100 likes | 207 Views
Network Firewall Configuration and Control Concerns. Brent Hirschman (brent.hirschman@sprint.com). Major Concerns for Security. Greatest concern for security is impact on RF Resources Handset viruses becoming significant concern Intrusion Detection system needs to be included
E N D
Network Firewall Configuration and Control Concerns Brent Hirschman (brent.hirschman@sprint.com)
Major Concerns for Security • Greatest concern for security is impact on RF Resources • Handset viruses becoming significant concern • Intrusion Detection system needs to be included • Need to “Shut Down” Rogues Security Architecture Concerns • Parallel architectures for QoS, Security, AAA • Introduction of new Protocols • Intrusion Detection System Impact
User Profile DB Architecture Concerns Basic NFCC Architecture NNI Session Mgr NLSP or PFCP Profile Mgr Ntwk Pres. Agent Traffic Filters IP Ntwk RAN
Intrusion Detection System Intrusion Detection and Prevention Systems NNI RAD or DIA VAAA HAAA HA IP Ntwk Access Router PDSN RAN IP Ntwk Intrusion Detection and Prevention System
User Profile DB Intrusion Detection System Architecture Concerns Additional Capability of Intrusion Detection NNI Change Filters and tell PM of change and cause. Session Mgr NLSP or PFCP Profile Mgr Ntwk Pres. Agent Traffic Filters IP Ntwk RAN
VAAA HAAA User Profile DB HA IP Ntwk Access Router PDSN RAN Architecture Concerns - Basic AAA Picture NNI RAD or DIA
User Profile DB Architecture Concerns Basic NFCC Architecture NNI Session Mgr NLSP or PFCP Profile Mgr Ntwk Pres. Agent Traffic Filters IP Ntwk RAN
User Profile DB Architecture Concerns Basic QoS Architecture NNI Visited PDP COPS-PR Home PDP PEP PEP IP Ntwk RAN
User Profile DB Architecture Concerns Overlay Architecture – Why so many protocols? NNI RAD/DIA NSLP/PFCP COPS-PR AAA/SM/ PDP AAA/PM/ PDP HA/NPA/ PEP PDSN/TF/ PEP IP Ntwk RAN
Protocol Changes needed • RADIUS/DIAMETER – Need Peering and negotiation – only DIAMETER • COPS-PR – Need Visited and Home PDP – needed in world of Remote HAs. • NSLP/PFCP – Need for new protocol? Can we put it in another protocol? • Can we design a single protocol to do all this?