
MPLS VPN Security
Michael H. Behringer, Monique Morrow - Collection Networking Security
Résumé
A practical guide to hardening MPLS networks
- Define "zones of trust" for your MPLS VPN environment
- Understand fundamental security principles and how MPLS VPNs work
- Build an MPLS VPN threat model that defines attack points, such as VPN separation, VPN spoofing, DoS against the network's backbone, misconfigurations, sniffing, and inside attack forms
- Identify VPN security requirements, including robustness against attacks, hiding of the core infrastructure, protection against spoofing, and ATM/Frame Relay security comparisons
- Interpret complex architectures such as extranet access with recommendations of Inter-AS, carrier-supporting carriers, Layer 2 security considerations, and multiple provider trust model issues
- Operate and maintain a secure MPLS core with industry best practices
- Integrate IPsec into your MPLS VPN for extra security in encryption and data origin verification
- Build VPNs by interconnecting Layer 2 networks with new available architectures such as virtual private wire service (VPWS) and virtual private LAN service (VPLS)
- Protect your core network from attack by considering Operations, Administration, and Management (OAM) and MPLS backbone security incidents
Multiprotocol Label Switching (MPLS) is becoming a widely deployed technology, specifically for providing virtual private network (VPN) services. Security is a major concern for companies migrating to MPLS VPNs from existing VPN technologies such as ATM. Organizations deploying MPLS VPNs need security best practices for protecting their networks, specifically for the more complex deployment models such as inter-provider networks and Internet provisioning on the network.
MPLS VPN Security is the first book to address the security features of MPLS VPN networks and to show you how to harden and securely operate an MPLS network. Divided into four parts, the book begins with an overview of security and VPN technology. A chapter on threats and attack points provides a foundation for the discussion in later chapters. Part II addresses overall security from various perspectives, including architectural, design, and operation components. Part III provides practical guidelines for implementing MPLS VPN security. Part IV presents real-world case studies that encompass details from all the previous chapters to provide examples of overall secure solutions.
Drawing upon the authors' considerable experience in attack mitigation and infrastructure security, MPLS VPN Security is your practical guide to understanding how to effectively secure communications in an MPLS environment.
"The authors of this book, Michael Behringer and Monique Morrow, have a deep and rich understanding of security issues, such as denial-of-service attack prevention and infrastructure protection from network vulnerabilities. They offer a very practical perspective on the deployment scenarios, thereby demystifying a complex topic. I hope you enjoy their insights into the design of self-defending networks."
Jayshree V. Ullal, Senior VP/GM Security Technology Group, Cisco Systems®
L'auteur - Michael H. Behringer
Michael Behringer is a distinguished engineer at Cisco, where his expertise focuses on MPLS VPN security, service provider security, and denial-of-service (DoS) attack prevention. Prior to joining Cisco Systems, he was responsible for the design and implementation of pan-European networks for a major European Internet service provider.
L'auteur - Monique Morrow
Monique Morrow is a CTO consulting engineer at Cisco Systems, to which she brings more than 20 years' experience in IP internetworking, design, and service development for service providers. Monique led the engineering project team for one of the first European MPLS VPN deployments for a European Internet service provider.
Sommaire
- Part I MPLS VPN and Security Fundamentals
- MPLS VPN Security: An Overview
- A Threat Model for MPLS VPNs
- Part II Advanced MPLS VPN Security Issues
- MPLS Security Analysis
- Secure MPLS VPN Designs
- Security Recommendations
- How IPsec Complements MPLS
- Security of MPLS Layer 2 VPNs
- Secure Operation and Maintenance of an MPLS Core
- Part IV Case Studies and Appendixes
- Case Studies
- Appendix ADetailed Configuration Example for a PE
- Appendix BReference List
Caractéristiques techniques
PAPIER | |
Éditeur(s) | Cisco Press |
Auteur(s) | Michael H. Behringer, Monique Morrow |
Collection | Networking Security |
Parution | 13/07/2005 |
Nb. de pages | 290 |
Format | 18,5 x 23 |
Couverture | Broché |
Poids | 535g |
Intérieur | Noir et Blanc |
EAN13 | 9781587051838 |
Avantages Eyrolles.com
Consultez aussi
- Les meilleures ventes en Graphisme & Photo
- Les meilleures ventes en Informatique
- Les meilleures ventes en Construction
- Les meilleures ventes en Entreprise & Droit
- Les meilleures ventes en Sciences
- Les meilleures ventes en Littérature
- Les meilleures ventes en Arts & Loisirs
- Les meilleures ventes en Vie pratique
- Les meilleures ventes en Voyage et Tourisme
- Les meilleures ventes en BD et Jeunesse
- Informatique Informatique d'entreprise Sécurité
- Informatique Réseaux et télecommunications Ouvrages généraux
- Informatique Réseaux et télecommunications Protocoles et standards
- Informatique Réseaux et télecommunications Protocoles et standards L2TP
- Informatique Réseaux et télecommunications Protocoles et standards MPLS
- Informatique Réseaux et télecommunications Administration réseau
- Informatique Réseaux et télecommunications Réseaux privés virtuels
- Informatique Réseaux et télecommunications Sécurité réseau
- Informatique Réseaux et télecommunications Sécurité réseau Protocoles et standards MPLS
- Informatique Réseaux et télecommunications Sécurité réseau Sécurité internet
- Informatique Réseaux et télecommunications Equipements réseaux Routeurs Routeurs et commutateurs