IPX and IoT

Arelion’s IoT backbone separates IoT traffic from public Internet traffic, connecting operators and enterprises directly to device management platforms via a highly scalable and robust IPX transport solution.

The backbone for the Internet of Things

The possibilities of IoT are huge, but so are the consequences. That’s why we believe IoT demands a backbone featuring the highest industry standards. Your dedicated IoT backbone connects mobile operators and enterprises directly to device management platforms in a single network hop with the lowest possible delay. Learn more about what Internet backbone is and what makes a good Internet backbone.

Partition traffic from the public internet

The "things" are coming – and so is their data. As this continues to grow, and as more applications become mission-critical, peering logic driven by 5G goes to the next level. Many IoT applications call for a higher quality of end-to-end connectivity and security.

You get the end-2-end oversight required for all your IoT traffic. By using pre-integrated service-topology, we can get you quickly to market in order to capitalize on the emerging possibilities of IoT.

What customers say

DENT has chosen Arelion as one of the central partners for its mobile cloud solutions. As a digital and global operator, we provide our customers (...) the most convenient way of staying online while traveling. Arelion meets the high demands for reliability and security of our customers and its great experience in IPX networks helps us to innovate. Arelion’s fair pricing models also help us to stay ahead of the competition.

Philipp Gasteiger, Senior Consultant, Digital Oxygen GmbH

1NCE GmbH has been cooperating with Arelion for a year and Arelion has had a very fast and constructive dialogue since first meeting. The progress (...) of the project was ensured very professionally. In fact, at our request, a new project was created – IPX connection to AWS cloud, which also supports AWS specific features, like BGP community export and others. The flexibility with which Arelion provided the essentially customized product is at a very high level. In the context of operational cooperation, I would especially like to note very good announcements for planned maintenances – those are always very well explained and sent in timely manner. The overall communication is superb! We are very pleased with the cooperation and hope that it will continue and develop successfully with the development of our company.

Jans Jelinskis, Technical director, 1NCE Latvia SIA

    End-to-end control

    The Internet of Things (IoT) is expanding in all directions, with the potential to create real value – and real security concerns. When data transits between networks, you lose visibility, reliability, and security. The only way to guarantee end-2-end quality is to have end-2-end control. And that’s what we offer you.

    Our IoT backhaul solution is a hub and spoke configuration powered by our global IPX backbone. Our IPX network is GSMA-, IEEE- and I3F-compliant, and it is faster and easier to connect compared to layer-2 MPLS solutions. Your IoT traffic stays separate and safe from the Public Internet. We guarantee end-2-end, our network's lowest possible latency, with Class of Service (CoS) awareness and committed Quality of Service (QoS) for the best possible results, which we express in our Service Level Agreements.

    Reliable and accountable

    Our red and blue network architecture means full redundancy designed from the ground up. This means network availability of up to 99.999% at the edge. Critical applications, like autonomous vehicles, utilities, and health services increasingly rely on the IoT.
    At the same time, billions of commodity devices are rapidly joining the public Internet in a set-and-forget state, making security a make-or-break factor for the future of IoT. And, if anything does go wrong, you have the simplicity of a single point of accountability. We are always on call to assist you with our award-winning multi-lingual customer care team, available 24/7/365.

    Cloud connected IPX

    • Exten your network to the cloud – using our dedicated and private connections to AWS, Google, Azure, Oracle, and IBM - via Telia Carrier’s global backbone - to reach, e.g. your virtual packet gateways or any other cloud-placed nodes or platforms.
    • Controlled cloud connectivity – using these direct connections to the major cloud providers, we provide you with a secure inroad to the cloud. Cloud Connect is a private and dedicated connection that bypasses the public Internet – giving you more control of your bandwidth, with high levels of security and reliability.
    • Scaling multiple clouds – Cloud Connect allows you to use a single port to connect to one or multiple cloud providers – making it a cost efficient way to scale cloud connectivity. Your bandwidth needs for cloud usage will aways be serviceable as we operate with ample capacity to ensure our global backbone is optimized for highly scalable, burstable workloads.
    • Fast response – just like your business, we offer a high degree of agility. The average contract lead time is 7 days and average delivery time is 21 days.
    Read more about the defination of Cloud Connect and connectivity methods.

    Technique and security

    Technical highlights
    Features
    Checked Data segmentation to prevent signaling-storms and traffic-bursts
    Checked Faster and easier to connect compared to layer-2 MPLS solutions
    Checked Based on end-to-end, low latency DWDM network
    Checked 24/ 7/365 help desk with direct access to specialist security partners
    Checked Easy to integrate with third party VAS services and firewalls
    Security highlights

    Our dedicated and private AS8837 IPX network operates on top of Arelion’s backbone.

    Secure by design features
    Checked Compliant with all applicable GSMA standards for IPX security & DNS (IR.34, IR.67, IR.77 etc.)
    Checked Experienced in addressing IoT-platform interoperability challenges
    Checked Facility to route traffic to your IoT steering platform and roaming hubs
    Checked Automatic switchover thanks to fully redundant Red and Blue networks
    Checked NOC situated in a well secured and connected building with multiple power sources
    Checked Physical and logical security considered from design to deployment
    Checked Network-wide User Acceptance Policy
    Checked Customer Service authentication procedures
    Checked Clear customer data handling policies
    Checked Clear customer instructions regarding business changes and incident management

    IPX to Cloud Connect solution

    10 quick questions for Robert Sommeling, Arelion Operations product manager

    How does Arelion reach its roaming partners?

    Since Arelion is a Tier 1 IPX, we cover complete A-Z reach across our direct and peering reach. This applies to GRX, Diameter and SS7 (a full reach list is available upon request).

    Describe Arelion's service continuity mechanisms

    Arelion's IPX network is designed to support Multiple Services over One Port (MSOP). This means that where our customer is using us for IP Transit services, we can logically separate IPX traffic on the same physical port. Dedicated IPX port capacity is also central to what we do, which supports increase in security and overall availability.

     

    Arelion recommends redundant base architectures. Each port can be configured using VLANs to logically separate, control and measure individual dedicated traffic streams. Furthermore, our IPX network is Class of Service (CoS) aware, allowing Mobile Operators to prioritize traffic streams according to CoS recommendations.

    Today we support Data Payload (GRX, includes S8), Diameter (DRX), SIGTRAN (RoamConnect), Voice over IPX (VolPX), and loT backhaul (M2M traffic). Our network contains IP-STP's, Diameter-Routers and SIP-Proxies to support hosted interworking solutions for all traffic types.

     

    • Arelion has a Multi Terabit enabled, fully redundant and geographically diverse IPv4 and IPv6 dual stack IPX Core and distribution network. It has been designed and built with complete redundancy and security as starting point, and as such is compliant with all relevant GSMA IPX guidelines (a/o PRD IR.34, IR.67 & IR.77)
    • Arelion implements a fully redundant physical and logical IPX network architecture
    • We advise our clients to adhere a fully redundant physical architecture as well, deployed in either a simplex B (dual links) or full mesh B-Quad (4 links) design
    • The SIGTRAN and Diameter capacities should be dimensioned to support not more than 40% link utilization to always ensure that in a failover scenario the redundant links have ample capacity to support the additional load
    • Arelion advises the configuration of SCTP associations in an M3UA or M2PA multihomed configuration
    • We advise all signaling protocols to be load shared and balanced in an Active / Active configuration
    • Data Payload traffic such as GRX/S8 can be supported in an Active / Active, or Active / Standby configuration. Active/ Standby is recommended
    • Arelion can support redundancy over IPsec. However, it is not recommended for signaling protocols as it can cause sub-optimal performance of SCTP timers, leading to buffering and re-transmits.
    • Arelion follows strict implementation and testing procedures, before declaring services as 'ready for use'
    Describe Internet backbone architecture topology (incl. redundancy & reliability mechanisms in place)

    Arelion owns and operates one of the world's largest fully diverse MPLS core networks.

    • IPX PoP diversity: Geographical diversity was key in the planning and implementation our IPX infrastructure. Arelion IPX is currently deployed in geographically diverse PoPs around the globe with additional PoPs in planning stages.
    • IPX PoP hardware redundancy: Within each IPX PoP, there is a complete redundant infrastructure. All aggregate and core routers, switches, firewalls, have been deployed in pairs to provide for the highest level of diversity within each IPX PoP. At our core PoPs we have deployed redundant Diameter proxies, 3GPP DNS servers and IPX proxies. Dual-power, dual-processor and fault-tolerant systems are deployed at all PoPs to aid in seamless recovery and auto-healing abilities. Furthermore, at each IPX PoP, we have deployed redundant core routers allowing changes in either customer access or core functionality without impact to customer traffic.
    • IPX PoP Transport Redundancy and Diversity: Our IPX PoPs are inter-connected on our fully meshed Multi Terabit enabled IPX backbone. The backbone access circuits are provisioned with complete diversity. Every effort is given to provision the circuits with no single point of failure or common point of interconnect, including access into the customer facility/conduit where possible. Additionally, our core infrastructure is designed so that any single connection into an IPX PoP will support all traffic for that PoP in a potential fail-over scenario amongst others achieved via our world-wide, both logical as well as physical fully separated Red and Blue DWDM backbone network.
    • Service availability: Carrier-grade - 99.999% with SLA
    • DNS redundancy support: Arelion's DNS infrastructure is deployed in a gee-redundant design for both .gprs and .3gppnetwork DNS servers.
    • Proxy redundancy support: Diameter and network proxies are gee-redundant and engineered to provide full failover capabilities between sites.

     

    Security

    Arelion IPX backbone is configured for protection against different forms of security threats such as DDoS/DoS, packet spoofing, route spoofing, label spoofing, etc. 
    As aforementioned, we follow the GSMA IR.77 guidelines for inter-operator provider security rules that include Anti-Route and Anti-Packet spoofing protection. On the Ethernet layer, we also deploy VLANs to logically separate traffic for different services including GRX/ SB Data Payload, SIGTRAN and Diameter, which is integrated to the corresponding service segment by dedicated MPLS VPNs on the IP transport layer. Our IPX network is completely isolated from public Internet and unauthorized access is denied.

     

    The following are a sample of examples of the measures taken for protection our IPX backbone network:

     

    Route spoofing protection

    • Customers identify what networks they wish to advertise, and Arelion confirms that they are entitled to advertise those networks to IPX
    • Arelion's IPX network edge routers check all route advertisements against a pre-defined prefix-list to determine if that route is for a network, which belongs to that customer
    • Any non-compliant advertisements are discarded at the Edge routers

     

    Packet spoofing protection

    • Customers identify what networks they wish to advertise
    • All incoming packets are checked against a pre-defined access-list to ensure that the source address belongs to the Operator's networks. Arelion's IPX Edge routers discard any IP packets that arrive from sources that do not belong to the Operator's advertised networks

     

    Label spoofing protection

    • Since packets only enter the Arelion IPX MPLS network via pre-defined PE-CE interfaces, label spoofing is not possible. Arelion does not exchange undefined MPLS Labels
    • Packets on our customer-facing connections; all customer interconnectivity is established via Native IP at layers 2/3
    • Arelion IPX does not participate in any Inter-AS or Carrier-Supporting-Carrier connectivity which would allow labelled-packets from outside sources to enter the Arelion IPX backbone

     

    SIGTRAN Security Features include the following:

    • Guard against port scanning
    • Guard against UDP/TCP flooding
    • Guard against DDoS
    • MTP security features
    • SCCP security features
    • TCAP security features
    • MAP security features
    • CAP security features
    • INAP security features
    • Obtaining subscriber information
    • Eavesdropping on subscriber traffic
    • SMS frauds
    • Open SMSC
    • Network outage and disruption of subscriber services
    • DoS against network elements
    • DoS against users
    • Authentication vector theft
    • Interworking specific attacks
    • MTP policing
    • SCCP policing
    • TCAP policing
    • MAP policing
    • CAP policing
    • Combination of parameters for policing
    • Cat 1 MAP Messages blocking
    • Blocking of traffic from non-partners
    • Separate reporting of all signalling security incidents

     

    Our dedicated and private AS8837 IPX network operates on top of Arelions Blue and Red, wholly owned (trench and sea-cable upwards) fully redundant DWDM topology.

     

    Arelions IPX is designed in a layered manor. At each backbone location, the Arelion IPX network divided over two more (local) gee-redundant sites, where one site is connected to our Red-DWDM network and the other to our Blue-DWDM network. The fully divergent DWDM network itself is about 75,000 km wide and spans across the whole globe in such a manner that at no point wherever - these two networks cross each other.

     

    The IPX core network then is attached and integrated further, whilst using a single AS (8837) into a layer we refer to as the distribution layer by connecting strategically placed, worldwide distributed, fully redundant duo-lPX routers (each time: one on Red and the other on Blue).

    Arelion can provide the kmz maps for fibers from the locations of the physical interconnects to specified locations of customer interest.

    Arelion can provide 10 Gb (Base-LR) ports at over 400 locations globally.

    All services can be delivered on redundant physical NNl's (Network-to-Network Interface), configured using VLANs for complete logical separation and class of service attribution. GRX is typically configured in Active / Standby mode, and SIGTRAN and Diameter Protocols are configured using Active / Active mode allowing proper load-sharing.

    What happens when we agree on specific POPs for NNI?

    Subject to working on an agreed final design with our customers, Arelion will define a detailed demarcation point during the s solution design phase (standard TC demark in the PoP, no cross-connect included, no local-tail included).

    Timeframes needed for requested capacity upgrades & reductions as well as for any requirement for prior notice

    Once a service is delivered and in production, service upgrades and downgrades can be done very quickly. If no augmentation is needed to the physical architecture, changes to bandwidth can be done the same day as the order is executed. Orders can usually be completed in 2 business days, subject to standard network freeze periods, e.g., Christmas.

     

    If any physical component needs to be augmented, it can take from 2 weeks for a cross connect, to 8 weeks for a local tail or leased line; pending 3rd party suppliers. For this reason, we, as standard propose to build the solution using redundant 10 Gb ports from day one, to avoid running out of capacity.

    SLA level (especially important - guaranteed time of restoring)

    Please refer to our SLA documents and Master Service agreements, available upon request. As a minimum, Arelion's SLA is compliant to GSMA PRD IR.34 (version updates are available upon request, or at the GSMA Info Centre http://infocentre2.gsma.com/).

    Additional general information
    • Delivery time all services (accurate date to be agreed bilaterally)
      • Please allow an average of 4 to 6 weeks for delivery times, including cross-connects. If leased lines are required, this will increase time to 8 to 12 weeks. All pending 3rd party suppliers
    • Payment for outgoing traffic only
      • Only outbound traffic is chargeable (Outbound means from customer to Arelion)
    • Monthly payment for burst:
      • Payment for the burst traffic is billed in arrears, meaning 30 days after the traffic has been measured, collated
    • Currency
      • Payment in major global currencies is preferred, including US Dollar, Euro, British Pounds and Swedish krona
      • Warranties - Except as otherwise stated in this agreement, Arelion makes no representations or warranties about the service or the quality of the service provided, whether express, implied, by operation of law or in fact including, without limitation, any warranty of merchantability or fitness for a particular purpose
      • Upgrades - service upgrades and downgrades are available during the term of the agreement with 7 days' notice, and on completion of a new service order form

     

    Delivery - a dedicated service delivery manager will work with you to ensure fast implementation of the services

    More about IPX to cloud

    Learn more about why to choose IPX to Cloud Connect solution. The solution is aimed for customers that require more control of their bandwidth, i.e. a high level of flexibility and scalability, using a dedicated connection to the cloud.