<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>my web 0.2 website &#187; The &#8216;net</title>
	<atom:link href="http://www.andyd.net/category/the-net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.andyd.net</link>
	<description>Andy Davidson\&#039;s tech blog</description>
	<lastBuildDate>Wed, 08 Jun 2011 14:10:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>IP Drought begins today in Asia-Pacific</title>
		<link>http://www.andyd.net/2011/ip-drought-begins-today-in-asia-pacific/</link>
		<comments>http://www.andyd.net/2011/ip-drought-begins-today-in-asia-pacific/#comments</comments>
		<pubDate>Thu, 14 Apr 2011 09:52:09 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Sys Admin]]></category>
		<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[ipv6]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=287</guid>
		<description><![CDATA[<p>That&#8217;s it &#8211; the Asia Pacific region is the first to run out of IPv4 addresses.</p>
<p>This happened following an <a href="http://mailman.nanog.org/pipermail/nanog/2011-April/035233.html" onclick="javascript:urchinTracker ('/outbound/article/mailman.nanog.org');">assignment</a> of around half a million addresses to support the users at the Chinanet Fujian Province Network.</p>
<p>The pool of available addresses to the region including some of the world&#8217;s largest populations, such as China, India, Indonesia, and some of the world&#8217;s largest economies, such as Japan and Australia, has depleted to such low levels, that the registry responsible for distribution of these addresses will now ration them, such that any ISP requesting space will be given a single block of 1,024 addresses, on a single occasion only.</p>
<p>This is enough space to allow the ISP only to host NAT or ipv4 to ipv6 translation technologies.  It is not enough to address a large content infrastructure, hosting environment, or internet access customer-base.</p>
<p>The rules of the game have today changed for 50% of the world&#8217;s population, and they will change in Europe too in a few short months too.  If you do not have an IPv6 plan, then this is your new significant business risk &#8211; how will users with v6 only connections reach your content?  And if this is through a translation mechanism, how will you ensure quality, or that your end-to-end protocols (like voice, video, etc.) will work ?</p>
<p>Get in touch to continue the conversation!</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2011/ip-drought-begins-today-in-asia-pacific/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Encouraging peering in South Africa</title>
		<link>http://www.andyd.net/2010/mweb-encouraging-peering-in-south-africa/</link>
		<comments>http://www.andyd.net/2010/mweb-encouraging-peering-in-south-africa/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 22:37:13 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[asn]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[ixp]]></category>
		<category><![CDATA[lonap]]></category>
		<category><![CDATA[mweb]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[ripe]]></category>
		<category><![CDATA[ripe ris]]></category>
		<category><![CDATA[routing table]]></category>
		<category><![CDATA[south africa]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=262</guid>
		<description><![CDATA[<p>I read with some excitement that South African ISP <a href="http://www.mweb.co.za/" onclick="javascript:urchinTracker ('/outbound/article/www.mweb.co.za');">MWEB</a> have disconnected their transit connections with other ISPs in South Africa, claiming that their existing services from Vodacom and Telkom South Africa were congested and expensive, and detrimental to the quality of internet services in the country.</p>
<p><a href="http://www.ris.ripe.net/mt/asinuse-result.html?as=10474&amp;rrc_id=1000&amp;interval=1&amp;outype=html&amp;submit=Search" onclick="javascript:urchinTracker ('/outbound/article/www.ris.ripe.net');">According to the RIPE RIS service</a>, the links between MWEB (AS10474) to Telkom South Africa (AS5713) were disconnected on the November 2nd &#8211; Telkom being the original transit provider that MWEB used.</p>
<p>MWEB have detected that congestion reduces, therefore service levels increase when traffic bypasses the incumbent and is delivered directly to other ISPs in their region via peering links.  If a network refuses to peer, MWEB simply deliver the traffic to local providers via their international links &#8211; possibly just as congested, but available at a fraction of a cost.  If traffic is then delivered to the incumbents via links they themselves pay for, the incumbents also have a financial incentive to peer.</p>
<p>Peering is the best way to encourage enormous capacities between ISPs and other networks, because a direct one-to-one connection can be monitored and well managed in order to guarantee availability for internet traffic.  Peering therefore increases available bandwidth and reduces bandwidth costs.  This will enable high the sort of services that require high-bandwidth availability, like streaming media and high definition video conferencing.</p>
<p>Interestingly, thirty minutes after the adjacency with Telkom was severed, it appeared that MWEB picked up a new transit customer &#8211; Yebo, AS12258, with Yebo&#8217;s prefixes being advertised to Interoute (again, according to RIPE RIS).  The commercial nature of this downstream relationship is, however, not revealed by the routing table.</p>
<p>The incumbent is perfectly entitled to &#8211; and well placed to &#8211; sell excellent transit links into the local market, but their strategy to do that, as I <a href="http://www.andyd.net/2010/building-an-ip-market-from-scratch/" >explained in my last article</a>, must be to make the transit product in their key regions excellent &#8211; this means to peer with the <em>key</em> other local providers (not all providers) in the market, and to ensure that capacities across their backbone and to customers are well managed and available for traffic.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/mweb-encouraging-peering-in-south-africa/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Building an IP Market from scratch</title>
		<link>http://www.andyd.net/2010/building-an-ip-market-from-scratch/</link>
		<comments>http://www.andyd.net/2010/building-an-ip-market-from-scratch/#comments</comments>
		<pubDate>Sat, 06 Nov 2010 13:40:00 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[non-tech]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[ixp]]></category>
		<category><![CDATA[menog]]></category>
		<category><![CDATA[middle east]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[renesys]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=259</guid>
		<description><![CDATA[<p>At Menog 7, I had the pleasure of enjoying an <a href="http://www.menog.net/sites/default/files/menog-cowie-22102010.pdf" onclick="javascript:urchinTracker ('/outbound/article/www.menog.net');">explanation of the Middle East IP market place (link)</a>, provided by <a href="http://www.renesys.com/blog/author/james-cowie-1/" onclick="javascript:urchinTracker ('/outbound/article/www.renesys.com');">James Cowie at research organisation Renesys</a>.</p>
<p>It demonstrates clearly that deregulated markets offer enormous advantages over controlled ones, and should serve well as a reminder to operators and policy makers that simply <em>getting out of the way</em> could be the best way to further their aims for industry in any given region.  This is mainly because:</p>
<ul>
<li>Allowing networks to interconnect freely (calculated as number of active ASNs in a region), and the size of the market (calculated from the pool of announced ip addresses in a region) are strongly correlated (slide 8).  My guess is that more organisations get online, because competition leads to price falling, whilst the versatility and relevance of services offered increases.</li>
<li>When there are a larger number of networks in a region, the global carriers have a greater incentive (more customers!) to run diverse connectivity into the region.  This leads to a huge advantage to firms in a region, their connectivity carries on despite local major fibre breaks. (slide 25, 36)</li>
<li>Content moves out of the US/Western Europe and into the local market place, creating opportunity (and jobs) for local players, and improving the performance of services for local users.</li>
</ul>
<p>Incumbent networks in this region have a huge opportunity to grow revenues, as the market expands, as long as they are willing to interconnect widely in this region.  As the number of providers in a region expands, customers will be able to (and, according to this research, <em>actually do</em>) pick between innovative and disruptive new providers with excellent regional (via peering), and international (via transit) capacities.  Peering also makes capacity cheap, because traffic can stay local to the ISP.  An incumbent provider that refuses to peer in order to retain market share will not be able to compete in quality terms with the new providers.  Defending a 100% market share is impossible in a competitive market, so the strategy must change, the aim must become enjoying the fruits of a booming market instead of monopoly.  As the Renesys slides say, there is no dominent IXP in this region yet, with many networks dragging traffic to London, Amsterdam or Frankfurt to exchange, but this will change as the density of providers in the Middle East reaches a critical mass.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/building-an-ip-market-from-scratch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Building an Internet Exchange Point</title>
		<link>http://www.andyd.net/2010/building-internet-exchange-technical-information-slides/</link>
		<comments>http://www.andyd.net/2010/building-internet-exchange-technical-information-slides/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 18:02:28 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[asn]]></category>
		<category><![CDATA[euroix]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[ixp]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[lonap]]></category>
		<category><![CDATA[menog]]></category>
		<category><![CDATA[network]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=255</guid>
		<description><![CDATA[<p>I&#8217;m in Istanbul at <a href="http://www.menog.net/meetings/menog7/start-ixp" onclick="javascript:urchinTracker ('/outbound/article/www.menog.net');">MENOG7</a> in order to present in a panel about internet exchange points.  Our aim is to give groups of ISP networks in the Middle East enough knowledge to start internet exchange points, so there will also be presentations on the business case and organisational checklists.  I am presenting on the technical pre-requisites required to build an Internet Exchange point.</p>
<p>Setting up an Internet Exchange point is simple from a technology point of view, but requires significant planning, and community support for the plans.  Read the slides to find out more about what must be planned.</p>
<p>Download:  <a href="http://www.andyd.net/media/talks/Building_an_IXP.pdf" >[Slides + Notes (recommended)] </a>~ <a href="http://www.andyd.net/media/talks/Building_an_IXP-Display.pdf" >[Slides alone]</a></p>
<p>View directly from Slideshare (requires flash):</p>
<div id="__ss_5505989" style="width: 477px;"><strong><a href="http://www.slideshare.net/andy.d/building-an-internet-exchange-point-technical-checklist"title="Building an Internet Exchange Point - Technical Checklist"  onclick="javascript:urchinTracker ('/outbound/article/www.slideshare.net');">Building an Internet Exchange Point &#8211; Technical Checklist</a></strong><object id="__sse5505989" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="477" height="510" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/doc_player.swf?doc=buildinganixp-101020123736-phpapp01&amp;rel=0&amp;stripped_title=building-an-internet-exchange-point-technical-checklist&amp;userName=andy.d" /><param name="name" value="__sse5505989" /><param name="allowfullscreen" value="true" /><embed id="__sse5505989" type="application/x-shockwave-flash" width="477" height="510" src="http://static.slidesharecdn.com/swf/doc_player.swf?doc=buildinganixp-101020123736-phpapp01&amp;rel=0&amp;stripped_title=building-an-internet-exchange-point-technical-checklist&amp;userName=andy.d" name="__sse5505989" allowscriptaccess="always" allowfullscreen="true"></embed></object>
</div>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/building-internet-exchange-technical-information-slides/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LONAP Route Servers Pass Milestone</title>
		<link>http://www.andyd.net/2010/lonap-route-servers-milestone/</link>
		<comments>http://www.andyd.net/2010/lonap-route-servers-milestone/#comments</comments>
		<pubDate>Mon, 18 Oct 2010 21:47:06 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>
		<category><![CDATA[asn]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[lonap]]></category>
		<category><![CDATA[route-servers]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=248</guid>
		<description><![CDATA[<p>I noticed earlier that <a href="http://www.lonap.net/" onclick="javascript:urchinTracker ('/outbound/article/www.lonap.net');">LONAP</a> had passed a fantastic milestone just before the weekend &#8211; of the ninety nine networks which are <a href="http://www.lonap.net/members.shtml" onclick="javascript:urchinTracker ('/outbound/article/www.lonap.net');">plugged into the exchange</a>, more than half of the networks choose to connect to each other via the route-server.</p>
<p>A route-server is a fantastic way for networks to start to peer (swap internet traffic) at Internet Exchanges, and results in instant success after connection.  A network with an open peering policy can connect to the internet exchange, and then get peering with more than half of all the other networks on the exchange by bringing up a single pair of BGP sessions.</p>
<p>When a route-server peering is established, a BGP session is setup between your router and LONAP&#8217;s route database.  LONAP advertise all of the prefixes of the other connected members to you, but the traffic between you and the other members flows between you and your peer <em>directly</em> (it does not need to traverse the route-server.)  Members do not need to open their network to their own customers at the route servers, they can send special messages to the route-servers to prevent certain networks from seeing prefixes.</p>
<p>Route-servers are not new, but have had a bad reputation for stability for several years.  With our colleagues at several other community exchanges, including the LINX, we shared bugs, workarounds, and feature requirements with each other and the main open-source route-server vendors.  Eventually, we were able to <a href="http://www.uknof.org.uk/uknof15/Davidson-Bakeoff.pdf" onclick="javascript:urchinTracker ('/outbound/article/www.uknof.org.uk');">report considerable improvement in stability last December</a>.  As a result, we at LONAP selected BIRD and OpenBGPd as our route server vendors, and built a support framework to link our configuration with the LONAP configuration system.</p>
<p>Since then we have been advocating the route-servers to our members, and the fact that they are now providing a stable stepping-stone to more than half of our peers shows that this effort was worthwhile.  If you would like to start to peer, but need to be assured of instant success and results, then <a href="http://www.andyd.net/contact/" >contact Andy</a> for information about how the route-servers at LONAP can help.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/lonap-route-servers-milestone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Open Access Fibre</title>
		<link>http://www.andyd.net/2010/uk-open-access-fibre/</link>
		<comments>http://www.andyd.net/2010/uk-open-access-fibre/#comments</comments>
		<pubDate>Wed, 13 Oct 2010 20:03:16 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[non-tech]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=238</guid>
		<description><![CDATA[<p>One of the main questions that enterprises ask <a href="http://www.netsumo.com/" onclick="javascript:urchinTracker ('/outbound/article/www.netsumo.com');">NetSumo</a> is how they can get access to better office connectivity, because their applications and workflow demand ever increasing quantities of bandwidth.  Solving bandwidth capacity issues in the data centre is easy today and less expensive than it has ever been, but turning up huge capacities in your home or office is much more expensive.</p>
<p>Solving this bandwidth starvation is the role of fibre optics and next-generation broadband.  A relatively simple way to roll out fibre backed technology is to use VDSL &#8211; service providers run high capacity fibre optic networks to distribution boxes in streets (FTTC &#8211; Fibre to the Cabinet), and utilise the existing copper infrastructure between street and house or business carries high speed internet.  The shortness of the copper run enables higher speeds. This is increasingly available from companies such as <a href="http://www.digitalregionbroadband.co.uk/"title="Digital Region Broadband"  onclick="javascript:urchinTracker ('/outbound/article/www.digitalregionbroadband.co.uk');">Digital Region Broadband</a>, who offer 40Mbit broadband at consumer prices, but is obviously only available in specific neighbourhoods where the streetboxes have been rolled out.</p>
<p>Removing the copper element will enable much higher speeds and new products like premise-to-premise connectivity.  FTTP &#8211; Fibre to the Premises opens up a world where connectivity between service provider and your office can run at 100Mbit or Gigabit speeds.  Office-to-home or Office-to-office connectivity that runs at Gigabit or even 10Gigabit would be possible too. This would make remote-working via high definition video conferencing, ultra high speed access to company resources and files, and also better quality and more interactive entertainment services a normal thing for everyone.</p>
<p>However, a national &#8211; even urban wide &#8211; fibre rollout project is expensive because of the construction (civils) costs, legal costs, and impact on neighbourhoods.</p>
<p>Earlier this month, Ofcom released a <a href="http://stakeholders.ofcom.org.uk/consultations/wla/statement" onclick="javascript:urchinTracker ('/outbound/article/stakeholders.ofcom.org.uk');">statement on wholesale access products</a>, explaining that they were planning to require BT to make access to their existing ducts, intending to make fibre rollout cheaper.  The two key mechanisms are:</p>
<ul>
<li>Virtual Unbundled Local Access &#8211; BT offer other service providers access to existing fibre.</li>
<li>Physical Infrastructure Access &#8211; BT offer service providers space in their fibre ducts, allowing service providers to run their <em>own</em> fibre.</li>
</ul>
<p><strong>I welcome this development</strong>, but hope that the regulation framework mandated by Ofcom does not remove the incentive BT to roll out new ducts and fibres.  The regulation will be a success if it enables more regional FTTC broadband schemes like the one cited in South Yorkshire, and also if it makes new FTTP the &#8216;norm&#8217; for all new housing developments and telecoms upgrades.  Further, another huge disincentive from rolling out fibre based services &#8212; the <a href="http://www.andyd.net/2010/the-modern-day-window-tax-on-the-internet/"title="UK Fibre Tax Bad"  >UK fibre tax</a> &#8212; must also be repealed in order to achieve the <a href="http://www.wired.co.uk/news/archive/2010-09/24/european-broadband-plans" onclick="javascript:urchinTracker ('/outbound/article/www.wired.co.uk');">typical 30Mbit/sec broadband</a> that the EU wish to see for all citizens by 2020.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/uk-open-access-fibre/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010 will be a bad year for ipv4</title>
		<link>http://www.andyd.net/2010/2010-will-be-a-bad-year-for-ipv4/</link>
		<comments>http://www.andyd.net/2010/2010-will-be-a-bad-year-for-ipv4/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 20:08:28 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Sys Admin]]></category>
		<category><![CDATA[The 'net]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[telecoms]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=178</guid>
		<description><![CDATA[<p>We are now at the end of January, but IPv4, the Internet&#8217;s core addressing protocol still has a nasty hangover, and all signs are pointing to 2010 being a bad year for the protocol.</p>
<p>Since January 1st, a few key milestones have passed, indicating how urgent the IPv4 rundown problem has become. Firms that rely on internet connectivity must take urgent action in light of the events:</p>
<ul>
<li>The allocation last week of two further /8s (blocks of IPv4 addresses with the same number before the first dot) to APNIC mean that for the first time, less than <a href="http://www.nro.net/media/less-than-10-percent-ipv4-addresses-remain-unallocated.html" onclick="javascript:urchinTracker ('/outbound/article/www.nro.net');">just ten percent of the IPv4 unallocated pool is available </a>to be assigned.  At current utilisation rates, this pool will be exhausted in only 600 days.  Of course, the internet could stop growing, but all signs point away from this&#8230;</li>
<li>The allocation of 1.0.0.0/8 is the assignment of the first really &#8216;dirty&#8217; block of addresses, signalling that we really are in the run-down period.  Bad network design decisions in the past have meant that networks have &#8216;borrowed&#8217; the use of addresses starting 1. for &#8216;internal use only&#8217; or special applications on their network.  This means that organisations assigned address space starting &#8217;1&#8242; may well have partial connectivity even though they are rightfully assigned the space.  Examples are the <a href="http://www.zapzone.com.my/faq.php#u7" onclick="javascript:urchinTracker ('/outbound/article/www.zapzone.com.my');">braindead hotspot operators who take addresses like 1.1.1.1 </a>to trigger hotspot logout, but a handful of examples appear across this address range.</li>
<li>RIPE NCC, the organisation who assign addresses to networks in and around Europe have this month implemented their &#8216;run down&#8217; policy which will mean that organisations requesting space will only be able to cater for their <a href="http://www.ripe.net/ripe/policies/proposals/2009-03.html" onclick="javascript:urchinTracker ('/outbound/article/www.ripe.net');">growth requirements for a very short amount of time</a>.  This is to evenly spread the inevitable misery across the ISP community.</li>
</ul>
<p>RIPE members should thoroughly audit their address space so that they can ensure that their records are accurate, because RIPE are more likely to ensure that address space is assigned to your end users in line with the community&#8217;s policies.  ISPs and services providers who need help can contact me for further information or specific assistance.</p>
<p>Organisations who rely on internet connectivity for their products should ensure their providers have an IPv6 migration plan in place.  Otherwise end-to-end connectivity for your home or office is unlikely to be something you can enjoy looking beyond the runout period.  Companies hosting network services, for example a website, should enquire what their host&#8217;s IPv6 plans are, and start to enable their services via v6.</p>
<p>There is real traction to ensure v6 support appears in both the hardware and services you need to connect to the internet.  It is easier today than before to find help making your services available via v6.  The alternatives &#8211; patchy connectivity via nested stacks of ipv4 islands, or no more end-to-end connectivity (so that your internet service is a walled garden), have much worse consequencies than learning to roll v6.</p>
<p>Engineers know the facts by now and have no excuse.  For more information, see the RIPE NCC&#8217;s information site, <a href="http://www.ipv6actnow.org/" onclick="javascript:urchinTracker ('/outbound/article/www.ipv6actnow.org');">ipv6actnow</a>.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/2010-will-be-a-bad-year-for-ipv4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IXP Bake Off Results</title>
		<link>http://www.andyd.net/2010/ixp-bake-off-results/</link>
		<comments>http://www.andyd.net/2010/ixp-bake-off-results/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 19:08:41 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=173</guid>
		<description><![CDATA[<p>Here are some slides that present some <a href="http://www.uknof.org.uk/uknof15/Davidson-Bakeoff.pdf" onclick="javascript:urchinTracker ('/outbound/article/www.uknof.org.uk');">research undertaken by a number of European Internet Exchange points (IXPs)</a>, which I presented at UKNOF15 last week.  They may be of interest to networks which connect to IXPs who have been considering connecting to the local multi-lateral peering (MLP) service, but are unsure whether testing has proved that the functionality and performance of the new &#8216;next-generation&#8217; offerings (namely BIRD and OpenBGPd) are fit for purpose.</p>
<p>The slides show that the new route-servers perform splendidly well compared with traditional Quagga based MLPs, also that route-servers are now free of &#8216;first generation code&#8217; bugs, and also that they handle your prefixes transparently &#8211; as you would expect.</p>
<p>Interestingly, BIRD and OpenBGPd behave identically &#8216;on the wire&#8217; so IXPs are encouraged to use multi-vendor MLP on their platform for increased reliability and stability.  The new breed of route-server code is dependable and tested, so networks that would like to connect should draw confidence from this testing, and IXPs wishing to roll out MLP services should feel confident in the software tested.</p>
<p>Happy peering!</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2010/ixp-bake-off-results/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DNSSEC and SSL certificates</title>
		<link>http://www.andyd.net/2009/dnssec-and-ssl-certificates/</link>
		<comments>http://www.andyd.net/2009/dnssec-and-ssl-certificates/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 11:48:45 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Sys Admin]]></category>
		<category><![CDATA[The 'net]]></category>
		<category><![CDATA[domains]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=169</guid>
		<description><![CDATA[<p>Dr. Jörg Schweiger of the German domain name registry DENIC posed an interesting question at this morning&#8217;s first <a href="http://www.denog.de/"title="Deutsche Network Operators Group"  onclick="javascript:urchinTracker ('/outbound/article/www.denog.de');">DENOG </a>meeting, in Frankfurt.</p>
<p>Would domain name users who are concerned about the accuracy of data served pay extra for the ability to sign their DNS zone ?  A handful of people in the room raised their hand in agreement, but the overwhelming majority of operators did not.</p>
<p>His argument was that this compared well with SSL certification authorities who sell certificates that suggest that visitors to a website are interacting with a validated entity, and the technology guarantees privacy between the visitor and the website.  It&#8217;s this technology which makes buying and selling online safe.</p>
<p>However, I think that DNSSEC has different aims altogether &#8211; simply to guarantee that DNS data is not changed en-route between the authoratative server, through the caches, all the way to users.  Therefore there are significant attack mitigation reasons to deploy DNSSEC, so I hope that operators will begin trials (we are doing so), and that the pace of trials will quicken as <a href="http://www.ripe.net/ripe/meetings/ripe-59/presentations/abley-dnssec-root-zone.pdf" onclick="javascript:urchinTracker ('/outbound/article/www.ripe.net');">the root zone will be signed this year</a>.</p>
<p>If DNSSEC is deployed as designed, then temporary and brief mistakes will not be imported into DNS caches, users will not fall foul to tampered data in caches, and we all receive an authenticated/secure channel for distributing DNS data inside an organisation.</p>
<p>The argument that Dr. Schweiger used is that DNSSEC adds an operational and technical burden to registries (extra communication with registrars, more complex software, additional CPU and bandwidth requirements).</p>
<p>I hope that my colleagues in other organisations agree that there are significant infrastructure advantages to freely allowing DNSSEC to grow, and that Moore&#8217;s Law, automation, and the fact that DNS registries normally find it simple to peer widely with ISP networks will offset the needs to consider the commercial signing model.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2009/dnssec-and-ssl-certificates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPv6 Track at NANOG</title>
		<link>http://www.andyd.net/2009/ipv6-track-at-nanog/</link>
		<comments>http://www.andyd.net/2009/ipv6-track-at-nanog/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 16:16:45 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[The 'net]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[peering]]></category>
		<category><![CDATA[telecoms]]></category>

		<guid isPermaLink="false">http://www.andyd.net/?p=154</guid>
		<description><![CDATA[<p>Greetings from Philadelphia!  I am <a href="http://www.nanog.org/streaming.php" onclick="javascript:urchinTracker ('/outbound/article/www.nanog.org');">presenting as part of the IPv6 at NANOG46 (click here for info of how to watch)</a> at 9:30PM UK time today, or <a href="http://www.andyd.net/media/talks/v6-enterprise-black.pdf" >download the IPv6 for Enterprises presentation here</a>, or <a href="http://www.nanog.org/meetings/nanog46/abstracts.php?pt=MTM3NCZuYW5vZzQ2&amp;nm=nanog46" onclick="javascript:urchinTracker ('/outbound/article/www.nanog.org');">see information about the other speakers here</a>..</p>
<p>The messages are clear and simple.  Working now to get ready for the IPv6 transition will be less expensive and lower risk than waiting for IPv4 starvation to hurt.  I interviewed some key enterprises about their specific grumbles but the great news is that most are transitional and already people are working on fixing them.</p>
<p></p>
<p></p>
]]></description>
		<wfw:commentRss>http://www.andyd.net/2009/ipv6-track-at-nanog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

