SlideShare una empresa de Scribd logo
1 de 3
Descargar para leer sin conexión
Fig.1
                                               NIB – II
                           Srinagar          TOPOLOGY

                                                          Shimla
                          Chandigarh

                                                                   IGW
                                                      Delhi


                                             Noida                   Noida



                              Jaipur
                                                                                                           Guwahati
                                                                   Lucknow

                                                                                              Patna
Gandhinagar / Ahmedabad
                                         Bhopal


             Mumbai                                                                                       Kolkata
              BRAS
                                          Chattisgarh                                                      IGW
  IGW
                                                                                                      Kolkata

  Mumbai



                                                          H-bad
     IGW          Pune                                    BRAS
                                                                                           Bhubaneshwar
                                                                      IGW


            Goa



                              Bangalore
                                                                         Chennai
                                                     Bangalore
                                                                          IGW
                                                                     Chennai
                                              IGW

                                                                             Pondicherry
                                                                      Back Office facilities – Web hosting,
                                                                      Customer servers, Messaging, Caching,
                             Ernakulam                                Billing, etc.
           IGW                                                        CORE Router
                                                                         EDGE Router
                                                                         BRAS

                                                                           STM16
                          Thiruvanthapuram
                                                                           STM1
Fig. 2
                                                     NIB – II
                                                  ARCHITECTURE
             DIAL – UP
           CONNECTIONS                     TO OTHER CORE ROUTERS




                                                                                             NATIONAL INTERNET
                                                                                                  EXCHANGE
                                                                                                 TO CONNECT
           PSTN NETWORK                                                                     ALL ISPs AND PROVIDE
                                                                                                   COMMON
                                                                                               INTERNATIONAL
                                                                                                   GATEWAY
                                                       CORE ROUTER
           RAS

DIAL – UP                                                                                         EDGE ROUTERS          NIEX
SERVICE EDGE ROUTERS                                                                                                EDGE ROUTER
  EDGE
ROUTER                                                       TIER I


                 BRAS                      BRAS                       BRAS                                     BRAS



                 EDGE ROUTERS              EDGE ROUTERS                    EDGE ROUTERS              EDGE ROUTERS




                                                                                                                        MPLS VPN
                                                                                                     EDGE ROUTERS
 TIER II        TIER II       TIER II   TIER II        TIER II         TIER II                                        EDGE ROUTER



      TIER II           TIER II              TIER II             TIER II

                                                                                       DSLAMs




                                        DSLAMs

                                                                                  Leased Lines from VPN Subscriber Premises
Explanatory Motes on VPN Vulnerability

Slide 1 shows the topology of a typical ISP’s IP network over which
    both Internet and VPN services are laid out. This is the topology of
    BSNL’s NIB – ii. Five cities are connected in a full mesh
    connectivity to form the core IP back-bone across India. Other
    cities are connected through tri-node rings from the nodes of the
    core network through the Tier-1 switch at these nodes.

Slide 2 shows the architecture of each of these nodes. The core router
    at the node sits on the Tier 1 switch. From these switches are
    taken the router connections for all the services – VPN, Internet
    through Broadband and PSTN. Thus you will note that there is
    continuous physical connectivity between all the routers in this IP
    network through the Tier 1 switch at each IP Node (POP). Thus
    there is continuous public domain access to the VPN routers.

1.   In any IP network, public or private, the WAN ports of all routers in
     the network have continuous physical access to each other. Thus
     while a router port is engaged in communication with another in the
     network, a third port can have simultaneous communications with
     it. If the IP network is in the public domain (Internet) or has access
     from the public domain (VPN), this third port could be that of a
     hacker.
2.   Thus while the various security protocols like IP Sec, etc., can
     transport the data from one computer to another securely, the LAN
     and the data bases residing on it are exposed to public domain
     through a VPN which has public domain access for reasons
     explained in 1 above.
3.   For WAN computing it is necessary to have a real private network
     (at least for data communications). Once this is there then inter-
     locational voice / fax can be run over this network at marginal
     increase in the operating cost, using the patented PVDTN
     system.
4.   You should not expose your company data bases to the public
     domain through Internet, ISDN back-up, or VPN (which has public
     domain access) for reasons explained earlier in 1 above.
5.   The MPLS networks currently in vogue are another form of VPN
     network and are subject to the comments in 1 to 4 above.

We do hope the above notes will explain the security vulnerability of
     your data bases when these are on LANs connected to VPN
     (MPLS or other wise) of any service provider.
If you wish to secure your data bases 100% then use point-to-
     point leased lines for inter-locational computer connectivity.

Más contenido relacionado

Más de MIDAS Automation & Telecommunications Pvt. Ltd. (MIDAUTEL) (11)

Pvdtn
PvdtnPvdtn
Pvdtn
 
Smsdg layout & functioning
Smsdg layout & functioningSmsdg layout & functioning
Smsdg layout & functioning
 
Nwan
NwanNwan
Nwan
 
Llbu
LlbuLlbu
Llbu
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Vo p pstn
Vo p   pstnVo p   pstn
Vo p pstn
 
Mobile
MobileMobile
Mobile
 
Telephony
TelephonyTelephony
Telephony
 
Mpls p2 p
Mpls   p2 pMpls   p2 p
Mpls p2 p
 
Pvdtn fa qs
Pvdtn fa qsPvdtn fa qs
Pvdtn fa qs
 
Pvdtn presentation
Pvdtn presentationPvdtn presentation
Pvdtn presentation
 

Último

mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docxPoojaSen20
 
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991RKavithamani
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppCeline George
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesFatimaKhan178732
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxSayali Powar
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationnomboosow
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxpboyjonauth
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...RKavithamani
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfJayanti Pande
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
Arihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfArihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfchloefrazer622
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdfQucHHunhnh
 

Último (20)

mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docx
 
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
Industrial Policy - 1948, 1956, 1973, 1977, 1980, 1991
 
URLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website AppURLs and Routing in the Odoo 17 Website App
URLs and Routing in the Odoo 17 Website App
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and Actinides
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communication
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptx
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
Staff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSDStaff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSD
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Arihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfArihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdf
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 

Vpn1

  • 1. Fig.1 NIB – II Srinagar TOPOLOGY Shimla Chandigarh IGW Delhi Noida Noida Jaipur Guwahati Lucknow Patna Gandhinagar / Ahmedabad Bhopal Mumbai Kolkata BRAS Chattisgarh IGW IGW Kolkata Mumbai H-bad IGW Pune BRAS Bhubaneshwar IGW Goa Bangalore Chennai Bangalore IGW Chennai IGW Pondicherry Back Office facilities – Web hosting, Customer servers, Messaging, Caching, Ernakulam Billing, etc. IGW CORE Router EDGE Router BRAS STM16 Thiruvanthapuram STM1
  • 2. Fig. 2 NIB – II ARCHITECTURE DIAL – UP CONNECTIONS TO OTHER CORE ROUTERS NATIONAL INTERNET EXCHANGE TO CONNECT PSTN NETWORK ALL ISPs AND PROVIDE COMMON INTERNATIONAL GATEWAY CORE ROUTER RAS DIAL – UP EDGE ROUTERS NIEX SERVICE EDGE ROUTERS EDGE ROUTER EDGE ROUTER TIER I BRAS BRAS BRAS BRAS EDGE ROUTERS EDGE ROUTERS EDGE ROUTERS EDGE ROUTERS MPLS VPN EDGE ROUTERS TIER II TIER II TIER II TIER II TIER II TIER II EDGE ROUTER TIER II TIER II TIER II TIER II DSLAMs DSLAMs Leased Lines from VPN Subscriber Premises
  • 3. Explanatory Motes on VPN Vulnerability Slide 1 shows the topology of a typical ISP’s IP network over which both Internet and VPN services are laid out. This is the topology of BSNL’s NIB – ii. Five cities are connected in a full mesh connectivity to form the core IP back-bone across India. Other cities are connected through tri-node rings from the nodes of the core network through the Tier-1 switch at these nodes. Slide 2 shows the architecture of each of these nodes. The core router at the node sits on the Tier 1 switch. From these switches are taken the router connections for all the services – VPN, Internet through Broadband and PSTN. Thus you will note that there is continuous physical connectivity between all the routers in this IP network through the Tier 1 switch at each IP Node (POP). Thus there is continuous public domain access to the VPN routers. 1. In any IP network, public or private, the WAN ports of all routers in the network have continuous physical access to each other. Thus while a router port is engaged in communication with another in the network, a third port can have simultaneous communications with it. If the IP network is in the public domain (Internet) or has access from the public domain (VPN), this third port could be that of a hacker. 2. Thus while the various security protocols like IP Sec, etc., can transport the data from one computer to another securely, the LAN and the data bases residing on it are exposed to public domain through a VPN which has public domain access for reasons explained in 1 above. 3. For WAN computing it is necessary to have a real private network (at least for data communications). Once this is there then inter- locational voice / fax can be run over this network at marginal increase in the operating cost, using the patented PVDTN system. 4. You should not expose your company data bases to the public domain through Internet, ISDN back-up, or VPN (which has public domain access) for reasons explained earlier in 1 above. 5. The MPLS networks currently in vogue are another form of VPN network and are subject to the comments in 1 to 4 above. We do hope the above notes will explain the security vulnerability of your data bases when these are on LANs connected to VPN (MPLS or other wise) of any service provider. If you wish to secure your data bases 100% then use point-to- point leased lines for inter-locational computer connectivity.