Beruflich Dokumente
Kultur Dokumente
ISP/IXP Workshops
ISP Workshops
ISP Workshops
ISP Workshops
PoP Topologies
! Core routers high speed trunk connections ! Distribution routers and Access routers high port density ! Border routers connections to other providers ! Service routers hosting and servers ! Some functions might be handled by a single router
ISP Workshops
PoP Design
! Modular Design ! Aggregation Services separated according to
connection speed customer service contention ratio security considerations
ISP Workshops
ISP Workshops
ISP Workshops
ISP Workshops
ISP Workshops
PoP Modules
! Low Speed customer connections
PSTN/ISDN dialup Low bandwidth needs Low revenue, large numbers
ISP Workshops
10
PoP Modules
! Broad Band customer connections
xDSL, Cable and Wireless High bandwidth needs Low revenue, large numbers
ISP Workshops
11
PoP Modules
! PoP Core
Two dedicated routers High Speed interconnect Backbone Links ONLY Do not touch them!
! Border Network
Dedicated border router to other ISPs The ISPs front door Transparent web caching? Two in backbone is minimum guarantee for redundancy
ISP Workshops
12
PoP Modules
! ISP Services
DNS (cache, secondary) News (still relevant?) Mail (POP3, Relay, Anti-virus/anti-spam) WWW (server, proxy, cache)
! Hosted Services/DataCentres
Virtual Web, WWW (server, proxy, cache) Information/Content Services Electronic Commerce
ISP Workshops
13
PoP Modules
! Network Operations Centre
Consider primary and backup locations Network monitoring Statistics and log gathering Direct but secure access
ISP Workshops
14
Web Cache AS5400 Primary Rate T1/E1 2811 To Core Routers 2800/3800 PSTN lines to built-in modems
15
To Core Routers
ISP Workshops
16
Channelised T3/E3
To Core Routers
Channelised OC3/OC12
ISP Workshops
17
IP, ATM
To Core Routers
18
WWW cache
Mail Relay
NEWS
DNS cache
ISP Workshops
19
ISP Workshops
20
Border Module
ISP1
ISP2
To core routers
ISP Workshops
21
NOC Module
To core routers Out of Band Management Network Hosted Network Gateway Routers
2811/32async
ISP Workshops
22
2811/32async To the NOC NetFlow enabled NetFlow Collector Out of Band Ethernet routers
ISP Workshops
23
ISP Workshops
24
Backbone Design
! Routed Backbone ! Switched Backbone
Virtually obsolete
! Point-to-point circuits
nx64K, T1/E1, T3/E3, OC3, OC12, GigE, OC48, 10GigE, OC192
ISP Workshops
25
! ISP essential services distributed around backbone ! NOC and backup NOC ! Redundant backbone links
ISP Workshops
26
Customer connections
Customer connections
ISP Services
External connections
Operations Centre
External connections
27
ISP Workshops
Backbone Links
! ATM/Frame Relay
Virtually disappeared due to overhead, extra equipment, and shared with other customers of the telco MPLS has replaced ATM & FR as the telco favourite
! Leased Line/Circuit
Most popular with backbone providers IP over Optics and Metro Ethernet very common in many parts of the world
ISP Workshops
28
ISP Workshops
29
POP Two
POP Three
POP One
Alternative/Backup Path
ISP Workshops
30
! Think big
More redundancy Less impact of upgrades Less impact of failures
ISP Workshops
31
POP Two
Metropolitan Links
POP Three
POP One
Metropolitan Links
32
ISP Services
ISP Workshops
33
ISP Services
! Most ISP services such as DNS, Mail, etc are easily deliverable on low budget hardware platforms
Single Rack Unit in height (1RU) Dual processor is default now RAM is very cheap (may as well use 2Gbytes or more) Hard drives are very cheap (SCSI more reliable) Unix like operating systems (FreeBSD, Debian, Ubuntu, CentOS) are very common In addition to commercial operating systems such as Solaris, RedHat Enterprise Linux &c Minimal overhead, minimal OS install, plus the service required
ISP Workshops
34
ISP Workshops
35
ISP Workshops
36
ISP Workshops
37
10800 10800 10800 10800 10800 10800 10800 10800 3600 3600 3600 10800 3600 3600 113685 10800
NS NS NS NS NS NS NS NS A A A A A A A A
ns1.apnic.net. ns3.apnic.net. ns4.apnic.net. ns5.apnic.com. cumin.apnic.net. ns-sec.ripe.net. tinnie.arin.net. tinnie.apnic.net. 202.12.29.25 202.12.28.131 202.12.31.140 203.119.43.200 202.12.29.59 202.12.29.60 193.0.0.196 199.212.0.53
Zone secondaried by RIPE NCC in Amsterdam ARIN in Washington Geographical and service provider redundancy this is the perfect example!
ISP Workshops 2010 Cisco Systems, Inc. All rights reserved.
39
ISP Workshops
40
DIAL network
To Core Routers
Radius proxy
! DIAL users automatically given the IP addresses of DNS caches when they dial in
ISP Workshops 2010 Cisco Systems, Inc. All rights reserved.
41
ISP Workshops
42
ISP Workshops
43
ISP Workshops
44
ISP Workshops
45
46
SpamAssassin ClamAV
mail.isp.net ISP Mail Gateway
SpamAssassin ClamAV
ISP Workshops
47
MX MX MX MX MX MX MX MX MX
10 10 10 10 10 10 15 20 25
49
ISP Workshops
50
Customer connections
Customer connections
POP Three
POP One
News Feeder
News Feeder
External connections
External connections
51
ISP Workshops
Customer connections
Customer connections
POP Three
POP One
News Feeder
News Feeder
External connections
External connections
52
ISP Workshops
IMPORTANT: Do NOT allow non-customers to use your news system for posting messages
ISP Workshops 2010 Cisco Systems, Inc. All rights reserved.
53
Addressing
ISP Workshops
54
! North America
ARIN http://www.arin.net
ISP Workshops
55
ISP Workshops
56
! Become a member of your Regional Internet Registry and get your own allocation
Require a plan for a year ahead General policies are outlined in RFC2050, more specific details are on the individual RIR website
ISP Workshops
57
58
59
60
ISP Workshops
61
ISP Workshops
62
Customer assignments
Infrastructure Loopbacks
! Phase Two
223.10.0.0/20
223.10.0.1 223.10.5.255 /24 /24 223.10.15.255
Original assignments
ISP Workshops 2010 Cisco Systems, Inc. All rights reserved.
New Assignments
63
ISP Workshops
64
ISP Workshops
65
Routing Protocols
ISP Workshops
66
Routing Protocols
! IGP Interior Gateway Protocol
carries infrastructure addresses, point-to-point links examples are OSPF, ISIS, EIGRP...
ISP Workshops
67
ISP Workshops
68
! Policy
Control reachability to prefixes Merge separate organizations Connect multiple IGPs
ISP Workshops
69
! Exterior
Specifically configured peers Connecting with outside networks Set administrative boundaries Binds ASs together
ISP Workshops
70
! Exterior
Carries customer prefixes Carries Internet prefixes EGPs are independent of ISP network topology
ISP Workshops
71
BGP4 IXP
ISP Workshops 2010 Cisco Systems, Inc. All rights reserved.
Static/BGP4 Customers
72
ISP Workshops
73
! IGP details:
Should only have router loopbacks, backbone WAN point-topoint link addresses, and network addresses of any LANs having an IGP running on them Strongly recommended to use inter-router authentication Use inter-area summarisation if possible
ISP Workshops
74
Use contiguous addresses for backbone WAN links in each area then summarise into backbone area Dont summarise router loopback addresses as iBGP needs those (for next-hop) Use iBGP for carrying anything which does not contribute to the IGP Routing process
ISP Workshops
75
ISP Workshops
76
ISP Workshops
77
Security
ISP Workshops
78
Security
! ISP Infrastructure security ! ISP Network security ! Security is not optional! ! ISPs need to:
Protect themselves Help protect their customers from the Internet Protect the Internet from their customers
ISP Workshops
79
ISP Workshops
80
ISP Workshops
81
Mail Relay
NEWS
DNS cache
Web server
82
Outbound
ICMP Allow DNS udp/53 and tcp/53 Block all access to ISP address range
ISP Workshops
83
! Staff responsibility
Password policy, strangers, temp staff Employee exit procedures
! RFC2196
(Site Security Handbook)
! RFC3871
(Operational Security Requirements for Large ISP IP Network Infrastructure )
ISP Workshops 2010 Cisco Systems, Inc. All rights reserved.
84
! Effective filtering
Network borders see Cisco ISP Essentials Customer connections unicast RPF on ALL of them Network operation centre ISP corporate network behind firewall
ISP Workshops
85
ISP Workshops
86
Your customers should not be sending any IP packets out to the Internet with a source address other then the address you have allocated to them!
ISP Workshops
87
ISP Workshops
88
ISP Workshops
89
ISP Workshops
90
(Optional) Out of band WAN link to other PoPs Modem access to PSTN for out of band dialin
91
ISP Workshops
92
Test Laboratory
ISP Workshops
93
Test Laboratory
! Designed to look like a typical PoP
Operated like a typical PoP
! Used to trial new services or new software under realistic conditions ! Allows discovery and fixing of potential problems before they are introduced to the network
ISP Workshops
94
Test Laboratory
! Some ISPs dedicate equipment to the lab ! Other ISPs purchase ahead so that todays lab equipment becomes tomorrows PoP equipment ! Other ISPs use lab equipment for hot spares in the event of hardware failure
ISP Workshops
95
Test Laboratory
! Cant afford a test lab?
Set aside one spare router and server to trial new services Never ever try out new hardware, software or services on the live network
ISP Workshops
96
Operational Considerations
ISP Workshops
97
Operational Considerations
Why design the worlds best network when you have not thought about what operational good practices should be implemented?
ISP Workshops
98
ISP Workshops
99
ISP Workshops
100
ISP Workshops
101
Summary
ISP Workshops
102
ISP Workshops
103
ISP/IXP Workshops
ISP Workshops
104