IPVPN Information Model Requirements - - PowerPoint PPT Presentation

ipvpn information model
SMART_READER_LITE
LIVE PREVIEW

IPVPN Information Model Requirements - - PowerPoint PPT Presentation

IPVPN Information Model Requirements <draft-iyer-ipvpn-infomodel-req-00.txt> Information Model <draft-iyer-ipvpn-infomodel-00.txt> Mahadevan Iyer, Arnold Jansen - Alcatel Outline Context Requirement


slide-1
SLIDE 1

IPVPN Information Model

  • Requirements

<draft-iyer-ipvpn-infomodel-req-00.txt>

  • Information Model

<draft-iyer-ipvpn-infomodel-00.txt>

  • Mahadevan Iyer, Arnold Jansen - Alcatel
slide-2
SLIDE 2

Outline

  • Context
  • Requirement
  • Overview
  • Details
  • Implementation
slide-3
SLIDE 3

Context

  • | Service Level | --> SLS capture customer requirement/service

goals(Tequila)

  • <>---------> Service goal to network policy

translation

  • | Network Level | --> IP VPN policies capture network
  • ---------------- requirements

<>---------> Network policy to devices level specifications

  • | Device Level | --> Device specific configuration(SNMP MIBS)
slide-4
SLIDE 4

Requirement

  • A mutual understanding between the service

level and the network on how the service is to be provisioned in the network

– A standardized means of communicating requirements from the service level to the provider network – A standardized means of accepting requirements on the network and aligning the network elements

slide-5
SLIDE 5

Network Requirement

Service Provider Network L3 Access + Distribution + L3 Edge CE CE L3 Access + Distribution + L3 Edge CE L3 Access + Distribution + L3 Edge

Policing VPN Forwarding Instance Traffic Trunk

slide-6
SLIDE 6

Usage

Service Clients CE Policy Server

  • Dedicated

VPN gateway Central Office

  • VPN gateway
  • BRAS

Edge/Core IP routers PE Policy Server

CPE Based User VPNs CO Based User VPNs MPLS/BGP Network VPNs

Common policy information model

  • PDP
slide-7
SLIDE 7

Details

  • |

+--------------+

  • |1..n(placement) [Implements the Service] | |
  • +--------------------------------------------------------+ |
  • | ipvpnServicePolicyRule

|x-+

  • +--------------------------------------------------------+
  • o
  • |

| | |

  • |1 [Membership] | |1..n [Reachability] |
  • +--------------------------+ | +------------------------+ |
  • |gpsPolicyCompoundCondition| | |ipvpnPolicyRoutingAction| |
  • +--------------------------+ | +------------------------+ |
  • |

|

  • [Security, QoS, NAT] |1 [Admin, Dist] |1
  • +-----------------+ +-----------------+
  • | gpsPolicyGroup | |ipvpnPolicyDomain|
  • +-----------------+ +-----------------+
slide-8
SLIDE 8

PolicyValue Extensions

  • +----gpsPolicyValue[QPIM]
  • |
  • +-------gpsPolicyIPv4AddrValue[QPIM]
  • |
  • +-------gpsPolicyIPv6AddrValue[QPIM]
  • |
  • +-------ipvpnApplicationSignatureValue(this document)
  • |
  • +-------ipvpnEnforcerProfileValue(this document)
slide-9
SLIDE 9

Policy Action Extensions

  • +----PolicyAction[PCIM]
  • |
  • +-------ipvpnPolicyRoutingAction(this document)
  • |
  • +-------ipvpnPolicyNATAction(this document)
  • |
  • +-------ipvpnPolicyTrafficTrunkAction(this document)
  • |
  • +-------ipvpnPolicyFirewallAction(this document)
  • |
  • +-------ipvpnPolicyEncryptionAction(this document)
  • |
  • +-------qoSPolicyPRAction[QPIM]
  • |
  • +-------qoSPolicyRSVPAction[QPIM]
  • |
  • +-------qoSPolicyRSVPSignalCtrlAction[QPIM]
  • |
  • +-------qoSPolicyRSVPInstallAction[QPIM]
slide-10
SLIDE 10

IP Service Description

  • Simple example of an IP service

– Connect specific sites S1, S2, S3 (hub-spoke) – Provide QoS assurances for certain IP flows between the sites – Provide internet access and protect the sites – Encrypt all the traffic between S1 and S2

slide-11
SLIDE 11

IP VPN Definition

  • Connectivity Requirement

– Membership

  • PolicyEnforcerCondition = PE1, PE2, …

– Reachability

  • RoutingAction = S1 – PE1 – PE2 – S2
  • PolicyGroup

– QoS Requirement

  • Specific flow has min/max bandwidth, DSCP marking
  • Traffic trunk requirements over PE1 – PE2

– Security requirement

  • Firewall traffic from the internet to the sites
  • Encrypt traffic between S1 and S2
slide-12
SLIDE 12

Implementation

  • | Service Level | --> SLS capture customer requirement/service

goals(Tequila)

  • <>---------> Service goal to network policy

translation

  • | Network Level | --> IP VPN policies capture network
  • ---------------- requirements

<>---------> Network policy to devices level specifications

  • | Device Level | --> Device specific configuration(SNMP MIBS)
slide-13
SLIDE 13

Usage

Service Clients CE Policy Server

  • Dedicated

VPN gateway Central Office

  • VPN gateway
  • BRAS

Edge/Core IP routers PE Policy Server

CPE Based User VPNs CO Based User VPNs MPLS/BGP Network VPNs

Common ipvpn policy information model Topology Model + Requirements model

  • PDP

<draft-scandariato-ppvpn-info-model>