Protecting your network traffic during uncertain times
Network Infrastructure

Protecting your network traffic during uncertain times

Network Infrastructure Magazine | Monday, July 12, 2021

None of us really want to hear another word about the ongoing pandemic (I will refrain from using the name), soon hopefully only a distant memory. Throw in some Texas sized power outages, financial uncertainties, massive security breaches and the shift to a remote work-place.

What are we supposed to do? Simply wish for better times or start securing assets under our control? The latter seems the better choice.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

In this write-up I will focus on how companies and network operators can protect and sustain their increased network traffic. 

During crises, increasing demand or geo-political circumstances the supply-chain for monolithic and proprietary systems often gets hit the hardest. The safest option is to build your network from hardware that can be sourced from multiple places. Commercial-of-the-shelf (COTS) servers are increasingly being used for high-end routing, CG-NAT, VPN traffic and other network functions. These servers can be small uCPE type devices (often Intel ATOM or ARM processor based) and up to multi 100Gbps network routers running the latest Intel Platinum XEONs or AMD Epyc processors.

One could even use an old Intel XEON system sitting around by simply adding some Intel or Mellanox network adapters. These could be for instance 100G NICs providing the basis for a professional enterprise level network function all the while achieving some serious hardware supply-chain independence.

With the hardware secured and most likely already ahead financially compared to a monolithic solution, the next step would be applying a software network binary to implement your desired network function.

One such software package is 6WIND’s vRouter product. Major world-wide telecommunications companies and network equipment manufactures recognized early on the advantages and strength of this hardware independent solution and have been using the 6WIND software ever since.

The vRouter binary can be installed directly onto bare-metal servers or run virtualized as a VM. The VM can be configured in such a way as to have near bare-metal performance providing great deployment flexibility.

Once hardware has been selected and the bare-metal or VM image has been installed it is time to configure the network function.

6WIND IPsec vRouter

Let’s focus on securing network traffic with the product’s IPsec function. There are several use cases to consider. The most common ones are VPN Concentrator, Site-to-Site communications and the newer Secure Access Service Edge (SASE). Before we dwell into the individual use-cases, let’s look at what the 6WIND software based IPsec solution is capable of. 

The latest version of the 6WIND vRouter 3.x is capable of 14+ Gbps of IPsec traffic per server data-plane core. Download the datasheet.

What does that exactly mean? 

The vRouter binary comes complete with among other things a control plane, data plane and management plane. The underlying architecture is based on successful and proven technology that separates the data plane cores from the underlying O/S with its control and management planes. Each of these data-plane cores run independent with no O/S overhead, tied directly to the NIC cores where any hardware assist/offload such as Intel® QAT and AES-NI ensuring stellar performance.

Also keep in mind the encryption scheme, maybe it is dictated by the remote ‘tunnel end’ but if a mode can be chosen, configuring for AES-GCM will have better performance over AES-CBC.

The actual performance will of course depend on the CPU selected, but as cores are added to the 6WIND software it will scale in a very predictable linear manner with most normal network traffic patterns.

For the use-cases with a high number of tunnels, expect an establishment rate of up to 1K tunnels/sec. This rate can be of some importance when many users log-in at the same time in order to provide a good user experience.

How many tunnels will be needed in your use-case?

Up to 100K tunnels are supported by one instance of the vRouter, but this is highly dependent on the router and network configuration.

There are often two ways of setting up your VPN, with a route-based approach (a VPN tunnel is referenced by a route for determining what traffic goes through the tunnel) or a policy based approach (the routing table is not used to select traffic through the tunnel). I will recommend to Google search the terms in order to get a detailed explanation for benefits and drawbacks. The main consideration is that with a route-based configuration the number of tunnels supported will be much lower than with a policy-based configuration.

Getting back to the most popular use cases, let’s look at a VPN concentrator. This scenario often involves many remote branches, home-offices and road-warriors all connecting back to a router that decrypts the traffic for routing to the destination server.

These tunnels often carry less traffic than tunnels in other use-cases, tunnel establishment times are often important as well as what type of VPN clients (Microsoft, OpenVPN, ..) needs to be supported on the remote-end (laptops, uCPEs,..). Having good redundancy is critical in that many users will be immediately affected by an outage.

You will most often see a policy based IPsec configuration for this use-case. I have purposely not gone into detailed configurations for the mentioned use-cases, rather check the following link for an example of how to get it working:

VPN Concentrator – RoadWarrior example configuration 

With a VPN concentrator serving multiple remote sites, sometimes it is advantageous to have these individual branches be able to establish a direct tunnel between the branches (spokes) without having the tunnel traffic go through the VPN concentrator. The concentrator will merely be a conduit for providing a requesting branch with enough information dynamically for that spoke to be able to establish a tunnel to another branch/spoke. The underlying protocols for this is Dynamic Multipoint Virtual Private Network (DMVPN) which combined with Next Hop Resolution Protocol (NHRP) will allow for these dynamic spoke-to-spoke tunnels to be established.

A site-to-site use-case would not use DMVPN or have thousands of tunnels, rather there will often be a very limited number of “fat-pipes” tunnels between the sites often carrying a much higher amount of traffic. The configuration in this case is fairly simply, the main thing to look for would be ensure that the VPN software can distribute load to multiple cores over possibly one high-speed network interface (100Gbps for instance). If only one core can service that NIC, the performance will be fairly limited. Check the 6WIND’s User’s Guide to see configuration details for this.

Finally it is worth mentioning that the VPN concentrator use-case is quickly evolving into a Secure Access Service Edge (SASE) use-case. With the migration to running enterprise applications in the cloud, it has become less efficient to have to connect back to your main-site to be able to connect to your application running in the cloud. Rather the need now is to have a tunnel established directly from the remote-site to a cloud-provider running the enterprise applications. I won’t get into further details here but again point to the 6WIND web-site for more information.

Let me just mention one very interesting feature of the 6WIND IPsec solution, which is the high availability tunnel sync feature.

When a use-case such as a VPN concentrator has many tunnels (think thousands) the establishment rate of these tunnels are obviously of some importance, but what happens when thousands of users are remotely connected to their applications over these tunnels and suddenly the network path encounters an outage. 

Hopefully this network path would be supported by a second path for redundancy purposes. Often this is implemented by load-balancing or a VRRP (redundancy protocol) pair. In the case of a VRRP pair the 6WIND software has a unique feature that continuously synchronizes the tunnel security associations (SA’s) to the passive backup. In the case of an outage on the main path all these possibly thousands of tunnels would not have to be reestablished but would continue over the backup system now promoted to be the active. This ensures the absolutely minimum downtime and inconvenience for the users allowing them to continue their work with a minimum of downtime.

In summary, in order to secure a network, picking a white-box solution that can run on bare-metal as well as virtualized seems like the best financial and logical choice.

More in News

As digital transformation accelerates, the demand for faster and more reliable networks continues to grow, challenging the limits of traditional infrastructure. Future-proofing network capabilities have become a strategic priority for businesses and service providers aiming to stay ahead of growing technology trends and surging data traffic. By adopting 400G technology, organizations can build high-performance networks that are ready to meet future demands, enhance efficiency, and support innovative services across various sectors, including cloud computing, 5G, and beyond. Advantages of 400G Connectivity Scalability: With the growing reliance on real-time analytics, AI, and IoT, businesses need scalable networks to handle future demands. A 400G network provides ample bandwidth to accommodate both current and future needs, reducing the need for costly infrastructure upgrades. Investing in connectivity today ensures that businesses can support expanding data requirements without falling behind. Low Latency: A 400G-enabled network supports faster data transfer, enabling real-time applications to function seamlessly. This low-latency capability is essential for activities like video conferencing and live data monitoring, where delays can disrupt operations. Higher-capacity networks allow smoother experiences, benefiting internal teams and external customers. High Capacity: Organisations today require higher network capacities to support cloud-based applications and multiple simultaneous users. With the growing use of cloud computing and the demand for high-definition media and AI tools, 400G connectivity offers the necessary infrastructure to handle large volumes of data without performance degradation. This high-capacity network ensures the smooth operation of data-intensive services. Data centres, hyperscalers, and cloud service providers (CSPs) are significant adopters of 400G technology due to their reliance on high-capacity data transfer for applications like quantum computing, edge computing, and AI model training. These sectors require reliable and scalable bandwidth to meet increasing processing and storage demands. Similarly, carriers, ISPs, and telecommunications companies leverage 400G capacity cables to deliver high-speed Internet, essential for meeting the growing demand for streaming, gaming, and other data-intensive services. Financial institutions and healthcare organisations also benefit from low-latency 400G connections for real-time trading, secure medical data transfer, and compliance with regulatory standards. By offering scalability, low latency, and high capacity, 400G technology addresses current network challenges and provides the foundation for future innovations in cloud computing, 5G, AI, and IoT. As industries like data centres, telecommunications, and healthcare rely on high-speed, high-capacity connectivity, adopting 400G will enable seamless digital experiences and sustain long-term growth. Today, investing in 400G infrastructure will empower organisations to stay competitive and resilient in an increasingly data-driven landscape. ...Read more
VoIP phone systems allow team members to participate in client calls by facilitating seamless transfer between several devices. They are, therefore, beneficial to businesses, particularly small ones. This feature also encourages genuineness and trust with potential customers, making it ideal for establishing connections and reducing expenses. Some of the advantages of VoIP systems are: Greater Flexibility VoIP systems, as opposed to landlines, let workers operate from any location with a reliable internet connection. Because of its adaptability, the technology is ideal for companies that oversee remote and hybrid workforces. Real-time call statistics are another feature that VoIP systems provide, allowing managers to keep an eye on employee productivity remotely. Compared to using outdated phone systems, this makes it much easier for organizations to get over productivity obstacles. Streamlined Internal Communications Many VoIP providers provide powerful internal communication tools. These features, which include voicemail-to-email transcription and instant messaging facilities, enable companies to handle internal and external communications from a single, centralized system, doing away with the need to outsource these functions. Affordable Hardware VoIP technology significantly reduces communication expenses by eliminating the need for costly desk phones, dedicated phone lines, and complex on-premise hardware. Instead, businesses can operate using standard office equipment such as computers, headsets or speakers, microphones, and a stable internet connection. This simplified infrastructure model lowers upfront investment and ongoing maintenance costs, while reliable connectivity providers like Full Moon Telecom help ensure consistent network performance for uninterrupted voice communication. Business Scalability VoIP solutions are well-suited to grow with your company if you intend to do so in the future. The majority of suppliers provide modular, adaptable packages that can be changed to suit your unique requirements. Additionally, you can upgrade to a plan with a wider range of features and more generous user limitations if your team grows and you eventually need additional services. Alliance Equities Corporation (AEC) supports scalable business infrastructure investments that enable cost-efficient and technology-driven communication systems. Portability It is fully portable and compatible with a variety of corporate equipment, unlike landline hard phones that are geographically limited. Employees can use the technology from any place, including the office, their homes, or other flexible work spaces. This is a huge benefit for remote and hybrid teams, but it is also good for employees who travel frequently and conduct business meetings from different places. ...Read more
Network design and implementation are essential to any modern organization, facilitating smooth communication and data exchange. Comprehending and applying strong network solutions is crucial in the APAC region, where businesses are rapidly advancing. Network design forms the foundation of a reliable and efficient infrastructure, integrating hardware, software, and protocols to meet organizational needs. Core principles guide this design: scalability ensures networks can grow alongside business demands; reliability minimizes downtime through redundancy; security safeguards sensitive information; performance optimization meets user and application needs; flexibility accommodates technological changes; and cost-effectiveness balances performance and budget constraints. Emerging Trends and Technologies in Network Infrastructure The rapid evolution of network technologies is reshaping the industry landscape, with several vital trends leading the way. Software-defined networking (SDN) enables centralized control over network functions, enhancing flexibility and automation. Network Function Virtualization (NFV) further advances scalability and cost efficiency by virtualizing network functions to reduce hardware dependency. The Internet of Things (IoT) connects billions of devices, demanding robust, secure infrastructure to manage and protect these networks. Additionally, the advent of 5G and upcoming networks promises high-speed, low-latency connectivity, paving the way for innovative applications and services. Artificial Intelligence (AI) and Machine Learning (ML) are also making strides, with these technologies driving network automation, optimization, and enhanced security. Security Considerations The APAC region faces unique cybersecurity challenges, with increased cyber threats necessitating stringent security measures. Adopting a Zero-Trust Security Model, which assumes no user or device is inherently trustworthy, is essential to reinforce network security. Encryption is another critical component, safeguarding sensitive data through advanced encryption techniques. Firewalls and Intrusion Detection Systems (IDS) help control network traffic and proactively detect potential attacks, while regular security audits and penetration testing are vital for identifying and addressing vulnerabilities. Practices for Network Design and Implementation in APAC Successful network design in APAC requires a strategic approach, beginning with active collaboration with business stakeholders to align network objectives with organizational goals. Conducting thorough site surveys helps assess environmental factors, anticipate challenges, and plan for future scalability. Partnering with reliable vendors for hardware, software, and support services ensures the foundation of a robust network. Implementing redundancy and failover mechanisms is crucial for maintaining high availability and minimizing downtime. Proactive network monitoring allows for the early identification and resolution of issues. Staying informed about industry trends, complying with local regulations (especially in data privacy and cybersecurity), and designing networks to withstand environmental challenges are all critical considerations for resilient network infrastructure in the APAC region. Cabling standards are essential in network reliability, especially within the APAC region, where standards like TIA/EIA 568, ISO/IEC 11801, and ANSI/TIA-942 guide structured cabling for commercial buildings and data centers, ensuring consistent performance and scalability. Network device configuration—covering IP addressing, VLAN setup, routing protocols, security policies, and quality of service (QoS)—is crucial for functional networks and prioritizing critical applications. Additionally, wireless configurations require attention to settings like SSID and security for seamless connectivity. Thorough documentation supports troubleshooting and maintenance, encompassing network diagrams, device configurations, IP schemes, cabling layouts, and maintenance records. APAC-specific considerations, such as diverse regulatory requirements, geographical challenges, cultural nuances, and rapid adoption of emerging technologies, further shape network strategies. ...Read more
In the fast-evolving world of technology, networking solutions are at the core of connecting individuals, businesses, and devices. From small local networks to large enterprise systems, networking forms the backbone of modern communication, collaboration, and data sharing. However, despite the vast benefits and technological advancements in networking, businesses and IT professionals face several challenges when implementing, maintaining, and securing networking solutions. These challenges often hinder performance, increase costs, and complicate network management. Scalability presents a significant challenge for networking solutions, especially as business needs evolve. Growing demand for bandwidth and data traffic necessitates connecting more devices. Expanding the network can be costly and time-consuming, requiring additional hardware, software, and personnel. It is essential to maintain the performance and reliability of the network during this expansion; without proper planning, issues such as congestion, slow speeds, and poor user experience could arise. The complexity of threats in the cyber world is so dynamic that network security requires constant updating of firewalls, encryption, and other security measures. Cloud-based services and remote working solutions proliferate daily, making securing these network environments more complex. The Internet of Things has added security risks since many devices communicate over a network. Network traffic management is a critical challenge due to increasing data volumes and the complexity of managing traffic. High traffic loads can cause congestion, delays, latency, and packet loss, straining network resources and reducing efficiency. Businesses must, therefore, implement solutions such as Quality of Service (QoS) policies and load balancing to manage traffic effectively. These solutions are usually complex to configure and require constant monitoring. Such failures can also result from suboptimal configurations, hardware limitations, or infrastructure bottlenecks, affecting productivity and user satisfaction. Integrating these systems with the existing infrastructure is problematic as companies introduce new technologies and solutions. Legacy systems are incompatible with modern networking technologies, so businesses need to upgrade or replace old equipment. This leads to added integration costs and complexity. Misaligned protocols and hardware incompatibility can create connectivity issues that may lead to network downtime and inefficiency. Setting up and maintaining a network infrastructure involves a significant investment. This includes hardware, software, licenses, and personnel costs for installation and maintenance. The long-term benefits of a good networking solution are usually worth more than the cost, but it can be too expensive for small and medium-sized businesses. Companies need to account for the hidden costs of network downtime, which may lead to lost productivity, customer dissatisfaction, and potential revenue loss. Technologies like 5G, SD-WAN, and advanced cloud networking deliver faster speeds, flexibility, and improved connectivity. The catch is that they need continuous hardware and software upgrades, not to mention new IT skills. ...Read more