Page 2 - Overview of ISC
1-2 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Overview of ISC The notable ISC network elements are as follows: • ISC Network Management Subnet The ISC Network Management Subnet is required when the service provider’s servic...
Page 3 - ISC Features
1-3 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Overview of ISC It is not required that the set of IPv4 addresses used in any two VPNs be mutually exclusive because the PEs translate IPv4 addresses into IPv4 VPN entities by u...
Page 5 - Resource Pools
1-5 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Overview of ISC Figure 1-3 Access Domain Assigned 2. All the network elements have been discovered during the Autodiscovery process, as well as the network topology (connectivit...
Page 6 - Features and Functions Provided in Provisioning with ISC
1-6 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Overview of ISC • Route Distinguisher (RD) pool : The IP subnets advertised by the CE routers to the PE routers are augmented with a 64-bit prefix called a route distinguisher (...
Page 9 - The Customer’s and Provider’s View of the Network
1-9 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center The Customer’s and Provider’s View of the Network The Customer’s and Provider’s View of the Network From the customer’s point of view, they see their internal routers communicat...
Page 12 - Mapping IPsec Tunnels to MPLS VPNs; Using Templates to Customize Configuration Files
1-12 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Using Templates to Customize Configuration Files Mapping IPsec Tunnels to MPLS VPNs Provisioning network-based IPsec VPNs in order to map IPsec tunnels to MPLS VPNs involves bo...
Page 13 - Uses for the Template Function
1-13 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Using Templates to Customize Configuration Files The template files and data files are in XML format. The template file, its data files, and all template configuration file fil...
Page 14 - About MPLS VPNs
1-14 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center About MPLS VPNs • Audit Existing Services : Checks and evaluates configuration of deployed service to see if the service is still in effect. • Audit Routing Reports : Checks th...
Page 15 - Characteristics of MPLS VPNs; Intranets and Extranets
1-15 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center About MPLS VPNs Characteristics of MPLS VPNs MPLS VPNs have the following characteristics: • Multiprotocol Border Gateway Protocol-Multiprotocol (MP-BGP) extensions are used to...
Page 17 - VRF Implementation Considerations
1-17 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center About MPLS VPNs Figure 1-9 VRFs for Sites in Multiple VPNs VRF Implementation Considerations When implementing VPNs and VRFs, Cisco recommends you keep the following considerat...
Page 18 - Creating a VRF Instance
1-18 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center About MPLS VPNs • The MPLS VPN backbone relies on the appropriate Interior Gateway Protocol (IGP) that is configured for MPLS, for example, EIGRP, or OSPF. When you issue a sho...
Page 19 - Route Target Communities
1-19 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center About MPLS VPNs ISC chooses route target values by default, but you can override the automatically assigned RT values if necessary when you first define a CERC in the ISC softw...
Page 20 - Hub and Spoke Considerations
1-20 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center About MPLS VPNs ISC supports multiple CEs per site and multiple sites connected to the same PE. Each CERC has unique route targets (RT), route distinguisher (RD) and VRF naming...
Page 21 - Security Requirements for MPLS VPNs; Address Space and Routing Separation; Address Space Separation
1-21 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs Security Requirements for MPLS VPNs This section discusses the security requirements for MPLS VPN architectures. This section concentrates o...
Page 22 - Hiding the MPLS Core Structure
1-22 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs Given addressing and routing separation across an MPLS core network, MPLS offers in this respect the same security as comparable Layer 2 VPN...
Page 23 - Resistance to Attacks; Securing the Routing Protocol
1-23 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs Resistance to Attacks It is not possible to directly intrude into other VPNs. However, it is possible to attack the MPLS core, and try to at...
Page 24 - Label Spoofing
1-24 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs In practice, access to the PE router over the CE-PE interface can be limited to the required routing protocol by using access control lists ...
Page 25 - Securing the MPLS Core; Trusted Devices
1-25 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs For security reasons, a PE router should never accept a packet with a label from a CE router. Cisco routers implementation is such that pack...
Page 26 - Separation of CE-PE Links
1-26 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs • PE-P link: use LDP MD5 authentication • P-P This prevents attackers from spoofing a peer router and introducing bogus routing information....
Page 27 - MP-BGP Security Features; Security Through IP Address Resolution
1-27 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs From a security point of view, the merged VPNs behave like one logical VPN, and the security mechanisms described above apply now between th...
Page 28 - Ensuring VPN Isolation
1-28 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs The forwarding table for a PE contains only address entries for members of the same VPN. The PE rejects requests for addresses not listed in...
Page 29 - NBI Benefits; Distributed Load Balancing
1-29 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center Security Requirements for MPLS VPNs • Layer 2 VPN Service • MPLS VPN Service • Inventory • IPsec VPN Service • FireWall Service • NAT Service • SLA • Deployment Flow Engine • D...
Page 31 - The Four-Tier System Architecture
1-31 Cisco IP Solution Center, 3.0: MPLS VPN Management User Guide, 3.0 OL-4344-01 Chapter 1 About Cisco IP Solution Center The Four-Tier System Architecture Figure 1-12 Redundant Load Balancing Configuration The Four-Tier System Architecture The Cisco ISC architecture is a four-tier architecture. T...