| MPLS VPN Security addresses the security features of MPLS VPN networks & shows how to harden & securely operate an MPLS network. The book begins with an overview of security and VPN technology. A chapter on threats & attack points provides a foundation for the discussion in later chapters. Part II addresses overall security from various perspectives, including architectural, design, and operation components. Part III provides guidelines for implementing MPLS VPN security. Part IV presents case studies that encompass details from the previous chapters to provide examples of overall secure solutions. Topics include:
- Define "zones of trust" for your MPLS VPN environment;
- Understand fundamental security principles & how MPLS VPNs work;
- Build an MPLS VPN threat model that defines attack points, such as VPN separation, VPN spoofing, DoS against the network's backbone, misconfigurations, sniffing, and inside attack forms; Identify VPN security requirements, including robustness against attacks, hiding of the core infrastructure, protection against spoofing, and ATM/Frame Relay security comparisons; Interpret complex architectures such as extranet access with recommendations of Inter-AS, carrier-supporting carriers, Layer 2 security considerations, and multiple provider trust model issues; Operate & maintain a secure MPLS core with industry best practices; Integrate IPsec into your MPLS VPN for extra security in encryption & data origin verification;
- Build VPNs by interconnecting Layer 2 networks with new available architectures such as virtual private wire service (VPWS) & virtual private LAN service (VPLS);
- Protect your core network from attack by considering Operations, Administration, & Management (OAM) and MPLS backbone security incidents. | |