Carrier is using Cisco’s encryption technology to augment its MPLS-based offering
endif; ?>AT&T Monday is expected to launch a data encryption enhancement for its MPLS-based IP VPN service, using Cisco’s new Group Encryption Transport technology for VPN and data security.
In the first quarter of 2007, AT&T customers connecting multiple sites via IP VPN services will have the option to encrypt the data running over those MPLS pipes, adding an additional layer of security AT&T says. To do this, AT&T is using Cisco’s GET, which lets the carrier designate groups of trusted sites on a customer’s network, and allow these sites to easily share encrypted data.
For AT&T customers who subscribe to the managed IP VPN service, a Cisco ISR router (with the latest IOS version, which supports GET) would be installed on site, hooked into AT&T’s MPLS network, and managed by the carrier.
“The beauty of [GET] is how simple it is for us to offer encryption anywhere they want it on the network,” says Burt Winter, executive director of MPLS VPN services for AT&T.
GET lets users share encrypted data streams among designated members of a trusted group. In GET, which is based on an IETF standard, only data payloads are encrypted, while TCP/IP headers are not — unlike in IPSec VPNs, which encapsulate the entire packet. By not encapsulating the packet, GET allows the traffic to travel over any network. Cisco says this is a better way to send secure traffic over a WAN vs. traditional VPN tunnels, which requires a separate VPN tunnel overlay network on top of a routed IP network.
In AT&T’s case, the carrier is not using GET as a base for a VPN service but to add additional encryption for data running over its IP VPNs.
“MPLS VPNs today are as secure as frame relay and ATM ever were,” says Winter. “[GET] adds an additional level of encrypted security that certain customers in verticals such as healthcare and government would like to see.”
Pricing for the GET-based encryption add-on to AT&T’s service will be announced when the service launches in early 2007, the company says.




