AWS Site-To-Site VPN User Guide AWS Site-To-Site VPN User Guide

Total Page:16

File Type:pdf, Size:1020Kb

AWS Site-To-Site VPN User Guide AWS Site-To-Site VPN User Guide AWS Site-to-Site VPN User Guide AWS Site-to-Site VPN User Guide AWS Site-to-Site VPN: User Guide Copyright © Amazon Web Services, Inc. and/or its affiliates. All rights reserved. Amazon's trademarks and trade dress may not be used in connection with any product or service that is not Amazon's, in any manner that is likely to cause confusion among customers, or in any manner that disparages or discredits Amazon. All other trademarks not owned by Amazon are the property of their respective owners, who may or may not be affiliated with, connected to, or sponsored by Amazon. AWS Site-to-Site VPN User Guide Table of Contents What is Site-to-Site VPN ..................................................................................................................... 1 Concepts ................................................................................................................................... 1 Working with Site-to-Site VPN ..................................................................................................... 1 Site-to-Site VPN limitations ......................................................................................................... 2 Pricing ...................................................................................................................................... 2 How AWS Site-to-Site VPN works ........................................................................................................ 3 Site-to-Site VPN Components ...................................................................................................... 3 Virtual private gateway ....................................................................................................... 3 Transit gateway ................................................................................................................. 3 Customer gateway device .................................................................................................... 4 Customer gateway ............................................................................................................. 4 IPv4 and IPv6 support ................................................................................................................ 4 Site-to-Site VPN categories ......................................................................................................... 4 Site-to-Site VPN tunnel options ................................................................................................... 5 Site-to-Site VPN tunnel authentication options ............................................................................ 10 Pre-shared keys ................................................................................................................ 10 Private certificate from AWS Certificate Manager Private Certificate Authority .......................... 10 Site-to-Site VPN tunnel initiation options .................................................................................... 10 VPN tunnel IKE initiation options ....................................................................................... 10 Rules and limitations ........................................................................................................ 11 Working with VPN tunnel initiation options ......................................................................... 11 Endpoint replacements ............................................................................................................. 11 Endpoint replacements during VPN tunnel updates .............................................................. 11 Endpoint replacements during VPN connection modifications ................................................ 12 Customer gateway options ........................................................................................................ 12 Accelerated Site-to-Site VPN connections .................................................................................... 13 Enabling acceleration ........................................................................................................ 14 Rules and restrictions ........................................................................................................ 14 Pricing ............................................................................................................................ 14 Site-to-Site VPN routing options ................................................................................................ 14 Static and dynamic routing ................................................................................................ 15 Route tables and VPN route priority ................................................................................... 15 Routing during VPN tunnel endpoint updates ...................................................................... 17 IPv4 and IPv6 traffic ......................................................................................................... 17 Getting started ................................................................................................................................ 18 Prerequisites ............................................................................................................................ 18 Create a customer gateway ....................................................................................................... 19 Create a target gateway ............................................................................................................ 20 Create a virtual private gateway ......................................................................................... 20 Create a transit gateway ................................................................................................... 20 Configure routing ..................................................................................................................... 20 (Virtual private gateway) Enable route propagation in your route table .................................... 21 (Transit gateway) Add a route to your route table ................................................................ 22 Update your security group ....................................................................................................... 22 Create a Site-to-Site VPN connection .......................................................................................... 22 Download the configuration file ................................................................................................. 23 Configure the customer gateway device ...................................................................................... 24 Architectures .................................................................................................................................... 25 Single and multiple connection examples .................................................................................... 25 Single Site-to-Site VPN connection ..................................................................................... 25 Single Site-to-Site VPN connection with a transit gateway ..................................................... 25 Multiple Site-to-Site VPN connections ................................................................................. 26 Multiple Site-to-Site VPN connections with a transit gateway ................................................. 26 Site-to-Site VPN connection with AWS Direct Connect .......................................................... 27 iii AWS Site-to-Site VPN User Guide AWS VPN CloudHub ................................................................................................................. 27 Overview ......................................................................................................................... 28 Pricing ............................................................................................................................ 29 Using redundant Site-to-Site VPN connections to provide failover .................................................. 29 Your customer gateway device ........................................................................................................... 32 Example configuration files ....................................................................................................... 33 Requirements for your customer gateway device .......................................................................... 35 Configuring a firewall between the internet and your customer gateway device ................................ 38 Multiple VPN connection scenarios ............................................................................................. 39 Routing for your customer gateway device .................................................................................. 40 Example configurations for static routing .................................................................................... 40 Example configuration files ............................................................................................... 40 User interface procedures for static routing ......................................................................... 41 Additional information for Cisco devices .............................................................................. 50 Testing ............................................................................................................................ 51 Example configurations for dynamic
Recommended publications
  • Usporedba Linux I Microsoft Poslužiteljske Infrastrukture Kao Potpore Poslovanju Malih Tvrtki
    USPOREDBA LINUX I MICROSOFT POSLUŽITELJSKE INFRASTRUKTURE KAO POTPORE POSLOVANJU MALIH TVRTKI Stanešić, Josip Undergraduate thesis / Završni rad 2020 Degree Grantor / Ustanova koja je dodijelila akademski / stručni stupanj: Algebra University College / Visoko učilište Algebra Permanent link / Trajna poveznica: https://urn.nsk.hr/urn:nbn:hr:225:716198 Rights / Prava: In copyright Download date / Datum preuzimanja: 2021-10-02 Repository / Repozitorij: Algebra Univerity College - Repository of Algebra Univerity College VISOKO UČILIŠTE ALGEBRA ZAVRŠNI RAD Usporedba Linux i Microsoft poslužiteljske infrastrukture kao potpore poslovanju malih tvrtki Josip Stanešić Zagreb, veljača 2020. Pod punom odgovornošću pismeno potvrđujem da je ovo moj autorski rad čiji niti jedan dio nije nastao kopiranjem ili plagiranjem tuđeg sadržaja. Prilikom izrade rada koristio sam tuđe materijale navedene u popisu literature, ali nisam kopirao niti jedan njihov dio, osim citata za koje sam naveo autora i izvor, te ih jasno označio znakovima navodnika. U slučaju da se u bilo kojem trenutku dokaže suprotno, spreman sam snositi sve posljedice, uključivo i poništenje javne isprave stečene dijelom i na temelju ovoga rada. U Zagrebu 1. veljače 2020. Josip Stanešić Predgovor Želio bih se zahvaliti svom mentoru i profesoru Vedranu Dakiću, profesorima Silviju Papiću i Jasminu Redžepagiću kao i svim ostalim profesorima na uloženom trudu, prenesenom znanju i odličnom preddiplomskom studiju. Također se želim zahvaliti obitelji na svoj podršci pruženoj tijekom studija. Prilikom uvezivanja rada umjesto ove stranice ne zaboravite umetnuti original potvrde o prihvaćanju teme završnog rada kojeg ste preuzeli u studentskoj referadi Sažetak Male tvrtke osnova su ekonomije Europe. U suvremenom poslovanju IT tehnologija i samim time IT infrastruktura nužni su za poslovanje čak i u tvrtkama kojima osnovna djelatnost nije u području informacijsko-komunikacijskih tehnologija.
    [Show full text]
  • President's Corner
    TAPR PSR #137 Winter 2018 President’s Corner By Steve Bible, N7HPR TAPR will be at the HamSCI Workshop <https://tinyurl.com/y8errhsu > on February 23 and 24 at the New Jersey Institute of Technology in Newark. I, along with a handful of other TAPR officers and board members will attend the workshop, which will focus on the results of the 2017 Great American Eclipse ham radio ionospheric experiment and the development of a Personal Space Weather station. As in the past, TAPR will be at Hamvention <http://www.hamvention.org> in May with a suite of booths, our highly regarded TAPR Forum and the annual TAPR- AMSAT Banquet, President’s Corner 01 In the fall, the 37th annual ARRL/TAPR Digital Communications Conference PulsePuppy 02 (DCC) will take place September 14-16 in Albuquerque, New Mexico. The Greg Jones Memorial Endowment 03 conference invites technical papers for presentation at the conference and for Phase 4 Space Kickoff 04 publication in the Conference Proceedings (presentation at the conference is not XC-3006 06 required for publication). Papers are due by July 31, 2018, to Maty Weinberg, Evangelizing Ham Radio Data Modes 07 Set Up an IPv6 Gateway on Packet 08 ARRL, 225 Main St., Newington, CT 06111 or via e-mail to [email protected]. The TAPR Wear Available 10 Conference website <http://www.tapr.org/dcc> has full details. Aruba on a Sloper 11 Hope to see you in Newark, Xenia and Albuquerque! N7DRB SK 12 Write Here! 13 73, On the Net 13 Steve Bible, N7HPR, President TAPR The Fine Print 14 ### Our Membership App 15 TAPR is a community that provides leadership and resources to radio amateurs for the purpose of advancing the radio art.
    [Show full text]
  • Master Thesis
    Master's Programme in Computer Network Engineering, 60 credits MASTER Connect street light control devices in a secure network THESIS Andreas Kostoulas, Efstathios Lykouropoulos, Zainab Jumaa Network security, 15 credits Halmstad 2015-02-16 “Connect street light control devices in a secure network” Master’s Thesis in Computer Network engineering 2014 Authors: Andreas Kostoulas, Efstathios Lykouropoulos, Zainab Jumaa Supervisor: Alexey Vinel Examiner: Tony Larsson Preface This thesis is submitted in partial fulfilment of the requirements for a Master’s Degree in Computer Network Engineering at the Department of Information Science - Computer and Electrical Engineering, at University of Halmstad, Sweden. The research - implementation described herein was conducted under the supervision of Professor Alexey Vinel and in cooperation with Greinon engineering. This was a challenging trip with both ups and downs but accompanied by an extend team of experts, always willing to coach, sponsor, help and motivate us. For this we would like to thank them. We would like to thank our parents and family for their financial and motivational support, although distance between us was more than 1500 kilometres. Last but not least we would like to thank our fellow researchers and friends on our department for useful discussions, comments, suggestions, thoughts and also creative and fun moments we spend together. i Abstract Wireless communications is a constantly progressing technology in network engineering society, creating an environment full of opportunities that are targeting in financial growth, quality of life and humans prosperity. Wireless security is the science that has as a goal to provide safe data communication between authorized users and prevent unauthorized users from gaining access, deny access, damage or counterfeit data in a wireless environment.
    [Show full text]
  • Cisco Router Block Wan Request
    Cisco Router Block Wan Request Equalitarian Fletcher sometimes daggled any aftershock unchurch conceptually. Computational Felix never personifies so proficiently or blame any pub-crawl untunably. Precedential and unsupervised Scott outspoke while cephalic Ronny snag her midlands weak-mindedly and kotows unsafely. Can you help me? Sometime this edge can become corrupted and needs to be cleared out and recreated. Install and Tuning Squid Proxy Server for Windows. Developed powerful partnerships with each physical network address on wan request. Lot we need to wan request to establish a banner for each nic ip blocks java applets that you find yourself having different. Proxy will obscure any wan cisco require a banner for yourself inside network address in its child and password: select os of attacks? Authorized or https, follow instructions below and see if a cisco and share your isp and sends vrrp advertisements, surf a traveling businesswoman connects after migration done on. Iax trunk on vpn for ospf network devices and how will have three profiles to be found over time a routing towards internet security profile. Pfsense box blocks as your wan cisco router request cisco router block wan requests specifically for commenting. Centralize VLAN, outbound policy, firewall rules, configuration profiles and more in minutes. Uncheck block cisco router wan request check box displays detailed statistics: wan request through our go. Fragmentation is choppy and asa would be the cisco request to content; back of connect wan rules for outside world? Is to configure static content on the result in theory this may block cisco wan router request check out ping requests.
    [Show full text]
  • Windows Server 2012 R2 Directaccess
    Windows Server 2012 R2 DirectAccess Deployment Guide UPDATED: 25 March 2021 Windows Server 2012 R2 DirectAccess Copyright Notices Copyright © 2002-2021 Kemp Technologies, Inc. All rights reserved. Kemp Technologies and the Kemp Technologies logo are registered trademarks of Kemp Technologies, Inc. Kemp Technologies, Inc. reserves all ownership rights for the LoadMaster and Kemp 360 product line including software and documentation. Used, under license, U.S. Patent Nos. 6,473,802, 6,374,300, 8,392,563, 8,103,770, 7,831,712, 7,606,912, 7,346,695, 7,287,084 and 6,970,933 kemp.ax 2 Copyright 2002-2021, Kemp Technologies, All Rights Reserved Windows Server 2012 R2 DirectAccess Table of Contents 1 Introduction 5 1.1 Document Purpose 5 1.2 Intended Audience 5 1.3 Related Firmware Version 5 1.4 About the Author 6 1.5 Assumptions 6 2 Load Balancing DirectAccess 7 2.1 Example Environment Setup 8 2.2 Prerequisites 9 3 Virtual Service Configuration 10 3.1 Enable Subnet Originating Requests Globally 10 3.2 Configure DirectAccess for Load Balancing 11 3.3 Configure the Servers Virtual Services 11 3.3.1 Configure a DirectAccess Server Virtual Service 12 3.3.2 Configure an Additional Virtual Service for the DirectAccess Server 13 3.3.3 Configure a Network Location Server (NLS) Virtual Service 14 3.3.4 Configure an NLS (Offloaded) Virtual Service 15 3.4 Configure DirectAccess to use a Load-Balanced NLS 17 3.5 Configure Geographic Load Balancing for NLS 18 4 Multisite Configuration and Load Balancing 22 4.1 Configure DirectAccess for Multisite 22 kemp.ax
    [Show full text]
  • WINDOWS® 8.1 in DEPTH Copyright © 2014 by Pearson Education, Inc
    Windows® 8.1 Brian Knittel Paul McFedries 800 East 96th Street Indianapolis, Indiana 46240 WINDOWS ® 8.1 IN DEPTH Copyright © 2014 by Pearson Education, Inc. All rights reserved. No part of this book shall be reproduced, stored in a Editor-in-Chief retrieval system, or transmitted by any means, electronic, mechanical, photo- Greg Wiegand copying, recording, or otherwise, without written permission from the publisher. No patent liability is assumed with respect to the use of the information con- Executive Editor tained herein. Although every precaution has been taken in the preparation of Rick Kughen this book, the publisher and author assume no responsibility for errors or omis- sions. Nor is any liability assumed for damages resulting from the use of the Development Editor information contained herein. Todd Brakke ISBN-13: 978-0-7897-5281-9 Managing Editor ISBN-10: 0-7897-5281-6 Sandra Schroeder Library of Congress Control Number: 2014930138 Printed in the United States of America Senior Project Editor Tonya Simpson First Printing: March 2014 Trademarks Copy Editor All terms mentioned in this book that are known to be trademarks or service Cheri Clark marks have been appropriately capitalized. Que Publishing cannot attest to the Senior Indexer accuracy of this information. Use of a term in this book should not be regarded as affecting the validity of any trademark or service mark. Cheryl Lenser Windows is a registered trademark of Microsoft Corporation. Technical Editor Warning and Disclaimer Karen Weinstein Every effort has been made to make this book as complete and as accurate as Editorial Assistant possible, but no warranty or fitness is implied.
    [Show full text]
  • Ipv6 — an Introduction
    IPv6 — An introduction Owen DeLong [email protected] Portions Copyright © 2009-2014 by Hurricane Electric, used under license to Owen DeLong More IPv4 NAT Are you fscking kidding me? ©2014 Black Lotus Communications IPv6 Transition -- How ready are we? n Things that are ready Backbones CMTS Systems (DOCSIS 3) MacOS (10.4+) Linux (2.6 Kernels) Windows (7, 2008, XP (limited)) WiMax (specification, head end equipment) LTE (some) CPE (very limited) Early Adopters and some industry experts Black Lotus Me ©2014 Black Lotus Communications IPv6 Transition -- How ready are we? ▪ Things that are NOT ready ➢ PON Systems ➢ DSL Systems ➢ CMTS Systems (DOCSIS 2) ➢ WDS/EVDO/HSPA ➢ WIMAX (handsets, providers) ➢ Older Windows (XP and earlier) ➢ Embedded systems ➢ Printers ➢ Home entertainment devices ➢ CPE (most) ➢ Most IT staff and management ©2014 Black Lotus Communications An Important Decision ▪ Which Approach will you take? IPv4 is just fine. IPv4/IPv6 Dual Stack Now We just need MOAR NAT!! My dual stack network is running great! ©2014 Black Lotus Communications What we’ll cover ▪ Basics of IPv6 ▪ IPv6 Addressing Methods ➢ SLAAC ➢ DHCP ➢ Static ➢ Privacy ▪ Linux Configuration for Native Dual Stack ▪ IPv6 without a native backbone available ▪ Free IPv6? ©2014 Black Lotus Communications Some additional topics ▪ Routing ▪ Firewalls ▪ DNS ▪ Reverse DNS ▪ Troubleshooting ▪ Staff Training ©2014 Black Lotus Communications Basics: IPv4 vs. IPv6 Property IPv4 Address IPv6 Address Bits 32 128 Total address 3,758,096,384 unicast 42+ Undecilion assignable
    [Show full text]
  • F5 and Windows Server 2012 Directaccess/Remote Access Services
    White Paper F5 and Windows Server 2012 DirectAccess/Remote Access Services The F5 BIG-IP platform provides high availability, performance, and scalability when used to deliver traffic management and load balancing for the Microsoft Windows Server 2012 Remote Access Solutions: DirectAccess and Remote Access Services. by Ryan Korock Technical Director, Microsoft Solutions White Paper F5 and Windows Server 2012 Direct Access/Remote Access Services Contents Introduction 3 Benefits of Using F5 Products with DirectAccess and VPN 3 Architecture 4 A DirectAccess/VPN Server Front End 5 A Layered Approach with DirectAccess/VPN Servers 5 Dual Interface Vs. Single Interface DirectAccess/VPN Deployments 6 Single Site Vs. Multisite Deployment 8 Conclusion 9 2 White Paper F5 and Windows Server 2012 Direct Access/Remote Access Services Introduction For Windows 8 and Windows Server 2012, Microsoft has taken two remote access technologies found in previous versions of Windows Server, DirectAccess and VPN Server, and pulled them under the same management umbrella called simply Remote Access. F5 technologies can be deployed to manage traffic and balance loads on these services. Originally introduced in Windows Server 2008 R2 and Windows 7, DirectAccess shifted previous remote access technology. Unlike traditional VPNs, in which connections have been manually initiated at the user level, DirectAccess makes use of a seamless, system-level connection. This means that remote, domain-joined systems will automatically and securely build a corporate network presence upon boot. VPN, formerly known as Remote Access Services (RAS), was introduced in Windows NT and includes the traditional Windows VPN technologies, including IKEv2, SSTP, PPTP, and L2TP. Windows Server 2012 customers can deploy DirectAccess, VPN, or both, and it is often beneficial to deploy both.
    [Show full text]
  • Amazon Web Services: Overview of Security Processes
    Amazon Web Services: Overview of Security Processes March 2020 For the latest technical content, see Best Practices for Security, Identity & Compliance https://aws.amazon.com/architecture/ security-identity-compliance Archived Notices Customers are responsible for making their own independent assessment of the information in this document. This document: (a) is for informational purposes only, (b) represents current AWS product offerings and practices, which are subject to change without notice, and (c) does not create any commitments or assurances from AWS and its affiliates, suppliers or licensors. AWS products or services are provided “as is” without warranties, representations, or conditions of any kind, whether express or implied. The responsibilities and liabilities of AWS to its customers are controlled by AWS agreements, and this document is not part of, nor does it modify, any agreement between AWS and its customers. © 2020 Amazon Web Services, Inc. or its affiliates. All rights reserved. Archived Contents Introduction .......................................................................................................................... 1 Shared Security Responsibility Model ................................................................................ 1 AWS Security Responsibilities ......................................................................................... 2 Customer Security Responsibilities ................................................................................. 2 AWS Global Infrastructure Security
    [Show full text]
  • IOS XR Attestation Trust Me, Or Trust Me Not?
    IOS XR Attestation Trust me, or Trust me not? Dan Backman, Portfolio Architect @jonahsfo BRKSPG-1768 Cisco Webex Teams Questions? Use Cisco Webex Teams to chat with the speaker after the session How 1 Find this session in the Cisco Events Mobile App 2 Click “Join the Discussion” 3 Install Webex Teams or go directly to the team space 4 Enter messages/questions in the team space BRKSPG-2415 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3 Agenda • Risks to the Network Infrastructure • Measuring and Validating Trust in Cisco IOS-XR routers • New commands for Trust Integrity Measurement in IOS XR • Building a Service to Report on Trust Evidence • Conclusion BRKSPG-2415 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 Trusted Platform “Integrity, not just security.” © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public “Network devices are ideal targets. Most or all organizational and customer traffic must traverse these critical devices.” Source: US-CERT Alert (TA18-106A) Original release date: April 16, 2018 “The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations.” Source: US-CERT Alert (TA16-250A) Original release date: Sep 6, 2016 BRKSPG-2415 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 6 Growing Concerns for Service Providers Targeted attacks on Critical Infrastructure Impact on Economy Untrusted Locations Complex to Manage BRKSPG-2415 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7 How do I know my device has not been compromised? What is Trustworthy and Why Does It Matter? To build a trustworthy platform The network infrastructure must be constructed on a platform of trustworthy technologies to ensure devices operating are authentic and can create verifiable evidence that they have not been altered.
    [Show full text]
  • Building Ipv6 Based Tunneling Mechanisms for Voip Security
    WK,QWHUQDWLRQDO0XOWL&RQIHUHQFHRQ6\VWHPV6LJQDOV 'HYLFHV Building IPv6 Based Tunneling Mechanisms for VoIP Security Amzari J. Ghazali, Waleed Al-Nuaimy, Ali Al-Ataby, Majid A. Al-Taee Department of Electrical Engineering and Electronics University of Liverpool, UK e-mail: {amzari.ghazali, wax, ali.ataby, altaeem}@liv.ac.uk Abstract—Internet protocol version 6 (IPv6) was such as Toredo, 6to4 and manual configuration [4]. developed to resolve the IPv4 address exhaustion Despite the benefits of using IPv6, there are still problem and support new features. However, IPv6 still challenges and obstacles in implementing and comprises some defectiveness of IPv4 protocol such as practically using IPv6 VoIP [5]. The issues of the multimedia security. This paper presents IPv6-based transition from the current IPv4 network to IPv6 as tunneling mechanisms for securing Voice over Internet Protocol (VoIP) network traffic using OpenSwan IPSec well as VoIP performance for both IP versions need (site-to-site). IPSec with Triple Data Encryption to be assessed and compared. Algorithm (3DES) is used to create a Virtual Private Evaluation of VoIP performance with IPSec in Network (VPN) on top of existing physical networks. IPv4, IPv6 and 6to4 networks using Teredo for NAT Secure communication mechanisms can therefore be provided for data and control information transmitted traversal in a test LAN was previously reported in between networks. Secure VoIP-oriented mechanisms [6]. The testbed used softphones to setup calls, and on VPN IPv6 have been designed, implemented and background traffic was generated to create congestion tested successfully using open source approaches. The on the links and routers. The results demonstrated the performance of the IPv6 VoIP network is assessed feasibility of using a single Linux box to handle experimentally in terms of several performance metrics IPSec, 6to4 and NAT processing, and it was found including jitter, throughput and packet loss rate.
    [Show full text]
  • By Steve Guendert, Ph.D. Long-Distance Extension Networks Between Data Centers
    Fibre Channel over Internet Protocol ver the past decade, extension networks for storage have become commonplace and continue to grow in size and importance. Growth isn’t limited to new Odeployments but also involves the expansion of existing deployments. Requirements for data protection will never Basics for ease, as the economies of many countries depend on successful and continued business operations; thus, laws have been passed mandating data protection. Modern-day dependence on remote data replication (RDR) means there’s little tolerance for lapses that leave data vulnerable to loss. In IBM mainframe environments, reliable and resilient networks—to the point of no frame loss and in-order frame delivery—are necessary for error-free operation, high performance and operational ease. This improves availability, reduces risk and operating expenses and, most important of all, reduces risk of data loss. A previous article, “Storage Networking Business Mainframers Continuity Solutions” (Enterprise Tech Journal, October/ November 2013, available at http://entsys.me/ixond), introduced the various topologies and protocols used for the networks associated with business continuity, disaster recovery and continuous availability (BC/DR/CA). This article focuses in-depth on one of those protocols— Fibre Channel over Internet Protocol (FCIP)—and how it’s used in a mainframe environment to provide By Steve Guendert, Ph.D. long-distance extension networks between data centers. B • Enterprise Tech Journal • Winter 2013/2014Enterprise Tech Journal • Winter 2013/2014 Because of the higher costs of long-distance dark fiber FC devices in the fabric are unaware of the presence of the connectivity compared with other communications IP network.
    [Show full text]