As the network control information and user data are transmitted in a different channel, thus the problem of resource conflict between the planes can be avoid, which eliminates the impact of data plane attacks on the control plane. And common end systems users can not access the core networking devices other than the separators. Thus the DoS attacks to these devices can be prevented. The 3N architecture enhances the capability of network infrastructure protection.