February 14, 2013 POIWG Technical Overview CR 13351 / HM-3430 Ku Forward Capability.

Slides:



Advertisements
Similar presentations
Kalpesh Vyas & Seward Khem
Advertisements

TCP/IP MODEL Maninder Kaur
CST Computer Networks NAT CST 415 4/10/2017 CST Computer Networks.
Chapter 17 Networking Patricia Roy Manatee Community College, Venice, FL ©2008, Prentice Hall Operating Systems: Internals and Design Principles, 6/E William.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
Page 1 NASA MSFC Engineering Directorate Huntsville, Alabama HOSC DTN Work.
SIS_DTN 1 DTN HOSC DTN Gateway Test Report May 2010 Cleveland, OH 2012.
CSCI 530 Lab Firewalls. Overview Firewalls Capabilities Limitations What are we limiting with a firewall? General Network Security Strategies Packet Filtering.
ISS Institutional DTN Overview for CCSDS
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 14: Troubleshooting Remote Connections.
Professor Michael J. Losacco CIS 1150 – Introduction to Computer Information Systems Communications and Networks Chapter 8.
Lesson 20 – OTHER WINDOWS 2000 SERVER SERVICES. DHCP server DNS RAS and RRAS Internet Information Server Cluster services Windows terminal services OVERVIEW.
CS 356 Systems Security Spring Dr. Indrajit Ray
Lecture slides prepared for “Business Data Communications”, 7/e, by William Stallings and Tom Case, Chapter 8 “TCP/IP”.
1 Enabling Secure Internet Access with ISA Server.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 3: TCP/IP Architecture.
Open Source DTN for ISS Payloads Concept Proposal, 05-Jun Open-source DTN communication software for ISS Payloads Kevin K. Gifford BioServe Space.
1 The Firewall Menu. 2 Firewall Overview The GD eSeries appliance provides multiple pre-defined firewall components/sections which you can configure uniquely.
Networks – Network Architecture Network architecture is specification of design principles (including data formats and procedures) for creating a network.
SISG - SSI ADD Service, Physical, and Protocol View Document Figures Ver 0.4, 2 Sept 09 Peter Shames, et al.
Module 4: Configuring ISA Server as a Firewall. Overview Using ISA Server as a Firewall Examining Perimeter Networks and Templates Configuring System.
June 2004 SIW-4 - IP in Space Implementation Guide 1 Handbook for Using IP Protocols for Space Missions James Rash - NASA/GSFC Keith Hogie, Ed Criscuolo,
Page No. 1 Kelvin Nichols Payload Operations and Integration Center EO50 Delay Tolerant Networking (DTN) Implementation on the International Space Station.
1 Chapter 7: NAT in Internet and Intranet Designs Designs That Include NAT Essential NAT Design Concepts Data Protection in NAT Designs NAT Design Optimization.
Network and Perimeter Security Paula Kiernan Senior Consultant Ward Solutions.
1 Networking Chapter Distributed Capabilities Communications architectures –Software that supports a group of networked computers Network operating.
OS Services And Networking Support Juan Wang Qi Pan Department of Computer Science Southeastern University August 1999.
Chapter 2 Protocols and the TCP/IP Suite 1 Chapter 2 Protocols and the TCP/IP Suite.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 11: Network Address Translation for IPv4 Routing And Switching.
Security fundamentals Topic 10 Securing the network perimeter.
1 Chapters 2 & 3 Computer Networking Review – The TCP/IP Protocol Architecture.
NASA MSFC Mission Operations Laboratory MSFC NASA MSFC Mission Operations Laboratory Ku - Band, DTN, and enhanced payload utilization.
Internet Protocol Storage Area Networks (IP SAN)
Introduction to Networks v5.1 Chapter 6: Network Layer.
SYSTEM ADMINISTRATION Chapter 10 Public vs. Private Networks.
NASA MSFC Mission Operations Laboratory MSFC NASA MSFC Mission Operations Laboratory HOSC Payload Ethernet Gateway (HPEG) HOSC Service Supporting IP Access.
ESA UNCLASSIFIED – For Official Use MPCC Project Ground Overview Peter Wellings, ESA/HSO-ICG 22 January 2015.
NASA MSFC Engineering Directorate Huntsville, Alabama 10/29/2012 HOSC DTN Activities October 2013.
NASA MSFC Engineering Directorate Mission Operations Laboratory MSFC NASA MSFC Engineering Directorate Mission Operations Laboratory Increment 19/18 Soyuz.
Page No. 1 Pre-decisional, For Internal Use Only Payload Network Attached Storage (NAS) for International Space Station (ISS) Operations Concept Sponsoring.
Cisco I Introduction to Networks Semester 1 Chapter 6 JEOPADY.
NASA MSFC Mission Operations Laboratory MSFC NASA MSFC Mission Operations Laboratory Cadre Currency Training: Ku Forward Capability and Operations – Phases.
Belgian User Support & Operations Centre METERON SUPVIS-E Operations using Ku-Fwd POIWG#38 23 Jul 2015.
This courseware is copyrighted © 2016 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
Sponsoring Org/Office Code: MSFC/EO30 Name of Forum: POIWG
NASA MSFC Mission Operations Laboratory MSFC NASA MSFC Mission Operations Laboratory POIWG #35 January 27-31, 2014 Ann Bathew EO03/Operations Directors.
National Aeronautics and Space Administration (NASA) Glenn Research Center SAMS KU Forward Lessons Learned 1 Kevin McPherson NASA GRC Payload Operation.
Page No. 1 ISS_CM_019 (Rev 09/2011) Pre-decisional, For Internal Use Only Payload Video and the PIA Bryan Walls.
NASA MSFC Mission Operations Laboratory MSFC NASA MSFC Mission Operations Laboratory Kelvin Nichols, EO50 March 2016 MSFC ISS DTN Project Status.
Page No. 1 Overview Kelvin Nichols Payload Operations and Integration Center EO50 SSCN Delay Tolerant Networking (DTN)
Security fundamentals
CCNA Routing and Switching Routing and Switching Essentials v6.0
HOSC DTN Gateway Test Report
Service, Physical, and Protocol View Document Figures
HOSC DTN Work.
ISS Institutional DTN Overview for CCSDS
Ku - Band, DTN, and enhanced payload utilization
Chapter 6: Network Layer
Chapter 10: Device Discovery, Management, and Maintenance
CCNA Routing and Switching Routing and Switching Essentials v6.0
NAT , Device Discovery Chapter 9 , chapter 10.
Network Architecture Introductory material
Review of Important Networking Concepts
* Essential Network Security Book Slides.
Chapter 10: Device Discovery, Management, and Maintenance
Technology for a NASA Space-based Science Operations Grid Internet2 Members Meeting Advanced Applications Track Session April, 2003 Robert N. Bradford.
AbbottLink™ - IP Address Overview
Chapter 11: Network Address Translation for IPv4
Presentation transcript:

February 14, 2013 POIWG Technical Overview CR / HM-3430 Ku Forward Capability

February 14, 2013 HM-3430 Review Introduction Primary Objectives of changes being implemented 1. Do not deprecate any current capability 2. Add the capability to store all uplink and downlink data that is not APID defined (by network address) 3. Provide Ku band management capability 4. Map payload/APID/Source network address to users 5. Allow the uplink path to be user selected and provide status 6. Proxy HOSC users to interface with the MCC-H Communications Data Processor (CDP) 7. Provide a common platform onboard for file transfer 8. Develop an appropriate test environments for Development, Test, and Verification 9. Development of User interfaces for ISS to ground Apps 10. Provide upcoming payload projects an internet like, standards based, direct methods to access on-board experiments 2

February 14, 2013 HM Introduction 3

February 14, 2013 Project Requirements Schedule PhaseDescriptionRequired DateDate Driver 1TCP access for Cadre to ISS Express Laptops and network devices, Video retrieval Enhancements ATP + 12 monthsInitial Cadre capability 2TCP access for remote users to their devices and cadre ability to move files via CFDP from HOSC EPC client ATP + 18 monthsCadre and initial remote user capability 3Remote user ability to move file via CFDP to their devices ATP + 24 monthsFinal capability implementation ATP of 01/03/2013 4

February 14, Point Architecture Custom controls are unique to each system – HOSC has implemented a four-tier architecture – Each tier has unique attributes which are critical to securing the user’s needs

February 14, 2013 What is the model for Payload LAN access via Ku-forward System Design HM 3430 Architecture

February 14,  Ku forward access is to bring Internet protocols to the ISS payload investigators  Do not break the current uplink model, extend to ku-band – Metering the uplink rate to reflect the traffic model allowed for payloads – Mapping of user/payload to private IP address onboard for uplink Do not allow a user to access other than approved assets – Scanning of all uplink streams for virus and/or protocol – Operable view of uplink activity Independent control of each uplink Control of single payloads and groups of payloads – Stream (RT) uplink and staging of uplink (files) – Logging of uplink data – Interface to MCC-H CDP – Ability to proxy (NAT) uplink from a remote user to CDP System Design HM-3430 Architecture

February 14,  Do not break the current uplink model, extend to ku-band (cont’d) – Mapping of users/payloads to private IP addresses onboard for downlink – Associate (map) private vehicle IP address to a payload/APID – Automated storage and retrieval of downlink data – Maintain the current capability of PDSS providing science data streams directly to users – Ability to proxy (NAT) downlink to a remote user – TCP for command line access – UDP for video/file transfers, etc. – ICMP System Design CR Architecture

February 14,  Extend the architecture without new hardware  Manage Ku forward on the OPS/TST servers  Access HOSC ISS Systems via a new ERIS service on current ePVT and PVT servers  PDSS is primarily complete with ECR HM-3420  EPC will be extended to support a command App for ku access  TReK will be extended to support ku access  Programmatic interface to be identified in PGUIDD  Available for all non-EPC accesses System Design HM-3430 Architecture

February 14, Information Architecture Regimen Based Security Model  All users are not eligible for Ku forward service  Requested service  Explicitly defined by service  Tier 1 is the client level  Users most login to the fully qualified PGUIDD ERIS interface  User direct access shall be via an EHS Ku Proxy  IP and port shall be explicitly checked  Access via VPN  No special purpose application required  Tier 2 is an ERIS server  Internal users are hosted on PVT servers  External users access via ePVT servers  Users will be prompted with their allowed configuration as defined by UCM  A user will only be allowed access based on their allowed configurations  Ku Proxy will encapsulate the user traffic to their onboard platform once verification is complete  Ku Proxy will pass encapsulated traffic to CCP (Tier 3 server)

February 14, Information Architecture Regimen Based Security Model  Tier 3 is an OPS server  All inputs consolidated for a single point of control  HPEG on the OPS server shall scan files, meter traffic, and routing to CDP with a Ground Transfer Header (GTH)  Remote users do not have access to OPS servers  No architectural or functional changes are expected at Tier 4

February 14, 2013 Backup 12

February 14, 2013 References – CCSDS B-2 AOS Space Data Link Protocol CCSDS B-2 – CCSDS B-4 Space Link Identifiers CCSDS B-4 – CCSDS B-2 Encapsulation Service CCSDS B-2 – CCSDS B-1 Space Packet Protocol CCSDS B-1 – CCSDS B-4 CCSDS File Delivery Protocol (CFDP) CCSDS B-4 – MSFC-SPEC-3618 International Space Station (ISS) Program ISS IP Ground Router (IIGoR) Architectural Control Document (ACD) 13 Project Requirements documents

February 14, 2013 Project Requirements Affected documents Level II – SSP 45001: Space Station Control Center to Huntsville Operations Support Center (HOSC) Interface Control Document International Space Station Program - Part II Revision B – SSP PDS, Rev E, Payload Data Sets Blank Book (Ground Data Services Blank Book Section) – SSP Rev C POIC Capabilities Document – SSP V1 Rev C POIC to Generic User Interface Definition Document (Vol. I) Revision C – SSP 57072, Appendix D, Standard Payload Integration Agreement for ISS Payloads 14