Investigative Research for an IP Peering Service for NetherLight
Research Project 2 #100 Arnold Buntsma Mar Badias Simó Assessor: Cees de Laat Supervisors: Gerben van Malenstein Migiel de Vos Max Mudde
Investigative Research for an IP Peering Service for NetherLight - - PowerPoint PPT Presentation
Investigative Research for an IP Peering Service for NetherLight Assessor: Cees de Laat Supervisors: Research Project 2 #100 Gerben van Malenstein Arnold Buntsma Migiel de Vos Mar Badias Sim Max Mudde NetherLight: open lightpath
Research Project 2 #100 Arnold Buntsma Mar Badias Simó Assessor: Cees de Laat Supervisors: Gerben van Malenstein Migiel de Vos Max Mudde
CREDITS: This presentation template was created by Slidesgo, including icons by Flaticon, and infographics & images by Freepik.
connections for ~70 clients
education networks and service providers that want to connect among them
2
3
How can NetherLight facilitate a state-of-the-art peering service which is flexible, secure, manageable and has a uniform setup?
4
5
○ Uniform ○ Spoofing & Hijacking ○ Hundreds of clients
6
7
Route Server Security IP Space
8
○ BGP sessions
○ Uniform peering relations ○ Ability to block prefixes
○ Filtered Routes ○ RPKI validation
interface
² https:/ /www.manrs.org/ixps/
9
CREDITS: This presentation template was created by Slidesgo, including icons by Flaticon, and infographics & images by Freepik.
10
Automation tools ○ Cisco NSO
○ SNMP ○ sFlow
11
12
13
14
15
https://github.com/Reseach-Project-2/testfaucet
16
Monitoring
sFlow or Gauge+Faucet
Management
Adapting IXP Manager or developing a new tool
Scalability
Theoretically, highly scalable
17
18
The client provides:
➔ Off-boarding procedure is more simple :) NL Provides:
19
20
Scalable: At least hundreds of clients. No hard limit. Management: Clients use the service in a uniform way. Configuration errors should be eliminated and minimal management effort needed from the NL team. Security: Clients unable to interfere with connections of other clients by for example MAC/IP spoofing and BGP hijacking.
To date, NetherLight can best create a peering service by adopting the first solution (MPLS-EVPN). As a more advanced solution over time, NetherLight should consider implementing the second solution proposed (OpenFlow) because of less management efgort, fine-grained control
21
Discussion & Conclusion
22
○ OpenFlow scalability research in production
To date, NetherLight can best create a peering service by adopting the first solution (MPLS-EVPN). As a more advanced solution over time, NetherLight should consider implementing the second solution proposed (OpenFlow) because of less management efgort, fine-grained control of traffjc, and vendor independency.
23
○ BGP sessions
○ Uniform peering relations ○ Ability to block prefixes
○ Filtered Routes ○ RPKI validation
24
25