Professional Documents
Culture Documents
www.nmcgroups.com
January 9, 2009
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Table of Contents
1. Network Requirements
2. Network Architecture: Topology Design
2.1 Aggregation Network for Towers
2.2 Aggregation Network for Villas
4. Network Availability
5. Scalability
6. QoS Design
6.1 QoS for Residential TPS Service
6.2 QoS for Business VPN Service
7. Multicast
8. Security
8.1 Security: Data Plane
8.2 Security: Control Plane & Management Plane
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
1. Network Requirements
Backbone
NOC-1
Backbone
NOC-2
BRAS/PE
BRAS/PE
#33 (=17+16)
#2
#1
#39
#2
# of Subscribers
Access Technology: FTTH (AON)
Residential TPS service
#15
#16
#1
Scalability
QoS
Multicast for IP-TV
Integration with Existing Broadband
Network (MPLS)
Easy Touch Provisioning
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
2. Network Architecture
Tower
Tenant
NOC-1
RG
20
DS(L2)
BRAS/PE P Router
10GE
1GE
8XGE
MDF
10GE
2x10GE
20
10GE
8XGE
10GE
Existing
MPLS Core
10GE
AS
AN
DS(L2)
BRAS/PE
P Router
NOC-2
RG (Residential Gateway)
AN (Access Node)
AS (Access Switch)
DS (Distribution Switch)
BRAS
Role of BRAS
Role of AS and DS
L2 Ethernet Aggregation
BRAS
BRAS (PE)
Traffic Path
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Tenant
RG
1
20
NOC-1
Co-existence of residential
and business subscribers
DS
BRAS/PE
P Router
10GE
8XGE
10GE
MDF
2x10GE
Existing
MPLS Core
10GE
4xGE
(1000baseTX)
20
P Router
AS
10GE
One AS is connected to
two NOCs (Dual Homing)
for protection
AN
10GE
DS
8XGE
BRAS/PE
NOC-2
RG
DS (Distribution Switch)
AN (Access Node)
AS (Access Switch)
10GE
1 GE (1000Base-TX)
BRAS/PE
1 GE (1000Base-FX)
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
RG
AN and AS are
centralized at NOC-1
AN
NOC-1
4xGE (T)
DS
AS
BRAS/PE
P Router
10GE
10GE
8XGE
One AS is
connected to two
10GE
NOCs (Dual
Homing) for
protection
2X10GE
Existing
MPLS Core
10GE
P Router
10GE
DS
8XGE
NOC-2
RG
DS (Distribution Switch)
AN (Access Node)
AS (Access Switch)
BRAS/PE
10GE
1 GE (1000Base-TX)
BRAS/PE
1 GE (1000Base-FX)
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
CPE
Residential
Internet Access
DHCP
C-VID=Internet(5)
Residential
Voice
DHCP
C-VID=Voice(3)
Residential
Video
DHCP
AS
DS
PE/BR
VRF
VRF
VRF
PE/SAR
PE2
PE3
VRF
VRF
MPLS L3 Voice VPN (LSP to PE: Data)
C-VID=Video(4)
Enterprise
C-VID=Ent. A
Internet Access
Static/Public Subnet
Enterprise
C-VID=Ent. B
L3 VPN
Private Addressing and Routing
Enterprise
C-VID=Ent. C
L2 VPN (PtP: EoMPLS)
Private Addressing and Routing
C-VID=Ent. D
Enterprise
L2 VPN (PtMP: VPLS)
Private Addressing and Routing
VRF
VRF
VRF
Per-Enterprise VLAN
(C-VID=Ent. A, S-VID=Ent. A)
Per-Enterprise VLAN
(C-VID=Ent. B, S-VID=Ent. B)
Per-Enterprise VLAN
(C-VID=Private Use, S-VID=Ent. C)
VRF
VRF
VRF
VRF
VRF
VRF
VSI
VRF
VRF
VSI
VSI
VSI
VSI
VSI
VSI
VSI
Per-Enterprise VLAN
(C-VID=Private Use, S-VID=Ent. D)
EAPS
VSI
VSI
VSI
VSI
VSI
VSI
VSI
VSI
VSI
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
Voice
Video
Data
AS
DS
Voice
Video
Data
802.1Q
Residential
A
Residential
B
N:1 VLAN
802.1ad
Bridging
S-VID
Voice
Video
Data
802.1ad (QinQ):
S-VID=Per AN VLAN, C-VID=Per Service VLAN
Per Service
VLAN
Encapsulation
IP/MPLS
Backbone
BRAS/PE
C-VID
MPLS L3VPN
per Service
Bridging
Outer VLAN
Inner VLAN
N:1 VLAN
Residential
C
VRF
Residential
D
VRF
<Tower A>
Voice VPN
Video VPN
Data VPN
VRF
N:1 VLAN
Residential
E
Residential
F
<NOC>
<Tower B>
Layer 2 (Ethernet)
Layer 3 (IP/MPLS)
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Service Separation: in the backhaul, by Per-Service VLAN (N:1 VLAN). Inside BRAS, by VRF (Each VRF has its
own interface and route information)
L2 Scalability Issues
MAC Learning at DS: 224K MAC addresses supported by DS >> 15K subscriber x 4 services = 60K
IP Address Management: Public IP address for Internet access, Private IP address for walled-garden service
(VoD, IP-TV, VoIP)
DHCP Option82 at AN (Per-service VLAN ID, Port ID, AN ID): Subscriber Identification, Location of
subscriber, Per-service IP address allocation
10
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
AS
DS
BRAS/PE
Per Enterprise
QinQ
Encapsulation
IP/MPLS
Backbone
Bridging
Enterprise ID
S-VID
C-VID
MPLS L2/L3
VPN per
Enterprise
Bridging
Outer VLAN
1:1 VLAN
Enterprise
A
Inner VLAN
VRF
Enterprise
B
VRF
1:1 VLAN
Enterprise
C
VSI
VSI
Enterprise
D
Ent-A L3 VPN
Ent-B L3 VPN
<Tower A>
1:1 VLAN
Enterprise
E
Enterprise
F
VSI
VSI
<Tower B>
<NOC>
Layer 2 (Ethernet)
Layer 2/3
11
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
MPLS L3 VPN
L3 VPN (vc-lsp)
Tunnel Signaling (LDP or RSVP-TE)
802.1ad
LSP Tunnel
IGP (IS-IS or OSPF)
Site-1, VPN-A
PE
PE
CE1
Site-2, VPN-A
CE2
Metro Ethernet
Backhaul
Site-1, VPN-B
CE1
IP/MPLS Backbone
Metro Ethernet
Backhaul
Site-2, VPN-B
CE2
12
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
PW Signaling
(Martini Signaling/RFC4447)
Per-enterprise VLAN (1:1 VLAN)
802.1Q
Per-enterprise VLAN
PW (vc-lsp)
Tunnel Signaling (LDP or RSVP-TE)
802.1ad
LSP Tunnel
IGP (IS-IS or OSPF)
Site-1, VPN-A
PE
PE
CE1
Site-2, VPN-A
CE2
Metro Ethernet
Backhaul
Site-1, VPN-B
CE1
IP/MPLS Backbone
Metro Ethernet
Backhaul
Site-2, VPN-B
CE2
RFC 4448 (Martini), Encapsulation Methods for Transport of Ethernet over MPLS Networks, April 2006
RFC 4447 (Martini), Pseudowire Setup and Maintenance Using LDP, April 2006
13
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
PW Signaling
(Martini Signaling/RFC4762 or BGP/RFC 4761)
Per-enterprise VLAN (1:1 VLAN)
802.1Q
Per-enterprise VLAN
802.1ad
LSP Tunnel
IGP (IS-IS or OSPF)
Site-1, VPN-A
PE
PE
CE1
Site-2, VPN-A
CE2
Metro Ethernet
Backhaul
Site-1, VPN-B
CE1
IP/MPLS Backbone
Metro Ethernet
Backhaul
Site-2, VPN-B
CE2
RFC 4762: Virtual Private LAN Service (VPLS) Using LDP Signaling, Jan. 2007
RFC 4761: RFC 4761 on Virtual Private LAN Service (VPLS) Using BGP for Auto-Discovery and Signaling, Jan. 2007
RFC 4664: Framework for Layer 2 Virtual Private Networks (L2VPNs), Sep. 2006
Copyright 2002-2013 NMC Consulting Group. All rights reserved.
14
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Link failure between AS and DS is major threatening and we can provide fast convergence of link fail (under 50ms) by EAPS
(Ethernet Automatic Protection Switching)
Ring based network resiliency protocol between AS and DS/PE, operate at layer 2
Provides SONET/SDH like fast convergence from network failures
Proven sub-50ms failover times for voice-class connections
Designed for carriers/ISPessential for convergence in the enterprise
IETF RFC 3619
NOC-1
DS
Normal Data
Traffic
Tower A
RG
BRAS/PE
AN
AS
EAPS Ring
Health Check
Messages sent out periodically
B
b
NOC-2
IP/MPLS
Backbone
DS
BRAS/PE
RFC3619: Extreme Networks Ethernet Automatic Protection Switching (EAPS) Version 1.0
Copyright 2002-2013 NMC Consulting Group. All rights reserved.
15
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
AS
DS
PE
VRRP Master
RG
AN
AS
DS
PE
EAPS
VRRP
Blocked Port
IP/MPLS
Backbone
IP/MPLS
Backbone
Become Active
RG
AN
AS
DS
PE
VRRP Master
RG
AN
VRRP Master
AS
DS
IP/MPLS
Backbone
Unicast Upstream
Unicast Downstream
AN
IP/MPLS
Backbone
RG
PE
AS
DS
PE
VRRP Master
RG
AN
VRRP Master
AS
DS
PE
Become Active
IP/MPLS
Backbone
IP/MPLS
Backbone
VRRP Master
16
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
AS
DS
PE
Enable
VRRP I/F tracking
IP/MPLS
Backbone
RG
AN
VRRP Master
AS
DS
PE
Disable
VRRP I/F tracking
VRRP Master
IP/MPLS
Backbone
Recovery by IGP
< Link Fail >
17
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
AS
DS
PE
DR
RG
AN
AS
DS
PE
EAPS
IP/MPLS
Backbone
PIM Hello
Blocked Port
IP/MPLS
Backbone
Become Active
RG
AN
AS
DS
PE
DR
RG
AN
DR
AS
DS
PE
IP/MPLS
Backbone
Multicast
Recovery by IGP
RG
AN
IP/MPLS
Backbone
AS
DS
PE
DR
RG
AN
DR
AS
DS
PE
Become Active
IP/MPLS
Backbone
IP/MPLS
Backbone
Recovery by IGP
< PE Fail >
DR
18
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
RG
AN
AS
DS
PE
IP/MPLS
Backbone
Recovery by IGP
< Link Fail >
19
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
5. Scalability
AS (BD 8806)
DS (BD 10808)
BRAS/PE (E320)
16K
224K
96K
1M
4K
4K
96K
10K
BRAS/PE (E320)
1K
500K
BRAS/PE (E320)
8K
1K
Totally 64K
20
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
L2 Scalability
Per-Enterprise VLAN must be provisioned through Ethernet backhaul network (Potential scaling issue)
802.1Q provides 4K distinct VLANs and 802.1ad provides 16M distinct VLANs
21
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
4 service classes
Internet bandwidth control for
both upstream and downstream
direction per residential
subscriber by RG & BRAS
Voice, IPTV and VoD traffic are
always higher priority than
Internet
BRAS
HIGH
IPTV (multicast)
VoD to All users
A
Per-Residential
shaping
SPQ
Internet to User-A
LOW
Internet to User-B
Internet to User-C
RG
802.1p
802.1p
DS
AS
AN
802.1p
BRAS/PE
802.1p
IP/MPLS
Backbone
RG ~ AN
AN ~ AS
AS ~ DS
DS ~ BRAS/PE
BRAS/PE ~ P
802.1p
802.1p
802.1p
802.1p
Voice
COS 5
COS 5
COS 5
COS 5
EXP 5
IPTV
COS 3
COS 3
COS 3
COS 3
DSCP AF3
VoD
COS 2
COS 2
COS 2
COS 2
EXP 2
Internet
COS 0
COS 0
COS 0
COS 0
EXP 0
22
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
PE
4 service classes
Bandwidth control for both upstream and
downstream direction per enterprise subscriber by
PE
PE supports hierarchical shaper
S-VLAN
1001
V
T
M
I
Per-Enterprise
Hierarchical shaping
(PIR/CIR)
3
RT Voice
RT Video
Mission Critical
Best Effort
S-VLAN
1400
S-VLAN
1500
AN
RG
DS
AS
BRAS/PE
IP/MPLS
Backbone
802.1p
802.1p
802.1p
802.1p
MPLS QoS
RG ~ AN
AN ~ AS
AS ~ DS
PE ~ P
802.1p
802.1p
802.1p
Voice
COS 5
COS 5
COS 5
EXP 5
VoD
COS 2
COS 2
COS 2
EXP 2
Mission Critical
COS 1
COS 1
COS 1
EXP 1
Internet
COS 0
COS 0
COS 0
EXP 0
23
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
7. Multicast
Tower A
RG
AN
AS
NOC-1
DR
DS
BRAS/PE
Tower B
RG
AN
AS
NOC-2
Tower C
RG
AN
IGMP Proxy
IP/MPLS
Backbone
IGMP
Snooping
AS
IGMP
Snooping
DS
BRAS/PE
IGMP
Snooping
IGMP Static
Join
All IPTV channels (multicast streams) are always reach to the core-facing port of DS for fast channel
zapping by IGMP Static Join function of BRAS/PE
24
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Defensive Features/Actions
NE
MAC attacks
Limit number of MAC address per port, Allow only static MAC address
AN, AS
VLAN hopping
Disable auto trunking on user-facing port, Do not use VLAN1 for anything
AN, AS, DS
AN, AS, DS
Limit number of MAC address per port, Allow only static MAC address
AN, AS
AN, AS, DS
ARP attacks
Storm attacks
AN, AS, DS
System attacks
CPU rate-limit & filtering, Prioritize control traffic (telnet, SNMP is high)
DHCP attacks
Limit number of MAC address per port, Check Integrity of DHCP message
AN, BRAS/PE
BRAS/PE
Smurf attacks
BRAS/PE
IGMP attacks
AN, AS
AN, AS
PIM attacks
BRAS/PE
25
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Defensive Features/Actions
NE
BRAS/PE
BRAS/PE
26
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
AS
DS
BRAS/PE
IP/MPLS
Backbone
27
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
AN
AS
DS
BRAS/PE
IP/MPLS
Backbone
28
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
9. Easy Touch Provisioning Tool: SSG (Service Selection Gateway) for TPS Users
BACK OFFICE
OSS/BSS
AAA
SERVICE
INTELLIGENCE
CONTROL PLANE
LDAP
10 LDAP Search: MAC ID/PW
11 LDAP Result: NULL return
Web Portal
Policy Server
DHCP
TRANSPORT
PLANE
RG
1 DHCP DISCOVER
2 DHCP OFFER
3 DHCP REQUEST
4 DHCP ACK
5 Client Table is created
AS
AN
RG
DS
AN
RG
RG
BRAS/SSG
IP/MPLS
Backbone
AS
AN
6 SI is created
29
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Connection Manager helps reduce overall administration and management costs by providing automated resource
management and rapid profile-based provisioning capabilities that speed deployment and time to market of Metro
Ethernet technologies
It provides 802.1Q VLAN, 802.1ad QinQ provisioning methods for AN, AS and DS
IP/MPLS
Backbone
RG/CE
Site-1, VPN-A
AS
AN
DS
BRAS/PE
PE
CE
Site-2, VPN-A
CE
RG/CE
Site-1, VPN-B
Per Enterprise VLAN
Site-2, VPN-B
30
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Network management systems make use of a wide range of tools, applications, interfaces and devices to assist the network
operators work in monitoring and maintaining the network. A standard model is defined by the ITU-T for all management
systems, called FCAPS
Fault management
Configuration management
Accounting management
Performance management
Security management
FCAPS
Fault
Configuration
Accounting
Performance
Security
NMS
DHCP
AN EMS
AS/DS EMS
Northbound
(SNMP, XML)
BRAS EMS
Southbound
(SNMP)
TFTP/FTP
BRAS
RG/CPE
IP/MPLS Core
Network elements
RG/CPE
AN
AS
DS
Internet
31
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
EMS/NMS Features
General managements
Fault
Configuration
Performance/Statistics Reports
Security
Topology map
Fault detection
Resource initialization
Data collection
Command history
Alarm generation
Provisioning
Data reporting
Access logging
Alarm handling
Data analysis
Error logging
Remote configuration
Alarm history
Data backup
2
Topology map
- Network topology map
- Elements status view
1
Elements lists
- Elements lists view
- Elements searching
- Diagnostics for elements
3
Alarm statistics summary
- Alarm count per fault category
- Alarm Color per fault category
32
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Sub features
Monitoring condition
System General
Information
Descriptions
Monitoring time, retry count, retry timeout
Monitoring condition and threshold control based on system performance
Topology MAP
Utility
Alarm history
Tool-tip
display detail information when you move the mouse across a element or port
Element information
CPU, MEMORY, DISK, temperature, element boot time, OS version, number of interface
Interface information
Performance reports
System resource
Performance
Traffic performance
Configuration
Elements status
Elements configuration
Node and port configuration such as VLAN, QoS, ACL, Multicast, etc
Port status
Element/Link management
33
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
Fault
Statistics Report
Security
Backup and Restore of
Data
Sub features
SNMP Trap
Alarm notify
Alarm history
Alarm severity management
Syslog management
Alarm analysis report for each
elements
Alarm analysis report for the each
interfaces
Alarm threshold
Report file format
Elements or Port inventory report
Descriptions
SNMP TRAP, syslog, CLI
web event , e-mail, sms
Alarm history search
Critical, Major, Minor, Warning, Normal
syslog collect, syslog history search
Analysis of the alarm count, alarm duration and alarm type for each elements
Analysis of the alarm count, alarm duration and alarm type for each interfaces
Traffic statistics
Account management
34
Netmanias Technical Document: Backhaul Network Design for TPS & VPN Service
End of Document
35
00
01
02
03
04
05
06
07
08
09
10
11
12
13
eMBMS/Mobile IPTV
CDN/Mobile CDN
Transparent Caching
BSS/OSS
Services
Cable TPS
Voice/Video Quality
IMS
Policy Control/PCRF
IPTV/TPS
LTE
Mobile
Network
Mobile WiMAX
Carrier WiFi
LTE Backaul
Data Center Migration
Carrier Ethernet
FTTH
Wireline
Network
Data Center
Metro Ethernet
MPLS
IP Routing
36