ISP Network Design. ISP Workshops

Size: px
Start display at page:

Download "ISP Network Design. ISP Workshops"

Transcription

1 ISP Network Desig ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese ( Last updated 27 th February

2 Ackowledgemets p This material origiated from the Cisco ISP/IXP Workshop Programme developed by Philip Smith & Barry Greee p Use of these materials is ecouraged as log as the source is fully ackowledged ad this otice remais i place p Bug fixes ad improvemets are welcomed Please workshop (at) bgp4all.com Philip Smith 2

3 ISP Network Desig p PoP Topologies ad Desig p Backboe Desig p Upstream Coectivity & Peerig p Addressig p Routig Protocols p Security p Out of Bad Maagemet p Operatioal Cosideratios 3

4 Poit of Presece Topologies 4

5 PoP Topologies p Core routers high speed truk coectios p Distributio routers ad Access routers high port desity p Border routers coectios to other providers p Service routers hostig ad servers p Some fuctios might be hadled by a sigle router 5

6 PoP Desig p Modular Desig p Aggregatio Services separated accordig to coectio speed customer service cotetio ratio security cosideratios 6

7 Modular PoP Desig Backboe lik to aother PoP ISP Services (DNS, Mail, News, FTP, WWW) Web Cache Other ISPs Hosted Services & Datacetre Backboe lik to aother PoP Cosumer Dial Access Network Core Cosumer cable, xdsl ad wireless Access Busiess customer aggregatio layer Chaelised circuits for leased lie circuit delivery Network Operatios Cetre GigE fibre truks for MetroE circuit delivery MetroE customer aggregatio layer 7

8 Modular Routig Protocol Desig p Modular IGP implemetatio IGP area per PoP Core routers i backboe area (Area 0/L2) Aggregatio/summarisatio where possible ito the core p Modular ibgp implemetatio BGP route reflector cluster Core routers are the route-reflectors Remaiig routers are cliets & peer with route-reflectors oly 8

9 Poit of Presece Desig 9

10 PoP Modules p Low Speed customer coectios ADSL2, Cable, Public Wireless, PSTN access Low badwidth eeds Low reveue, large umbers p Busiess customer coectios 10Mbps to 100Mbps speed rage Delivery over SDH or MetroEtheret liks Medium badwidth eeds Medium reveue, medium umbers 10

11 PoP Modules p Highbad Busiess customer coectios From 100Mbps to over 1Gbps Etheret, Fibre, or high ed SDH High badwidth eeds High reveue, low umbers 11

12 PoP Modules p PoP Core Two dedicated routers High Speed itercoect Backboe Liks ONLY Do ot touch them! p Border Network Dedicated border router to other ISPs The ISP s frot door Trasparet web cachig? Two i backboe is miimum guaratee for redudacy 12

13 PoP Modules p ISP Services DNS (cache, secodary) News (still relevat?) Mail (POP3, Relay, Ati-virus/ati-spam) WWW (server, proxy, cache) p Hosted Services/DataCetres Virtual Web, WWW (server, proxy, cache) Iformatio/Cotet Services Electroic Commerce 13

14 PoP Modules p Network Operatios Cetre Cosider primary ad backup locatios Network moitorig Statistics ad log gatherig Direct but secure access p Out of Bad Maagemet Network The ISP Network Safety Belt 14

15 PSTN & Broadbad Access Module Web Cache Telephoe Network DSLAM IP, ATM BRAS Access Network Gateway Routers Cable RAS Cable System To Core Routers Primary Rate T1/E1 Digital Modem Access Servers SSG, DHCP, TACACS+ or Radius Servers/Proxies, DNS resolver, Cotet 15

16 Busiess Customer Access Module Chaelised T1/E1 Aggregatio Edge Metro Etheret To Core Routers Direct Fibre Liks 16

17 High Speed Access Module Metro Etheret Aggregatio Edge Direct Fibre Liks To Core Routers Chaelised OC3/OC12 17

18 ISP Services Module To core routers Service Network Gateway Routers WWW cache DNS Secodar y POP3s IMAPs SMTP Host (i) SMTP Relay (out) DNS Resolver 18

19 Hosted Services Module To core routers Hosted Network Gateway Routers vla11 vla12 vla13 vla14 vla15 vla16 vla17 Customer 1 Customer 3 Customer 5 Customer 7 Customer 2 Customer 4 Customer 6 19

20 Border Module To local IXP NB: router has o default route + local AS routig table oly ISP1 ISP2 Network Border Routers To core routers 20

21 NOC Module To core routers Critical Services Module Out of Bad Maagemet Network Hosted Network Gateway Routers Firewall Corporate LAN asyc termial server NetFlow Aalyser TACACS+ server SYSLOG server Primary DNS Billig, Database ad Accoutig Systems Network Operatios Cetre Staff 21

22 Out of Bad Network Out of Bad Maagemet Network Router cosoles Termial server To the NOC NetFlow Collector NetFlow eabled routers Out of Bad Etheret 22

23 Backboe Network Desig 23

24 Backboe Desig p Routed Backboe p Switched Backboe ATM/Frame Relay core etwork Now obsolete p Poit-to-poit circuits x64k, T1/E1, T3/E3, OC3, OC12, GigE, OC48, 10GigE, OC192, OC768, 100GE p ATM/Frame Relay service from telco T3, OC3, OC12, delivery Easily upgradeable badwidth (CIR) Almost vaished i availability ow 24

25 Distributed Network Desig p PoP desig stadardised operatioal scalability ad simplicity p ISP essetial services distributed aroud backboe p NOC ad backup NOC p Redudat backboe liks 25

26 Distributed Network Desig ISP Services Customer coectios Backup Operatios Cetre POP Two Customer coectios Customer coectios ISP Services POP Three POP Oe ISP Services Exteral coectios Operatios Cetre Exteral coectios 26

27 Backboe Liks p ATM/Frame Relay Virtually disappeared due to overhead, extra equipmet, ad shared with other customers of the telco MPLS has replaced ATM & FR as the telco favourite p Leased Lie/Circuit Most popular with backboe providers IP over Optics ad Metro Etheret very commo i may parts of the world 27

28 Log Distace Backboe Liks p These usually cost more p Importat to pla for the future This meas at least two years ahead Stay i budget, stay realistic Uplaed emergecy upgrades will be disruptive without redudacy i the etwork ifrastructure 28

29 Log Distace Backboe Liks p Allow sufficiet capacity o alterative paths for failure situatios Sufficiet ca deped o the busiess strategy Sufficiet ca be as little as 20% Sufficiet is usually over 50% as this offers busiess cotiuity for customers i the case of lik failure Some busiesses choose 0% p Very short sighted, meaig they have o spare capacity at all!! 29

30 Log Distace Liks POP Two Log distace lik POP Three POP Oe Alterative/Backup Path 30

31 Metropolita Area Backboe Liks p Ted to be cheaper Circuit cocetratio Choose from multiple suppliers p Thik big More redudacy Less impact of upgrades Less impact of failures 31

32 Metropolita Area Backboe Liks POP Two Metropolita Liks POP Three POP Oe Metropolita Liks Traditioal Poit to Poit Liks 32

33 Upstream Coectivity ad Peerig 33

34 Trasits p Trasit provider is aother autoomous system which is used to provide the local etwork with access to other etworks Might be local or regioal oly But more usually the whole Iteret p Trasit providers eed to be chose wisely: Oly oe p o redudacy Too may p more difficult to load balace p o ecoomy of scale (costs more per Mbps) p hard to provide service quality p Recommedatio: at least two, o more tha three

35 Commo Mistakes p ISPs sig up with too may trasit providers Lots of small circuits (cost more per Mbps tha larger oes) Trasit rates per Mbps reduce with icreasig trasit badwidth purchased Hard to implemet reliable traffic egieerig that does t eed daily fie tuig depedig o customer activities p No diversity Chose trasit providers all reached over same satellite or same submarie cable Chose trasit providers have poor oward trasit ad peerig

36 Peers p A peer is aother autoomous system with which the local etwork has agreed to exchage locally sourced routes ad traffic p Private peer Private lik betwee two providers for the purpose of itercoectig p Public peer Iteret Exchage Poit, where providers meet ad freely decide who they will itercoect with p Recommedatio: peer as much as possible!

37 Commo Mistakes p Mistakig a trasit provider s Exchage busiess for a o-cost public peerig poit p Not workig hard to get as much peerig as possible Physically ear a peerig poit (IXP) but ot preset at it (Trasit sometimes is cheaper tha peerig!!) p Igorig/avoidig competitors because they are competitio Eve though potetially valuable peerig parter to give customers a better experiece

38 Private Itercoectio p Two service providers agree to itercoect their etworks They exchage prefixes they origiate ito the routig system (usually their aggregated address blocks) They share the cost of the ifrastructure to itercoect p Typically each payig half the cost of the lik (be it circuit, satellite, microwave, fibre, ) p Coected to their respective peerig routers Peerig routers oly carry domestic prefixes 38

39 Private Itercoectio Upstream Upstream PR PR ISP2 ISP1 p PR = peerig router Rus ibgp (iteral) ad ebgp (with peer) No default route No full BGP table Domestic prefixes oly p Peerig router used for all private itercoects 39

40 Public Itercoectio p Service provider participates i a Iteret Exchage Poit It exchages prefixes it origiates ito the routig system with the participats of the IXP It chooses who to peer with at the IXP p Bi-lateral peerig (like private itercoect) p Multi-lateral peerig (via IXP s route server) It provides the router at the IXP ad provides the coectivity from their PoP to the IXP The IXP router carries oly domestic prefixes 40

41 Public Itercoectio Upstream ISP6-PR ISP5-PR ISP4-PR IXP ISP1-PR ISP1 ISP3-PR ISP2-PR p ISP1-PR = peerig router of our ISP Rus ibgp (iteral) ad ebgp (with IXP peers) No default route No full BGP table Domestic prefixes oly p Physically located at the IXP 41

42 Public Itercoectio p The ISP s router IXP peerig router eeds careful cofiguratio: It is remote from the domestic backboe Should ot origiate ay domestic prefixes (As well as o default route, o full BGP table) Filterig of BGP aoucemets from IXP peers (i ad out) p Provisio of a secod lik to the IXP: (for redudacy or extra capacity) Usually meas istallig a secod router p p Coected to a secod switch (if the IXP has two more more switches) Itercoected with the origial router (ad part of ibgp mesh) 42

43 Public Itercoectio Upstream ISP6-PR ISP5-PR ISP1-PR2 ISP4-PR IXP ISP1-PR1 ISP1 ISP3-PR ISP2-PR p Provisio of a secod lik to the IXP meas cosiderig redudacy i the SP s backboe Two routers Two idepedet liks Separate switches (if IXP has two or more switches) 43

44 Upstream/Trasit Coectio p Two scearios: Trasit provider is i the locality p Which meas badwidth is cheap, pletiful, easy to provisio, ad easily upgraded Trasit provider is a log distace away p Over udersea cable, satellite, log-haul cross coutry fibre, etc p Each sceario has differet cosideratios which eed to be accouted for 44

45 Local Trasit Provider Trasit AR BR ISP1 p BR = ISP s Border Router Rus ibgp (iteral) ad ebgp (with trasit) Either receives default route or the full BGP table from upstream BGP policies are implemeted here (depedig o coectivity) Packet filterig is implemeted here (as required) 45

46 Distat Trasit Provider AR1 Trasit AR2 BR ISP1 p BR = ISP s Border Router Co-located i a co-lo cetre (typical) or i the upstream provider s premises Rus ibgp with rest of ISP1 backboe Rus ebgp with trasit provider router(s) Implemets BGP policies, packet filterig, etc Does ot origiate ay domestic prefixes 46

47 Distat Trasit Provider p Positioig a router close to the Trasit Provider s ifrastructure is strogly ecouraged: Log haul circuits are expesive, so the router allows the ISP to implemet appropriate filterig first Moves the bufferig problem away from the Trasit provider Remote co-lo allows the ISP to choose aother trasit provider ad migrate coectios with miimum dowtime 47

48 Distat Trasit Provider p Other poits to cosider: Does require remote hads support (Remote hads would plug or uplug cables, power cycle equipmet, replace equipmet, etc as istructed) Appropriate support cotract from equipmet vedor(s) Sesible to cosider two routers ad two log-haul liks for redudacy 48

49 Distat Trasit Provider AR1 Trasit AR2 BR1 BR2 ISP1 p Upgrade sceario: Provisio two routers Two idepedet circuits Cosider secod trasit provider ad/or turig up at a IXP 49

50 Summary p Desig cosideratios for: Private itercoects p Simple private peerig Public itercoects p Router co-lo at a IXP Local trasit provider p Simple upstream itercoect Log distace trasit provider p Router remote co-lo at datacetre or Trasit premises 50

51 Upstream Coectivity ad Peerig Case Study How Seacom chose their iteratioal peerig locatios ad trasit providers 51

52 Objective p Obtai high grade Iteret coectivity for the wholesale market i Africa to the rest of the world p Emphasis o: Reliability Itercoectivity desity Scalability 52

53 Metrics Needed i Determiig Solutio (1) p Focusig o operators that cover the destiatios mostly required by Africa i.e., Eglish-speakig (Europe, North America) p Iclude providers with good coectivity ito South America ad the Asia Pacific. p Little eed for providers who are strog i the Middle East, as demad from Africa for those regios is very, very low. 53

54 Metrics Needed i Determiig Solutio (2) p Split the operators betwee Marseille (where the SEACOM cable lads) ad Lodo (where there is good Iteret desity) To avoid outages due to backhaul failure across Europe Ad still maitai good access to the Iteret p Look at providers who are of similar size so as ot to fidget too much (or at all) with BGP tuig. p The providers eeded to support: 10Gbps ports Burstig badwidth/billig Future support for 100Gbps or N x 10Gbps 54

55 Metrics Needed i Determiig Solutio (3) p Implemet peerig at major exchage poits i Europe To off-set log term operatig costs re: upstream providers. 55

56 Implemetig Solutio p Coected to Level(3) ad GT-T (formerly Iteliquet, formerly Tiet) i Marseille p Coected to NTT ad TeliaSoera i Lodo p Peered i Lodo (LINX) p Peered i Amsterdam (AMS-IX) p BGP setup to prefer traffic beig exchaged at LINX ad AMS-IX p BGP setup to prefer traffic over the upstreams that we could ot peer away p No additioal tuig doe o either peered or trasit traffic, i.e., o prepedig, o de- aggregatio, etc. All traffic setup to flow aturally 56

57 Ed Result p 50% of traffic peered away i less tha 2x moths of peerig at LINX ad AMS-IX p 50% of traffic hadled by upstream providers p Equal traffic beig hadled by Level(3) ad GT-T i Marseille p Equal traffic beig hadled by TeliaSoera ad NTT i Lodo p Traffic distributio ratios across all the trasit providers is some 1:1:0.9:0.9 p This has bee steady state for the last 12x moths No BGP tuig has bee doe at all 57

58 Addressig 58

59 Where to get IP addresses ad AS umbers p Your upstream ISP p Africa AfriNIC p Asia ad the Pacific APNIC p North America ARIN p Lati America ad the Caribbea LACNIC p Europe ad Middle East RIPE NCC 59

60 Iteret Registry Regios 60

61 Gettig IP address space p Take part of upstream ISP s PA space or p Become a member of your Regioal Iteret Registry ad get your ow allocatio Require a pla for a year ahead Geeral policies are outlied i RFC2050, more specific details are o the idividual RIR website p There is o more IPv4 address space at IANA APNIC ad RIPE NCC are ow i their fial /8 IPv4 delegatio policy phase Limited IPv4 available IPv6 allocatios are simple to get i most RIR regios 61

62 What about RFC1918 addressig? p RFC1918 defies IPv4 addresses reserved for private Iterets Not to be used o Iteret backboes p Commoly used withi ed-user etworks NAT used to traslate from private iteral to public exteral addressig Allows the ed-user etwork to migrate ISPs without a major iteral reumberig exercise p ISPs must filter RFC1918 addressig at their etwork edge 62

63 What about RFC1918 addressig? p There is a log list of well kow problems: p Icludig: False belief it coserves address space Adverse effects o Traceroute Effects o Path MTU Discovery Uexpected iteractios with some NAT implemetatios Iteractios with edge ati-spoofig techiques Peerig usig loopbacks Adverse DNS Iteractio Serious Operatioal ad Troubleshootig issues Security Issues p false sese of security, defeatig existig security techiques 63

64 Private versus Globally Routable IP Addressig p Ifrastructure Security: ot improved by usig private addressig Still ca be attacked from iside, or from customers, or by reflectio techiques from the outside p Troubleshootig: made a order of magitude harder No Iteret view from routers Other ISPs caot distiguish betwee dow ad broke p Summary: ALWAYS use globally routable IP addressig for ISP Ifrastructure 64

65 Addressig Plas ISP Ifrastructure p Address block for router loop-back iterfaces p Address block for ifrastructure Per PoP or whole backboe Summarise betwee sites if it makes sese Allocate accordig to geuie requiremets, ot historic classful boudaries p Similar allocatio policies should be used for IPv6 as well ISPs just get a substatially larger block (relatively) so assigmets withi the backboe are easier to make 65

66 Addressig Plas Customer p Customers are assiged address space accordig to eed p Should ot be reserved or assiged o a per PoP basis ISP ibgp carries customer ets Aggregatio ot required ad usually ot desirable 66

67 Addressig Plas ISP Ifrastructure p Phase Oe / /24 Customer Address & p-t-p liks Ifrastructure Loopbacks 67

68 Addressig Plas ISP Ifrastructure p Phase Oe / /24 Customer Address & p-t-p liks Ifrastructure Loopbacks p Phase Two / /24 / Origial assigmets New Assigmets 68

69 Addressig Plas Plaig p Registries will usually allocate the ext block to be cotiguous with the first allocatio Miimum allocatio could be /21 Very likely that subsequet allocatio will make this up to a /20 So pla accordigly 69

70 Addressig Plas (cotd) p Documet ifrastructure allocatio Eases operatio, debuggig ad maagemet p Documet customer allocatio Cotaied i ibgp Eases operatio, debuggig ad maagemet Submit etwork object to RIR Database 70

71 Routig Protocols 71

72 Routig Protocols p IGP Iterior Gateway Protocol Carries ifrastructure addresses, poit-to-poit liks Examples are OSPF, IS-IS,... p EGP Exterior Gateway Protocol Carries customer prefixes ad Iteret routes Curret EGP is BGP versio 4 p No coectio betwee IGP ad EGP 72

73 Why Do We Need a IGP? p ISP backboe scalig Hierarchy Modular ifrastructure costructio Limitig scope of failure Healig of ifrastructure faults usig dyamic routig with fast covergece 73

74 Why Do We Need a EGP? p Scalig to large etwork Hierarchy Limit scope of failure p Policy Cotrol reachability to prefixes Merge separate orgaizatios Coect multiple IGPs 74

75 Iterior versus Exterior Routig Protocols p Iterior Automatic eighbour discovery Geerally trust your IGP routers Prefixes go to all IGP routers Bids routers i oe AS together p Exterior Specifically cofigured peers Coectig with outside etworks Set admiistrative boudaries Bids AS s together 75

76 Iterior versus Exterior Routig Protocols p Iterior Carries ISP ifrastructure addresses oly ISPs aim to keep the IGP small for efficiecy ad scalability p Exterior Carries customer prefixes Carries Iteret prefixes EGPs are idepedet of ISP etwork topology 76

77 Hierarchy of Routig Protocols Other ISPs BGP BGP ad OSPF/IS-IS BGP Static/BGP IXP Customers 77

78 Routig Protocols: Choosig a IGP p OSPF ad IS-IS have very similar properties Review the IS-IS vs OSPF presetatio p Which to choose? Choose which is appropriate for your operators experiece I most vedor releases, both OSPF ad IS-IS have sufficiet erd kobs to tweak the IGP s behaviour OSPF rus o IP IS-IS rus o ifrastructure, alogside IP IS-IS supports both IPv4 ad IPv6 OSPFv2 (IPv4) plus OSPFv3 (IPv6) 78

79 Routig Protocols: IGP Recommedatios p Keep the IGP routig table as small as possible If you ca cout the routers ad the poit-to-poit liks i the backboe, that total is the umber of IGP etries you should see p IGP details: Should oly have router loopbacks, backboe WAN poit-to-poit lik addresses, ad etwork addresses of ay LANs havig a IGP ruig o them Strogly recommeded to use iter-router autheticatio Use iter-area summarisatio if possible 79

80 Routig Protocols: More IGP recommedatios p To fie tue IGP table size more, cosider: Usig ip uumbered o customer poit-to-poit liks saves carryig that /30 i IGP p (If customer poit-to-poit /30 is required for moitorig purposes, the put this i ibgp) Use cotiguous addresses for backboe WAN liks i each area the summarise ito backboe area Do t summarise router loopback addresses as ibgp eeds those (for ext-hop) Use ibgp for carryig aythig which does ot cotribute to the IGP Routig process 80

81 Routig Protocols: ibgp Recommedatios p ibgp should carry everythig which does t cotribute to the IGP routig process Iteret routig table Customer assiged addresses Customer poit-to-poit liks Access etwork dyamic address pools, passive LANs, etc 81

82 Routig Protocols: More ibgp Recommedatios p Scalable ibgp features: Use eighbour autheticatio Use peer-groups to speed update process ad for cofiguratio efficiecy Use commuities for ease of filterig Use route-reflector hierarchy p Route reflector pair per PoP (overlaid clusters) 82

83 Security 83

84 Security p ISP Ifrastructure security p ISP Network security p Security is ot optioal! p ISPs eed to: Protect themselves Help protect their customers from the Iteret Protect the Iteret from their customers p The followig slides are geeral recommedatios Do more research o security before deployig ay etwork 84

85 ISP Ifrastructure Security p Router & Switch Security Use Secure Shell (SSH) for device access & maagemet p Do NOT use Telet Device maagemet access filters should oly allow NOC ad device-to-device access p Do NOT allow exteral access Use TACACS+ for user autheticatio ad authorisatio p Do NOT create user accouts o routers/switches 85

86 ISP Ifrastructure Security p Remote access For Operatios Egieers who eed access while ot i the NOC Create a SSH server host (this is all it does) p Or a Secure VPN access server Ops Egieers coect here, ad the they ca access the NOC ad etwork devices 86

87 ISP Ifrastructure Security p Other etwork devices? These probably do ot have sophisticated security techiques like routers or switches do Protect them at the LAN or poit-to-poit igress (o router) p Servers ad Services? p SNMP Protect servers o the LAN iterface o the router Cosider usig iptables &c o the servers too Apply access-list to the SNMP ports Should oly be accessible by maagemet system, ot the world 87

88 ISP Ifrastructure Security p Geeral Advice: Routers, Switches ad other etwork devices should ot be cotactable from outside the AS Achieved by blockig typical maagemet access protocols for the ifrastructure address block at the etwork perimeter p E.g. ssh, telet, http, smp, Use the ICSI Netalyser to check access levels: p Do t block everythig: BGP, traceroute ad ICMP still eed to work! 88

89 ISP Network Security p Effective filterig Protect etwork borders from traffic which should ot be o the public Iteret, for example: p LAN protocols (eg etbios) p Well kow exploit ports (used by worms ad viruses) p Drop traffic arrivig ad goig to private ad o-routable address space (IPv4 ad IPv6) Achieved by packet filters o border routers p Remote trigger blackhole filterig 89

90 ISP Network Security RTBF p Remote trigger blackhole filterig ISP NOC ijects prefixes which should ot be accessible across the AS ito the ibgp Prefixes have ext hop poitig to a blackhole address All ibgp speakig backboe routers cofigured to poit the blackhole address to the ull iterface Traffic destied to these blackhole prefixes are dropped by the first router they reach p Applicatio: Ay prefixes (icludig RFC1918) which should ot have routability across the ISP backboe 90

91 ISP Network Security RTBF p Remote trigger blackhole filterig example: Origi router: router bgp redistribute static route-map black-hole-trigger! ip route Null0 tag 66! route-map black-hole-trigger permit 10 match tag 66 set local-preferece 1000 set commuity o-export set ip ext-hop ! ibgp speakig backboe router: ip route ull0 91

92 ISP Network Security RTBF p Resultig routig table etries: gw1#sh ip bgp BGP routig table etry for /32, versio Paths: (1 available, best #1, table Default-IP-Routig-Table) Not advertised to ay peer Local from ( ) Origi IGP, metric 0, localpref 1000, valid, iteral, best Commuity: o-export gw1#sh ip route Routig etry for /32 Kow via "bgp 64509", distace 200, metric 0, type iteral Last update from :04:52 ago Routig Descriptor Blocks: * , from , 00:04:52 ago Route metric is 0, traffic share cout is 1 AS Hops 0 92

93 ISP Network Security urpf p Uicast Reverse Path Forwardig p Strogly recommeded to be used o all customer facig static iterfaces BCP 38 (tools.ietf.org/html/bcp38) Blocks all uroutable source addresses the customer may be usig Iexpesive way of filterig customer s coectio (whe compared with packet filters) p Ca be used for multihomed coectios too, but extreme care required 93

94 Aside: What is urpf? src= fa0/0 router FIB: /24 fa0/ /24 gi0/1 gi0/1 p Router compares source address of icomig packet with FIB etry If FIB etry iterface matches icomig iterface, the packet is forwarded If FIB etry iterface does ot match icomig iterface, the packet is dropped 94

95 Aside: What is urpf? src= fa0/0 router FIB: /24 fa0/ /24 gi0/1 gi0/1 p Router compares source address of icomig packet with FIB etry If FIB etry iterface matches icomig iterface, the packet is forwarded If FIB etry iterface does ot match icomig iterface, the packet is dropped 95

96 Security Summary p Implemet RTBF Iside ISP backboe Make it available to BGP customers too p They ca sed you the prefix you eed to block with a special commuity attached p You match o that commuity, ad set the ext-hop to the ull address p Implemet urpf For all static customers p Use SSH for device access p Use TACACS+ for autheticatio 96

97 Out of Bad Maagemet 97

98 Out of Bad Maagemet p Not optioal! p Allows access to etwork equipmet i times of failure p Esures quality of service to customers Miimises dowtime Miimises repair time Eases diagostics ad debuggig 98

99 Out of Bad Maagemet p OoB Example Access server: modem attached to allow NOC dial i cosole ports of all etwork equipmet coected to serial ports LAN ad/or WAN lik coects to etwork core, or via separate maagemet lik to NOC p Full remote cotrol access uder all circumstaces 99

100 Out of Bad Network Equipmet Rack Equipmet Rack Router, switch ad ISP server cosoles (Optioal) Out of bad WAN lik to other PoPs Modem access to PSTN for out of bad diali Etheret to the NOC 100

101 Out of Bad Maagemet p OoB Example Statistics gatherig: Routers are NetFlow ad syslog eabled Maagemet data is cogestio/failure sesitive Esures maagemet data itegrity i case of failure p Full remote iformatio uder all circumstaces 101

102 Test Laboratory 102

103 Test Laboratory p Desiged to look like a typical PoP Operated like a typical PoP p Used to trial ew services or ew software uder realistic coditios p Allows discovery ad fixig of potetial problems before they are itroduced to the etwork 103

104 Test Laboratory p Some ISPs dedicate equipmet to the lab p Other ISPs purchase ahead so that today s lab equipmet becomes tomorrow s PoP equipmet p Other ISPs use lab equipmet for hot spares i the evet of hardware failure 104

105 Test Laboratory p Ca t afford a test lab? Set aside oe spare router ad server to trial ew services Never ever try out ew hardware, software or services o the live etwork p Every major ISP i the US ad Europe has a test lab It s a serious cosideratio 105

106 Operatioal Cosideratios 106

107 Operatioal Cosideratios Why desig the world s best etwork whe you have ot thought about what operatioal good practices should be implemeted? 107

108 Operatioal Cosideratios Maiteace p Never work o the live etwork, o matter how trivial the modificatio may seem Establish maiteace periods which your customers are aware of p e.g. Tuesday 4-7am, Thursday 4-7am p Never do maiteace o the last workig day before the weeked Uless you wat to work all weeked cleaig up p Never do maiteace o the first workig day after the weeked Uless you wat to work all weeked preparig 108

109 Operatioal Cosideratios Support p Differetiate betwee customer support ad the Network Operatios Cetre Customer support fixes customer problems NOC deals with ad fixes backboe ad Iteret related problems p Network Egieerig team is last resort They desig the ext geeratio etwork, improve the routig desig, implemet ew services, etc They do ot ad should ot be doig support! 109

110 Operatioal Cosideratios NOC Commuicatios p NOC should kow cotact details for equivalet NOCs i upstream providers ad peers p Or cosider joiig the INOC-DBA system Voice over IP phoe system usig SIP Rus over the Iteret for more iformatio 110

111 ISP Network Desig Summary 111

112 ISP Desig Summary p KEEP IT SIMPLE & STUPID! (KISS) p Simple is elegat is scalable p Use Redudacy, Security, ad Techology to make life easier for yourself p Above all, esure quality of service for your customers 112

113 ISP Network Desig ISP Workshops 113

Transitioning to BGP

Transitioning to BGP Trasitioig to BGP ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 24 th April

More information

The Value of Peering

The Value of Peering The Value of Peerig ISP/IXP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 25 th

More information

ISP and IXP Design. Point of Presence Topologies. ISP Network Design. PoP Topologies. Modular PoP Design. PoP Design INET 2000 NTW

ISP and IXP Design. Point of Presence Topologies. ISP Network Design. PoP Topologies. Modular PoP Design. PoP Design INET 2000 NTW ISP Network Design PoP Topologies and Design ISP and IXP Design Backbone Design Addressing INET 2000 NTW Routing Protocols Security Out of Band Management IXP/IXP Workshops 1999, Cisco Systems, Inc. 1

More information

IS-IS in Detail. ISP Workshops

IS-IS in Detail. ISP Workshops IS-IS i Detail ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 27 th November

More information

Introduction to The Internet

Introduction to The Internet Itroductio to The Iteret ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 13 th

More information

Deploying 32-bit ASNs

Deploying 32-bit ASNs Deployig 32-bit ASNs ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 26 th September

More information

BGP Attributes and Path Selection. ISP Training Workshops

BGP Attributes and Path Selection. ISP Training Workshops BGP Attributes ad Path Selectio ISP Traiig Workshops 1 BGP Attributes The tools available for the job 2 What Is a Attribute?... Next Hop AS Path MED...... p Part of a BGP Update p Describes the characteristics

More information

ISP Systems Design. ISP Workshops

ISP Systems Design. ISP Workshops ISP Systems Desig ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 24 th April

More information

IS-IS for IPv6. ISP Workshops

IS-IS for IPv6. ISP Workshops IS-IS for IPv6 ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 8 th April 2018

More information

Introduction to OSPF. ISP Training Workshops

Introduction to OSPF. ISP Training Workshops Itroductio to OSPF ISP Traiig Workshops 1 OSPF p Ope Shortest Path First p Lik state or SPF techology p Developed by OSPF workig group of IETF (RFC 1247) p OSPFv2 stadard described i RFC2328 p Desiged

More information

Simple Multihoming. ISP Training Workshops

Simple Multihoming. ISP Training Workshops Simple Multihomig ISP Traiig Workshops 1 Why Multihome? p Redudacy Oe coectio to iteret meas the etwork is depedet o: p Local router (cofiguratio, software, hardware) p WAN media (physical failure, carrier

More information

IPv6 Deployment Planning

IPv6 Deployment Planning IPv6 Deploymet Plaig ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 5 th July

More information

IPv6 Deployment Planning

IPv6 Deployment Planning IPv6 Deploymet Plaig ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 8 th April

More information

IPv6 Routing Protocols. ISP Training Workshops

IPv6 Routing Protocols. ISP Training Workshops IPv6 Routig Protocols ISP Traiig Workshops 1 Iitial IPv6 Cofiguratio for Cisco IOS 2 IPv6 Cofiguratio o Cisco IOS p To eable IPv6 the followig global commads are required: Router(cofig)# ipv6 uicast-routig

More information

IS-IS for ISPs. ISP Workshops

IS-IS for ISPs. ISP Workshops IS-IS for ISPs ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 21 st April 2017

More information

Web OS Switch Software

Web OS Switch Software Web OS Switch Software BBI Quick Guide Nortel Networks Part Number: 213164, Revisio A, July 2000 50 Great Oaks Boulevard Sa Jose, Califoria 95119 408-360-5500 Mai 408-360-5501 Fax www.orteletworks.com

More information

IPv6 Addressing. ISP Workshops

IPv6 Addressing. ISP Workshops IPv6 Addressig ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 12 th April 2018

More information

BGP Best Current Practices. ISP Training Workshops

BGP Best Current Practices. ISP Training Workshops BGP Best Curret Practices ISP Traiig Workshops 1 Cofigurig BGP Where do we start? 2 IOS Good Practices p ISPs should start off with the followig BGP commads as a basic template: router bgp 64511 bgp determiistic-med

More information

IPv6 Addressing. ISP Workshops

IPv6 Addressing. ISP Workshops IPv6 Addressig ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 21 st October

More information

Global Support Guide. Verizon WIreless. For the BlackBerry 8830 World Edition Smartphone and the Motorola Z6c

Global Support Guide. Verizon WIreless. For the BlackBerry 8830 World Edition Smartphone and the Motorola Z6c Verizo WIreless Global Support Guide For the BlackBerry 8830 World Editio Smartphoe ad the Motorola Z6c For complete iformatio o global services, please refer to verizowireless.com/vzglobal. Whether i

More information

IPv6 Routing Protocol Security

IPv6 Routing Protocol Security IPv6 Routig Protocol Security ITU/APNIC/PacNOG21 IPv6 Workshop 4 th 8 th December 2017 Nuku alofa These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/)

More information

IPv6 Deployment Study

IPv6 Deployment Study IPv6 Deploymet Study ISP Workshops These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/) Last updated 8 th April

More information

Data Protection: Your Choice Is Simple PARTNER LOGO

Data Protection: Your Choice Is Simple PARTNER LOGO Data Protectio: Your Choice Is Simple PARTNER LOGO Is Your Data Truly Protected? The growth, value ad mobility of data are placig icreasig pressure o orgaizatios. IT must esure assets are properly protected

More information

Avid Interplay Bundle

Avid Interplay Bundle Avid Iterplay Budle Versio 2.5 Cofigurator ReadMe Overview This documet provides a overview of Iterplay Budle v2.5 ad describes how to ru the Iterplay Budle cofiguratio tool. Iterplay Budle v2.5 refers

More information

n Based on unrealistic growth forecast n Overcapacity: Fiber 5x100 in three years n Wireless: Expensive spectrum licenses n Fibers

n Based on unrealistic growth forecast n Overcapacity: Fiber 5x100 in three years n Wireless: Expensive spectrum licenses n Fibers EECS228a Research Topics Jea Walrad www.eecs.berkeley.edu/~wlr of Networks Walrad 52 of Networks Pricig of Services Competitio of Users Competitio of Providers Suggested Readigs: http://www.bgsu.edu/departmets/tcom/aota.htm

More information

Windows Server 2008 R2 networking

Windows Server 2008 R2 networking Chapter3 Widows Server 2008 R2 etworkig Orgaizatios large ad small deped o computer etworks to operate their busiesses. Employees require aywhere access to data, while cliets ad busiess parters demad ehaced

More information

MOTIF XF Extension Owner s Manual

MOTIF XF Extension Owner s Manual MOTIF XF Extesio Ower s Maual Table of Cotets About MOTIF XF Extesio...2 What Extesio ca do...2 Auto settig of Audio Driver... 2 Auto settigs of Remote Device... 2 Project templates with Iput/ Output Bus

More information

n Learn how resiliency strategies reduce risk n Discover automation strategies to reduce risk

n Learn how resiliency strategies reduce risk n Discover automation strategies to reduce risk Chapter Objectives Lear how resiliecy strategies reduce risk Discover automatio strategies to reduce risk Chapter #16: Architecture ad Desig Resiliecy ad Automatio Strategies 2 Automatio/Scriptig Resiliet

More information

L I N U X. Unit 6 S Y S T E M DHCP & DNS (BIND) A D M I N I S T R A T I O n DPW

L I N U X. Unit 6 S Y S T E M DHCP & DNS (BIND) A D M I N I S T R A T I O n DPW it 6 HCP & (B) oa Warre HCP ervice yamically assigs a P address to requestig machies P addresses are leased scope of addresses ca be assiged or excluded from assigmet HCP servers do ot talk to each other

More information

Basic allocator mechanisms The course that gives CMU its Zip! Memory Management II: Dynamic Storage Allocation Mar 6, 2000.

Basic allocator mechanisms The course that gives CMU its Zip! Memory Management II: Dynamic Storage Allocation Mar 6, 2000. 5-23 The course that gives CM its Zip Memory Maagemet II: Dyamic Storage Allocatio Mar 6, 2000 Topics Segregated lists Buddy system Garbage collectio Mark ad Sweep Copyig eferece coutig Basic allocator

More information

Resource Public Key Infrastructure for Secure Border Gateway Protocol

Resource Public Key Infrastructure for Secure Border Gateway Protocol Resource Public Key Ifrastructure for Secure Border Gateway Protocol George Chag, Majid Ariaezhad, ad Ljiljaa Trajković gkchag@sfu.ca, ariaezhad@live.com, ljilja@sfu.ca Commuicatio Networks Laboratory

More information

BE Software Upgrades to ITALYCS 5. It s in the. Software

BE Software Upgrades to ITALYCS 5. It s in the. Software BE Software Upgrades to ITALYCS 5 It s i the Software UPGRADES WE OFFER Brampto Egieerig is offerig customers with ITALYCS 2 ad ITALYCS 4 systems the opportuity to upgrade their existig systems to the

More information

IPv6 Transition Planning

IPv6 Transition Planning IPv6 Trasitio Plaig ITU/APNIC/PacNOG21 IPv6 Workshop 4 th 8 th December 2017 Nuku alofa These materials are licesed uder the Creative Commos Attributio-NoCommercial 4.0 Iteratioal licese (http://creativecommos.org/liceses/by-c/4.0/)

More information

USER GUIDE FOR VENDOR LISTING DATASHEET

USER GUIDE FOR VENDOR LISTING DATASHEET USER GUIDE FOR VENDOR LISTING DATASHEET Vedor Database Maagemet System (VDMS) Uit Cotracts Sectio Cotracts, Purchasig Ad Logistics Departmet (CPL) Level 2 Khartoum Tower Gamhouria St. PO 12527 Khartoum

More information

n Explore virtualization concepts n Become familiar with cloud concepts

n Explore virtualization concepts n Become familiar with cloud concepts Chapter Objectives Explore virtualizatio cocepts Become familiar with cloud cocepts Chapter #15: Architecture ad Desig 2 Hypervisor Virtualizatio ad cloud services are becomig commo eterprise tools to

More information

Introduction to The Internet

Introduction to The Internet Introduction to The Internet ITU/APNIC/MOIC IPv6 Workshop 19 th 21 st June 2017 Thimphu These materials are licensed under the Creative Commons Attribution-NonCommercial 4.0 International license (http://creativecommons.org/licenses/by-nc/4.0/)

More information

Security and Communication. Ultimate. Because Intercom doesn t stop at the hardware level. Software Intercom Server for virtualised IT platforms

Security and Communication. Ultimate. Because Intercom doesn t stop at the hardware level. Software Intercom Server for virtualised IT platforms Because Itercom does t stop at the hardware level by Commed Software Itercom Server for virtualised IT platforms Ready for VMware Ready for Hyper-V VoIP Ultimate availability Itercom Server as a app The

More information

Introduction to Network Technologies & Layered Architecture BUPT/QMUL

Introduction to Network Technologies & Layered Architecture BUPT/QMUL Itroductio to Network Techologies & Layered Architecture BUPT/QMUL 2018-3-12 Review What is the Iteret? How does it work? Whe & how did it come about? Who cotrols it? Where is it goig? 2 Ageda Basic Network

More information

Announcements. Reading. Project #4 is on the web. Homework #1. Midterm #2. Chapter 4 ( ) Note policy about project #3 missing components

Announcements. Reading. Project #4 is on the web. Homework #1. Midterm #2. Chapter 4 ( ) Note policy about project #3 missing components Aoucemets Readig Chapter 4 (4.1-4.2) Project #4 is o the web ote policy about project #3 missig compoets Homework #1 Due 11/6/01 Chapter 6: 4, 12, 24, 37 Midterm #2 11/8/01 i class 1 Project #4 otes IPv6Iit,

More information

1. SWITCHING FUNDAMENTALS

1. SWITCHING FUNDAMENTALS . SWITCING FUNDMENTLS Switchig is the provisio of a o-demad coectio betwee two ed poits. Two distict switchig techiques are employed i commuicatio etwors-- circuit switchig ad pacet switchig. Circuit switchig

More information

IPv6 Transition Strategies. Philip Smith APNIC 44 Taichung, Taiwan 7 th 14 th September 2017

IPv6 Transition Strategies. Philip Smith APNIC 44 Taichung, Taiwan 7 th 14 th September 2017 IPv6 Trasitio Strategies Philip Smith APNIC 44 Taichug, Taiwa 7 th 14 th September 2017 Last updated 12 th September 2017 1 Presetatio Slides p Will be available o http://bgp4all.com/dokuwiki/cofereces/

More information

Lecture 28: Data Link Layer

Lecture 28: Data Link Layer Automatic Repeat Request (ARQ) 2. Go ack N ARQ Although the Stop ad Wait ARQ is very simple, you ca easily show that it has very the low efficiecy. The low efficiecy comes from the fact that the trasmittig

More information

100 Internet Exchange Points And Beyond!

100 Internet Exchange Points And Beyond! 100 Iteret Exchage Poits Ad Beyod! April 2016 LACNIC 25 Havaa Cuba Walt Wolly, Director Itercoectio Strategy Hurricae Electric AS6939 Who is Walt Wolly? Hurricae Electric AS6939 2 years Amazo AS16509 4

More information

CMSC Computer Architecture Lecture 12: Virtual Memory. Prof. Yanjing Li University of Chicago

CMSC Computer Architecture Lecture 12: Virtual Memory. Prof. Yanjing Li University of Chicago CMSC 22200 Computer Architecture Lecture 12: Virtual Memory Prof. Yajig Li Uiversity of Chicago A System with Physical Memory Oly Examples: most Cray machies early PCs Memory early all embedded systems

More information

performance to the performance they can experience when they use the services from a xed location.

performance to the performance they can experience when they use the services from a xed location. I the Proceedigs of The First Aual Iteratioal Coferece o Mobile Computig ad Networkig (MobiCom 9) November -, 99, Berkeley, Califoria USA Performace Compariso of Mobile Support Strategies Rieko Kadobayashi

More information

150 Internet Exchange Points And Beyond!

150 Internet Exchange Points And Beyond! 150 Iteret Exchage Poits Ad Beyod! HKNOG 2018 Hog Kog Walt Wolly, Director Itercoectio Strategy Hurricae Electric AS6939 Who is Walt Wolly? Hurricae Electric AS6939 4 years Amazo AS16509 4 years Director

More information

Session Initiated Protocol (SIP) and Message-based Load Balancing (MBLB)

Session Initiated Protocol (SIP) and Message-based Load Balancing (MBLB) F5 White Paper Sessio Iitiated Protocol (SIP) ad Message-based Load Balacig (MBLB) The ability to provide ew ad creative methods of commuicatios has esured a SIP presece i almost every orgaizatio. The

More information

JavaFX. JavaFX 2.2 Installation Guide Release 2.2 E August 2012 Installation instructions by operating system for JavaFX 2.

JavaFX. JavaFX 2.2 Installation Guide Release 2.2 E August 2012 Installation instructions by operating system for JavaFX 2. JavaFX JavaFX 2.2 Istallatio Guide Release 2.2 E20474-06 August 2012 Istallatio istructios by operatig system for JavaFX 2.2 JavaFX/JavaFX 2.2 Istallatio Guide E20474-06 Copyright 2008, 2012, Oracle ad/or

More information

Quality of Service. Spring 2018 CS 438 Staff - University of Illinois 1

Quality of Service. Spring 2018 CS 438 Staff - University of Illinois 1 Quality of Service Sprig 2018 CS 438 Staff - Uiversity of Illiois 1 Quality of Service How good are late data ad lowthroughput chaels? It depeds o the applicatio. Do you care if... Your e-mail takes 1/2

More information

Data diverse software fault tolerance techniques

Data diverse software fault tolerance techniques Data diverse software fault tolerace techiques Complemets desig diversity by compesatig for desig diversity s s limitatios Ivolves obtaiig a related set of poits i the program data space, executig the

More information

Course Information. Details. Topics. Network Examples. Overview. Walrand Lecture 1. EECS 228a. EECS 228a Lecture 1 Overview: Networks

Course Information. Details. Topics. Network Examples. Overview. Walrand Lecture 1. EECS 228a. EECS 228a Lecture 1 Overview: Networks Walrad Lecture 1 Course Iformatio Lecture 1 Overview: Networks Jea Walrad www.eecs.berkeley.edu/~wlr Istructor: Jea Walrad Office Hours: M-Tu 1:00-2:00 Time/Place: MW 2:00-3:30 i 285 Cory Home Page: http://wwwist.eecs.berkeley.edu/~ee228a

More information

1100 Appliances. Big security for small branches. Datasheet: Check Point 1100 Appliances FEATURES BENEFITS GATEWAY SOFTWARE BLADES

1100 Appliances. Big security for small branches. Datasheet: Check Point 1100 Appliances FEATURES BENEFITS GATEWAY SOFTWARE BLADES Datasheet: Check Poit 00 Appliaces 00 Big security for small braches 00 Appliaces YOUR CHALLENGE I the age of global busiess ad icreasigly more distributed workforce, remote ad brach staff demad access

More information

G2 T Made in the USA. Specification Sheet G2T-001 G2T Mainframes with Touchscreen Accepts G2 Plug-in Modules Four Sizes: 2RU, 3RU, 6RU and 8RU

G2 T Made in the USA. Specification Sheet G2T-001 G2T Mainframes with Touchscreen Accepts G2 Plug-in Modules Four Sizes: 2RU, 3RU, 6RU and 8RU Specificatio Sheet G2T-001 G2T Maiframes with Touchscree Accepts G2 Plug-i Modules Four Sizes: 2RU, 3RU, 6RU ad 8RU Geeral The G2T maiframes are the latest additio to our fieldprove G2 family of products

More information

1&1 Next Level Hosting

1&1 Next Level Hosting 1&1 Next Level Hostig Performace Level: Performace that grows with your requiremets Copyright 1&1 Iteret SE 2017 1ad1.com 2 1&1 NEXT LEVEL HOSTING 3 Fast page loadig ad short respose times play importat

More information

3/10/2011. Copyright Link Technologies, Inc.

3/10/2011. Copyright Link Technologies, Inc. Mikrotik Certified Trainer / Engineer MikroTik Certified Dude Consultant Consulting Since 1997 Enterprise Class Networks WAN Connectivity Certifications Cisco, Microsoft, MikroTik BGP/OSPF Experience Deployed

More information

Network Time Protocol (NTP)

Network Time Protocol (NTP) Network Time Protocol (NTP) Quick ad Dirty for AfNOG 2018 (Michuki Mwagi) Origial slides by Ayitey Bulley About NTP Network Time Protocol project http://tp.org NTP is a protocol desiged to sychroize the

More information

1100 Appliances. Big security for small branches. Datasheet: Check Point 1100 Appliances FEATURES BENEFITS GATEWAY SOFTWARE BLADES

1100 Appliances. Big security for small branches. Datasheet: Check Point 1100 Appliances FEATURES BENEFITS GATEWAY SOFTWARE BLADES Formoreiformatio,pleasecal877.449.0458,oremailusatSales@CorporateArmor.com. Datasheet: Check Poit 00 Appliaces 00 Big security for small braches 00 Appliaces YOUR CHALLENGE I the age of global busiess

More information

Service Provider Multihoming

Service Provider Multihoming Service Provider Multihoming ISP Workshops These materials are licensed under the Creative Commons Attribution-NonCommercial 4.0 International license (http://creativecommons.org/licenses/by-nc/4.0/) Last

More information

Customer Portal Quick Reference User Guide

Customer Portal Quick Reference User Guide Customer Portal Quick Referece User Guide Overview This user guide is iteded for FM Approvals customers usig the Approval Iformatio Maagemet (AIM) customer portal to track their active projects. AIM is

More information

CS 111: Program Design I Lecture 19: Networks, the Web, and getting text from the Web in Python

CS 111: Program Design I Lecture 19: Networks, the Web, and getting text from the Web in Python CS 111: Program Desig I Lecture 19: Networks, the Web, ad gettig text from the Web i Pytho Robert H. Sloa & Richard Warer Uiversity of Illiois at Chicago April 3, 2018 Goals Lear about Iteret Lear about

More information

Identifying and Cabling Circuit Cards. Identifying and Cabling Circuit Cards - 1

Identifying and Cabling Circuit Cards. Identifying and Cabling Circuit Cards - 1 Cards Cards - 1 Cards Cards This sectio provides the basic iformatio you eed to coect cables to the faceplates of circuit cards that are istalled i the system. Additioal steps may be required for some

More information

Firewall and IDS. TELE3119: Week8

Firewall and IDS. TELE3119: Week8 Firewall ad IDS TELE3119: Week8 Outlie Firewalls Itrusio Detectio Systems (IDSs) Itrusio Prevetio Systems (IPSs) 8-2 Example Attacks Disclosure, modificatio, ad destructio of data Compromise a host ad

More information

ICS Regent. Communications Modules. Module Operation. RS-232, RS-422 and RS-485 (T3150A) PD-6002

ICS Regent. Communications Modules. Module Operation. RS-232, RS-422 and RS-485 (T3150A) PD-6002 ICS Reget Commuicatios Modules RS-232, RS-422 ad RS-485 (T3150A) Issue 1, March, 06 Commuicatios modules provide a serial commuicatios iterface betwee the cotroller ad exteral equipmet. Commuicatios modules

More information

Introduction to The Internet

Introduction to The Internet Introduction to The Internet ITU/APNIC/MICT IPv6 Security Workshop 23 rd 27 th May 2016 Bangkok Last updated 5 th May 2015 1 Introduction to the Internet p Topologies and Definitions p IP Addressing p

More information

Morgan Kaufmann Publishers 26 February, COMPUTER ORGANIZATION AND DESIGN The Hardware/Software Interface. Chapter 5

Morgan Kaufmann Publishers 26 February, COMPUTER ORGANIZATION AND DESIGN The Hardware/Software Interface. Chapter 5 Morga Kaufma Publishers 26 February, 28 COMPUTER ORGANIZATION AND DESIGN The Hardware/Software Iterface 5 th Editio Chapter 5 Set-Associative Cache Architecture Performace Summary Whe CPU performace icreases:

More information

Ones Assignment Method for Solving Traveling Salesman Problem

Ones Assignment Method for Solving Traveling Salesman Problem Joural of mathematics ad computer sciece 0 (0), 58-65 Oes Assigmet Method for Solvig Travelig Salesma Problem Hadi Basirzadeh Departmet of Mathematics, Shahid Chamra Uiversity, Ahvaz, Ira Article history:

More information

BGP Multihoming ISP/IXP Workshops

BGP Multihoming ISP/IXP Workshops BGP Multihoming ISP/IXP 1 Why Multihome? Redundancy One connection to internet means the network is dependent on: Local router (configuration, software, hardware) WAN media (physical failure, carrier failure)

More information

CORD Test Project in Okinawa Open Laboratory

CORD Test Project in Okinawa Open Laboratory CORD Test Project i Okiawa Ope Laboratory Fukumasa Morifuji NTT Commuicatios Trasform your busiess, trasced expectatios with our techologically advaced solutios. Ageda VxF platform i NTT Commuicatios Expectatio

More information

System and Software Architecture Description (SSAD)

System and Software Architecture Description (SSAD) System ad Software Architecture Descriptio (SSAD) Diabetes Health Platform Team #6 Jasmie Berry (Cliet) Veerav Naidu (Project Maager) Mukai Nog (Architect) Steve South (IV&V) Vijaya Prabhakara (Quality

More information

CSC 220: Computer Organization Unit 11 Basic Computer Organization and Design

CSC 220: Computer Organization Unit 11 Basic Computer Organization and Design College of Computer ad Iformatio Scieces Departmet of Computer Sciece CSC 220: Computer Orgaizatio Uit 11 Basic Computer Orgaizatio ad Desig 1 For the rest of the semester, we ll focus o computer architecture:

More information

Panel for Adobe Premiere Pro CC Partner Solution

Panel for Adobe Premiere Pro CC Partner Solution Pael for Adobe Premiere Pro CC Itegratio for more efficiecy The makes video editig simple, fast ad coveiet. The itegrated pael gives users immediate access to all medialoopster features iside Adobe Premiere

More information

Lecturers: Sanjam Garg and Prasad Raghavendra Feb 21, Midterm 1 Solutions

Lecturers: Sanjam Garg and Prasad Raghavendra Feb 21, Midterm 1 Solutions U.C. Berkeley CS170 : Algorithms Midterm 1 Solutios Lecturers: Sajam Garg ad Prasad Raghavedra Feb 1, 017 Midterm 1 Solutios 1. (4 poits) For the directed graph below, fid all the strogly coected compoets

More information

Multiprocessors. HPC Prof. Robert van Engelen

Multiprocessors. HPC Prof. Robert van Engelen Multiprocessors Prof. Robert va Egele Overview The PMS model Shared memory multiprocessors Basic shared memory systems SMP, Multicore, ad COMA Distributed memory multicomputers MPP systems Network topologies

More information

G2 T. Specification Sheet G2T-001 G2T Touchscreen Mainframes Accepts G2 Plug-in Modules Four Sizes: 2RU, 3RU, 6RU and 8RU

G2 T. Specification Sheet G2T-001 G2T Touchscreen Mainframes Accepts G2 Plug-in Modules Four Sizes: 2RU, 3RU, 6RU and 8RU G2 T Geeral The G2T Maiframes are part of our field-prove G2 family of products ad replaces the G2S maiframes. The mai differece is the all ew frot pael touchscree desig which replaces the older VF display

More information

Principles of modern LAN design and operation. Guido Marchetto Fulvio Risso Politecnico di Torino

Principles of modern LAN design and operation. Guido Marchetto Fulvio Risso Politecnico di Torino Priciples of moder LAN desig ad operatio Guido Marchetto Fulvio Risso Politecico di Torio 1 Copyright otice This set of trasparecies, hereiafter referred to as slides, is protected by copyright laws ad

More information

Structuring Redundancy for Fault Tolerance. CSE 598D: Fault Tolerant Software

Structuring Redundancy for Fault Tolerance. CSE 598D: Fault Tolerant Software Structurig Redudacy for Fault Tolerace CSE 598D: Fault Tolerat Software What do we wat to achieve? Versios Damage Assessmet Versio 1 Error Detectio Iputs Versio 2 Voter Outputs State Restoratio Cotiued

More information

Baan Tools User Management

Baan Tools User Management Baa Tools User Maagemet Module Procedure UP008A US Documetiformatio Documet Documet code : UP008A US Documet group : User Documetatio Documet title : User Maagemet Applicatio/Package : Baa Tools Editio

More information

Switching Hardware. Spring 2018 CS 438 Staff, University of Illinois 1

Switching Hardware. Spring 2018 CS 438 Staff, University of Illinois 1 Switchig Hardware Sprig 208 CS 438 Staff, Uiversity of Illiois Where are we? Uderstad Differet ways to move through a etwork (forwardig) Read sigs at each switch (datagram) Follow a kow path (virtual circuit)

More information

Appendix D. Controller Implementation

Appendix D. Controller Implementation COMPUTER ORGANIZATION AND DESIGN The Hardware/Software Iterface 5 th Editio Appedix D Cotroller Implemetatio Cotroller Implemetatios Combiatioal logic (sigle-cycle); Fiite state machie (multi-cycle, pipelied);

More information

Switch Construction CS

Switch Construction CS Switch Costructio CS 00 Workstatio-Based Aggregate badwidth /2 of the I/O bus badwidth capacity shared amog all hosts coected to switch example: Gbps bus ca support 5 x 00Mbps ports (i theory) I/O bus

More information

CMSC Computer Architecture Lecture 10: Caches. Prof. Yanjing Li University of Chicago

CMSC Computer Architecture Lecture 10: Caches. Prof. Yanjing Li University of Chicago CMSC 22200 Computer Architecture Lecture 10: Caches Prof. Yajig Li Uiversity of Chicago Midterm Recap Overview ad fudametal cocepts ISA Uarch Datapath, cotrol Sigle cycle, multi cycle Pipeliig Basic idea,

More information

Building Converged Cisco Multilayer Switched Networks (BCMSN) LearnSmart Exam Manual

Building Converged Cisco Multilayer Switched Networks (BCMSN) LearnSmart Exam Manual Maual BCMSN Buildig Coverged Cisco Multilayer Switched Networks (BCMSN) LearSmart Maual Copyright 2011 by PrepLogic, LLC Product ID: 011242 Productio Date: July 19, 2011 All rights reserved. No part of

More information

Japan IPv6 Measurement

Japan IPv6 Measurement Japa IPv6 Measuremet Tomohiro Fujisaki NTT/IPv6 Promotio Coucil i Japa IPv6 Readiess Measuremet BoF APNIC 43 28 February 2017 Summary of IPv6 deploymet status i Japa Networks Major three cellular carriers

More information

Morgan Kaufmann Publishers 26 February, COMPUTER ORGANIZATION AND DESIGN The Hardware/Software Interface. Chapter 5.

Morgan Kaufmann Publishers 26 February, COMPUTER ORGANIZATION AND DESIGN The Hardware/Software Interface. Chapter 5. Morga Kaufma Publishers 26 February, 208 COMPUTER ORGANIZATION AND DESIGN The Hardware/Software Iterface 5 th Editio Chapter 5 Virtual Memory Review: The Memory Hierarchy Take advatage of the priciple

More information

Guide to Applying Online

Guide to Applying Online Guide to Applyig Olie Itroductio Respodig to requests for additioal iformatio Reportig: submittig your moitorig or ed of grat Pledges: submittig your Itroductio This guide is to help charities submit their

More information

Advanced Multihoming. BGP Traffic Engineering

Advanced Multihoming. BGP Traffic Engineering Advanced Multihoming BGP Traffic Engineering 1 Service Provider Multihoming Previous examples dealt with loadsharing inbound traffic Of primary concern at Internet edge What about outbound traffic? Transit

More information

Next generation IP- based multimedia services on cable TV networks

Next generation IP- based multimedia services on cable TV networks Iteratioal Telecommuicatio Uio Next geeratio IP- based multimedia services o cable TV etworks Volker Leisse ECCA Pre - coferece draft ITU-T Workshop All Star Network Access Geeva, 2-4 Jue 2004 Outlie o

More information

Linux DNS (BIND), DHCP and Servers

Linux DNS (BIND), DHCP and  Servers it 8 Liux (B), HCP ad mail ervers oa Warre HCP oa Warre HCP ervice yamically assigs a P address to requestig machies P addresses are leased P addresses are leased scope of addresses ca be assiged or excluded

More information

Chapter 2 Distributed Information Systems Architecture

Chapter 2 Distributed Information Systems Architecture Prof. Dr.-Ig. Stefa Deßloch AG Heterogee Iformatiossysteme Geb. 36, Raum 329 Tel. 0631/205 3275 dessloch@iformatik.ui-kl.de Chapter 2 Distributed Iformatio Systems Architecture Chapter Outlie (Distributed)

More information

Administrative UNSUPERVISED LEARNING. Unsupervised learning. Supervised learning 11/25/13. Final project. No office hours today

Administrative UNSUPERVISED LEARNING. Unsupervised learning. Supervised learning 11/25/13. Final project. No office hours today Admiistrative Fial project No office hours today UNSUPERVISED LEARNING David Kauchak CS 451 Fall 2013 Supervised learig Usupervised learig label label 1 label 3 model/ predictor label 4 label 5 Supervised

More information

The isoperimetric problem on the hypercube

The isoperimetric problem on the hypercube The isoperimetric problem o the hypercube Prepared by: Steve Butler November 2, 2005 1 The isoperimetric problem We will cosider the -dimesioal hypercube Q Recall that the hypercube Q is a graph whose

More information

IPv6 Deployment Planning. Philip Smith PacNOG 10, Nouméa 21 st November 2011

IPv6 Deployment Planning. Philip Smith PacNOG 10, Nouméa 21 st November 2011 IPv6 Deployment Planning Philip Smith PacNOG 10, Nouméa 21 st November 2011 1 Introduction Presentation introduces the high level planning considerations which any network operator needs to be aware of

More information

Service Provider Multihoming

Service Provider Multihoming Service Provider Multihoming ISP Workshops Last updated 18 September 2013 1 Service Provider Multihoming p Previous examples dealt with loadsharing inbound traffic n Of primary concern at Internet edge

More information

Realistic Storage of Pending Requests in Content-Centric Network Routers

Realistic Storage of Pending Requests in Content-Centric Network Routers Realistic Storage of Pedig Requests i Cotet-Cetric Network Routers Wei You, Bertrad Mathieu, Patrick Truog, Jea-Fraçois Peltier Orage Labs Laio, Frace {wei.you, bertrad2.mathieu, patrick.truog, jeafracois.peltier}@orage.com

More information

BGP Multihoming. ISP/IXP Workshops

BGP Multihoming. ISP/IXP Workshops BGP Multihoming ISP/IXP Workshops 1 Why Multihome? Redundancy One connection to internet means the network is dependent on: Local router (configuration, software, hardware) WAN media (physical failure,

More information

Introduction Requirements of NTT network

Introduction Requirements of NTT network Itroductio Requiremets of NTT etwork p NTT groups have provided various services with reliability ad scalability by dedicated high-ed routers. High-ed core routers Service Network services Additioal fuctios

More information

Introduction and Overview

Introduction and Overview Chapter 1 Itroductio ad Overview 1.1 Opportuities Offered by The Iteret Protocol versio 6 () is ow gaiig mometum as a improved etwork layer protocol. There is much commercial iterest ad activity i Europe

More information

IPv6 Deployment Strategies. IPv6 Training Day 18 th September 2012 Philip Smith APNIC

IPv6 Deployment Strategies. IPv6 Training Day 18 th September 2012 Philip Smith APNIC IPv6 Deployment Strategies IPv6 Training Day 18 th September 2012 Philip Smith APNIC 1 Introduction p Presentation introduces the high level planning considerations which any network operator needs to

More information

Data Warehousing. Paper

Data Warehousing. Paper Data Warehousig Paper 28-25 Implemetig a fiacial balace scorecard o top of SAP R/3, usig CFO Visio as iterface. Ida Carapelle & Sophie De Baets, SOLID Parters, Brussels, Belgium (EUROPE) ABSTRACT Fiacial

More information

Reliable Transmission. Spring 2018 CS 438 Staff - University of Illinois 1

Reliable Transmission. Spring 2018 CS 438 Staff - University of Illinois 1 Reliable Trasmissio Sprig 2018 CS 438 Staff - Uiversity of Illiois 1 Reliable Trasmissio Hello! My computer s ame is Alice. Alice Bob Hello! Alice. Sprig 2018 CS 438 Staff - Uiversity of Illiois 2 Reliable

More information