I’m looking to get some feedback on WAN security specifically referring to Metro Ethernet.
The situation is that my company is now receiving Metro Ethernet services from our Service Provider. Now, we are a Gov’t organization managing IT services, and infrastructure for Tax Services and Revenue Collection Agencies across the island. So that lays the base that our data is sensitive…almost as sensitive as bank information.
With leased lines, we didn’t use encryption as leased lines where deemed (private). This was obviously a wrong view and are in the process of correcting this.
With the move to Metro Ethernet, we’ve decided that some encryption has to take place. We have Cisco routing infrastructure at all sites (2800 and 3800 series routers). We have approximately 52 sites.
The issue is 2-fold
1. Without considering the sensitivity of the data, is Metro Ethernet as “secure” as leased lines? Is it really necessary to use encryption? Do many people use encryption on their Metro connection or do they trust the Service Provider?
2. Will routers alone be able to handle the encryption? What are the minimum router specs necessary to facilitate IPSec encryption among the Metro-E sites.
For the app being used across the WAN, The application architecture has it that most communication takes place in a Hub spoke manner i.e. Head Office has Database, while other sites access DB.
Currently, we have 1Mbps Metro Links which have a average max utilization of 13%.
Hopefully with all the info provided…some informed answers can be provided.