<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>my web 0.2 website &#187; peering</title>
	<atom:link href="http://www.andyd.net/category/peering/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.andyd.net</link>
	<description>Andy Davidson's tech blog</description>
	<lastBuildDate>Sun, 27 Jun 2010 00:29:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>IXP Bake Off Results</title>
		<link>http://www.andyd.net/2010/ixp-bake-off-results/</link>
		<comments>http://www.andyd.net/2010/ixp-bake-off-results/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 19:08:41 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=173</guid>
		<description><![CDATA[<p>Here are some slides that present some <a href="http://www.uknof.org.uk/uknof15/Davidson-Bakeoff.pdf" onclick="javascript:urchinTracker ('/outbound/article/www.uknof.org.uk');">research undertaken by a number of European Internet Exchange points (IXPs)</a>, which I presented at UKNOF15 last week.  They may be of interest to networks which connect to IXPs who have been considering connecting to the local multi-lateral peering (MLP) service, but are unsure whether testing has proved that the functionality and performance of the new &#8216;next-generation&#8217; offerings (namely BIRD and OpenBGPd) are fit for purpose.</p>
<p>The slides show that the new route-servers perform splendidly well compared with traditional Quagga based MLPs, also that route-servers are now free of &#8216;first generation code&#8217; bugs, and also that they handle your prefixes transparently &#8211; as you would expect.</p>
<p>Interestingly, BIRD and OpenBGPd behave identically &#8216;on the wire&#8217; so IXPs are encouraged to use multi-vendor MLP on their platform for increased reliability and stability.  The new breed of route-server code is dependable and tested, so networks that would like to connect should draw confidence from this testing, and IXPs wishing to roll out MLP services should feel confident in the software tested.</p>
<p>Happy peering!</p>
<p></p>

<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/ixp-bake-off-results/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPv6 Track at NANOG</title>
		<link>http://www.andyd.net/2009/ipv6-track-at-nanog/</link>
		<comments>http://www.andyd.net/2009/ipv6-track-at-nanog/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 16:16:45 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=154</guid>
		<description><![CDATA[<p>Greetings from Philadelphia!  I am <a href="http://www.nanog.org/streaming.php" onclick="javascript:urchinTracker ('/outbound/article/www.nanog.org');">presenting as part of the IPv6 at NANOG46 (click here for info of how to watch)</a> at 9:30PM UK time today, or <a href="http://www.andyd.net/media/talks/v6-enterprise-black.pdf" >download the IPv6 for Enterprises presentation here</a>, or <a href="http://www.nanog.org/meetings/nanog46/abstracts.php?pt=MTM3NCZuYW5vZzQ2&amp;nm=nanog46" onclick="javascript:urchinTracker ('/outbound/article/www.nanog.org');">see information about the other speakers here</a>..</p>
<p>The messages are clear and simple.  Working now to get ready for the IPv6 transition will be less expensive and lower risk than waiting for IPv4 starvation to hurt.  I interviewed some key enterprises about their specific grumbles but the great news is that most are transitional and already people are working on fixing them.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2009/ipv6-track-at-nanog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The internet is still broken, guys&#8230;</title>
		<link>http://www.andyd.net/2009/asn32-asn4-internet-broken/</link>
		<comments>http://www.andyd.net/2009/asn32-asn4-internet-broken/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 20:32:01 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[asn32]]></category>
		<category><![CDATA[asn4]]></category>
		<category><![CDATA[broken]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[nanog]]></category>
		<category><![CDATA[rfc]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=122</guid>
		<description><![CDATA[<p>I complained on December 10th 2008 that The Internet was <a href="http://www.andyd.net/index.php/2008/12/10/internet-broken-for-asn32-speakers-today/" >broken for 4-byte ASN speakers</a>.  <a href="http://rob.sh/" onclick="javascript:urchinTracker ('/outbound/article/rob.sh');">Rob Shakir</a>, Jonathan Oddy, and I have been researching in detail the mechanism by which a faulty announcement by an end-site network in the Ukraine was able to<strong> break BGP</strong> (the protocol that glues different networks on the internet together, one of the most<strong> significant building blocks of the internet</strong>) for hosts that supported ASN4 &#8211; the evolution of the protocol to support &#8216;large&#8217; AS numbers (unique network IDs).</p>
<p>Some history in very brief terms &#8211; all networks on the internet that participate in BGP need a number to identify themselves.  On the public internet, this number normally needs to be globally unique.  The number can be between 1 and 65,535, and we have close to 50,000 of these numbers in use.  To grow past this number, the BGP standard needs to be modified.  The modification is described in a document called <a href="http://www.ietf.org/rfc/rfc4893.txt"title="Support for 4 byte as numbers"  onclick="javascript:urchinTracker ('/outbound/article/www.ietf.org');">rfc4893</a>, and this document was accepted by the community last May.</p>
<p>The first incarnations of router software that support these large AS numbers is now circulating. <span style="text-decoration:blink;"><strong>Due to flaws in the standards that exist in January 2009, if you install one, you may become disconnected from the internet</strong></span>.</p>
<p>Why? Some more background, first: BGP allows for large networks to configure &#8216;hints&#8217; in their router configuration, by dividing their network into several small networks (confederations).  The information about the &#8216;virtual&#8217; divisions of the network should be removed from the BGP messages which are sent to other networks, but if a network supports large ASN in some parts, and not in others, the <strong>routers in the legacy part of the network may not know to test</strong> the &#8216;large number&#8217; section of a BGP message for the presence of an internal confederation ID.  The standard tries to take this into account by explicitly forbidding that confederation ID be passed between networks in the asn4 part of the BGP message.</p>
<p>However, should this occur by accident, what are the effects?  Well, elsewhere in the Large ASN standard, it states that <strong>the connection between two networks should be severed</strong> if Confederation ASN appear to be leaked in the ASN4 part of the BGP message.  This means that networks which do not understand large ASN can <strong>forward a broken message to a network which does understand </strong>large ASN.  At which point the network which does understand large ASN should tear down the session.</p>
<p>Since this message can be delivered over a transit session, this means the receiving ISP loses their connection to the internet via that ISP.  If it learns the router over every ISP, then the network can <strong>lose its connection to the internet entirely</strong>.</p>
<p>The message that I reported was leaking in December is still leaking.  AS196629 (AS3.21 in legacy asdot notation) is announcing to AS35320, who are not stripping their confederation information from the large-asn section of BGP messages.  If you learn the prefix via AS196629&#8217;s other transit, AS6886, then you are fine.  If you learn the prefix via AS35320, you are (today) receiving a broken message.</p>
<p>We tested out how Cisco IOS is coping with this broken message using the first generation of code for the cisco 7200 router that understands ASN4.  We peered the router to <a href="http://www.netsumo.com/" onclick="javascript:urchinTracker ('/outbound/article/www.netsumo.com');">NetSumo</a>&#8217;s research and development network, AS15653.  Cisco honours the standard/rfc, and breaks the session.  Since it learns the dirty message on the transit session, the router <strong>disconnected our test network from the internet entirely</strong> :</p>
<ul>
<li>*Jan 16 11:29:58.531: %BGP-5-ADJCHANGE: neighbor 193.239.32.2 Up</li>
<li>*Jan 16 11:30:02.595: %BGP-6-ASPATH: Invalid AS path (65044 65048 65062) 3.21 23456 received from 193.239.32.2: Confederation found in AS4_PATH</li>
<li>*Jan 16 11:30:02.595: %BGP-5-ADJCHANGE: neighbor 193.239.32.2 Down BGP Notification sent</li>
<li>*Jan 16 11:30:02.595: %BGP-3-NOTIFICATION: sent to neighbor 193.239.32.2 3/1 (update malformed) 27 bytes E0111803 030000FE 140000FE 180000FE 26 FFFF FFFF FFFF FFFF FFFF FFFF FFFF FFFF 0050 0200 0000 3540 0101 0240 020C 0205 3D25 2114 89F8 5BA0 5BA0 4003 04C1 EF20 02E0 1118 0303 0000 FE14 0000 FE18 0000 FE26 0202 0003 0015 0000 5BA0 175B CFDA</li>
</ul>
<p>If you work in this field, I implore you to <a href="http://www.merit.edu/mail.archives/nanog/msg14345.html" onclick="javascript:urchinTracker ('/outbound/article/www.merit.edu');">read the more thorough analysis on the nanog list</a>, and participate in the discussion to work out how we should correct the standard, to allow routers to behave differently when a dirty message is received.  If we do not, then there is a simple, easy to understand, and easy to implement mechanism to <strong>break the internet</strong>, as soon as networks upgrade to the current version of their routing software.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2009/asn32-asn4-internet-broken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Openness and telecoms</title>
		<link>http://www.andyd.net/2009/openness-and-telecoms/</link>
		<comments>http://www.andyd.net/2009/openness-and-telecoms/#comments</comments>
		<pubDate>Thu, 01 Jan 2009 17:57:30 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[non-tech]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://www.andyd.net/index.php/2009/01/01/openness-and-telecoms/</guid>
		<description><![CDATA[<p>This is a response to <a href="http://ecommconf.com/blog/2009/01/skype-openness-and-walled-gard.html" onclick="javascript:urchinTracker ('/outbound/article/ecommconf.com');">Lee Dryburgh&#8217;s article on Skype</a>.  We had a debate on <a href="http://www.twitter.com/andyd" onclick="javascript:urchinTracker ('/outbound/article/www.twitter.com');">Twitter</a>, but I have not yet mastered the art of debate in 140 characters!</p>
<p>Lee&#8217;s premise is that <em>&#8220;Certainly Skype is not a walled garden. All things being relative, it&#8217;s certainly not overly closed either.&#8221;</em>  Lee claims that the accusations of closeness are unfair, because they are levied by commentators who advocate SIP based addressing and dialing rather than any other system.</p>
<p>This is not my premise.  I claim that Skype is closed because calls are signalled and completed using protocols that are entirely secret as a matter of policy.  Skype&#8217;s founder presented at Spring VON 2007 and stated that if Skype did not <a href="http://skypejournal.com/blog/2007/03/niklas_briefs_von.html" onclick="javascript:urchinTracker ('/outbound/article/skypejournal.com');">keep their protocols entirely secret</a>, then Skype would be full of spam and attack like email is.  I think this is a poisonous claim, telephone networks have been interconnecting around the world since telephony was conceived.  By not allowing telecoms firms to interconnect between the skype namespace and other networks, Skype have prevented openness to develop and maintain a monopoly position. That&#8217;s perfectly acceptable business, but it is not in the slightest bit open.</p>
<p><img width="304" height="188" id="image103" alt="walled.jpg" src="http://www.andyd.net/wp-content/uploads/2009/01/walled.jpg" />Randy Bush googled Walled Garden for a recent presentation and found this cartoon.  I like this definition because it&#8217;s correct.  Is Skype a Walled Garden ?  Lee says a Walled Garden is a commercial restriction, for example, &#8220;<em>sharing of ringtones via Bluetooth, using WiFi from a PDA, having access to all Web sites</em>&#8220;.  I think that only allowing interconnection with the purchase of an upgrade like SkypeOut is a restrictive or practice that suggests Skype is a Walled Garden.  Worst of all a call between two VoIP networks using this method requires default PSTN routing, which harms signal quality, and prevents the expansion of next-generation services such as Wideband/High Definition audio.</p>
<p>The meshing of networks, whether they are traditional voice or IP networks, leads to higher audio quality and increased reliability.  Keeping telephony systems and protocols secret in order to prevent meshing may well be a viable business model, but it is not an open business model.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2009/openness-and-telecoms/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Internet broken for ASN32 speakers today.</title>
		<link>http://www.andyd.net/2008/internet-broken-for-asn32-speakers-today/</link>
		<comments>http://www.andyd.net/2008/internet-broken-for-asn32-speakers-today/#comments</comments>
		<pubDate>Wed, 10 Dec 2008 22:23:06 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[telecoms]]></category>

		<guid isPermaLink="false">http://www.andyd.net/index.php/2008/12/10/internet-broken-for-asn32-speakers-today/</guid>
		<description><![CDATA[<p>Not trying to point fingers or name-and-shame, just to raise the profile of a nasty little bug handling breaches of RFC4893.  This post is basically shaped from a message I posted to <a href="http://www.merit.edu/mail.archives/nanog/msg13416.html" onclick="javascript:urchinTracker ('/outbound/article/www.merit.edu');">nanog</a> earlier.</p>
<p>AS196629 (3.21 in asdot) announce 91.207.218.0/23.  Experienced eyes will notice that this is quite a large as number.  It&#8217;s a &#8216;new&#8217; 4-byte ASN.  When an OpenBGPd speaker with 4-Byte ASN support receives the update for <em>this</em> message, the session is torn down with the daemon logging a &#8216;fatal error&#8217;. Why?<br />
OpenBGPd is checking AS4_PATH to ensure that it contains only AS_SET and AS_SEQUENCE types, as per RFC4893.  When processing the UPDATE for 91.207.218.0/23 it sees :</p>
<blockquote><p>91.207.218.0/23<br />
Path Attributes &#8211; Origin: Incomplete<br />
Flags: 0&#215;40 (Well-known, Transitive, Complete)<br />
Origin: Incomplete (2)<br />
AS_PATH: xx xx 35320 23456 (13 bytes)<br />
AS4_PATH: (65044 65057) 196629 (7 bytes)</p></blockquote>
<p>See the confederation ASNs in the AS4_PATH ?  Thats forbidden :</p>
<blockquote><p>To prevent the possible propagation of confederation path segments outside of a confederation, the path segment types   AS_CONFED_SEQUENCE and AS_CONFED_SET [RFC3065] are declared invalid for the AS4_PATH attribute. <em>RFC 4893.</em></p></blockquote>
<p>The RFC does not suggest how to handle AS4_PATH violations, but if the bad path is learned on every upstream, this will cause a network with obgpd edges to disconnect from the internet&#8230;. Modifying the OpenBGPd software to permit AS_CONFED_SEQUENCE, AS_CONFED_SET in an as4_path causes the path to be accepted and the session is not torn down.  This isn&#8217;t a great fix.<br />
The impact today is fairly limited as there are relatively few bgp   speakers honouring the 4-byte ASN protocol extension rules, but as   code that support these features creeps around the internet, the next   time this happens the impact could be much greater, so we need to   understand which implementation of which BGP software caused this   illegal origination.</p>
<p>From a software point of view, I want to see a configurable option to reject the route but keep the session, reject the route and drop the session, accept the route but log/send trap, etc.</p>
<p>In any case we need to publish the arrangement that has led to this mistake so that other networks using the same toolset to originate prefixes can avoid the same situation happening.  I have made contact with an engineer at the NOC who are investigating.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2008/internet-broken-for-asn32-speakers-today/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>2011 &#8211; An addressing odyssey. Preparing enterprise for IPv6.</title>
		<link>http://www.andyd.net/2008/2011-an-addressing-odyssey-preparing-enterprise-for-ipv6/</link>
		<comments>http://www.andyd.net/2008/2011-an-addressing-odyssey-preparing-enterprise-for-ipv6/#comments</comments>
		<pubDate>Thu, 04 Dec 2008 23:11:05 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Sys Admin]]></category>
		<category><![CDATA[The 'net]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[non-tech]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://www.andyd.net/index.php/2008/12/04/2011-an-addressing-odyssey-preparing-enterprise-for-ipv6/</guid>
		<description><![CDATA[<p>Yesterday I gave a talk to Sheffield GeekUp on <a href="http://www.andyd.net/media/talks/2011-addressing-odyssey.pdf" >preparing enterprises for IPv6</a> [download].  The premise of the talk was :</p>
<ul>
<li>IPv4 addresses are scarse, and at current consumption rates, the IANA pool of free v4 addresses will be gone at the start of 2011.</li>
<li>This starts a &#8220;Post IPv4 world&#8221; where the IPv4 internet continues to function as before (certainly initially), but obtaining new addresses becomes harder and expensive.  This inhibits expansion of existing firms, and new entrants to the market.</li>
<li>Address trading is likely to lead to a larger routing table, meaning that failure-recovery times increase, and the risk of blackholes on the internet increases.</li>
<li>Large broadband providers may not have enough v4 addresses to give one address per customer.  This means protocol translation techniques need to be used, which break the end to end model.  We rely on the end to end model when innovating new services on the internet.</li>
<li>If services and consumers gradually roll v4 and v6 (dual stack), the negative impact of markets for addresses, routing problems, and translation can be mitigated.</li>
<li>Service providers are enabling v6 in the core.  Enterprises need to move next in order to get the world v6 ready.</li>
</ul>
<p>The advice I gave was :</p>
<ul>
<li>Today&#8217;s market leaders are already learning v6 lessons in their labs, (e.g. ipv6.google.com).  They are doing this to help them retain market leadership.  If you want to retain your market position, start labbing your applications and service provision with v6.</li>
<li>Write a policy stating all new purchases of infrastructure and services need to be from providers with v6 support, or a well defined v6 road map.  In other words, make v6 a &#8220;life cycle upgrade&#8221;.</li>
<li>Share information, and learn information from your industry peers.</li>
<li>I also listed some advice to developers with regard to v4 and v6 differences.</li>
<li>I then delivered a very quick primer to those who have not seen v6 deployed before.</li>
</ul>
<p>My hope is that this talk is improved upon and delivered internationally to enterprises.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2008/2011-an-addressing-odyssey-preparing-enterprise-for-ipv6/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>VoIP For Network Operators Tutorial</title>
		<link>http://www.andyd.net/2008/voip-for-network-operators-tutorial/</link>
		<comments>http://www.andyd.net/2008/voip-for-network-operators-tutorial/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 19:26:41 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://www.andyd.net/index.php/2008/10/13/voip-for-network-operators-tutorial/</guid>
		<description><![CDATA[<p>These are the slides that I presented at <a href="http://www.nanog.org/meetings/nanog44/" onclick="javascript:urchinTracker ('/outbound/article/www.nanog.org');">NANOG44</a> in Los Angeles on Sunday, &#8220;<a href="http://www.andyd.net/media/talks/voip_for_service_providers.pdf"title="VoIP For Service Providers"  >VoIP For Network Operators</a>&#8220;.</p>
<p>This talk was for network operators looking to build voice segments of their network, and the slides cover</p>
<ul>
<li>Voice Basics for SPs</li>
<li>Why Operators should care</li>
<li>Voice Peering</li>
<li>Metrics</li>
<li>VoIP Security</li>
</ul>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2008/voip-for-network-operators-tutorial/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Youtube pushed off the air</title>
		<link>http://www.andyd.net/2008/youtube-pushed-off-the-air/</link>
		<comments>http://www.andyd.net/2008/youtube-pushed-off-the-air/#comments</comments>
		<pubDate>Sun, 24 Feb 2008 22:01:40 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.andyd.net/index.php/2008/02/24/youtube-pushed-off-the-air/</guid>
		<description><![CDATA[<p>In between browsing Facebook and Youtube, the UK economy generates $1,930,000,000 of output a year.  Thats $550,000 every two and a half hours.  Well if today had been a work day, there&#8217;d have been one two and a half hour period where that was much higher.  That&#8217;s because in a pique of routing excitement, Pakistan Telecom managed to hide Youtube from most of the internet for that length of time.</p>
<p>Pakistan Telecom and Youtube are likely to have no commercial relationship in place to carry Youtube traffic &#8211; particularly as around two hours ago, according to Yahoo News, the story broke that the <a href="http://uk.news.yahoo.com/afp/20080224/ttc-denmark-media-islam-pakistan-interne-0de2eff_1.html" onclick="javascript:urchinTracker ('/outbound/article/uk.news.yahoo.com');">Pakistan Government required ISPs operating in the country to block Youtube</a>.  Despite this, Pakistan Telecom were able to cause ISPs all over the world to send traffic that should be destined for Youtube to Pakistan instead.</p>
<p>This is because the protocol that determines how to find my network on the internet, is shaped by how &#8220;specific&#8221; the announcement of my network is.  If I make an announcement of a network of 1,024 addresses, and someone else makes a second announcement of 256 addresses within a subset of my 1,024, then the network which announces the smaller subset win the traffic destined to those hosts.  This is a feature &#8211; fully by design &#8211; of the BGP routing protocol.  Almost every time a more specific block of addresses is announced, this is because the administrators of those networks intend for the routing to be different for a subset of a large number of addresses.</p>
<p>Sadly, there are accidents from time to time &#8211; another network can announce a subset of my addresses without my knowledge or permission, and they win the traffic that should have gone to me.  This happened today &#8211; it seems that Pakistan Telecom decided to inject a fake route to <em>their</em> network containing Youtube&#8217;s webservers, and accidently then leaked that route to the networks they connect to.</p>
<p>Small networks and end sites can limit the chances that they will leak bad routes by explicitly listing the network addresses that they intend to send to their upstream or peered networks.  Larger networks may find it harder to stop themselves propagating someone else&#8217;s mistake, because they may have a contract to carry forward any announcement that their customers make.  Furthermore, the complexities of their own networks mean that an engineer working under pressure after announcements made by government ministers are more likely to make a typo error and do the wrong thing.</p>
<p><a href="http://www.lightbluetouchpaper.org/" onclick="javascript:urchinTracker ('/outbound/article/www.lightbluetouchpaper.org');">Richard Clayton</a> presented a very interesting set of commentaries at the last LINX meeting.  He commented that right now its very obvious indeed when someone hijacks some of my network space in this way, because all of my traffic disappears.  Youtube were probably aware that something was very wrong within moments of the announcement.  What if someone builds an infrastructure to steal my traffic &#8211; or at least some of my traffic &#8211; but after doing something with it, they send it back to me, it is much harder for me to spot that anything is wrong.</p>
<p>This is a significant risk to ecommerce infrastructures that competitors or e-pirates could seize upon opportunities to steal customer behaviour data.  What if a wizard stole the network containing your web server, proxied your shop, but set up a fake checkout?  How quickly would you spot?</p>
<p>Because this problem is inherent to the routing protocol, this is the obvious place to fix it.  There are attempts to <a href="http://www.ir.bbn.com/sbgp/" onclick="javascript:urchinTracker ('/outbound/article/www.ir.bbn.com');">blend PKI with routing information</a>, so that peers can verify the validity of your announcements.  S/BGP (secure BGP) requires me to sign my announcements, and gives my peers a method to check in an impartial internet community database that my announcement is valid.  It is the sort of technology that would have prevented Youtube from disappearing off the air today.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2008/youtube-pushed-off-the-air/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>European Internet exchange update slides</title>
		<link>http://www.andyd.net/2008/european-internet-exchange-update-slides/</link>
		<comments>http://www.andyd.net/2008/european-internet-exchange-update-slides/#comments</comments>
		<pubDate>Sun, 20 Jan 2008 15:15:30 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>

		<guid isPermaLink="false">http://www.andyd.net/index.php/2008/01/20/european-internet-exchange-update-slides/</guid>
		<description><![CDATA[<p>I presented a <a href="http://www.uknof.org.uk/uknof9/Davidson-IX-update.pdf" onclick="javascript:urchinTracker ('/outbound/article/www.uknof.org.uk');">talk on recent European Internet exchange news [download]</a> with Mike Hughes from the LINX last week at <a href="http://www.uknof.org.uk/" onclick="javascript:urchinTracker ('/outbound/article/www.uknof.org.uk');">UKNOF</a>.  Many of the attendees run networks that do not peer publicly, so it was a pleasure to explain the impact that European IXPs have on member traffic.  We also then gave a perspective on peering in London.</p>
<p>Many of the statistics came from Serge at Euro-IX who did the leg work for the raw figures.</p>
<p>The highlight points of the talk were</p>
<ul>
<li>Euro-IX identify 103 exchanges in Europe, in 31 countries.  (3 in 1993)</li>
<li>8 Exchanges in the UK (was 9 until BT&#8217;s UK6x closed)</li>
<li>At the end of 2007 networks publicly peered 1.215Tbit/sec at peak.</li>
<li>More public peering in EU than US (but it&#8217;s cheaper to peer in EU thanks to lower x-connect fees, and cheap ubiquitous mutual exchanges)</li>
<li>London is #1 for network reach &#8211; 601 networks peer publicly, 415 peer exclusively in the UK.</li>
<li>22% of LINX members peer exclusively at LINX, 31% of LONAP members peer exclusively at LONAP.</li>
<li>577 networks peer at more than one IXP, and one network (Colt) is present at 19 exchanges!</li>
<li>Last year the good weather in April caused an additional summer-time traffic dips in Europe, in addition to the regular dip in July/August</li>
</ul>
<p>There&#8217;s other stuff in the slides too, such as the usual traffic updates for various major exchanges in Europe.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2008/european-internet-exchange-update-slides/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Voice peering</title>
		<link>http://www.andyd.net/2007/voice-peering/</link>
		<comments>http://www.andyd.net/2007/voice-peering/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 13:07:09 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://www.andyd.net/index.php/2007/12/06/voice-peering/</guid>
		<description><![CDATA[<p>I come from an IP engineering background, and now work in a telecoms role with <a href="http://www.localphone.com/" onclick="javascript:urchinTracker ('/outbound/article/www.localphone.com');">Localphone.com</a>.  Huge amounts of crossover exist between the two disciplines, especially now that inter-company telecommunications interconnections are now regularly made over IP, but much of what someone will learn about peering in the voice world will not be mellifluous to someone with a background in IP peering.</p>
<p>I attended a PulverMedia <a href="http://www.newmarketpeering.com/2007/florida/web/" onclick="javascript:urchinTracker ('/outbound/article/www.newmarketpeering.com');">conference on voice peering</a> last week, with some preconceptions about what I imagined voice peering to be.  These are some things I learned after talking to people at the conference.  <a href="http://ipcarrier.blogspot.com/" onclick="javascript:urchinTracker ('/outbound/article/ipcarrier.blogspot.com');">Gary Kim</a> gave one of the most useful insights when he complained that he was, &#8220;More confused about where peering is going today than he was two years ago.&#8221;</p>
<p>&#8220;Why can&#8217;t I configure a voice peer like I can configure a BGP peer?&#8221; is a typical question.  The answer is simple.  When you peer using IP, the protocol is well known and established, prefixes are in a ubiquitous standard, peering is typically settlement free (and when its not, pricing is transparent and easy to calculate as mostly all traffic is equal &#8211; from a billing perspective).</p>
<p>The sad dichotomy is that in the voice world, prefixes (telephone numbers) behaviour is not identical, the protocols different companies use will be different (media codecs, call signalling, dtmf), and thanks to the regulators and history of commercial telephony peering is hardly ever settlement free.</p>
<p>This complexity has led to the emergence of another traditional pattern in telecoms &#8211; a barrier to entry.  Clearing houses who will abstract peers from each other.  They mediate media codecs, signaling differences, and perform CDR mediation.  A barrier to entry, because they don&#8217;t want to do this for free.  This is a model which is not great for many telcos who quite rightly don&#8217;t want to yield control of their outbound dialplans to any third party.  Abstracting my media might mean callers get lower quality calls, and leave me as a service provider with poor visibility of the route that a call between two parties takes.  Abstracting signaling without me being aware means that error messages about calls are lost in translation.</p>
<p>The clearing house model is also a natural monopoly.  If a company is a member of one clearing house, and I am a member of another, then there is no way for us to peer using the traditional clearing-house model.  Some clearing houses have suggested a protocol that would permit clearing houses to peer (<a href="http://www.spiderregistry.net/" onclick="javascript:urchinTracker ('/outbound/article/www.spiderregistry.net');">share their registry data</a>) &#8211; effectively increasing the reach &#8211; but this potentially further increases the layers of abstraction between me as a service provider and a peer.</p>
<p>Before I explain what I think the answer is, let me explain a few of the reasons why peering between telephony companies is good.  Peering between competitive telecoms companies reduces their dependency on national incumbent providers.  Two large non-incumbent telcos can peer, possibly meaning that TDM legs are removed from a call which is IP at both ends resulting in better quality calls, possibly permitting the use of new ultra-clear wideband-audio codecs, and typically at cheaper rates than connecting through an incumbent party.  This gives telecoms customers cheap calls at a higher quality.  As a result this is an important strategy for next-gen telcos.</p>
<p>Telecoms companies need to communicate their prefixes and standards bilaterally &#8211; that is to say, without a clearing house.  I am working with some of the people I met at the conference on a new Internet-Draft to suggest the protocol that would facilitate this (like TRIP, but with enough understanding of commercial logic in the protocol to make it useful).  I&#8217;m hoping to publish the first draft later this month.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2007/voice-peering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
