
Spoofed
VLAN Trunk
Switch X
Trust Me 4. Username:
Stevep
Telecom Password:
3bmChtr
Ethernet Security:
An Example of What Can Go Wrong
5. Username: Stevep 3. Wow, CAM Tables Are 3. Wow, CAM Tables Are
Password: 3bmChtr Full; Ill Flood All New Full; Ill Flood All New
Sessions as I Cant Learn Sessions as I Cant Learn
1. Use Password New MAC addresses! New MAC addresses!
Recovery and
Reconfigure My
Port to a Trunk
3. Wow, CAM Tables Are
Thanks Full; Ill Flood All New
Stevep!! Sessions as I Cant Learn
Spoofed New MAC addresses!
VLAN Trunk
Switch X
Trust Me 4. Username:
2. Launch MACOF Attack Stevep
Telecom Password:
480,000 Mac/min
3bmChtr
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
What Can I Do to Secure My Network?
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 77
Ethernet Security:
#1. Secure Your Routers or Switches
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
#1. Secure Your Routers or Switches (Cont.)
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 79
Ethernet Security:
#2. Secure Your Control Protocols
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 80
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
#2. Secure Your Control Protocols (Cont.)
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 81
Ethernet Security:
#3. Secure Your Communications
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
#4. Track and Log Everything
Log Routing protocol adjacency changes
It may be an unauthorized device?
Track interface changes (up/down)
It may point to a device that has been password
recovered
Track Configuration changes
Was the configuration change known and authorized?
Did the change occur after a power cycle?
Track Firewall and IDS violations
It may identify an attack?
Maintain an audit trail for analysis
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 83
Ethernet Security:
SP Recommendations
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 84
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
SP Recommendations
STP Attacks
VLAN Hopping
Attacks
MAC Attacks
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 85
Ethernet Security:
SP Recommendations
BPDU Filter (for Egress SP BPDU)
MAC ACLs (for Ingress CE BPDU)
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
SP Recommendations
Disable Password Recovery
VTP Mode Transparent
LOOP Guard
Prune All Unused VLANs from
Allowed List
Remove VLAN 1 and Reserved
VLANs from Trunks
Reserve a VLAN ID for the
Native VLAN on the SP Trunks
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 87
Ethernet Security:
SP Recommendations
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 88
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
SP Recommendations
BPDU Filter (for Egress SP BPDU) Disable Password Recovery
MAC ACLs (for Ingress CE BPDU) VTP Mode Transparent
Ethernet Security:
Proactive Security Management
Switch X
Trust Me Time to
Telecom Work!!!
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 90
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
Proactive Security Management (scenario 1)
1. Use Password
Recovery and Try
to Reconfigure My
Port to a Trunk
2. As a Result of
What a Bad Disabling Password
Day!! Recoverythe
Spoofed Configuration File Is
VLAN Trunk Lost!!!
Switch X
Trust Me What a Nice
Telecom Day!!!
OPT-2045
Attack in Unsuccessful!!!
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 91
Ethernet Security:
Proactive Security Management (scenario 2)
1. Use
Password
Recovery and
Try to
Reconfigure My
Port to a Trunk
What a
Nice Day!!
Spoofed
VLAN Trunk
Switch X
Trust Me
Telecom
2. Launch MACOF
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 92
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet Security:
Proactive Security Management (scenario 2)
What a
Terrible Day!! 3. Huh, VLAN MAC limit
Spoofed allows me to Learn only
VLAN Trunk 250 MAC Addresses for
That VLAN; Ill shutdown
the associated VLAN
Switch X
Trust Me interface
Telecom
4. Username: Stevep
Password: 3bmchtr
OPT-2045
Attack in Unsuccessful!!!
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 93
Ethernet SecuritySummary
Be aware of the security risks
Whitepapers at
http://naughty.monkey.org/~dugsong/dsniff/
Run dSniff against the service!
Cisco has robust solutions today
RootGuard, Port Security, TACACs, etc.
Cisco is working on several initiatives
802.1x supplicant
Anti-ARP spoofing mechanisms
MAC address limits per VLAN, and more
Please refer to http://www.cisco.com/go/safe
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 94
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Agenda
Introduction
Advanced
Topics Services
Considerations
for IP Multicast L2 Service
IP Multicast
Traffic on a Metro Inter-Working
Ethenet Network;
How to Choose
the Right Service
for Multicast
Quality
Security
of Service
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 95
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 96
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
The Impact of IP Multicast
on Metro Ethernet Services
This Is What We Expect of the SP for IP Multicast on
a Multipoint service constrained traffic
IP Multicast Source
IP Multicast Source
Sprayer A
Sprayer B
SP Network
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
The Impact of IP Multicast
on Metro Ethernet Services
OK Rtr-A
Wants Group
OK, Host A X. Ill Forward
Wants Group X,
Ill Ask Rtr-B
SP Network
IP Multicast Source
IP Multicast Source
Sprayer A
Sprayer B
SP Network
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
The Impact of IP Multicast
on Metro Ethernet Services
This Is What We get for IP Multicast
on an Point to Point service
IP multicast constrained to those sites that
actually request the data
Enterprise has complete control
Reduced resource and bandwidth overhead
Improved control over join and leave process
Improved convergence characteristics
SP Network
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 101
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Metro Ethernet - IP Multicast
considerations
IP Multicast should be considered when
selecting Metro Ethernet services
If an Enterprise has
A large volume of IP Multicast traffic
Mismatched bandwidth i.e. 10/100/1000 connected sites
A MultiPoint service may be a poor service choice
Agenda
Evolution of
Ethernet with Introduction
Support for LMI
and OAM
Signaling; What Advanced
Standards Bodies Topics Services
Are Involved
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 104
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet LMI and End-to-End OAM
Is the Other
End there?
SP Network
L2PING?
L2Trace?
LMILocal Management Interface
OAMOperation, Administration and Maintenance
Ethernet services offer very flexible and high-speed service
offerings at Layer 2 and Layer 3, but
Ethernet lacks certain carrier class features such as LMI and
OAM functions
Several industry bodies are investigating functions that are
available in Layer 3
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 105
Ethernet Local
Management Interface (LMI)
An LMI informs a CPE device about the state of the
interconnecting circuit and can signal other information
such as bandwidth parameters, network addresses, etc
Relevant to point-to-point circuits such as ATM PVCs,
Frame Relay DLCIs and now being looked at for Ethernet
ERS/EWS models Frame Relay or ATM using VLAN IDs as
VC identifiers
Ethernet LMI will be an important development for Ethernet
service adoption
Not a trivial issue to resolve due to architectural
considerations
Also requires and end-to-end signaling mechanism to
carry far end circuit state (OAM)
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 106
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Ethernet LMI Operation
LMI Update: Red VLAN Is UP and Has 2mbps CIR, 5mbps PIR
LMI Update: Blue VLAN Is UP and Has 10mbps CIR, 20mbps PIR
LMI Update: Green VLAN Is Down
CE
CE
LMI OAM
SP Network X
CE
OAM Message: Green VLAN Is Down
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
End-to-End Ethernet OAM
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 109
Agenda
What Is Metro Ethernet
and Why Is It Relevant to
Enterprise Customers
Evolution of
Ethernet with Introduction What Services to
Support for LMI Expect from a
and OAM Metro Ethernet
Signaling; What Advanced SP, P2P, MP2MP,
Standards Bodies Topics Services
MPLS VPN, CPE
Are Involved Considerations
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Unified VPN Platform Solutions
NMS/OSS
Ethernet RPR xWDM SONET/SDH
ONS
ONS
Catalyst
Catalyst 4000
4000 155x0
155x0 ONS
ONS 15327
15327
Cisco
Cisco
Cisco 10700
Cisco 10700 Cisco
Cisco Catalyst
Catalyst
12000
12000 7600
7600 Catalyst
Catalyst 3550/2950
3550/2950 6500
6500
ONS15600
ONS15600 ONS
ONS 15454
15454
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 111
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
Recommended Reading
IP Quality of Service
ISBN: 1578701163
Developing IP Multicast
Networks
ISBN: 1578700779
Available on-site at the Cisco Company Store
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 113
Session OPT-2045
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 114
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr
OPT-2045
8017_05_2003_c2 2003, Cisco Systems, Inc. All rights reserved. 115
Copyright 2003, Cisco Systems, Inc. All rights reserved. Printed in USA.
Presentation_ID.scr