SlideShare a Scribd company logo
1 of 8
Nera
Managed IP
Transparent IP Service Over
Inmarsat Mobile Packet Data System (MPDS)
Peter Coffman VP NAM / Oddvieg Tretterud Senior Engineer M2M Solutions
Managed IP Service
 Managed, reliable IP based
satellite service
 Secure VPN between Enterprise
and Inmarsat network access
point
 Global coverage through one
interface
 Includes “always on” capability
for on-demand polling
 Allows for use of private, static
IP addresses
 Well suited for
 Customers who already have
an application, but need Wide
Area Wireless coverage
 Fixed, long term installations
L2TPL2TP SBSHLES
Inmarsat MPDS NetworkEnterprise
Workstation
Workstation
Workstation
IPSec
Firewall
Server
M2M Gateway
VPN MiniPC
MPDS
modem
AT cmd
IP
Remote SiteRouter
Router
IP service
Nera Support
Nera Offering
 Network services with airtime
 Inmarsat Mobile Packet Data (MPDS)
 Real time IP based data service
 Support
 Satellite packet data terminal
 Tailor made for data use
 ATEX approved for use in hazardous environments
 MiniPC
 Controls satellite terminal and maintains the communication link
 Allows for embedded applications
 “Always on” capability provided through a hosted gateway and tailor
made connection software on the client side
 24/7 monitoring of
 The VPN connection
 Data sessions with remote sites
 VPN server can be provided as an option
Managed IP - Value Add
 Allows for closer monitoring and follow up of each remote client
 M2M Gateway maintains tunnels with several Inmarsat Home Land Earth Stations (HLES)
 Provides a secure VPN connection from the Enterprise into the MPDS network over the Internet
 Provides one physical point of access
 Only one single VPN from Enterprise to Gateway is required to reach any site globally
 Remote sites can use multiple Inmarsat stations for redundancy through one Enterprise VPN
 Enables Enterprise users to poll, to request data or to initiate data transfers to the
remote clients any time
 Allows use of static, private IP addresses
 One IP address uniquely identifies the remote user
 Corporate side can route outbound traffic based on IP address without need for additional mapping
arrangements
 “Always on” data connection support is made possible through
 Administering and handling of own IP addresses
 Client Connection software
 Remote client optimized recovery software to prevent need for human attention or
intervention
 Managed service reduces complexity and need for customer involvement
 Wide Area Wireless communication is operated by network experts
 Customers can focus on core business
Gateway functions
 Maintain and monitor
secure tunnels with
 Inmarsat HLES’s
 Enterprises
 Authorize end users
 Administer, manage and
assign IP addresses to
clients
 Maintain data connections
 Routes data
 Generate statistics
 One customer interface to
multiple HLES’s
LNS
Radius
Wireless Matrix
M2M Gateway
RT
Server
VPN
SBS
HLES
1
Secure
Internet
LAC
Inmarsat Service Provider SBS
HLES
1
Secure
Internet LAC
SBS
HLES
1
Secure
Internet LAC
Inmarsat Service Provider
HLES 1
HLES 2
HLES 3
MPDS
modem
IP Mini
PC
Remote Site
MPDS
modem
IP Mini
PC
Remote Site
MPDS
modem
IP Mini
PC
Remote Site
Remote Side
 MiniPC
 Supports embedded
applications
 Low power consumption
 Small form factor
 Software for
 Automatic set up
 Monitoring of connection
 Mechanism to recover from
error situations without human
intervention
 Satellite terminals supported
 NWC Data
 F55
MiniPC Nera World Communicator Data
L2TP tunnel
L2TP tunnel
Ethernet
Cisco
Router
Customer Host
PC
PC
IP address 2IP address 1
Private IP range
Subnet
E.g. 10.142.X.X
Transparent IP Option 1: Router behind firewall
Customer Host
Transparent IP Option 2: No firewall
Gateway
Firewall
MPDS
modem
MiniPC
Remote Side
IP address assigned,
E.g. 10.142.2.19Ethernet
Cisco
Router
Customer Host
PC
PC
IP address 1
Private IP range
Subnet
E.g. 10.142.X.X
GatewayIPSec tunnel
MPDS
modem
MiniPC
Remote Side
IP address assigned,
E.g. 10.142.2.19
Address 1 and 2 must be
within the same subnet
Information needed from customer:
1) NWC Data satellite terminal’s forward ID
2) Public IP address (1) for router
3) Public IP address (2) for firewall (Option
1 only)
4) IP subnet used
5) IPSec preshared key
6) IPSec encryption method
a) DES-56
*)
b) 3DES-168
7) IPSec IKE proposal for Phase 1
a) 3DES with SHA1,
Diffie-Hellman group 2 (1024 bits)
b) 3DES with MD5,
Diffie-Hellman group 2 (1024 bits)
c) DES with SHA1,
Diffie-Hellman group 2 (1024 bits)
d) DES with SHA1,
Diffie-Hellman group 1 (768 bits) *)
e) DES with MD5
Diffie-Hellman group 1 (768 bits)
*)
*)
Recommended
IPSec tunnel
Inmarsat
HLES
Inmarsat
HLES
Architecture
Parameter Registration
 Input needed from customer
 MPDS modem’s Forward ID
 Destination IP address (server
to communicate with)
 IP address of VPN server
 IP address of firewall (when
applicable)
 Subnet used
 IPSec pre-shared key
 IPSec encryption method
 IPSec IKE
 Nera assigns
 Client’s IP address

More Related Content

What's hot

IoT Communication protocols Overview
IoT Communication protocols OverviewIoT Communication protocols Overview
IoT Communication protocols OverviewGuy Vinograd ☁
 
VPN (virtual Private Network)
VPN (virtual Private Network)VPN (virtual Private Network)
VPN (virtual Private Network)Chandan Jha
 
Ch7 ccna exploration 3 lan switching and wireless
Ch7 ccna exploration 3 lan switching and wirelessCh7 ccna exploration 3 lan switching and wireless
Ch7 ccna exploration 3 lan switching and wirelesskratos2424
 
IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...
IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...
IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...Mikael Falkvidd
 
Wireless Security null seminar
Wireless Security null seminarWireless Security null seminar
Wireless Security null seminarNilesh Sapariya
 
Frost & Sullivan Global Mobile VPN Products Market
Frost & Sullivan Global Mobile VPN Products MarketFrost & Sullivan Global Mobile VPN Products Market
Frost & Sullivan Global Mobile VPN Products MarketNetMotion Wireless
 
Virtual private network feature and benefits
Virtual private network feature and benefitsVirtual private network feature and benefits
Virtual private network feature and benefitsAnthony Daniel
 
4G LTE Security - What hackers know?
4G LTE Security - What hackers know?4G LTE Security - What hackers know?
4G LTE Security - What hackers know?Stephen Kho
 
Motorola Wing 5.6 specification sheet
Motorola  Wing 5.6 specification sheetMotorola  Wing 5.6 specification sheet
Motorola Wing 5.6 specification sheetAdvantec Distribution
 
Wireless Networking Security
Wireless Networking SecurityWireless Networking Security
Wireless Networking SecurityAnshuman Biswal
 
Wireless intelligent network
Wireless intelligent networkWireless intelligent network
Wireless intelligent networksuryakant singh
 

What's hot (20)

IoT Communication protocols Overview
IoT Communication protocols OverviewIoT Communication protocols Overview
IoT Communication protocols Overview
 
VPN presentation - moeshesh
VPN presentation - moesheshVPN presentation - moeshesh
VPN presentation - moeshesh
 
VPN (virtual Private Network)
VPN (virtual Private Network)VPN (virtual Private Network)
VPN (virtual Private Network)
 
Vpn rsvp
Vpn rsvpVpn rsvp
Vpn rsvp
 
Kira128i
Kira128iKira128i
Kira128i
 
Securing wireless network
Securing wireless networkSecuring wireless network
Securing wireless network
 
IoT setup and pairing
IoT setup and pairingIoT setup and pairing
IoT setup and pairing
 
Ch7 ccna exploration 3 lan switching and wireless
Ch7 ccna exploration 3 lan switching and wirelessCh7 ccna exploration 3 lan switching and wireless
Ch7 ccna exploration 3 lan switching and wireless
 
IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...
IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...
IoT LPWAN network security: Sigfox and LoRaWAN (Mikael Falkvidd @ Knowit secu...
 
Wireless Security null seminar
Wireless Security null seminarWireless Security null seminar
Wireless Security null seminar
 
Vpn
VpnVpn
Vpn
 
Frost & Sullivan Global Mobile VPN Products Market
Frost & Sullivan Global Mobile VPN Products MarketFrost & Sullivan Global Mobile VPN Products Market
Frost & Sullivan Global Mobile VPN Products Market
 
Virtual private network feature and benefits
Virtual private network feature and benefitsVirtual private network feature and benefits
Virtual private network feature and benefits
 
4G LTE Security - What hackers know?
4G LTE Security - What hackers know?4G LTE Security - What hackers know?
4G LTE Security - What hackers know?
 
Virtual Private Network VPN
Virtual Private Network VPNVirtual Private Network VPN
Virtual Private Network VPN
 
Tap Into the Health of Your Network
Tap Into the Health of Your NetworkTap Into the Health of Your Network
Tap Into the Health of Your Network
 
Motorola Wing 5.6 specification sheet
Motorola  Wing 5.6 specification sheetMotorola  Wing 5.6 specification sheet
Motorola Wing 5.6 specification sheet
 
Wireless Networking Security
Wireless Networking SecurityWireless Networking Security
Wireless Networking Security
 
firewall
firewallfirewall
firewall
 
Wireless intelligent network
Wireless intelligent networkWireless intelligent network
Wireless intelligent network
 

Similar to Managed IP solution

PriveComms PriveIN mesh digital operation field overview 2020
PriveComms PriveIN mesh digital operation field overview 2020PriveComms PriveIN mesh digital operation field overview 2020
PriveComms PriveIN mesh digital operation field overview 2020Arimo Koivisto
 
12 Understanding V P Ns
12  Understanding  V P Ns12  Understanding  V P Ns
12 Understanding V P NsAamirAziz
 
MTX M2M brochure-2017
MTX M2M brochure-2017MTX M2M brochure-2017
MTX M2M brochure-2017Jesus Santos
 
Firetide Wireless Mesh Nodes for Transportation
Firetide Wireless Mesh Nodes for TransportationFiretide Wireless Mesh Nodes for Transportation
Firetide Wireless Mesh Nodes for TransportationPaul Richards
 
Acit Mumbai - understanding vpns
Acit Mumbai - understanding vpnsAcit Mumbai - understanding vpns
Acit Mumbai - understanding vpnsSleek International
 
Virtual Private Networks
Virtual Private NetworksVirtual Private Networks
Virtual Private NetworksDivam Goyal
 
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALAVIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALASaikiran Panjala
 
Alvarion Wi Mesh Wi2 Presentation
Alvarion Wi Mesh    Wi2 PresentationAlvarion Wi Mesh    Wi2 Presentation
Alvarion Wi Mesh Wi2 PresentationMonark Goel
 
Virtual Private Network (VPN).
Virtual Private Network (VPN).Virtual Private Network (VPN).
Virtual Private Network (VPN).Debasis Chowdhury
 
VirtualPrivateNetwork.ppt
VirtualPrivateNetwork.pptVirtualPrivateNetwork.ppt
VirtualPrivateNetwork.ppttahaniali27
 
About vpn network .ppt
About vpn network .pptAbout vpn network .ppt
About vpn network .pptshanbelayayu
 
Virtual Private Network Presentation.ppt
Virtual Private Network Presentation.pptVirtual Private Network Presentation.ppt
Virtual Private Network Presentation.pptmocec17097
 
A Comprehensive Guide to Acquire Information on 4G Router
A Comprehensive Guide to Acquire Information on 4G RouterA Comprehensive Guide to Acquire Information on 4G Router
A Comprehensive Guide to Acquire Information on 4G RouterE-Lins Technology Co. Ltd.
 
Wireless Metropolitan Area Networks
Wireless Metropolitan Area NetworksWireless Metropolitan Area Networks
Wireless Metropolitan Area NetworksDilum Bandara
 

Similar to Managed IP solution (20)

PriveComms PriveIN mesh digital operation field overview 2020
PriveComms PriveIN mesh digital operation field overview 2020PriveComms PriveIN mesh digital operation field overview 2020
PriveComms PriveIN mesh digital operation field overview 2020
 
Accessing remote networks
Accessing remote networksAccessing remote networks
Accessing remote networks
 
V P N
V P NV P N
V P N
 
12 Understanding V P Ns
12  Understanding  V P Ns12  Understanding  V P Ns
12 Understanding V P Ns
 
MTX M2M brochure-2017
MTX M2M brochure-2017MTX M2M brochure-2017
MTX M2M brochure-2017
 
Firetide Wireless Mesh Nodes for Transportation
Firetide Wireless Mesh Nodes for TransportationFiretide Wireless Mesh Nodes for Transportation
Firetide Wireless Mesh Nodes for Transportation
 
Acit Mumbai - understanding vpns
Acit Mumbai - understanding vpnsAcit Mumbai - understanding vpns
Acit Mumbai - understanding vpns
 
Virtual Private Networks
Virtual Private NetworksVirtual Private Networks
Virtual Private Networks
 
VPN_ppt.ppt
VPN_ppt.pptVPN_ppt.ppt
VPN_ppt.ppt
 
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALAVIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
 
Vpnppt1884
Vpnppt1884Vpnppt1884
Vpnppt1884
 
Alvarion Wi Mesh Wi2 Presentation
Alvarion Wi Mesh    Wi2 PresentationAlvarion Wi Mesh    Wi2 Presentation
Alvarion Wi Mesh Wi2 Presentation
 
Virtual Private Network (VPN).
Virtual Private Network (VPN).Virtual Private Network (VPN).
Virtual Private Network (VPN).
 
VirtualPrivateNetwork.ppt
VirtualPrivateNetwork.pptVirtualPrivateNetwork.ppt
VirtualPrivateNetwork.ppt
 
About vpn network .ppt
About vpn network .pptAbout vpn network .ppt
About vpn network .ppt
 
VPN mean .ppt
VPN mean .pptVPN mean .ppt
VPN mean .ppt
 
Virtual Private Network Presentation.ppt
Virtual Private Network Presentation.pptVirtual Private Network Presentation.ppt
Virtual Private Network Presentation.ppt
 
Vpn_NJ ppt
Vpn_NJ pptVpn_NJ ppt
Vpn_NJ ppt
 
A Comprehensive Guide to Acquire Information on 4G Router
A Comprehensive Guide to Acquire Information on 4G RouterA Comprehensive Guide to Acquire Information on 4G Router
A Comprehensive Guide to Acquire Information on 4G Router
 
Wireless Metropolitan Area Networks
Wireless Metropolitan Area NetworksWireless Metropolitan Area Networks
Wireless Metropolitan Area Networks
 

Managed IP solution

  • 1. Nera Managed IP Transparent IP Service Over Inmarsat Mobile Packet Data System (MPDS) Peter Coffman VP NAM / Oddvieg Tretterud Senior Engineer M2M Solutions
  • 2. Managed IP Service  Managed, reliable IP based satellite service  Secure VPN between Enterprise and Inmarsat network access point  Global coverage through one interface  Includes “always on” capability for on-demand polling  Allows for use of private, static IP addresses  Well suited for  Customers who already have an application, but need Wide Area Wireless coverage  Fixed, long term installations L2TPL2TP SBSHLES Inmarsat MPDS NetworkEnterprise Workstation Workstation Workstation IPSec Firewall Server M2M Gateway VPN MiniPC MPDS modem AT cmd IP Remote SiteRouter Router IP service Nera Support
  • 3. Nera Offering  Network services with airtime  Inmarsat Mobile Packet Data (MPDS)  Real time IP based data service  Support  Satellite packet data terminal  Tailor made for data use  ATEX approved for use in hazardous environments  MiniPC  Controls satellite terminal and maintains the communication link  Allows for embedded applications  “Always on” capability provided through a hosted gateway and tailor made connection software on the client side  24/7 monitoring of  The VPN connection  Data sessions with remote sites  VPN server can be provided as an option
  • 4. Managed IP - Value Add  Allows for closer monitoring and follow up of each remote client  M2M Gateway maintains tunnels with several Inmarsat Home Land Earth Stations (HLES)  Provides a secure VPN connection from the Enterprise into the MPDS network over the Internet  Provides one physical point of access  Only one single VPN from Enterprise to Gateway is required to reach any site globally  Remote sites can use multiple Inmarsat stations for redundancy through one Enterprise VPN  Enables Enterprise users to poll, to request data or to initiate data transfers to the remote clients any time  Allows use of static, private IP addresses  One IP address uniquely identifies the remote user  Corporate side can route outbound traffic based on IP address without need for additional mapping arrangements  “Always on” data connection support is made possible through  Administering and handling of own IP addresses  Client Connection software  Remote client optimized recovery software to prevent need for human attention or intervention  Managed service reduces complexity and need for customer involvement  Wide Area Wireless communication is operated by network experts  Customers can focus on core business
  • 5. Gateway functions  Maintain and monitor secure tunnels with  Inmarsat HLES’s  Enterprises  Authorize end users  Administer, manage and assign IP addresses to clients  Maintain data connections  Routes data  Generate statistics  One customer interface to multiple HLES’s LNS Radius Wireless Matrix M2M Gateway RT Server VPN SBS HLES 1 Secure Internet LAC Inmarsat Service Provider SBS HLES 1 Secure Internet LAC SBS HLES 1 Secure Internet LAC Inmarsat Service Provider HLES 1 HLES 2 HLES 3 MPDS modem IP Mini PC Remote Site MPDS modem IP Mini PC Remote Site MPDS modem IP Mini PC Remote Site
  • 6. Remote Side  MiniPC  Supports embedded applications  Low power consumption  Small form factor  Software for  Automatic set up  Monitoring of connection  Mechanism to recover from error situations without human intervention  Satellite terminals supported  NWC Data  F55 MiniPC Nera World Communicator Data
  • 7. L2TP tunnel L2TP tunnel Ethernet Cisco Router Customer Host PC PC IP address 2IP address 1 Private IP range Subnet E.g. 10.142.X.X Transparent IP Option 1: Router behind firewall Customer Host Transparent IP Option 2: No firewall Gateway Firewall MPDS modem MiniPC Remote Side IP address assigned, E.g. 10.142.2.19Ethernet Cisco Router Customer Host PC PC IP address 1 Private IP range Subnet E.g. 10.142.X.X GatewayIPSec tunnel MPDS modem MiniPC Remote Side IP address assigned, E.g. 10.142.2.19 Address 1 and 2 must be within the same subnet Information needed from customer: 1) NWC Data satellite terminal’s forward ID 2) Public IP address (1) for router 3) Public IP address (2) for firewall (Option 1 only) 4) IP subnet used 5) IPSec preshared key 6) IPSec encryption method a) DES-56 *) b) 3DES-168 7) IPSec IKE proposal for Phase 1 a) 3DES with SHA1, Diffie-Hellman group 2 (1024 bits) b) 3DES with MD5, Diffie-Hellman group 2 (1024 bits) c) DES with SHA1, Diffie-Hellman group 2 (1024 bits) d) DES with SHA1, Diffie-Hellman group 1 (768 bits) *) e) DES with MD5 Diffie-Hellman group 1 (768 bits) *) *) Recommended IPSec tunnel Inmarsat HLES Inmarsat HLES Architecture
  • 8. Parameter Registration  Input needed from customer  MPDS modem’s Forward ID  Destination IP address (server to communicate with)  IP address of VPN server  IP address of firewall (when applicable)  Subnet used  IPSec pre-shared key  IPSec encryption method  IPSec IKE  Nera assigns  Client’s IP address