100 likes | 214 Vues
This document outlines critical concerns regarding network firewall configuration and security control, highlighting the significant impacts on RF resources and the growing threat of handset viruses. It emphasizes the necessity for robust intrusion detection systems, the importance of addressing rogue devices, and the complexities introduced by new protocols. The architecture challenges related to user profile databases and quality of service (QoS) are discussed, alongside the requirement for enhanced filtering mechanisms. A cohesive strategy for managing these technologies and protocols is essential for ensuring secure network operations.
E N D
Network Firewall Configuration and Control Concerns Brent Hirschman (brent.hirschman@sprint.com)
Major Concerns for Security • Greatest concern for security is impact on RF Resources • Handset viruses becoming significant concern • Intrusion Detection system needs to be included • Need to “Shut Down” Rogues Security Architecture Concerns • Parallel architectures for QoS, Security, AAA • Introduction of new Protocols • Intrusion Detection System Impact
User Profile DB Architecture Concerns Basic NFCC Architecture NNI Session Mgr NLSP or PFCP Profile Mgr Ntwk Pres. Agent Traffic Filters IP Ntwk RAN
Intrusion Detection System Intrusion Detection and Prevention Systems NNI RAD or DIA VAAA HAAA HA IP Ntwk Access Router PDSN RAN IP Ntwk Intrusion Detection and Prevention System
User Profile DB Intrusion Detection System Architecture Concerns Additional Capability of Intrusion Detection NNI Change Filters and tell PM of change and cause. Session Mgr NLSP or PFCP Profile Mgr Ntwk Pres. Agent Traffic Filters IP Ntwk RAN
VAAA HAAA User Profile DB HA IP Ntwk Access Router PDSN RAN Architecture Concerns - Basic AAA Picture NNI RAD or DIA
User Profile DB Architecture Concerns Basic NFCC Architecture NNI Session Mgr NLSP or PFCP Profile Mgr Ntwk Pres. Agent Traffic Filters IP Ntwk RAN
User Profile DB Architecture Concerns Basic QoS Architecture NNI Visited PDP COPS-PR Home PDP PEP PEP IP Ntwk RAN
User Profile DB Architecture Concerns Overlay Architecture – Why so many protocols? NNI RAD/DIA NSLP/PFCP COPS-PR AAA/SM/ PDP AAA/PM/ PDP HA/NPA/ PEP PDSN/TF/ PEP IP Ntwk RAN
Protocol Changes needed • RADIUS/DIAMETER – Need Peering and negotiation – only DIAMETER • COPS-PR – Need Visited and Home PDP – needed in world of Remote HAs. • NSLP/PFCP – Need for new protocol? Can we put it in another protocol? • Can we design a single protocol to do all this?