Arelion’s IoT backbone separates IoT traffic from public Internet traffic, connecting operators and enterprises directly to device management platforms via a highly scalable and robust IPX transport solution.
You get the end-2-end oversight required for all your IoT traffic. By using pre-integrated service-topology, we can get you quickly to market in order to capitalize on the emerging possibilities of IoT.
Our IoT backhaul solution is a hub and spoke configuration powered by our global IPX backbone. Our IPX network is GSMA-, IEEE- and I3F-compliant, and it is faster and easier to connect compared to layer-2 MPLS solutions. Your IoT traffic stays separate and safe from the Public Internet. We guarantee end-2-end, our network's lowest possible latency, with Class of Service (CoS) awareness and committed Quality of Service (QoS) for the best possible results, which we express in our Service Level Agreements.
Features |
|---|
|
|
Data segmentation to prevent signaling-storms and traffic-bursts |
|
|
Faster and easier to connect compared to layer-2 MPLS solutions |
|
|
Based on end-to-end, low latency DWDM network |
|
|
24/ 7/365 help desk with direct access to specialist security partners |
|
|
Easy to integrate with third party VAS services and firewalls |
Our dedicated and private AS8837 IPX network operates on top of Arelion’s backbone.
Secure by design features |
|---|
|
|
Compliant with all applicable GSMA standards for IPX security & DNS (IR.34, IR.67, IR.77 etc.) |
|
|
Experienced in addressing IoT-platform interoperability challenges |
|
|
Facility to route traffic to your IoT steering platform and roaming hubs |
|
|
Automatic switchover thanks to fully redundant Red and Blue networks |
|
|
NOC situated in a well secured and connected building with multiple power sources |
|
|
Physical and logical security considered from design to deployment |
|
|
Network-wide User Acceptance Policy |
|
|
Customer Service authentication procedures |
|
|
Clear customer data handling policies |
|
|
Clear customer instructions regarding business changes and incident management |
10 quick questions for Robert Sommeling, Arelion Operations product manager
Since Arelion is a Tier 1 IPX, we cover complete A-Z reach across our direct and peering reach. This applies to GRX, Diameter and SS7 (a full reach list is available upon request).
Arelion's IPX network is designed to support Multiple Services over One Port (MSOP). This means that where our customer is using us for IP Transit services, we can logically separate IPX traffic on the same physical port. Dedicated IPX port capacity is also central to what we do, which supports increase in security and overall availability.
Arelion recommends redundant base architectures. Each port can be configured using VLANs to logically separate, control and measure individual dedicated traffic streams. Furthermore, our IPX network is Class of Service (CoS) aware, allowing Mobile Operators to prioritize traffic streams according to CoS recommendations.
Today we support Data Payload (GRX, includes S8), Diameter (DRX), SIGTRAN (RoamConnect), Voice over IPX (VolPX), and loT backhaul (M2M traffic). Our network contains IP-STP's, Diameter-Routers and SIP-Proxies to support hosted interworking solutions for all traffic types.
Arelion owns and operates one of the world's largest fully diverse MPLS core networks.
Security
Arelion IPX backbone is configured for protection against different forms of security threats such as DDoS/DoS, packet spoofing, route spoofing, label spoofing, etc.
As aforementioned, we follow the GSMA IR.77 guidelines for inter-operator provider security rules that include Anti-Route and Anti-Packet spoofing protection. On the Ethernet layer, we also deploy VLANs to logically separate traffic for different services including GRX/ SB Data Payload, SIGTRAN and Diameter, which is integrated to the corresponding service segment by dedicated MPLS VPNs on the IP transport layer. Our IPX network is completely isolated from public Internet and unauthorized access is denied.
The following are a sample of examples of the measures taken for protection our IPX backbone network:
Route spoofing protection
Packet spoofing protection
Label spoofing protection
SIGTRAN Security Features include the following:
Our dedicated and private AS8837 IPX network operates on top of Arelions Blue and Red, wholly owned (trench and sea-cable upwards) fully redundant DWDM topology.
Arelions IPX is designed in a layered manor. At each backbone location, the Arelion IPX network divided over two more (local) gee-redundant sites, where one site is connected to our Red-DWDM network and the other to our Blue-DWDM network. The fully divergent DWDM network itself is about 75,000 km wide and spans across the whole globe in such a manner that at no point wherever - these two networks cross each other.
The IPX core network then is attached and integrated further, whilst using a single AS (8837) into a layer we refer to as the distribution layer by connecting strategically placed, worldwide distributed, fully redundant duo-lPX routers (each time: one on Red and the other on Blue).
Arelion can provide the kmz maps for fibers from the locations of the physical interconnects to specified locations of customer interest.
Arelion can provide 10 Gb (Base-LR) ports at over 400 locations globally.
All services can be delivered on redundant physical NNl's (Network-to-Network Interface), configured using VLANs for complete logical separation and class of service attribution. GRX is typically configured in Active / Standby mode, and SIGTRAN and Diameter Protocols are configured using Active / Active mode allowing proper load-sharing.
Subject to working on an agreed final design with our customers, Arelion will define a detailed demarcation point during the s solution design phase (standard TC demark in the PoP, no cross-connect included, no local-tail included).
Once a service is delivered and in production, service upgrades and downgrades can be done very quickly. If no augmentation is needed to the physical architecture, changes to bandwidth can be done the same day as the order is executed. Orders can usually be completed in 2 business days, subject to standard network freeze periods, e.g., Christmas.
If any physical component needs to be augmented, it can take from 2 weeks for a cross connect, to 8 weeks for a local tail or leased line; pending 3rd party suppliers. For this reason, we, as standard propose to build the solution using redundant 10 Gb ports from day one, to avoid running out of capacity.
Please refer to our SLA documents and Master Service agreements, available upon request. As a minimum, Arelion's SLA is compliant to GSMA PRD IR.34 (version updates are available upon request, or at the GSMA Info Centre http://infocentre2.gsma.com/).
Delivery - a dedicated service delivery manager will work with you to ensure fast implementation of the services
Learn more about why to choose IPX to Cloud Connect solution. The solution is aimed for customers that require more control of their bandwidth, i.e. a high level of flexibility and scalability, using a dedicated connection to the cloud.