RIPE Atlas. Philip Smith Network Startup Resource Center (NSRC) PacNOG 16 1 st December 2014, Honiara, Solomon Islands



Similar documents
Webinar: Advanced RIPE Atlas Usage

Building a logging pipeline with Open Source tools. Iñigo Ortiz de Urbina Cazenave

Introduction to The Internet

Introduction to The Internet. ISP/IXP Workshops

Introduction to Performance Measurements and Monitoring. Vinayak

Glossary of Technical Terms Related to IPv6

DNS Measurements, Monitoring & Quality Control

LESSON Networking Fundamentals. Understand TCP/IP

Other monitoring tools

Lab Organizing CCENT Objectives by OSI Layer

APNIC IPv6 Deployment

Communications and Networking

Using IPM to Measure Network Performance

Network: several computers who can communicate. bus. Main example: Ethernet (1980 today: coaxial cable, twisted pair, 10Mb 1000Gb).

Terminology. Internet Addressing System

1 Basic Configuration of Cisco 2600 Router. Basic Configuration Cisco 2600 Router

Operation and Technical Best Practice. IXP Automation and Operational Efficiency

Web Caching and CDNs. Aditya Akella

CS2107 Introduction to Information and System Security (Slid. (Slide set 8)

Technical Support Information Belkin internal use only

Interconnecting IPv6 Domains Using Tunnels

Planning the transition to IPv6

Lab 2. CS-335a. Fall 2012 Computer Science Department. Manolis Surligas

Getting started with IPv6 on Linux

Network Management & Monitoring Overview

Network Monitoring and Management Introduction to Networking Monitoring and Management

IPv6 and IPv4 Update from the RIPE NCC. Sandra Brás, Ferenc Csorba

Cape Girardeau Career Center CISCO Networking Academy Bill Link, Instructor. 2.,,,, and are key services that ISPs can provide to all customers.

Free Network Monitoring Software for Small Networks

Linux MDS Firewall Supplement

Measuring the Web: Part I - - Content Delivery Networks. Prof. Anja Feldmann, Ph.D. Dr. Ramin Khalili Georgios Smaragdakis, PhD

Chapter 11 Cloud Application Development

Next Generation Network Firewall

architecture: what the pieces are and how they fit together names and addresses: what's your name and number?

SIIT-DC: Stateless IP/ICMP Translation for IPv6 Data Centre Environments & SIIT-DC: Dual Translation Mode

Configuring Global Protect SSL VPN with a user-defined port

Internet Protocol: IP packet headers. vendredi 18 octobre 13

K-Root Name Server Operations

Chapter 1 Personal Computer Hardware hours

Planning and Maintaining a Microsoft Windows Server Network Infrastructure

Chapter 15: Advanced Networks

Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 6 Network Security

Cisco RV215W Wireless-N VPN Router

Configuring SSL VPN on the Cisco ISA500 Security Appliance

Introduction to Network Monitoring and Management

Cisco Change Management: Best Practices White Paper

Network Management and Monitoring Software

Computer Networks: DNS a2acks CS 1951e - Computer Systems Security: Principles and Prac>ce. Domain Name System

Procedure: You can find the problem sheet on Drive D: of the lab PCs. 1. IP address for this host computer 2. Subnet mask 3. Default gateway address

GUJARAT TECHNOLOGICAL UNIVERSITY, AHMEDABAD, GUJARAT. COURSE CURRICULUM COURSE TITLE: INFORMATION COMMUNICATION TECHNOLOGY (Code: )

Details. Some details on the core concepts:

5.0 Network Architecture. 5.1 Internet vs. Intranet 5.2 NAT 5.3 Mobile Network

v6sonar Report Service Overview and Case Study By Nephos6, Inc.

PLUMgrid Toolbox: Tools to Install, Operate and Monitor Your Virtual Network Infrastructure

Cisco ASA, PIX, and FWSM Firewall Handbook

Configuring Network Address Translation (NAT)

shortcut Tap into learning NOW! Visit for a complete list of Short Cuts. Your Short Cut to Knowledge

IPv6 Fundamentals: A Straightforward Approach

The Internet. On October 24, 1995, the FNC unanimously passed a resolution defining the term Internet.

How To Connect Ipv4 To Ipv6 On A Ipv2 (Ipv4) On A Network With A Pnet 2.5 (Ipvin4) Or Ipv3 (Ip V6) On An Ipv5

Essential Curriculum Computer Networking 1. PC Systems Fundamentals 35 hours teaching time

DDoS attacks on electronic payment systems. Sean Rijs and Joris Claassen Supervisor: Stefan Dusée

Infrastructure for active and passive measurements at 10Gbps and beyond

Pass Through Proxy. How-to. Overview:..1 Why PTP?...1

The Internet Introductory material.

Lesson 1 Quiz Certification Partners, LLC. All Rights Reserved. Version 2.0

IERG 4080 Building Scalable Internet-based Services

Web Traffic Capture Butler Street, Suite 200 Pittsburgh, PA (412)

Connecting to and Setting Up a Network

SIIT-DC: IPv4 Service Continuity for IPv6 Data Centres. Tore Anderson Redpill Linpro AS RIPE69, London, November 2014

Discovering Path MTU black holes on the Internet using RIPE Atlas

Understand SIP trunk and registration in DWG gateway Version: 1.0 Dinstar Technologies Co., Ltd. Date:

Document ID: Introduction

Configuring SNMP Cisco and/or its affiliates. All rights reserved. 1

Cyber Essentials. Test Specification

BASIC FIREWALL SERVICES

Troubleshooting and Maintaining Cisco IP Networks Volume 1

Network Management & Monitoring Overview

Preface 1. Introduction to Linux Networking 1.0 Introduction 2. Building a Linux Gateway on a Single-Board Computer 2.0 Introduction 2.

Copyright

Networking Basics and Network Security

EKT 332/4 COMPUTER NETWORK

Introduction to Routing

IPv6, Perspective from small to medium ISP

Configuring PA Firewalls for a Layer 3 Deployment

Network Monitoring. Sebastian Büttrich, NSRC / IT University of Copenhagen Last edit: February 2012, ICTP Trieste

IPv6 Diagnostic and Troubleshooting

Exam Questions SY0-401

Network Terminology Review

Design, Implementation and Evolution of a DNS anycast resolving service in a country-wide ISP network

Transcription:

Philip Smith Network Startup Resource Center (NSRC) PacNOG 16 1 st December 2014, Honiara, Solomon Islands

Intro

https://atlas.ripe.net 3

Atlas in the Pacific 4

Measurement Devices 5 v1 & v2: Lantronix XPort Pro v3: TP-Link TL-MR3020 powered from USB port - Does not work as a wireless router! - Same functionality as the old probe! anchor: Soekris net6501-70

Probes Photos 6

in Numbers: November 2014 7 7,300+ probes connected 8,000+ active users this year 5,000+ built-in measurements daily 6,000+ user-defined measurements daily - Four types of user-defined measurements available to probe hosts and RIPE NCC members: ping, traceroute, DNS, SSL Goal by end 2014: - 10,000 connected probes

Anchors 9 Anchors: well-known targets and powerful probes - Regional baseline & future history Anchoring measurements - Measurements between anchors - 200 probes targeting each anchor with measurements - Each probe measures 4-5 anchors Vantage points for new DNSMON service 92 anchors as of November 2014 - goal for 2014: 100 active anchors worldwide

Network Monitoring

Network Monitoring 11 Network operators use tools for monitoring health of networks - such as Nagios & Icinga Tools can receive input from, via API Benefits: - doing pings from 1000 out of 5000+ probes around the world - looking at your network from the outside - plug into your existing practices

Integration with Monitoring Systems 12 Three easy steps: 1. Create a ping measurement 2. Go to status checks URL 3. Add your alerts in Icinga or Nagios

Monitoring for DNS TLD operators 13

Monitoring DNS 14 Old DNSMON service migrated to Using anchors as vantage points - instead of TTM boxes Currently monitoring small selection of zones - root-nameservers & 30 cctlds and few gtlds New zones will be added next year On the roadmap: domain checks https://atlas.ripe.net/dnsmon https://labs.ripe.net/members/fatemah_mafi/an-updated-dns-monitoringservice

Contact 15 https://atlas.ripe.net Apply for an anchor: https://atlas.ripe.net/anchors/apply/ Mailing list for active users: ripe-atlas@ripe.net Roadmap: http://roadmap.ripe.net/ripe-atlas/ Articles & updates on RIPE Labs: https://labs.ripe.net/atlas Questions: atlas@ripe.net Twitter: @RIPE_Atlas and #RIPEAtlas

Success Stories

Mapping an Anchor 17 Exploring the potential of for mapping the packet layer topology Using the example of RIPE Atlas Anchor at VIX (Vienna) Pretty graphs, useful info https://labs.ripe.net/members/dfk/map-a-ripe-atlas-anchor

Reachability Testing 18 https://ripe68.ripe.net/presentations/226- Understanding_the_Reachability_of_IPv6_Lim ited_visibility_prefixes.pdf

Newest Stories 19 Using to Debug Network Issues - https://labs.ripe.net/members/tim_kleefass/how-fast-the-ripe-atlasanchor-has-paid-off Basic Evaluation of new IXP Peering Partners with and Zabbix - https://labs.ripe.net/members/daniel_gomez/basic-evaluation-ofnew-ixp-peering-partners-with-ripe-atlas-and-zabbix More: https://labs.ripe.net/atlas/user-experiences

Success Stories 20 Investigating problems of slow servers: - http://engineering.freeagent.com/2014/01/24/atlas-probes/ Measuring packet loss to determine congested networks, Jared Mauch, NTT Selective blackholing (examples based on ) - https://ripe68.ripe.net/presentations/176-ripe68_jsnijders_ddos_damage_control.pdf Anycast analysis: - https://labs.ripe.net/members/stephane_bortzmeyer/the-many-instances-of-the-l-rootname-server

More Success Stories 21 IXP: Measuring the effect of installing L-root in Belgrade / SOX DNS: Looking for most popular instances of.fr anycast servers Events: Measuring Internet outages in Turkey & Sudan

IPv6 & : Reachability Testing 22 Using to perform worldwide traces to measure round-trip times and other route measurements - We identified routes that can be optimised and sent to other POPs with much better response times - We also identified routes that can be optimised by changing the transit provider for the same POP - https://labs.ripe.net/members/becha/world-ipv6-launch-ripe-atlas-use-cases The success rate with IPv6-only domain names is much lower (~60%) than with "mixed" (both IPv4 and IPv6) domain names (~96%) - https://labs.ripe.net/members/stephane_bortzmeyer/how-many-ripe-atlas-probescan-resolve-ipv6-only-domain-names

IPv6 Troubleshooting 23 It is quite common in the IPv6 world to have devices that believe they are connected to the IPv6 Internet while they are not - When you use to measure the connectivity of an IPv6 device, 90% success is the maximal reachability you'll get. - https://labs.ripe.net/members/stephane_bortzmeyer/ how-many-atlas-probes-believe-they-have-ipv6-but-arewrong

Security Aspects 24 Probes have hardwired trust material (registration server addresses / keys) The probes don t have any open ports; they only initiate connections - this works fine with NATs, too Measurements are scheduled by centralised command servers via reverse ssh tunnels Probes don t listen to local traffic; there are no passive measurements running Measurement source code published Reported vulnerabilities: https://atlas.ripe.net/docs/security/

Questions? https://stat.ripe.net