SlideShare a Scribd company logo
1 of 3
Download to read offline
NIB – II
TOPOLOGY
Kolkata
Guwahati
Lucknow
Chattisgarh
Bhopal
Jaipur
Gandhinagar / Ahmedabad
Chandigarh
Shimla
Srinagar
Kolkata
Delhi
IGW
IGW
IGW
Mumbai
BRAS
NoidaNoida
Patna
Fig.1
PuneIGW
IGW
IGW
IGW
IGW
H-bad
BRAS
Pondicherry
Chennai
Thiruvanthapuram
Ernakulam
Mumbai
Chennai
Bangalore
Bangalore
CORE Router
BRAS
STM16
STM1
EDGE Router
Goa
Bhubaneshwar
Back Office facilities – Web hosting,
Customer servers, Messaging, Caching,
Billing, etc.
NIB – II
ARCHITECTURE
CORE ROUTER
TIER I
EDGE ROUTERS EDGE ROUTERS
EDGE ROUTERS
EDGE ROUTERS
BRAS BRAS BRAS BRAS
EDGE ROUTERS
NATIONAL INTERNET
EXCHANGE
TO CONNECT
ALL ISPs AND PROVIDE
COMMON
INTERNATIONAL
GATEWAY
NIEX
EDGE ROUTER
Fig. 2
EDGE ROUTERS
RAS
PSTN NETWORK
TO OTHER CORE ROUTERS
DIAL – UP
CONNECTIONS
DIAL – UP
SERVICE
EDGE
ROUTER
TIER II TIER II
TIER II TIER II
TIER IITIER II TIER II
TIER II TIER II
TIER II
DSLAMs
DSLAMs
Leased Lines from VPN Subscriber Premises
MPLS VPN
EDGE ROUTER
EDGE ROUTERS
Explanatory Motes on VPN Vulnerability
Slide 1 shows the topology of a typical ISP’s IP network over which
both Internet and VPN services are laid out. This is the topology of
BSNL’s NIB – ii. Five cities are connected in a full mesh
connectivity to form the core IP back-bone across India. Other
cities are connected through tri-node rings from the nodes of the
core network through the Tier-1 switch at these nodes.
Slide 2 shows the architecture of each of these nodes. The core router
at the node sits on the Tier 1 switch. From these switches are
taken the router connections for all the services – VPN, Internet
through Broadband and PSTN. Thus you will note that there is
continuous physical connectivity between all the routers in this IP
network through the Tier 1 switch at each IP Node (POP). Thus
there is continuous public domain access to the VPN routers.
1. In any IP network, public or private, the WAN ports of all routers in
the network have continuous physical access to each other. Thus
while a router port is engaged in communication with another in the
network, a third port can have simultaneous communications with
it. If the IP network is in the public domain (Internet) or has access
from the public domain (VPN), this third port could be that of afrom the public domain (VPN), this third port could be that of a
hacker.
2. Thus while the various security protocols like IP Sec, etc., can
transport the data from one computer to another securely, the LAN
and the data bases residing on it are exposed to public domain
through a VPN which has public domain access for reasons
explained in 1 above.
3. For WAN computing it is necessary to have a real private network
(at least for data communications). Once this is there then inter-
locational voice / fax can be run over this network at marginal
increase in the operating cost, using the patented PVDTN
system.
4. You should not expose your company data bases to the public
domain through Internet, ISDN back-up, or VPN (which has public
domain access) for reasons explained earlier in 1 above.
5. The MPLS networks currently in vogue are another form of VPN
network and are subject to the comments in 1 to 4 above.
We do hope the above notes will explain the security vulnerability of
your data bases when these are on LANs connected to VPN
(MPLS or other wise) of any service provider.
If you wish to secure your data bases 100% then use point-to-
point leased lines for inter-locational computer connectivity.

More Related Content

What's hot

Vpn presentation
Vpn presentationVpn presentation
Vpn presentationstolentears
 
Virtual Private Network (VPN)
Virtual Private Network (VPN)Virtual Private Network (VPN)
Virtual Private Network (VPN)Devolutions
 
VPN, Its Types,VPN Protocols,Configuration and Benefits
VPN, Its Types,VPN Protocols,Configuration and BenefitsVPN, Its Types,VPN Protocols,Configuration and Benefits
VPN, Its Types,VPN Protocols,Configuration and Benefitsqaisar17
 
my presentation on vpn
my presentation on vpnmy presentation on vpn
my presentation on vpnjadeja dhanraj
 
Virtual private network(vpn)
Virtual private network(vpn)Virtual private network(vpn)
Virtual private network(vpn)sonalikasingh15
 
Virtual Private Network
Virtual Private NetworkVirtual Private Network
Virtual Private NetworkOsp Dev
 
VPN (virtual private network)
VPN (virtual private network) VPN (virtual private network)
VPN (virtual private network) Netwax Lab
 
Vpn(virtual private network)
Vpn(virtual private network)Vpn(virtual private network)
Vpn(virtual private network)sonangrai
 
Mpls based vpn connectivity
Mpls based vpn connectivityMpls based vpn connectivity
Mpls based vpn connectivityPrem kumar
 
Virtual Private Network
Virtual Private NetworkVirtual Private Network
Virtual Private NetworkHASHIR RAZA
 
Virtual Private Network main
Virtual Private Network mainVirtual Private Network main
Virtual Private Network mainKanika Gupta
 
Virtual private network
Virtual private networkVirtual private network
Virtual private networkSowmia Sathyan
 
Bluetooth versus wi
Bluetooth versus wiBluetooth versus wi
Bluetooth versus wisher1242
 
VPN - Virtual Private Network
VPN - Virtual Private NetworkVPN - Virtual Private Network
VPN - Virtual Private NetworkPeter R. Egli
 

What's hot (20)

Vpn networks kami
Vpn networks kamiVpn networks kami
Vpn networks kami
 
Vpn presentation
Vpn presentationVpn presentation
Vpn presentation
 
Virtual Private Network (VPN)
Virtual Private Network (VPN)Virtual Private Network (VPN)
Virtual Private Network (VPN)
 
VPN, Its Types,VPN Protocols,Configuration and Benefits
VPN, Its Types,VPN Protocols,Configuration and BenefitsVPN, Its Types,VPN Protocols,Configuration and Benefits
VPN, Its Types,VPN Protocols,Configuration and Benefits
 
my presentation on vpn
my presentation on vpnmy presentation on vpn
my presentation on vpn
 
Virtual private network(vpn)
Virtual private network(vpn)Virtual private network(vpn)
Virtual private network(vpn)
 
VPN Virtual Private Network
VPN Virtual Private NetworkVPN Virtual Private Network
VPN Virtual Private Network
 
Slide.Week13
Slide.Week13Slide.Week13
Slide.Week13
 
Virtual Private Network
Virtual Private NetworkVirtual Private Network
Virtual Private Network
 
VPN (virtual private network)
VPN (virtual private network) VPN (virtual private network)
VPN (virtual private network)
 
Vpn(virtual private network)
Vpn(virtual private network)Vpn(virtual private network)
Vpn(virtual private network)
 
Unit 3
Unit 3Unit 3
Unit 3
 
Mpls based vpn connectivity
Mpls based vpn connectivityMpls based vpn connectivity
Mpls based vpn connectivity
 
Virtual Private Network
Virtual Private NetworkVirtual Private Network
Virtual Private Network
 
Virtual Private Network main
Virtual Private Network mainVirtual Private Network main
Virtual Private Network main
 
Virtual private network
Virtual private networkVirtual private network
Virtual private network
 
Bluetooth versus wi
Bluetooth versus wiBluetooth versus wi
Bluetooth versus wi
 
VPN - Virtual Private Network
VPN - Virtual Private NetworkVPN - Virtual Private Network
VPN - Virtual Private Network
 
Type of networking
Type of networkingType of networking
Type of networking
 
Wan
WanWan
Wan
 

Viewers also liked

Environmental biologist performance appraisal
Environmental biologist performance appraisalEnvironmental biologist performance appraisal
Environmental biologist performance appraisalalexaggenter
 
Antecendetes de la supervision y monitoreo de la educacion Esquema 1
Antecendetes de la supervision y monitoreo de la educacion Esquema 1Antecendetes de la supervision y monitoreo de la educacion Esquema 1
Antecendetes de la supervision y monitoreo de la educacion Esquema 1Leopardo Adan Castellon
 
Добропольские правоохранители посетили жителей поселка Ждановский города Добр...
Добропольские правоохранители посетили жителей поселка Ждановский города Добр...Добропольские правоохранители посетили жителей поселка Ждановский города Добр...
Добропольские правоохранители посетили жителей поселка Ждановский города Добр...Владимир Тимошенко
 
Histori of choclolate
Histori of choclolateHistori of choclolate
Histori of choclolateireag3929
 
FOI Freedom Of Information Request
FOI Freedom Of Information Request
FOI Freedom Of Information Request
FOI Freedom Of Information Request deeplycolleague65
 
Top 8 aircraft engineer resume samples
Top 8 aircraft engineer resume samplesTop 8 aircraft engineer resume samples
Top 8 aircraft engineer resume samplesvioletjohnson84
 
Arif Gunawan TE-D 5150711145
Arif Gunawan TE-D 5150711145Arif Gunawan TE-D 5150711145
Arif Gunawan TE-D 5150711145MardaniYusup
 
Tarea seminario 5
Tarea seminario 5 Tarea seminario 5
Tarea seminario 5 Marina Font
 
Forensic biologist performance appraisal
Forensic biologist performance appraisalForensic biologist performance appraisal
Forensic biologist performance appraisalalexaggenter
 
El mercado y el comportamiento del consumidor
El mercado y el comportamiento del consumidorEl mercado y el comportamiento del consumidor
El mercado y el comportamiento del consumidorjosemaria323
 
Jr buyer performance appraisal
Jr buyer performance appraisalJr buyer performance appraisal
Jr buyer performance appraisalalexaggenter
 
Top 8 bms engineer resume samples
Top 8 bms engineer resume samplesTop 8 bms engineer resume samples
Top 8 bms engineer resume samplesvioletjohnson84
 

Viewers also liked (18)

Environmental biologist performance appraisal
Environmental biologist performance appraisalEnvironmental biologist performance appraisal
Environmental biologist performance appraisal
 
Antecendetes de la supervision y monitoreo de la educacion Esquema 1
Antecendetes de la supervision y monitoreo de la educacion Esquema 1Antecendetes de la supervision y monitoreo de la educacion Esquema 1
Antecendetes de la supervision y monitoreo de la educacion Esquema 1
 
Добропольские правоохранители посетили жителей поселка Ждановский города Добр...
Добропольские правоохранители посетили жителей поселка Ждановский города Добр...Добропольские правоохранители посетили жителей поселка Ждановский города Добр...
Добропольские правоохранители посетили жителей поселка Ждановский города Добр...
 
Booosting 2015mei11 - Jos Lichtenberg - Dynamic architecture = dynamic industry
Booosting 2015mei11 - Jos Lichtenberg - Dynamic architecture = dynamic industryBooosting 2015mei11 - Jos Lichtenberg - Dynamic architecture = dynamic industry
Booosting 2015mei11 - Jos Lichtenberg - Dynamic architecture = dynamic industry
 
Histori of choclolate
Histori of choclolateHistori of choclolate
Histori of choclolate
 
FOI Freedom Of Information Request
FOI Freedom Of Information Request
FOI Freedom Of Information Request
FOI Freedom Of Information Request
 
Top 8 aircraft engineer resume samples
Top 8 aircraft engineer resume samplesTop 8 aircraft engineer resume samples
Top 8 aircraft engineer resume samples
 
Arif Gunawan TE-D 5150711145
Arif Gunawan TE-D 5150711145Arif Gunawan TE-D 5150711145
Arif Gunawan TE-D 5150711145
 
Tarea seminario 5
Tarea seminario 5 Tarea seminario 5
Tarea seminario 5
 
Forensic biologist performance appraisal
Forensic biologist performance appraisalForensic biologist performance appraisal
Forensic biologist performance appraisal
 
1. experiencia en cebada cervecera inta
1. experiencia en cebada cervecera inta1. experiencia en cebada cervecera inta
1. experiencia en cebada cervecera inta
 
El mercado y el comportamiento del consumidor
El mercado y el comportamiento del consumidorEl mercado y el comportamiento del consumidor
El mercado y el comportamiento del consumidor
 
Jr buyer performance appraisal
Jr buyer performance appraisalJr buyer performance appraisal
Jr buyer performance appraisal
 
Projeto de Lei 8001-2014
Projeto de Lei 8001-2014Projeto de Lei 8001-2014
Projeto de Lei 8001-2014
 
Municipio Productivo y Valor Agregado
Municipio Productivo y Valor Agregado   Municipio Productivo y Valor Agregado
Municipio Productivo y Valor Agregado
 
Macska naplo
Macska naploMacska naplo
Macska naplo
 
Top 8 bms engineer resume samples
Top 8 bms engineer resume samplesTop 8 bms engineer resume samples
Top 8 bms engineer resume samples
 
Eczema ( chàm)
Eczema ( chàm)Eczema ( chàm)
Eczema ( chàm)
 

Similar to Vpn1 (20)

F0322038042
F0322038042F0322038042
F0322038042
 
Network access layer security protocol
Network access layer security protocolNetwork access layer security protocol
Network access layer security protocol
 
MANAGING ORGANISATION USING VPN's : A SURVEY
MANAGING ORGANISATION USING VPN's : A SURVEYMANAGING ORGANISATION USING VPN's : A SURVEY
MANAGING ORGANISATION USING VPN's : A SURVEY
 
AWS VPC .pptx
AWS  VPC .pptxAWS  VPC .pptx
AWS VPC .pptx
 
Mcse question
Mcse questionMcse question
Mcse question
 
Virtual Private Network
Virtual Private NetworkVirtual Private Network
Virtual Private Network
 
International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)International Journal of Engineering Research and Development (IJERD)
International Journal of Engineering Research and Development (IJERD)
 
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALAVIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
VIRTUAL PRIVATE NETWORKS BY SAIKIRAN PANJALA
 
Virtual private networks
Virtual private networks Virtual private networks
Virtual private networks
 
Final isp
Final ispFinal isp
Final isp
 
Basic isp network design
Basic isp network designBasic isp network design
Basic isp network design
 
Unit 4
Unit 4Unit 4
Unit 4
 
my project publication
my project publicationmy project publication
my project publication
 
Vp ns
Vp nsVp ns
Vp ns
 
ACN.pptx
ACN.pptxACN.pptx
ACN.pptx
 
Vpn
Vpn Vpn
Vpn
 
V P N
V P NV P N
V P N
 
ComputerNetworksAssignment
ComputerNetworksAssignmentComputerNetworksAssignment
ComputerNetworksAssignment
 
Iap final
Iap finalIap final
Iap final
 
IRJET- A Survey of Working on Virtual Private Networks
IRJET- A Survey of Working on Virtual Private NetworksIRJET- A Survey of Working on Virtual Private Networks
IRJET- A Survey of Working on Virtual Private Networks
 

More from MIDAUTEL

Resurrection of isdn
Resurrection of isdnResurrection of isdn
Resurrection of isdnMIDAUTEL
 
Cloud computing
Cloud computingCloud computing
Cloud computingMIDAUTEL
 
Loc details.xlsx
Loc details.xlsxLoc details.xlsx
Loc details.xlsxMIDAUTEL
 
Sts presentation
Sts presentationSts presentation
Sts presentationMIDAUTEL
 
Pvdtn presentation
Pvdtn presentationPvdtn presentation
Pvdtn presentationMIDAUTEL
 
Pvdtn sts tech
Pvdtn sts techPvdtn sts tech
Pvdtn sts techMIDAUTEL
 
Pvdtn sts brochure
Pvdtn sts brochurePvdtn sts brochure
Pvdtn sts brochureMIDAUTEL
 
Executive presentation3
Executive presentation3Executive presentation3
Executive presentation3MIDAUTEL
 

More from MIDAUTEL (15)

Resurrection of isdn
Resurrection of isdnResurrection of isdn
Resurrection of isdn
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Ngn
NgnNgn
Ngn
 
Mpls p2 p
Mpls   p2 pMpls   p2 p
Mpls p2 p
 
Vo p pstn
Vo p   pstnVo p   pstn
Vo p pstn
 
Mobile
MobileMobile
Mobile
 
Telephony
TelephonyTelephony
Telephony
 
Nwan
NwanNwan
Nwan
 
Loc details.xlsx
Loc details.xlsxLoc details.xlsx
Loc details.xlsx
 
Sts presentation
Sts presentationSts presentation
Sts presentation
 
Pvdtn presentation
Pvdtn presentationPvdtn presentation
Pvdtn presentation
 
Llbu
LlbuLlbu
Llbu
 
Pvdtn sts tech
Pvdtn sts techPvdtn sts tech
Pvdtn sts tech
 
Pvdtn sts brochure
Pvdtn sts brochurePvdtn sts brochure
Pvdtn sts brochure
 
Executive presentation3
Executive presentation3Executive presentation3
Executive presentation3
 

Recently uploaded

SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Neo4j
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfngoud9212
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsAndrey Dotsenko
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024BookNet Canada
 

Recently uploaded (20)

SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024
 
The transition to renewables in India.pdf
The transition to renewables in India.pdfThe transition to renewables in India.pdf
The transition to renewables in India.pdf
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdf
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
 

Vpn1

  • 1. NIB – II TOPOLOGY Kolkata Guwahati Lucknow Chattisgarh Bhopal Jaipur Gandhinagar / Ahmedabad Chandigarh Shimla Srinagar Kolkata Delhi IGW IGW IGW Mumbai BRAS NoidaNoida Patna Fig.1 PuneIGW IGW IGW IGW IGW H-bad BRAS Pondicherry Chennai Thiruvanthapuram Ernakulam Mumbai Chennai Bangalore Bangalore CORE Router BRAS STM16 STM1 EDGE Router Goa Bhubaneshwar Back Office facilities – Web hosting, Customer servers, Messaging, Caching, Billing, etc.
  • 2. NIB – II ARCHITECTURE CORE ROUTER TIER I EDGE ROUTERS EDGE ROUTERS EDGE ROUTERS EDGE ROUTERS BRAS BRAS BRAS BRAS EDGE ROUTERS NATIONAL INTERNET EXCHANGE TO CONNECT ALL ISPs AND PROVIDE COMMON INTERNATIONAL GATEWAY NIEX EDGE ROUTER Fig. 2 EDGE ROUTERS RAS PSTN NETWORK TO OTHER CORE ROUTERS DIAL – UP CONNECTIONS DIAL – UP SERVICE EDGE ROUTER TIER II TIER II TIER II TIER II TIER IITIER II TIER II TIER II TIER II TIER II DSLAMs DSLAMs Leased Lines from VPN Subscriber Premises MPLS VPN EDGE ROUTER EDGE ROUTERS
  • 3. Explanatory Motes on VPN Vulnerability Slide 1 shows the topology of a typical ISP’s IP network over which both Internet and VPN services are laid out. This is the topology of BSNL’s NIB – ii. Five cities are connected in a full mesh connectivity to form the core IP back-bone across India. Other cities are connected through tri-node rings from the nodes of the core network through the Tier-1 switch at these nodes. Slide 2 shows the architecture of each of these nodes. The core router at the node sits on the Tier 1 switch. From these switches are taken the router connections for all the services – VPN, Internet through Broadband and PSTN. Thus you will note that there is continuous physical connectivity between all the routers in this IP network through the Tier 1 switch at each IP Node (POP). Thus there is continuous public domain access to the VPN routers. 1. In any IP network, public or private, the WAN ports of all routers in the network have continuous physical access to each other. Thus while a router port is engaged in communication with another in the network, a third port can have simultaneous communications with it. If the IP network is in the public domain (Internet) or has access from the public domain (VPN), this third port could be that of afrom the public domain (VPN), this third port could be that of a hacker. 2. Thus while the various security protocols like IP Sec, etc., can transport the data from one computer to another securely, the LAN and the data bases residing on it are exposed to public domain through a VPN which has public domain access for reasons explained in 1 above. 3. For WAN computing it is necessary to have a real private network (at least for data communications). Once this is there then inter- locational voice / fax can be run over this network at marginal increase in the operating cost, using the patented PVDTN system. 4. You should not expose your company data bases to the public domain through Internet, ISDN back-up, or VPN (which has public domain access) for reasons explained earlier in 1 above. 5. The MPLS networks currently in vogue are another form of VPN network and are subject to the comments in 1 to 4 above. We do hope the above notes will explain the security vulnerability of your data bases when these are on LANs connected to VPN (MPLS or other wise) of any service provider. If you wish to secure your data bases 100% then use point-to- point leased lines for inter-locational computer connectivity.