The data, control, and management planes
Network devices perform three different operations:
- Process and forward the data in transit. This is referred to as the data plane.
- Make forwarding decisions; that is, where to forward the data. This is referred to as the control plane.
- Enable the administrator, or the management system, to give commands and read information from the device. This is referred to as the management plane.
The following diagram shows how these three planes function:
Here, we can see the objectives of the data, control, and management planes.
The data plane
The data plane is responsible for forwarding information. It receives instructions from the control plane, such as routing tables, and forward packets from port to port. The forwarding tables can learn from various control plane functions. For example, several routing protocols can run in the control plane, while the result of them will be a single routing table in the control plane that is translated into a single forwarding table on the data plane.
The data plane is responsible for processing and delivering packets, so it is implemented on network interfaces and device CPUs.
Attacks on the forwarding table can be achieved by overloading the network, such as link flooding attacks and Distributed Denial of Service (DDoS) attacks.
The control plane
The control plane is where we determine how data should be forwarded in the data plane. The control plane includes routing protocols that exchange information between routers, multicast protocols, Quality of Service (QoS) protocols, and any other protocol that the network devices use to exchange information and make forwarding decisions. These protocols are running in the control plane, and their result is a forwarding table that is built in the data plane.
The control plane is part of the network device software, and it runs in the device's CPU.
Several types of attacks can be performed on the control plane. Some of them simply try to load the device resources (such as CPU and memory), while others try to confuse the protocols running on the device by sending fake routing updates and trying to divert traffic, to flood the device's ARP caches so that packets will be forwarded in the wrong direction, and so on.
The management plane
The management plane is responsible for interacting with the network device, whether these are interactions with the management system via protocols such as SNMP or NetFlow, REST APIs, or any other method that the device can work with or via human interactions with a Command-line Interface (CLI), web interface, or a dedicated client.
The management plane is implemented entirely by software. Attacks on the management plane mostly try to break into the network device to log in, by human or by machine, and make settings in violation of the enterprise policy with the intent to disrupt or break into network activity.
Now that we've talked about network devices and their structure, let's talk about the new designs in data networks; that is, SDN and NFV.