Professional Documents
Culture Documents
Introduction
Advanced
Topics Services
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
SP Remote
100 Mbps Metro Ethernet Office 2
Ethernet Network
10 Mbps
Ethernet
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
VPN A
VPN C
VPN B
MPLS VPN
VPN A
VPN A
VPN B
VPN C VPN C
VPN B
VPN A
FR, ATM, Ethernet
High-Speed Emergence of
Connectivity at Ethernet
Any Cost Service
Providers
TLS Service
W/ ATM Lane Optical
or ATM RFC1483 Emergence
Ethernet
Dominance
IP Prevalence
Velocity
2003, Cisco Systems, Inc. All rights reserved. 14
Metro Ethernet Services Evolution
Meeting Carrier Class
Technology Mainstream Smart
Niche in the Making
Spark Metro Pipes
Needs
Ethernet
Dominance
IP Prevalence Dependability
Optimization
Richness
Scale
Velocity
2003, Cisco Systems, Inc. All rights reserved. 15
Metro Ethernet Services Evolution
Meeting Carrier Class
Technology Mainstream Smart
Niche in the Making
Spark Metro Pipes
Needs
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
Ethernet Virtual
P2P MP
Connection
Customer
Router Bridge
Equipment
Ethernet-Based Services
Point-to-Point Multipoint
Ethernet
Ethernet Ethernet Ethernet Ethernet
Relay MPLS
Private Relay Wire Multipoint
Multipoint VPN
Line Service Service Service
Service
Over-
Over-subscription Yes Yes Yes No Yes
Layer 2 PDU Discard CDP, Discard CDP, Tunnel CDP, Tunnel CDP, Tunnel CDP,
Transparency VTP, STP* VTP, STP* VTP, STP* VTP, STP* VTP, STP*
CPE Type Router*** Router*** Router or Switch Router or Switch Router or Switch
Questions:
Can I connect switches to an ERS service?
Can I connect routers to an EWS service?
Do I need to worry about the STP protocol I am
running on my switches?
What are the valid CPE combinations?
Lets look at some scenarios
EWS is a port
based service
with L2 PDU
transparency
External loops can
be detected by the
end devices
Both L2 and L3
CPEs can be
connected to an
EWS UNI
Introduction
Advanced
Topics Services
Ethernet to ATM/FR
L2 Service Inter-Working:
IP Multicast
Inter-Working Bridged versus
Routed, CPE
Considerations
Quality
Security
of Service
Remote
Regional Office 1
Headquarters
TODAY 256 Kb
Frame Relay-
Connected
Branches
Service
Provider Remote
512 Kb Frame Relay Network Office 2
256 Kb
Remote
Regional Office 1
Headquarters
TOMORROW 256 Kb
Frame Relay-
Connected
Branches
Service
Provider Remote
100 Mbps Metro Ethernet Network Office 2
256 Kb
Ethernet
SIW Device
10 Mbps
Ethernet
Provides end-to-end L2 transport
services between two CEs with Remote
disparate interfaces Office 3
Ethernet-
Extends service footprint Connected
Branch
BUT It Is Not Trivial !!!
2003, Cisco Systems, Inc. All rights reserved. 38
Layer 2 Service
Inter-Working Complexities
ATM header
Tunnel label
LLC (AA-AA)
IRB / RBE LLC (03) OUI(00) VC label
OUI (80-C2)
PID (00-07)
Control word
PAD (00-00)
Ethernet Ethernet
Any
Frame Relay -2- Frame Relay
Any
PPP/HDLC PPP/HDLC
ATM ATM
BRE Sample
Configuration
Bridged: Routed:
Native service: Ethernet Native service: IP
Pro: ARP resolution done Pro: no configuration
by both end CPEs changes at ATM/FR CPE
Pro: implicit support for Cons: ARP
any L3 Network protocols resolution/spoofing done at
ATM-attached PE
Cons: ATM/FR CPE has to
(e.g. via BRE)
run in bridging mode, i.e.:
IRB for Frame Relay VC Cons: supports one L3
attachment circuits Network Protocol (IP)
RBE or IRB for ATM VC
attachment circuit
Introduction
Advanced
Topics Services
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
Why Is QoS Relevant
in Metro Ethernet;
What SLAs to Expect
from an SP
Classification Policing
Policer
Drops
SP EDGE
2003, Cisco Systems, Inc. All rights reserved. 59
Metro Ethernet End-to-End QoS
Marking of 802.1p CoS bits for differentiated
SLAs
Customer IP ToS maintained end-to-end
Congestion Avoidance and Egress Queuing
throughout the SP network
Congestion
Avoidance
Classification Policing Marking Queuing
Queue Shaped
Drops Scheduling
SP EDGE
2003, Cisco Systems, Inc. All rights reserved. 60
Metro Ethernet End-to-End QoS
SP Network
UNI UNI
SP Network
VoIP
UNI UNI
signaling traffic
Voice Ctrl 10%
Signaling and
Queue 4
Management
3 60% WRED
Threshold for 3
2003, Cisco Systems, Inc. All rights reserved. 62
Metro Ethernet End-to-End QoS
SP Network
Critical
UNI UNI
SP Network
UNI UNI
Best
Effort
UNI UNI
Example: SP WRR
Management PQ
QueueVoice
1
traffic
10%
Minimum BW Best Effort
Queue 2
management 7
Voice Ctrl 10%
and
Queue 4
Management
95% WRED
Threshold for 7
2003, Cisco Systems, Inc. All rights reserved. 65
Metro Ethernet End-to-End QoS
SNMP
SP Network Alarms VoIP
Critical
UNI UNI
Best
Effort
WRR
5 PQ
QueueVoice
1 WRED WRED
Threshold for 1 Threshold for 2
0
10% 40% 90%.
Best Effort
Queue 2
1
80%
2 CIR3 and PIR
Queue
Introduction
Advanced
Topics Services
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
How to Secure an
Enterprise Network
Connected to a Metro
Ethernet Provider
Switch X
Trust Me Time to
Work!!!
Telecom
1. Use Password
Recovery and
Reconfigure My
Port to a Trunk
What a Nice
Day!!!
Spoofed
VLAN Trunk
Switch X
Trust Me What a Nice
2. Launch MACOF Attack Day!!!
480,000 MAC/min
Telecom
Switch X
Trust Me What a Nice
Day!!!
Telecom
Thanks
Stevep!!
Spoofed
VLAN Trunk
Switch X 4. Username:
Trust Me
Stevep
Telecom Password:
3bmChtr
Switch X 4. Username:
Trust Me
2. Launch MACOF Attack Stevep
480,000 Mac/min
Telecom Password:
3bmChtr
STP Attacks
VLAN Hopping
Attacks
MAC Attacks
LOOP Guard
Prune All Unused VLANs from
Allowed List
Remove VLAN 1 and Reserved
VLANs from Trunks
Reserve a VLAN ID for the
Native VLAN on the SP Trunks
2003, Cisco Systems, Inc. All rights reserved. 86
Ethernet Security:
SP Recommendations
Switch X
Trust Me Time to
Work!!!
Telecom
1. Use Password
Recovery and Try
to Reconfigure My
Port to a Trunk
2. As a Result of
What a Bad Disabling Password
Day!! Recoverythe
Spoofed Configuration File Is
VLAN Trunk Lost!!!
Switch X
Trust Me What a Nice
Day!!!
Telecom
3. Switch Xs Has Been
Power Cycled and the
Configuration Has
Changed; Do Not Allow It Monitoring
to Attach to the Network! System
Attack in Unsuccessful!!!
2003, Cisco Systems, Inc. All rights reserved. 90
Ethernet Security:
Proactive Security Management (scenario 2)
1. Use
Password
Recovery and
Try to
Reconfigure My
Port to a Trunk
What a
Nice Day!!
Spoofed
VLAN Trunk
Switch X
Trust Me
Telecom
2. Launch MACOF
What a
Terrible Day!! 3. Huh, VLAN MAC limit
Spoofed allows me to Learn only
VLAN Trunk 250 MAC Addresses for
That VLAN; Ill shutdown
the associated VLAN
Switch X
Trust Me interface
Telecom
4. Username: Stevep
Password: 3bmchtr
Introduction
Advanced
Topics Services
Considerations
for IP Multicast L2 Service
IP Multicast
Traffic on a Metro Inter-Working
Ethenet Network;
How to Choose
the Right Service
for Multicast
Quality
Security
of Service
IP Multicast Source
Sprayer A IP Multicast Source
Sprayer B
SP Network
Discard Discard
Wasted SP Bandwidth ($$$)
Red Green
and Router Resources Are
IP Multicast Receiver Consumed Discarding IP Multicast Receiver
Sponge B Unnecessary Traffic Sponge A
SP Network
IP Multicast Source
Sprayer A IP Multicast Source
Sprayer B
SP Network
SP Network
Evolution of
Ethernet with Introduction
Support for LMI
and OAM
Signaling; What Advanced
Topics Services
Standards Bodies
Are Involved
L2 Service
IP Multicast
Inter-Working
Quality
Security
of Service
SP Network
L2PING?
L2Trace?
LMILocal Management Interface
OAMOperation, Administration and Maintenance
Ethernet services offer very flexible and high-speed service
offerings at Layer 2 and Layer 3, but
Ethernet lacks certain carrier class features such as LMI and
OAM functions
Several industry bodies are investigating functions that are
available in Layer 3
2003, Cisco Systems, Inc. All rights reserved. 104
Ethernet Local
Management Interface (LMI)
An LMI informs a CPE device about the state of the
interconnecting circuit and can signal other information
such as bandwidth parameters, network addresses, etc
Relevant to point-to-point circuits such as ATM PVCs,
Frame Relay DLCIs and now being looked at for Ethernet
ERS/EWS models Frame Relay or ATM using VLAN IDs as
VC identifiers
Ethernet LMI will be an important development for Ethernet
service adoption
Not a trivial issue to resolve due to architectural
considerations
Also requires and end-to-end signaling mechanism to
carry far end circuit state (OAM)
2003, Cisco Systems, Inc. All rights reserved. 105
Ethernet LMI Operation
LMI Update: Red VLAN Is UP and Has 2mbps CIR, 5mbps PIR
LMI Update: Blue VLAN Is UP and Has 10mbps CIR, 20mbps PIR
LMI Update: Green VLAN Is Down
CE
CE
LMI OAM
SP Network
X
CE
OAM Message: Green VLAN Is Down
NMS/OSS
IPMPLS, L2TPv3
Ethernet RPR xWDM SONET/SDH
ONS
Catalyst 4000 155x0 ONS 15327
Cisco
Cisco 10700 Cisco Catalyst
12000 7600 Catalyst 3550/2950 6500
ONS15600 ONS 15454