Enhance Telecom Network Security with Microtel Innovation’s Advanced TAPs

Microtel Network Security

In the dynamic and data-intensive telecommunications industry, network visibility is a critical requirement for ensuring the reliability, security, and efficiency of services. Among the essential components that enable this visibility are Network TAPs (Traffic Access Points). Microtel Innovation’s TAPs are engineered to deliver precise, non-intrusive access to network traffic, allowing operators to perform real-time monitoring and analysis without compromising network integrity.

A TAP is a vital component for any Telco operator aiming to maintain high standards of network visibility and security.

Technical Implementation: Strengthening Network Security and Optimization

Imagine a major telecommunications provider responsible for managing an extensive multi-tiered network that supports millions of users, each generating vast amounts of data daily. The provider is tasked with not only maintaining seamless service but also protecting sensitive data from increasingly sophisticated cyber threats. As the network grows more complex, conventional monitoring tools fall short in providing the necessary visibility to detect and mitigate potential issues in real-time.

Microtel Innovation TAP Solution

 

To address these challenges, the provider integrates Microtel Innovation’s Optical TAPs into critical segments of their network. This TAP is strategically deployed to monitor high-bandwidth links, ensuring that every packet of data is captured and forwarded to security appliances and network analyzers without causing any disruption to live traffic. Unlike SPAN (Switch Port Analyzer) port, which can introduce latency and packet loss under heavy load, Microtel’s TAP operates at full line rates, ensuring complete traffic capture even in the most demanding environments.

During a security audit, the provider’s monitoring system, fed by data from Microtel’s TAPs, detects anomalous traffic patterns indicative of an advanced persistent threat (APT) targeting the network’s core. Leveraging the detailed data streams provided by the TAPs, the security team can perform deep packet inspection, tracing the malicious activity back to its source and neutralizing the threat before any data exfiltration occurs. 

Technical Specifications and Performance Metrics of Microtel Innovation’s TAPs

Microtel Innovation’s TAPs are engineered to meet the demanding requirements of modern telecommunications networks. They are available in various configurations, including optical and copper, to accommodate different network types and speeds. Key technical features include:

High Availability: Designed for continuous operation with minimal maintenance, ensuring that network monitoring remains uninterrupted.

Full Line Rate Monitoring: Capable of capturing traffic at speeds up to 400 Gb/s without introducing latency or packet loss.

Versatile Deployment: Compatible with various network environments, including 1Gb/s, 10Gb/s, 25Gb/s, 40Gb/s, 100Gb/s and 400 Gb/s networks, and available in both single-mode and multimode fiber options.

Fail-Safe Operation: In the event of power loss, the TAP maintains the integrity of the network by defaulting to a pass-through mode, ensuring that traffic flow is not interrupted.

Compact Design: Optimized for space efficiency, allowing for deployment in high-density data center environments.

Microtel Innovation’s TAPs are a vital component for any Telco operator aiming to maintain high standards of network visibility and security. Their advanced features and reliable performance make them an indispensable tool for managing the complex demands of modern telecommunications networks.

Deduplication: Improve Monitoring Efficiency and Reporting Accuracy

 

WHY PACKET DEDUPLICATION?

It is common that a single packet capturing device (such as a passive probe, or any other passive tool analyzing the network performances) to receive multiple copies of the same data within a network.

This often occurs when customers use SPAN (also known as Port Mirroring) technology to collect traffic from multiple VLANs or ports on a switch/router and direct it to a single packet capturing device. In such cases, the packet capturing tool might see identical IP packets multiple times, even when network performance is not compromised.

Consider the following example: PC-A in VLAN 1 sends IP packets to PC-C in VLAN 2, routed through a multi-layer switch. At the switch’s mirror port, both ingress and egress copies of each packet from this stream are captured, creating duplicate packets. Monitoring only the ingress traffic would prevent this duplication, but then packets from PC-B to PC-A or PC-C would not be captured.

Fig.1: Simple port mirroring scheme

When all this traffic is directed to the same packet capturing tool, the device may interpret the duplicates as retransmissions, leading to an overestimation of data volume. This misinterpretation impairs effective network monitoring by skewing statistical accuracy and inflating perceived traffic levels or network errors.

MICROTEL INNOVATION SOLUTION

Removing duplicate packets at the monitoring tool level is not the solution. These tools are already burdened with handling and processing network traffic and typically lack the processing power to efficiently manage an additional, resource-intensive task like deduplication.

Microtel Innovation offers an effective solution with its product: A-XFE-DEDUP, a high-performance Network Packet Broker with 20 x 40/100 Gb/s input/output ports.

Its key features include:

  • Advanced Network Packet Broker with high-performance packet deduplication capabilities
  • Configurable packet fields for duplicate detection, with intervals ranging from 66 ms to 1 second
  • GTP Balancer with session-based GTP filtering

This device ensures efficient network monitoring by eliminating duplicate packets before they reach the monitoring tool, thereby maintaining data accuracy and reducing the load on monitoring systems.

Enhancing Digital Security: Microtel’s Contribution

Digital interactions, whether on public networks or within private networks, have taken on a predominant role in both interpersonal and business relationships. Therefore, it is essential to intervene to ensure that everything occurs in a secure online environment. For public networks, recent legal provisions in Italy have mandated operators (ISPs, Internet Service Providers) to strengthen their services to protect rights in two specific areas:

○ Parental Control
○ Copyright Control (Anti-piracy)

The responsibility to comply with these regulations falls on ISPs, and the implementation of these systems requires robust and reliable technical solutions.

Anti-piracy: combating the distribution of illicit streaming

The increasing spread of pirated content has prompted legislative action to curb illegal streaming activities. Microtel implemented a comprehensive anti-piracy solution, curtailing unauthorized streaming activities that allowed illegal access to paid TV content without a regular subscription.

By utilizing a combination of Microtel’s Aster technology for IP address blocking and a 3rd-party system for FQDN blocking, the client has a robust defense mechanism against the spread of illegal content. The platform, powered by AGCOM’s “Piracy Shield” infrastructure, allows the blocking of reported addresses within the strict deadlines defined by regulations (30 minutes from the report). 

Incorporating the A-640 packet broker, which boasts the ability to instantaneous adjustments to the distribution of network packets without significant downtime, ensures seamless management of vast amounts of data with minimal delays, maintaining an active link effortlessly.

Designed with a 1U box, Microtel’s Aster A-640 efficiently manages vast amounts of data, up to 6.4 Tb/s, leveraging high bandwidth enabled by its total number of input/output ports of 32×40/100 Gb/s, and ensuring minimal delays.

Microtel Innovation's A-640 packet broker ensures seamless management of vast amounts of data with minimal delays, maintaining an active link effortlessly.

The adoption of Microtel Innovation’s R&D department-developed monitoring software, Dardo, optimizes the management of all hardware devices engaged in continuous requests for domain and IP address blocking.

Possible developments

Thanks to its solid foundation, the implemented solution lends itself to a wide range of functional extensions within the scope of cybersecurity, including enhanced security for the growing number of IoT devices in use today.

In this ever-evolving digital landscape, a focus on innovation is crucial. To ensure a safer digital future and protect their online ecosystems, collaboration with technological partners like Microtel Innovation, who provide end-to-end solutions for traffic monitoring and control, as well as safeguarding corporate data, is strategic.

Dardo: The Network Device Management System by Microtel

Dardo is a Management System, developed by us at Microtel Innovation, designed to simplify and enhance the control of Microtel Innovation’ network devices. In this article, we will introduce you to the main features of Dardo, highlighting its distinctive characteristics and its added value in the network management landscape.

Introduction

In addition to optimizing the management of Microtel’ network devices, Dardo offers a comprehensive solution for traffic capture and analysis. The system provides operators with an intuitive interface for controlling individual devices, ensuring efficient network management.

System Description

Dardo provides a web interface accessible via a browser, with recommended support for Mozilla Firefox or Google Chrome. The application allows access to network devices through an Exercise & Maintenance (E&M) interface, enabling operators to control the selected device once logged in.

Key Features

1 | Overview

The overview page offers a geographical view of configured devices, allowing users to quickly identify the location and status of devices. Users can zoom in on the map to view detailed information about each device.

The geographical representation enables operators to identify device locations quickly and monitor their status in real-time. Furthermore, the zoom functionality allows specific areas to be enlarged for a more detailed view, making navigation intuitive and effective.

2 | Authentication

Dardo supports user and profile management, ensuring secure and personalized access to system functionalities. Users can be created and managed easily, with the ability to define roles and privileges for each profile.

3 | Devices

The section dedicated to devices offers a complete list of network devices managed by Dardo. Users can view detailed information about each device, manage alarms, and access usage statistics easily.

The device page allows users to monitor the operational status of devices and intervene promptly in case of anomalies. Through an intuitive interface, users can view detailed information about each device, including data such as IP address, operating status, and creation date.

4 | Centralized Management System

One of the standout features of Dardo is its capability to serve as a Centralized Management System, consolidating monitoring and control functions across various interfaces. Dardo seamlessly integrates with different network interfaces, offering comprehensive L1-L2 alarm collection and processing capabilities. This means that, regardless of the network infrastructure in place, whether it’s traditional copper-based networks or modern fiber-optic systems, Dardo can effectively monitor and manage the network’s health and performance.

5 | Statistics

Dardo’s intuitive GUI simplifies monitoring device performance and managing alarms, providing real-time statistics on bandwidth, packet loss, and latency to help operators quickly respond to network conditions. Alarms are categorized by severity, ensuring prompt attention to critical issues.

Conclusions

In conclusion, Dardo emerges as a comprehensive and reliable solution for managing network devices, offering advanced features and an intuitive interface. Thanks to its distinctive characteristics and user-friendly approach, Dardo stands as an essential ally for network administrators looking for effective tools for device control and management.

For more information on Dardo and its functionalities, feel free to reach out to us directly via email at marketing@microtelinnovation.com or through the contact form on our website. We’re here to assist you every step of the way.

Benefits of the “On-the-fly” feature

In today’s rapidly evolving digital landscape, network security and performance are paramount. Enterprises require efficient tools that can effectively manage and optimize network traffic. This is where packet brokers come into play, specifically, the A-640 packet broker, which offers a unique and powerful feature known as “on-the-fly” action. This article will explore the concept of on-the-fly action in packet brokers and discuss its benefits and implications in network operations.

Understanding "On-the-Fly" Action

The A-640 packet broker boasts the ability to perform actions and processes dynamically and in real-time, hence the term “on the fly.” This means that the device can make instantaneous decisions and adjustments to the routing and distribution of network packets with no downtime or manual intervention, keeping the link up and active

Instantaneous adjustments to the distribution of network packets without significant downtime

 Now let’s delve into some aspects related to the packet broker “on-the-fly” feature:

1 | Dynamic Traffic Redirection

One of the key advantages of on-the-fly action is the packet broker’s capability to dynamically redirect network traffic based on predefined criteria or conditions, either by user intervention or through an API system.                    For instance, it can swiftly reroute traffic in response to changes in network conditions, load balancing requirements, or security events. This flexibility ensures that network resources are efficiently utilized, enhancing performance and resilience.

2 | Packet Filtering

          Another compelling function of the packet broker’s on-the-fly action is its ability to perform real-time packet filtering.  With this feature, the device can dynamically identify and handle specific types of traffic according to defined filtering rules. This enables the packet broker to filter out malicious content or suspicious users on the fly, increasing network security and mitigating potential threats.

3 | "On-the-Fly" Load Balancing

        Efficient network resource utilization is a critical aspect of network management. Here, the on-the-fly load balancing feature shines. The A-640 packet broker can dynamically redistribute network traffic in real-time, optimally utilizing network resources. By adjusting the distribution of packets among different network links or servers based on the current load conditions, the packet broker ensures optimal performance and avoids bottlenecks.

Conclusions

The A-640 packet broker’s on-the-fly action feature revolutionizes network management by providing dynamic and real-time decision-making capabilities. With the ability to redirect traffic, perform packet filtering, and enable on-the-fly load balancing without significant downtime, this packet broker empowers enterprises to optimize network performance, enhance security, and adapt swiftly to changing network requirements. Embracing this innovative technology opens doors to efficient and scalable network management in an ever-evolving digital landscape.

Mobile Traffic Growth: How to manage it?

Due to the dramatic growth of mobile networks traffic, Telecom operators must upgrade monitoring and security tools because one single probe is not capable anymore to manage all User Plane traffic. Coherent balancing to several Probes is necessary and Microtel Innovation Aster A-640, thanks to its 32 x 100 GB ports, is the right investment for the future.

How to implement User Plane coherent balancing? Using GTP correlation may not be the right solution, because it requires lot of costly computational power. Moreover, it is difficult to implement in modern networks, where Control Plane Traffic and User Plane Traffic are often not in the same location.

Instead, Microtel Innovation Aster A-640 implement coherent balancing without using GTP correlation, and is able to balance User Plane Traffic in a way that all user plane sessions belonging to the same Subscriber are sent to the same Probe. 3G, 4G and 5G Core Network interfaces are supported; Aster A-640 can cope with up to 3,2 TB traffic.

Example: A-640 implementing GTP User Plane coherent balancing

 

USER PLANE BALANCING WITH ASTER A-640 – CASE HISTORY 

THE CHALLENGE

The customer, a Far East Tier1 Mobile operator, asked our support to manage the GTP traffic in a much more efficient way, given the growth it was having in the last period, achieving peak traffic values of 200G/250G in the Core Network sites.

Since the traffic was too much to be managed by one single probe, the Operator’s had to add additional probes, and to find the proper way to feed them: A-640 was the right solution that he was looking for.

Customer request was to feed all probes with the User Plane data, with the need that all traffic related to the same Mobile User has to be sent to the same probe, to grant a proper data analysis.

MICROTEL INNOVATION SOLUTION

To solve the customer issue the technical team proposed Microtel Aster A-640, a powerful L2-L4 advanced packet broker capable of balancing GTP User Plane traffic in a coherent way; both IPv6 and IPv4 are supported. It grants high flexibility and, using its special algorithm (no need for GTP correlation), A-640 can balance and forward specific subscriber sessions to one single tool.

A-640 has been installed, and it allows our customer to split the traffic toward 5 probes.

It receives 200G/250G data traffic during peak hours: input ports 1-2-3-4-7-8 are fed with GTP v2 (4G network) traffic, while input ports 5-6 receive GTP v1 (3G network) data.

Control plane traffic is replicated to all probes. User plane traffic is balanced in a coherent way to the 5 Probes the customer just installed: all sessions belonging to a single subscriber are sent to the same probe.

Solution: A-640 implementing GTP User Plane coherent balancing towards 5 customer Probes

New challenges in 5G network visibility

5G Network

5G deployments are moving beyond enhanced mobile broadband and fixed wireless access and are beginning to enable a wider range of use cases.

5G is the 5th generation mobile network: it is designed to connect virtually everyone and everything together including machines, objects, and devices. 5G wireless technology is meant to deliver higher multi-Gbps peak data speeds, ultra-low latency, more reliability, massive network capacity, increased availability, and a more uniform user experience to more users.

But: what about 5G Network Visibility? New challenges must be solved, and Microtel Innovation is here to help.

5G Network

The user plane traffic is continuously growing

Mobile traffic is growing more than expected, this is a clear trend of the past decades, and 5G networks will only accelerate it. Consumers and business users worldwide continue to create new demands and expectations for mobile networking. This ongoing trend is clearly highlighted by the adoption and use of mobile applications: social networking, video streaming and downloads, business productivity, e-commerce and gaming will drive the continued growth of mobile traffic.

According to the latest Ericsson Mobility Report, global mobile data is estimated to reach around 680EB per month by the end of 2021, and is projected to grow by a factor of around 4.6 to reach 370EB per month in 2027.

Global mobile network data traffic (EB per month)

How to handle all this traffic, in the Monitoring and Security space?

Microtel Innovation new Packet Brokers A-640 are the solution: they support session based traffic balancing to the security and monitoring tools, thanks to their capability to forward the traffic based on inner packet parameters. This is a key task to enable high volume user plane analysis. And they are future proof solutions: no problems with the growing traffic, since A-640 NPB can manage up to 3.2 Tbps of traffic.

Big infrastructure vendors tent to use their virtual TAP to provide virtual traffic to be monitored

 One challenge with the 5G Service-Based Architectures (SBA) is the encrypted nature of the communications between the 5G Core Network Functions.

NEM are proposing to do themselves the job of tapping the 5G network traffic, by means of their own virtual TAP, and to forward clear traffic (not encrypted) outside of the virtual infrastructure, usually by means of GRE tunnels, with the goal to feed monitoring and security tools. The format and transport of these data are still not standardized, but this seems to be a promising way to overcome the issue. 

A-640 NPBs are a perfect choice to actively handle GRE and VXLAN tunnel. They act as an active tunnel endpoint, with their own MAC/IP setting, they do tunnel termination and inside tunnel filtering and load balancing. In summary, they get the info from the vTAP, and they aggregate, filter and load balance them to the monitoring and security tools.

Additionally, the traffic sent by vTAPs can have multiple level of tunnels, since data coming from the virtual infrastructure are usually encapsulated using tunnels GRE, but also MPLS, VXLAN, VLAN, … in multiple levels: Microtel A-640 may strip partially or totally those encapsulations, in a configurable way depending on what the tools need, and filter and load balance original IP packets both on inner and outer parameters.

5G User Plane Balancing

THE CHALLENGE

Mobile networks are experiencing a continues traffic growth in last years: data traffic continues to grow at an exponential rate, driven by mobile video and OTT services. 

This is creating challenges for mobile operators, as they seek to keep up with traffic analysis and monitoring of all of the data on their network that needs to be processed and analysed.

Furthermore, the disaggregation of the control plane and physical separation of the control and user planes, actually used in modern networks like LTE CUPS and 5G deployments, adds additional complexity. 

For mobile carriers, efficiently and effectively monitor performance, Quality of Experience (QoE) and security for their services and subscribers, as well as identify and monetize new offerings is critical to success. But actual network probes that provide visibility into wireless core networks have limited capacity and may not cope with the exploding mobile subscriber traffic. Additional probes need to be added, and GTP User Plane traffic has to be balanced between them, granting that the whole IP Flow related to one particular session is sent to the same tool.

THE SOLUTION

Microtel Innovation Aster A-640 and A-648 gives the solution to this problem.

Balancing the GTP User Plane is not an easy task: it needs to be done in a way that grant that all the IP Flow traffic related to the same session is sent to the same probe, and assure best performances, so that the solution is future proof, ready for the growing data traffic that will be in the coming years.

How to do that? his can be achieved balancing the User Plane traffic using the Inner IP key, and doing that in hardware to avoid performances problems.

In fact, in GTP protocol the Inner IP is the Subscriber IP address, and balancing the traffic using such key will create User Plane traffic flows belonging to the same User IP sessions

Fig. 1 Inner IP in GTP frame (inner IP=IP packet sent by the phone)

Since the Control Plane traffic consists usually in a small percentage than the User Plane, there is no need to balance it. It can be forwarded to the Probes in different ways, depending on how the probe works: 

  • some monitoring systems have a Control Plane dedicated probe, in this case the Control Plane traffic is separated and sent only to the Control Plane probe (see fig2).
  • In other cases, User Plane probes require the Control Plane data too: in this situation the Network Packet Broker can replicate the Control Plane traffic and send it (all the Control Plane data) to each probe for further elaboration.

Fig. 2 GTP User Plane balancing using inner IP - example with 400G Input Traffic

Important to note, the solution described above makes no use of Control Plane-User Plane correlation, which is a very heavy activity to be done, and is in same cases difficult to implement, due to the fact that in modern networks, for example CUPS and 5G, Control Plane signalling and User Plane data are not always in the same location. 

To summarize, using Aster A-640 and Aster A-648 to balance User Plane traffic is the perfect solution when:

  • High performances are needed: Aster A-640 can cope with up to 3,2 TB traffic, with 32×40/100G input/output ports, each one of them can be used as 4×10/25G
  • Control Plane and User Plane data are not available in the same location, as it happens for example with CUPS and 5G Networks

Why Header Stripping?

THE CHALLENGE

In IP data communication networks, router and switches may create a tunnel between two points on a network that can securely transmit any kind of data between them. Tunnelling involves the encapsulation of an IP packet within another packet, adding a packet header. This encapsulation enables the packet to reach its destination through intermediary networks that do not support the packet’s protocol.

Different type of header may be used, depending on the place in the network and / or on the type of the network. A few examples are GRE, VLAN, MPLS, VN-Tag, VXLAN and GTP-U headers.

One example in telecommunication networks is GTP-U tunnel: it is used for efficiently carrying large volumes of user data within the mobile core network and between the radio access network and the core network.

In IP networks, one key application for MPLS tunnelling is switching traffic for a large enterprise across the service provider backbone, where MPLS labels keep the traffic distinct from other enterprises. In this case we may be in the following condition, when tapping MPLS tunnels between two routers, where they may be also the case that multiple stacked tags or labels might be present:

Tools that are not MPLS–aware nor VLAN-aware will not be able to analyse traffic received

The problem is that monitoring tools do usually not recognize tunnel headers, and the consequence is that they discard these packets as wrong packets, making impossible to properly analyse such networks. 

Header stripping is a useful feature also if the monitoring tools are able to recognize the tunnels and do the stripping, because doing that in an external appliance may provide greater efficiency for the tool where this process would degrade performances.

WHAT WE DO

Microtel Innovation NPB and Visibility Appliances analyses the input traffic, identifies specific headers such as MPLS, VLAN, VXLAN, VN-TAG, GTP-U and GRE, and removes them before sending the packets to the appropriate security and analysis tools. 

In this way analysis and monitoring tools are able to process traffic flows that they otherwise could not recognize because of an unreadable header type.

The solution is highly performant and scalable. Moreover, Microtel Innovation header stripping restores the inner frames: after this manipulation the resulting frame is a valid IP packet with a correct checksum.

Here is an example on how our system works: 

  • In Fig1 GTP-U header stripping is enabled, using the NPB GUI
  • Fig2 shows the result of the operation on the output traffic: since only frame 360 is GTP-U, this is the only one de-tunneled by the device.

Fig1: GTP-U header stripping is configured in the NPB GUI

Fig2: GTP-U frame header is stripped and the de-tunneled frame is sent to the NPB output port

IMSI filtering and subscribers visibility

How to offload the GTP User Plane traffic which does not belong to a list of subscribers?

THE CHALLENGE

Mobile data traffic continues to grow at an exponential rate, driven by mobile video and OTT services. Also if 5G is going to be deployed in many Telecom Operators networks, existing LTE mobile networks still have a high burden to carry, and it will continue to grow.

Monitoring this high volume traffic is a problem for the operators: they need it for troubleshooting and also for granting the best user experience to their customers, but the data traffic is growing at so high speed that they are not able to cope with it. 

In particular, for troubleshooting issues, sometime the information which are available in the GTP control plane is not enough: this is the case for example of a customer where the connection works perfectly, but OTT services, like skype, whatsapp, video, …, have some issues. 

In this case Telecom Operators need to analyse the User Plane traffic too: but they should do only for those subscribers who have the problems, otherwise they will kill probe processing capabilities. How to do that? The solution is to filter the User Plane traffic and forward it to the probes only for the subscribers who need that, and who belong to a specific list.

To identify uniquely the subscriber, the IMSI code may be used: IMSI is a unique number rigidly tied to the subscriber SIM card, and the operator can easily refer to its subscriber data base to identify such code.

This way the monitoring tools load will be highly reduced, and also privacy and legal issues will be solved.

THE SOLUTION

The solution which Microtel Innovation provides is robust, and do not require any difficult operator tasks: our Aster GTP Packet Brokers may filter the GTP User Plane traffic based on IMSI White and Black lists, by correlating GTP Control and User plane data. 

One specific Use Case is related to do User Plane troubleshooting, and in the same time to grant the compliance with the privacy regulations: some Operators, due to GDPR rules, have put in place a strict process which prevent them from forwarding subscribers User Plane traffic to the Monitoring Probes, without subscribers’ approval. User Plane traffic analysis can be done only if and when the subscriber authorizes such activity.

Using Microtel Innovation Aster GTP Packet Brokers, this is a very easy task to implement. While all Control Plane traffic is send to the monitoring tools for generic troubleshooting purposes, the following process can be used for the User Plane data:

  • Customer approval is required before sending the User Plane data to the tools, for troubleshooting or any other agreed purpose 
  • Through the Operator’s customer portal such approval is registered in the Operator’s data base
  • At this point, the customer IMSI may be added to the Aster GTP Packet Broker White List: just few clicks on our seamless and easy to use Graphical User Interface, and this is done
  • From now on, the Aster GTP Packet Broker send the customer user data to the tools
  • It will stop when the IMSI is removed from the Aster White List.

Fig1: How to make GDPR and user data analysis coexist: an existing implementation