Design, Implementation and Evolution of a DNS anycast resolving service in a country-wide ISP network
|
|
|
- Arnold Chase
- 10 years ago
- Views:
Transcription
1 Design, Implementation and Evolution of a DNS anycast resolving service in a country-wide ISP network Kostas Zorbadelos OTE SA Senior Systems & Network Engineer GRNOG 1 June
2 Presentation Outline OTE DNS Services Overview DNS Resolving Legacy Setup Network Topology Initial Anycast Setup (OSPF, IPv4) Current Anycast Setup (BGP, IPv4/IPv6) Improvements Future work Crazy ideas DNS Anycast Resolving - GRNOG 1 2
3 DNS services in OTE's network Authoritative DNS for company domains, customers and reverse IP space (~40K zones) Domain registrar for.gr DNS resolving for all customers in OTE's IP network (even customers with their own AS numbers and IP resources) DNS resolving for the infrastructure DNS Anycast Resolving - GRNOG 1 3
4 Presentation Outline OTE DNS Services Overview DNS Resolving Legacy Setup Network Topology Initial Anycast Setup (OSPF, IPv4) Current Anycast Setup (BGP, IPv4/IPv6) Improvements Future work Crazy ideas DNS Anycast Resolving - GRNOG 1 4
5 Legacy resolving service setup Will focus on the resolving services for the rest of the presentation Farms of machines behind load balancers in two physical DCs Clients were served two resolver IPs and directed to the primary and secondary locations Primary location basically a Single Point of Failure (SPOF) DNS Anycast Resolving - GRNOG 1 5
6 Legacy Setup DNS Anycast Resolving - GRNOG 1 6
7 Why service redesign? The services worked fine for many years Skepticism even inside the company for the service redesign There have been problems however in rare extreme cases Load balancer components EOL from the vendor DNS Anycast Resolving - GRNOG 1 7
8 Benefits from the service redesign No reliance on a single DC location for such a critical service geographic distribution DNS has all the characteristics for a service to be anycasted (connectionless over UDP or short-lived TCP connections, stateless query/responses) Many operators already operate anycast DNS services (with root operators the most prominent) No need for load balancer components, load balancing handled by the network routing layer Simplification of network setup DNS Anycast Resolving - GRNOG 1 8
9 Presentation Outline OTE DNS Services Overview DNS Resolving Legacy Setup Network Topology Initial Anycast Setup (OSPF, IPv4) Current Anycast Setup (BGP, IPv4/IPv6) Improvements Future work Crazy ideas DNS Anycast Resolving - GRNOG 1 9
10 Network topology We consider the typical core, distribution and access model The core has POPs in major cities (2 locations in Athens, Thessaloniki, Patra, Herakleio, Tripoli) with multi 10G interconnections The distribution layer performs layer 3 aggregation and has presence in many more locations (~40 POPs) The access layer (considering L3 access) is even more distributed Cisco gear in core, distribution, Juniper & Cisco in access DNS Anycast Resolving - GRNOG 1 10
11 The Core Main and only function to quickly forward packets Multi 10Gbps connectivity Contains the exit points to the global Internet and GRIX Not recommended (also by the vendor) to contain IP service nodes DNS Anycast Resolving - GRNOG 1 11
12 The Core (schema) DNS Anycast Resolving - GRNOG 1 12
13 Distribution / Access Distribution nodes aggregate access nodes Access nodes mostly terminate PPP sessions of users, but also contain leased line business customers Each access node has high availability backhaul connections to at least 2 distribution nodes Major project underway to simplify / consolidate access - distribution layers (BNG instead of BRAS nodes) Currently the user ratio is 40%/60% (BNG/BRAS) DNS Anycast Resolving - GRNOG 1 13
14 Distribution / Access example DNS Anycast Resolving - GRNOG 1 14
15 Anycast node placement With the above information on the topology the DNS anycast nodes were placed in few selected locations (POPs) at the distribution layer Too many locations at the access layer Not all distribution layer POPs suitable to host server equipment Easier access to nodes for the relevant operation teams an extra criterion DNS Anycast Resolving - GRNOG 1 15
16 Node placement (schema) DNS Anycast Resolving - GRNOG 1 16
17 Presentation Outline OTE DNS Services Overview DNS Resolving Legacy Setup Network Topology Initial Anycast Setup (OSPF, IPv4) Current Anycast Setup (BGP, IPv4/IPv6) Improvements Future work Crazy ideas DNS Anycast Resolving - GRNOG 1 17
18 Anycast node specs/choices Commodity Intel based machines (DELL R630/1 multicore CPU, 64GB RAM, 2x300GB disks, 4x1gbps NICs, DRAC remote management modules) Linux CentOS 6.x operating system Anycast IPs configured as loopbacks on the machines /30 point-to-point interfaces on each node IPtables on each node (host based security) BIND 9.x as nameserver No big departure from the legacy setup to also accommodate the operation teams and existing tools DNS Anycast Resolving - GRNOG 1 18
19 Anycast based on OSPF We are talking about anycast service inside a single AS (OTE's IP network) The initial approach was to use OSPF Each anycast node would participate in the network's IGP OSPF is the chosen IGP for IPv4 The belief was that the convergence time would be faster than other alternatives DNS Anycast Resolving - GRNOG 1 19
20 OSPF Topology DNS Anycast Resolving - GRNOG 1 20
21 Quagga config sample! Zebra configuration saved from vty! 2012/10/17 13:50:59! hostname <nodename>.otenet.gr password <vtypwd> enable password <enpwd> log syslog! interface em4 ip ospf network point-to-point ip ospf authentication messagedigest ip ospf message-digest-key 1 md5 <pwd> ip ospf dead-interval minimal hello-multiplier 3 ip ospf priority 0!! (continued next...)! (...continued) interface lo ip ospf cost 10 ip ospf priority 0! router ospf ospf router-id <server IP> log-adjacency-changes detail passive-interface lo network <anycast IP>/32 area X.X.X.X network <server IP>/30 area X.X.X.X! access-list MATCHALL permit any route-map IMPORT deny 10 match ip address MATCHALL! line vty DNS Anycast Resolving - GRNOG 1 21
22 Presentation Outline OTE DNS Services Overview DNS Resolving Legacy Setup Network Topology Initial Anycast Setup (OSPF, IPv4) Current Anycast Setup (BGP, IPv4/IPv6) Improvements Future work Crazy ideas DNS Anycast Resolving - GRNOG 1 22
23 DNS resolving dual stack There was a need to support IPv6 in the resolvers IPv6 connectivity / addressing was in place in OTE's IP network However, the IGP choice for IPv6 was ISIS No mature open source implementation of ISIS yet The initial plan was to proceed with static routes and tracking options (IOS IP SLAs) Input from RIPE 67 suggested we take a look at BGP for anycast IP injection DNS Anycast Resolving - GRNOG 1 23
24 BGP deployment We tested the idea to use BGP for anycast (/32, /128) route injection The anycast node makes an ebgp peering with the neighbouring distribution layer router Anycast nodes use a private AS number (65xxx) The anycast route is announced with no-advertise community The neighbouring router redistributes the anycast routes to OSPF/ISIS respectively DNS Anycast Resolving - GRNOG 1 24
25 BGP setup/choices There is a common approach for both IPv4/IPv6 Debugging is easier, setup is simpler There are various mature open source BGP implementations that can be used No convergence delay (convergence is faster in some cases!) We chose BIRD as the BGP daemon on the anycast server node DNS Anycast Resolving - GRNOG 1 25
26 BIRD config sample (1/2) /* BIRD DNS Anycast config bird.conf (bird6.conf is similar) */ log syslog name "bird" all; router id <routerid>; debug commands 9; protocol direct direct_lo { interface "lo*"; # Restrict network interfaces it works with } protocol device { scan time 60; } # Scan interfaces every 60 seconds (continued next...) DNS Anycast Resolving - GRNOG 1 26
27 BIRD config sample (2/2) (...continued) protocol bgp bgp_65xxx { description "DNS anycast BGP"; debug { states, routes, filters, interfaces, events }; local as 65xxx; neighbor <nei ip> as 6799; password "XXXXX"; # Password used for MD5 authentication } export filter { if proto = "direct_lo" then { # add no-advertise bgp_community = -empty-; bgp_community = add(bgp_community,(65535, 65282)); bgp_origin = 0; accept; } reject; }; import none; DNS Anycast Resolving - GRNOG 1 27
28 Presentation Outline OTE DNS Services Overview DNS Resolving Legacy Setup Network Topology Initial Anycast Setup (OSPF, IPv4) Current Anycast Setup (BGP, IPv4/IPv6) Improvements Future work Crazy ideas DNS Anycast Resolving - GRNOG 1 28
29 Operations Current setup contains 17 machines in 3 geo-locations for the customer resolvers (yes, we have overprovisioned!) Infrastructure is served by a different anycast cluster (2 machines, 2 geo-locations) All config is handled by ansible / mercurial VC (also blackholing of domains/eeep etc) The automation tools help us to test different resolving software Introduce software diversity DNS Anycast Resolving - GRNOG 1 29
30 Monitoring / measurements Each server has IPMI module accessible through the management LANs Monitoring / fault detection / alerting provided via a Nagios infrastructure already in place DNS measurements from BIND using cacti plugin Cacti / rrdtool for graph representations, also pnp4nagios Current set of tools adequate for operation and basic understanding of what is going on DNS Anycast Resolving - GRNOG 1 30
31 Next generation tools We can do much better in terms of measurements and visualization Real or near-real time visualization and analysis of DNS queries Anomaly detection and trend analysis Graphite/grafana seem very promising Use a big data approach for storage and analysis of the data using pcap captures DNS Anycast Resolving - GRNOG 1 31
32 Application load balancing There is a need for application load balancing using the DNS The most prominent application is IMS (SIP/VoIP) The clients whould be distributed in different SBC nodes in SIP signalling Currently we address this using BIND views Utilizing edns-client-subnet and gdnsd can produce a match better config for all applications with similar needs DNS Anycast Resolving - GRNOG 1 32
33 Authoritative setup We keep using a legacy setup for the authoritative service The relevant tools show their age (written about 10 years ago) IPv6 is not properly addressed DNS/IPAM integration for the reverse DNS (an issue for a seperate talk ;-) ) We should use the anycast approach there too We will start with the company/infrastructure domains DNS Anycast Resolving - GRNOG 1 33
34 New nodes' deployment The deployment of new nodes in the current setup is not an easy task Some nodes are under-utilized. Not all locations receive the same load We need to over-provision Would be great to introduce on-demand new nodes possibly from a few central cloud locations with VM setups We could also choose to deploy specific nodes to access routers Our BGP setup makes this possible, with a bit more complicated network setup (MPLS/VPN?) Rough initial idea in my head. If materializes another good presentation DNS Anycast Resolving - GRNOG 1 34
35 Questions? DNS Anycast Resolving - GRNOG 1 35
36 References tecture-for-k-root-local-nodes CCIE material on IP routing (OSPF, BGP) DNS Anycast Resolving - GRNOG 1 36
Transitioning to BGP. ISP Workshops. Last updated 24 April 2013
Transitioning to BGP ISP Workshops Last updated 24 April 2013 1 Scaling the network How to get out of carrying all prefixes in IGP 2 Why use BGP rather than IGP? p IGP has Limitations: n The more routing
Building Nameserver Clusters with Free Software
Building Nameserver Clusters with Free Software Joe Abley, ISC NANOG 34 Seattle, WA, USA Starting Point Discrete, single-host authoritative nameservers several (two or more) several (two or more) geographically
IPV6 SERVICES DEPLOYMENT
IPV6 SERVICES DEPLOYMENT LINX IPv6 Technical Workshop - March 2009 Jaco Engelbrecht Group Platforms Manager, clara.net DNS root zone goes AAAA! On 4 th February 2008 IANA added AAAA records for the A,
ISP Case Study. UUNET UK (1997) ISP/IXP Workshops. ISP/IXP Workshops. 1999, Cisco Systems, Inc.
ISP Case Study UUNET UK (1997) ISP/IXP Workshops ISP/IXP Workshops 1999, Cisco Systems, Inc. 1 Acknowledgements Thanks are due to UUNET UK for allowing the use of their configuration information and network
Campus IPv6 connection Campus IPv6 deployment
Campus IPv6 connection Campus IPv6 deployment Campus Address allocation, Topology Issues János Mohácsi NIIF/HUNGARNET Copy Rights This slide set is the ownership of the 6DISS project via its partners The
Using the Border Gateway Protocol for Interdomain Routing
CHAPTER 12 Using the Border Gateway Protocol for Interdomain Routing The Border Gateway Protocol (BGP), defined in RFC 1771, provides loop-free interdomain routing between autonomous systems. (An autonomous
Exterior Gateway Protocols (BGP)
Exterior Gateway Protocols (BGP) Internet Structure Large ISP Large ISP Stub Dial-Up ISP Small ISP Stub Stub Stub Autonomous Systems (AS) Internet is not a single network! The Internet is a collection
Interconnecting Cisco Networking Devices Part 2
Interconnecting Cisco Networking Devices Part 2 Course Number: ICND2 Length: 5 Day(s) Certification Exam This course will help you prepare for the following exam: 640 816: ICND2 Course Overview This course
ISP Systems Design. ISP Workshops. Last updated 24 April 2013
ISP Systems Design ISP Workshops Last updated 24 April 2013 1 Agenda p DNS Server placement p Mail Server placement p News Server placement p Services network design p Services Network Security 2 ISP Services
APNIC IPv6 Deployment
APNIC IPv6 Deployment Ulaanbaatar, Mongolia 19 October 2015 Issue Date: Revision: Overview Deployment motivation Network deployment IPv6 Services deployment IPv6 Anycast service IPv6 Cloud service Summary
BIRD Internet Routing Daemon. CZ.NIC z. s. p. o. Ondrej Filip / [email protected] NANOG-48, Austin, TX
BIRD Internet Routing Daemon CZ.NIC z. s. p. o. Ondrej Filip / [email protected] NANOG-48, Austin, TX 1 Project history Project started in 1999 Seminar project Charles University Prague Project slept
640-816: Interconnecting Cisco Networking Devices Part 2 v1.1
640-816: Interconnecting Cisco Networking Devices Part 2 v1.1 Course Introduction Course Introduction Chapter 01 - Small Network Implementation Introducing the Review Lab Cisco IOS User Interface Functions
Implementation of Business Linux Routers
Implementation of Business Linux Routers Presenter: Joseph Flasch [email protected] Why Use Linux as a Router? Cost Performance Reliability Open nature of Linux It's not IOS Multi-function nature of Linux
Address Scheme Planning for an ISP backbone Network
Address Scheme Planning for an ISP backbone Network Philip Smith Consulting Engineering, Office of the CTO Version 0.1 (draft) LIST OF FIGURES 2 INTRODUCTION 3 BACKGROUND 3 BUSINESS MODEL 3 ADDRESS PLAN
Cisco s Massively Scalable Data Center. Network Fabric for Warehouse Scale Computer
Network Fabric for Warehouse Scale Computer Cisco Massively Scalable Data Center Reference Architecture The data center network is arguably the most challenging design problem for a network architect.
Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.
Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials. CHAPTER 5 OBJECTIVES Configure a router with an initial configuration. Use the
The Complete IS-IS Routing Protocol
Hannes Gredler and Walter Goralski The Complete IS-IS Routing Protocol 4y Springer Contents Foreword Credits and Thanks vii ix 1 Introduction, Motivation and Historical Background 1 1.1 Motivation 1 1.2
Building a small Data Centre
Building a small Data Centre Cause we re not all Facebook, Google, Amazon, Microsoft Karl Brumund, Dyn RIPE71 1 Dyn what we do DNS, email, Internet Intelligence from where 28 sites, 100s of probes, clouds
Bell Aliant. Business Internet Border Gateway Protocol Policy and Features Guidelines
Bell Aliant Business Internet Border Gateway Protocol Policy and Features Guidelines Effective 05/30/2006, Updated 1/30/2015 BGP Policy and Features Guidelines 1 Bell Aliant BGP Features Bell Aliant offers
How to Configure Cisco 2600 Routers
Helsinki University of Technology Department of Communications and Networking How to Configure Cisco 2600 Routers Juha Järvinen 10.6.2004 [email protected] Modified by Zhong Yunqiu 7.8.2008 Table
Interconnecting IPv6 Domains Using Tunnels
Interconnecting Domains Using Tunnels Version History Version Number Date Notes 1 30 July 2002 This document was created. 2 19 May 2003 Updated the related documents section. This document describes how
Internet Firewall CSIS 4222. Packet Filtering. Internet Firewall. Examples. Spring 2011 CSIS 4222. net15 1. Routers can implement packet filtering
Internet Firewall CSIS 4222 A combination of hardware and software that isolates an organization s internal network from the Internet at large Ch 27: Internet Routing Ch 30: Packet filtering & firewalls
Module 12 Multihoming to the Same ISP
Module 12 Multihoming to the Same ISP Objective: To investigate various methods for multihoming onto the same upstream s backbone Prerequisites: Module 11 and Multihoming Presentation The following will
Understanding Route Redistribution & Filtering
Understanding Route Redistribution & Filtering When to Redistribute and Filter PAN-OS 5.0 Revision B 2013, Palo Alto Networks, Inc. www.paloaltonetworks.com Contents Overview... 3 Route Redistribution......
Deploying IP Anycast. Core DNS Services for University of Minnesota Introduction and General discussion
Deploying IP Anycast Core DNS Services for University of Minnesota Introduction and General discussion Agenda Deploying IPv4 anycast DNS What is ANYCAST Why is ANYCAST important? Monitoring and using ANYCAST
Application Note. Failover through BGP route health injection
Application Note Document version: v1.2 Last update: 8th November 2013 Purpose This application note aims to describe how to build a high available platform using BGP routing protocol to choose the best
Understanding Virtual Router and Virtual Systems
Understanding Virtual Router and Virtual Systems PAN- OS 6.0 Humair Ali Professional Services Content Table of Contents VIRTUAL ROUTER... 5 CONNECTED... 8 STATIC ROUTING... 9 OSPF... 11 BGP... 17 IMPORT
F5 Intelligent DNS Scale. Philippe Bogaerts Senior Field Systems Engineer mailto: [email protected] Mob.: +32 473 654 689
F5 Intelligent Scale Philippe Bogaerts Senior Field Systems Engineer mailto: [email protected] Mob.: +32 473 654 689 Intelligent and scalable PROTECTS web properties and brand reputation IMPROVES web application
Tutorial: Options for Blackhole and Discard Routing. Joseph M. Soricelli Wayne Gustavus NANOG 32, Reston, Virginia
Tutorial: Options for Blackhole and Discard Routing Joseph M. Soricelli Wayne Gustavus NANOG 32, Reston, Virginia Caveats and Assumptions The views presented here are those of the authors and they do not
DNS Best Practices. Mike Jager Network Startup Resource Center [email protected]
DNS Best Practices Mike Jager Network Startup Resource Center [email protected] This document is a result of work by the Network Startup Resource Center (NSRC at http://www.nsrc.org). This document may be
Infrastructure for active and passive measurements at 10Gbps and beyond
Infrastructure for active and passive measurements at 10Gbps and beyond Best Practice Document Produced by UNINETT led working group on network monitoring (UFS 142) Author: Arne Øslebø August 2014 1 TERENA
Multi-Homing Security Gateway
Multi-Homing Security Gateway MH-5000 Quick Installation Guide 1 Before You Begin It s best to use a computer with an Ethernet adapter for configuring the MH-5000. The default IP address for the MH-5000
Course Contents CCNP (CISco certified network professional)
Course Contents CCNP (CISco certified network professional) CCNP Route (642-902) EIGRP Chapter: EIGRP Overview and Neighbor Relationships EIGRP Neighborships Neighborship over WANs EIGRP Topology, Routes,
Deploying OSPF for ISPs. OSPF Design. Agenda. Service Providers. SP Architecture. SP Architecture. OSPF Design in SP Networks
Agenda OSPF Design in SP Networks Deploying OSPF for ISPs Adding Networks in OSPF OSPF in IOS ISP/IXP 1 2 Service Providers OSPF Design As applicable to Service Provider Networks SP networks are divided
Understanding Large Internet Service Provider Backbone Networks
Understanding Large Internet Service Provider Backbone Networks Joel M. Gottlieb IP Network Management & Performance Department AT&T Labs Research Florham Park, New Jersey [email protected] Purpose
IP Networking. Overview. Networks Impact Daily Life. IP Networking - Part 1. How Networks Impact Daily Life. How Networks Impact Daily Life
Overview Dipl.-Ing. Peter Schrotter Institute of Communication Networks and Satellite Communications Graz University of Technology, Austria Fundamentals of Communicating over the Network Application Layer
Introduction to Routing
Introduction to Routing How traffic flows on the Internet Philip Smith [email protected] RIPE NCC Regional Meeting, Moscow, 16-18 18 June 2004 1 Abstract Presentation introduces some of the terminologies used,
Global Server Load Balancing (GSLB) Concepts
Global Server Load Balancing (GSLB) Concepts Section Section Objectives GSLB Overview GSLB Configuration Options GSLB Components Server Mode Configuration 2 Global Server Load Balancing (GSLB) Key ACOS
Hands on Workshop. Network Performance Monitoring and Multicast Routing. Yasuichi Kitamura NICT Jin Tanaka KDDI/NICT APAN-JP NOC
Hands on Workshop Network Performance Monitoring and Multicast Routing Yasuichi Kitamura NICT Jin Tanaka KDDI/NICT APAN-JP NOC July 18th TEIN2 Site Coordination Workshop Network Performance Monitoring
Configuring and Testing Border Gateway Protocol (BGP) on Basis of Cisco Hardware and Linux Gentoo with Quagga Package (Zebra)
Configuring and Testing Border Gateway Protocol (BGP) on Basis of Cisco Hardware and Linux Gentoo with Quagga Package (Zebra) Contents Introduction Used Abbreviations Border Gateway Protocol (BGP) Overview
IPv6 Addressing. ISP Training Workshops
IPv6 Addressing ISP Training Workshops 1 Where to get IPv6 addresses p Your upstream ISP p Africa n AfriNIC http://www.afrinic.net p Asia and the Pacific n APNIC http://www.apnic.net p North America n
Interconnecting Cisco Network Devices 1 Course, Class Outline
www.etidaho.com (208) 327-0768 Interconnecting Cisco Network Devices 1 Course, Class Outline 5 Days Interconnecting Cisco Networking Devices, Part 1 (ICND1) v2.0 is a five-day, instructorled training course
Supporting Document PPP
Supporting Document PPP Content 1 Starter Kit... 3 2 Technical Specification Access... 3 2.1 Overview... 3 2.2 Upstream Policing for PPP@ISP... 3 2.3 Supported Protocols... 3 2.4 PPPoA... 3 2.5 PPPoE...
Internet Protocol: IP packet headers. vendredi 18 octobre 13
Internet Protocol: IP packet headers 1 IPv4 header V L TOS Total Length Identification F Frag TTL Proto Checksum Options Source address Destination address Data (payload) Padding V: Version (IPv4 ; IPv6)
100-101: Interconnecting Cisco Networking Devices Part 1 v2.0 (ICND1)
100-101: Interconnecting Cisco Networking Devices Part 1 v2.0 (ICND1) Course Overview This course provides students with the knowledge and skills to implement and support a small switched and routed network.
SEC-370. 2001, Cisco Systems, Inc. All rights reserved.
SEC-370 2001, Cisco Systems, Inc. All rights reserved. 1 Understanding MPLS/VPN Security Issues SEC-370 Michael Behringer SEC-370 2003, Cisco Systems, Inc. All rights reserved. 3
Campus LAN at NKN Member Institutions
Campus LAN at NKN Member Institutions RS MANI [email protected] 1/7/2015 3 rd Annual workshop 1 Efficient utilization Come from: Good Campus LAN Speed Segregation of LANs QoS Resilient Access Controls ( L2 and
IMPLEMENTING CISCO IP ROUTING V2.0 (ROUTE)
IMPLEMENTING CISCO IP ROUTING V2.0 (ROUTE) COURSE OVERVIEW: Implementing Cisco IP Routing (ROUTE) v2.0 is an instructor-led five day training course developed to help students prepare for Cisco CCNP _
Residential IPv6 IPv6 a t at S wisscom Swisscom a, n an overview overview Martin Gysi
Residential IPv6 at Swisscom, an overview Martin Gysi What is Required for an IPv6 Internet Access Service? ADSL L2 platform, IPv6 not required VDSL Complex Infrastructure is Barrier to Cost-efficient
NAT Using Source Routing through BGP Gateways
NAT Using Source Routing through BGP Gateways Best Practice Document Produced by the CESNET led Working Group on Network Monitoring (CBPD122) Authors: Pavel Kislinger, Vladimír Záhořík, CESNET September
Network Layers. CSC358 - Introduction to Computer Networks
Network Layers Goal Understand how application processes set up a connection and exchange messages. Understand how addresses are determined Data Exchange Between Application Processes TCP Connection-Setup
How to Setup Bare Metal Adaxa Suite Demonstration Box
How to Setup Bare Metal Adaxa Suite Demonstration Box Level 1 616 St Kilda Road Melbourne Victoria 3004 T:1-300-990-120 Email: [email protected] Web: www.adaxa.com Table of Contents Pre-Requisites 1.1 Hardware
How To Understand Bg
Table of Contents BGP Case Studies...1 BGP4 Case Studies Section 1...3 Contents...3 Introduction...3 How Does BGP Work?...3 ebgp and ibgp...3 Enabling BGP Routing...4 Forming BGP Neighbors...4 BGP and
How to Configure the Cisco UC500 for use with Integra Telecom SIP Solutions
How to Configure the Cisco UC500 for use with Integra Telecom SIP Solutions Overview: This document provides a reference for configuration of the Cisco UC500 IP PBX to connect to Integra Telecom SIP Trunks.
Example: Advertised Distance (AD) Example: Feasible Distance (FD) Example: Successor and Feasible Successor Example: Successor and Feasible Successor
642-902 Route: Implementing Cisco IP Routing Course Introduction Course Introduction Module 01 - Planning Routing Services Lesson: Assessing Complex Enterprise Network Requirements Cisco Enterprise Architectures
The Case for Source Address Routing in Multihoming Sites
The Case for Source Address Dependent Routing in Multihoming Marcelo Bagnulo, Alberto García-Martínez, Juan Rodríguez, Arturo Azcorra. Universidad Carlos III de Madrid Av. Universidad, 30. Leganés. Madrid.
Notice the router names, as these are often used in MPLS terminology. The Customer Edge router a router that directly connects to a customer network.
Where MPLS part I explains the basics of labeling packets, it s not giving any advantage over normal routing, apart from faster table lookups. But extensions to MPLS allow for more. In this article I ll
Cloud.com CloudStack Community Edition 2.1 Beta Installation Guide
Cloud.com CloudStack Community Edition 2.1 Beta Installation Guide July 2010 1 Specifications are subject to change without notice. The Cloud.com logo, Cloud.com, Hypervisor Attached Storage, HAS, Hypervisor
DNA. White Paper. DNA White paper Version: 1.08 Release Date: 1 st July, 2015 Expiry Date: 31 st December, 2015. Ian Silvester DNA Manager.
DNA White Paper Prepared by Ian Silvester DNA Manager Danwood Group Service Noble House Whisby Road Lincoln LN6 3DG Email: [email protected] Website: www.danwood.com\dna BI portal: https:\\biportal.danwood.com
DD2491 p1 2008. Load balancing BGP. Johan Nicklasson KTHNOC/NADA
DD2491 p1 2008 Load balancing BGP Johan Nicklasson KTHNOC/NADA Dual home When do you need to be dual homed? How should you be dual homed? Same provider. Different providers. What do you need to have in
Brocade to Cisco Comparisons
1 2 3 Console cables - The console cables are not interchangeable between Brocade and Cisco. Each vendor provides their console cable with each manageable unit it sells. Passwords - Neither Cisco or Brocade
OSPF Test Suite and Router configuration
OSPF Test Suite and Router configuration Codenomicon Solution Note Version: 2012-03-02 1 INTRODUCTION This document will give detailed information how to configure Cisco routers and OpenBSD servers to
For internal circulation of BSNLonly
E3-E4 E4 E&WS Overview of MPLS-VPN Overview Traditional Router-Based Networks Virtual Private Networks VPN Terminology MPLS VPN Architecture MPLS VPN Routing MPLS VPN Label Propagation Traditional Router-Based
Management, Logging and Troubleshooting
CHAPTER 15 This chapter describes the following: SNMP Configuration System Logging SNMP Configuration Cisco NAC Guest Server supports management applications monitoring the system over SNMP (Simple Network
Anycast Rou,ng: Local Delivery. Tom Daly, CTO h<p://dyn.com Up,me is the Bo<om Line
Anycast Rou,ng: Local Delivery Tom Daly, CTO h
Troubleshooting and Maintaining Cisco IP Networks Volume 1
Troubleshooting and Maintaining Cisco IP Networks Volume 1 Course Introduction Learner Skills and Knowledge Course Goal and E Learning Goal and Course Flow Additional Cisco Glossary of Terms Your Training
How To Set Up An Ip Firewall On Linux With Iptables (For Ubuntu) And Iptable (For Windows)
Security principles Firewalls and NAT These materials are licensed under the Creative Commons Attribution-Noncommercial 3.0 Unported license (http://creativecommons.org/licenses/by-nc/3.0/) Host vs Network
The benefits of BGP for every service provider
The benefits of BGP for every service provider UKUUG - Spring 2011 24th of March 2011 Thomas Mangin Exa Networks Whatever a speaker is missing in depth he will compensate for in length Montesquieu NO Networking
INTERCONNECTING CISCO NETWORK DEVICES PART 1 V2.0 (ICND 1)
INTERCONNECTING CISCO NETWORK DEVICES PART 1 V2.0 (ICND 1) COURSE OVERVIEW: Interconnecting Cisco Networking Devices, Part 1 (ICND1) v2.0 is a five-day, instructor-led training course that teaches learners
Network provider filter lab
Network provider filter lab Olof Hagsand Pehr Söderman KTH CSC Group Nr Name 1 Name 2 Name 3 Name 4 Date Instructor s Signature Table of Contents 1 Goals...3 2 Introduction...3 3 Preparations...3 4 Lab
Cisco Application Control Engine in the Virtual Data Center
Cisco Application Control Engine in the Virtual Data Center Q. What is Cisco Application Control Engine (ACE) the Virtual Data Center (AVDC)? A. AVDC is a solution that focuses on integrating key data
How To Learn Cisco Cisco Ios And Cisco Vlan
Interconnecting Cisco Networking Devices: Accelerated Course CCNAX v2.0; 5 Days, Instructor-led Course Description Interconnecting Cisco Networking Devices: Accelerated (CCNAX) v2.0 is a 60-hour instructor-led
How To Load Balance On A Bgg On A Network With A Network (Networking) On A Pc Or Ipa On A Computer Or Ipad On A 2G Network On A Microsoft Ipa (Netnet) On An Ip
Globally Distributed Content (Using BGP to Take Over the World) Horms (Simon Horman) [email protected] November 2001 http://supersparrow.org/ 1 Introduction Electronic content is becoming increasingly
Chapter 7 Configuring Trunk Groups and Dynamic Link Aggregation
Chapter 7 Configuring Trunk Groups and Dynamic Link Aggregation This chapter describes how to configure trunk groups and 802.3ad link aggregation. Trunk groups are manually-configured aggregate links containing
Use Domain Name System and IP Version 6
Use Domain Name System and IP Version 6 What You Will Learn The introduction of IP Version 6 (IPv6) into an enterprise environment requires some changes both in the provisioned Domain Name System (DNS)
s@lm@n Cisco Exam 400-201 CCIE Service Provider Written Exam Version: 7.0 [ Total Questions: 107 ]
s@lm@n Cisco Exam 400-201 CCIE Service Provider Written Exam Version: 7.0 [ Total Questions: 107 ] Cisco 400-201 : Practice Test Question No : 1 Which two frame types are correct when configuring T3 interfaces?
Fireware How To Dynamic Routing
Fireware How To Dynamic Routing How do I configure my Firebox to use BGP? Introduction A routing protocol is the language a router speaks with other routers to share information about the status of network
WHITE PAPER. Infoblox IPAM Integration with Microsoft AD Sites and Local Services
WHITE PAPER Infoblox IPAM Integration with Microsoft AD Sites and Local Services Infoblox IPAM Integration with Microsoft AD Sites and Local Services Today s enterprise infrastructure is dynamic, with
Supporting Document LNS Configuration
Supporting Document LNS Configuration Swisscom (Schweiz) AG Version 1-0 15.112010 Inhalt 1 General... 3 1.1 Appendix A: Load Balancing between POPs... 3 1.2 Appendix B: Examples of LNS and BGP Configurations...
IPv6 Fundamentals, Design, and Deployment
IPv6 Fundamentals, Design, and Deployment Course IP6FD v3.0; 5 Days, Instructor-led Course Description The IPv6 Fundamentals, Design, and Deployment (IP6FD) v3.0 course is an instructor-led course that
IPV6 FOR INTERNET SERVICE PROVIDERS STATE/LESSONS/STILL TO COME
IPV6 FOR INTERNET SERVICE PROVIDERS STATE/LESSONS/STILL TO COME Aaron Hughes, CEO 6connect [email protected] RIPE70 PERCEPTION OF IPV6 IMPLEMENTATIONS Network People We dual stacked the network years
Installing and Configuring Websense Content Gateway
Installing and Configuring Websense Content Gateway Websense Support Webinar - September 2009 web security data security email security Support Webinars 2009 Websense, Inc. All rights reserved. Webinar
Oracle SDN Performance Acceleration with Software-Defined Networking
Oracle SDN Performance Acceleration with Software-Defined Networking Oracle SDN, which delivers software-defined networking, boosts application performance and management flexibility by dynamically connecting
1 Basic Configuration of Cisco 2600 Router. Basic Configuration Cisco 2600 Router
1 Basic Configuration of Cisco 2600 Router Basic Configuration Cisco 2600 Router I decided to incorporate the Cisco 2600 into my previously designed network. This would give me two seperate broadcast domains
Session Manager Overview. Seattle IAUG Chapter Meeting
Session Manager Overview Seattle IAUG Chapter Meeting Agenda Session Manager continues to evolve.. Flexibility BYOD Soft Clients Endpoints SIPenablement 3 rd Party Adjuncts Centralized SIP Trunking Redundancy
"Charting the Course...
Description "Charting the Course... Course Summary Interconnecting Cisco Networking Devices: Accelerated (CCNAX), is a course consisting of ICND1 and ICND2 content in its entirety, but with the content
Description: Objective: Upon completing this course, the learner will be able to meet these overall objectives:
Course: Building Cisco Service Provider Next-Generation Networks, Part 2 Duration: 5 Day Hands-On Lab & Lecture Course Price: $ 3,750.00 Learning Credits: 38 Description: The Building Cisco Service Provider
LAN-Cell to Cisco Tunneling
LAN-Cell to Cisco Tunneling Page 1 of 13 LAN-Cell to Cisco Tunneling This Tech Note guides you through setting up a VPN connection between a LAN-Cell and a Cisco router. As the figure below shows, the
Configuring WCCP v2 with Websense Content Gateway the Web proxy for Web Security Gateway
Configuring WCCP v2 with Websense Content Gateway the Web proxy for Web Security Gateway Webinar December 2011 web security data security email security 2011 Websense, Inc. All rights reserved. Webinar
CCT vs. CCENT Skill Set Comparison
Operation of IP Data Networks Recognize the purpose and functions of various network devices such as Routers, Switches, Bridges and Hubs Select the components required to meet a given network specification
BGP (Border Gateway Protocol)
BGP (Border Gateway Protocol) Document revision 1.2 (Thu Mar 04 19:34:34 GMT 2004) This document applies to V2.8 Table of Contents Table of Contents General Information Summary Specifications Related Documents
About the Technical Reviewers
About the Author p. xiii About the Technical Reviewers p. xv Acknowledgments p. xvii Introduction p. xix IPv6 p. 1 IPv6-Why? p. 1 IPv6 Benefits p. 2 More Address Space p. 2 Innovation p. 3 Stateless Autoconfiguration
Task 20.1: Configure ASBR1 Serial 0/2 to prevent DoS attacks to ASBR1 from SP1.
Task 20.1: Configure ASBR1 Serial 0/2 to prevent DoS attacks to ASBR1 from SP1. Task 20.2: Configure an access-list to block all networks addresses that is commonly used to hack SP networks. Task 20.3:
DDoS Mitigation Techniques
DDoS Mitigation Techniques Ron Winward, ServerCentral CHI-NOG 03 06/14/14 Consistent Bottlenecks in DDoS Attacks 1. The server that is under attack 2. The firewall in front of the network 3. The internet
PT Activity 8.1.2: Network Discovery and Documentation Topology Diagram
Topology Diagram All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 1 of 6 Addressing Table Device Interface IP Address Subnet
