1
Chapter
8
Overview
SEG overview
The
Radisys
SEG
is
a
robust
telecom
security
gateway
based
on
Network
Domain
Security
(NDS)
standards
that
provides
stateful
firewalling
and
IPsec
tunneling
in
a
single
platform.
The
SEG
can
be
used
to
secure
any
large
IP
based
network.
In
its
first
release,
the
SEG
is
targeted
for
use
as
a
security
gateway
between
infrastructure
elements
in
LTE
Access/Backhaul
and
LTE
Evolved
Packet
Core
networks.
In
subsequent
releases,
the
SEG
will
support
current
generation
(2G/3G)
wireless
offload
applications
like
I
‐
WLAN,
UMA/GAN
and
Femtocell
that
are
evolving
to
LTE.
It
is
also
ideally
suited
for
high
performance
and
next
‐
gen
firewalling
scenarios.
The
Radisys
SEG
is
built
around
the
carrier
‐
grade
Advanced
Telecommunications
Computing
Architecture
(ATCA),
and
offers
world
‐
class
security
features
with
multi
‐
gigabit
throughput
and
performance.
The
main
component
of
the
Radisys
SEG
is
the
SEG
‐
100
security
module,
a
fully
contained
security
gateway
residing
on
an
ATCA
module.
The
SEG
‐
100
can
be
deployed
in
a
standalone
SEG
‐
11002
system,
or
integrated
into
other
ATCA
based
network
elements.
Both
standalone
and
integrated
configurations
support
carrier
grade
high
availability
with
redundant
hardware
and
sophisticated
fault
tolerant
software.
The
SEG
‐
11002
is
a
2U,
2
‐
slot
ATCA
system,
ideally
suited
for
initial
trials
and
small
‐
to
‐
medium
size
deployments.
It
contains
one
or
two
SEG
‐
100
modules,
and
can
be
configured
as
a
high
availability
system,
with
active
and
passive
SEG
‐
100s
providing
full
stateful
redundancy
for
IPsec
tunnels
and
packet
flows.
The
SEG
security
software
is
based
on
a
proprietary
operating
core
with
a
small
attack
surface,
making
the
application
processing
highly
secure
and
efficient.
The
software
processes
millions
of
concurrent
IP
packet
flows
in
real
time,
while
applying
a
rich
set
of
firewalling
rules
and
routing
policies.
It
also
sets
up
VPN/IPsec
tunnels,
using
secure
keys
and
applying
advanced
data
integrity
and
encryption
techniques.
SEG architecture
The
SEG
architecture
is
centered
on
the
concept
of
flows
.
Traditional
IP
routers
or
switches
commonly
inspect
all
packets
and
then
perform
forwarding
decisions
based
on
information
found
in
the
packet
headers.
With
this
approach,
packets
are
forwarded
without
any
sense
of
context,
which
eliminates
any
possibility
to
detect
and
analyze
complex
protocols
and
enforce
corresponding
security
policies.