Cisco ISP Workshops Internet exchange point Design 222 (c) 2003, Cisco Systems, Inc. All rights reserved. LAN switch needs to be securely configured management routers require TACACS+ authentication, vty security. If non-transit and no value add services ISPs require AS, basic IXP does not.
Cisco ISP Workshops Internet exchange point Design 222 (c) 2003, Cisco Systems, Inc. All rights reserved. LAN switch needs to be securely configured management routers require TACACS+ authentication, vty security. If non-transit and no value add services ISPs require AS, basic IXP does not.
Cisco ISP Workshops Internet exchange point Design 222 (c) 2003, Cisco Systems, Inc. All rights reserved. LAN switch needs to be securely configured management routers require TACACS+ authentication, vty security. If non-transit and no value add services ISPs require AS, basic IXP does not.
Cisco ISP Workshops Internet exchange point Design 222 (c) 2003, Cisco Systems, Inc. All rights reserved. LAN switch needs to be securely configured management routers require TACACS+ authentication, vty security. If non-transit and no value add services ISPs require AS, basic IXP does not.
Internet Exchange Point Design ISP/IXP Workshops ISP/IXP Workshops 222 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops IXP Design Layer 2 Exchange Point Layer 3 Exchange Point Transit Exchange Point Design Considerations 333 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Internet Exchange Points Layer 2 exchange point ethernet, ATM or Frame Relay switch Layer 3 exchange point router based central or distributed 4 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 Exchange The traditional IXP 555 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 Exchange ISP 1 ISP 2 ISP 3 IXP Management Network ISP 6 ISP 5 ISP 4 Ethernet Switch IXP Services: TLD DNS, Routing Registry Looking Glass, news, etc 666 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 Exchange ISP 1 ISP 2 ISP 3 IXP Management Network ISP 6 ISP 5 ISP 4 Ethernet Switches IXP Services: TLD DNS, Routing Registry Looking Glass, news, etc 777 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 Exchange Two switches for redundancy ISPs use dual routers for redundancy or loadsharing Offer services for the common good Internet portals and search engines DNS TLD, News, NTP servers Routing Registry and Looking Glass 888 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 Exchange Requires neutral IXP management usually funded equally by IXP participants 24x7 cover, support, value add services Secure and neutral location Configuration private address space if non-transit and no value add services ISPs require AS, basic IXP does not 999 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 Exchange Network Security Considerations LAN switch needs to be securely configured Management routers require TACACS+ authentication, vty security IXP services must be behind router(s) with strong filters 10 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 3 Exchange The wholesale transit ISP 11 11 11 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 3 Exchange ISP 1 ISP 2 ISP 3 IXP Management Network ISP 6 ISP 5 ISP 4 IXP Router IXP Services: TLD DNS, Routing Registry Looking Glass, news, etc 12 12 12 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 3 Exchange ISP 1 ISP 2 ISP 3 IXP Management Network ISP 6 ISP 5 ISP 4 IXP Routers IXP Services: TLD DNS, Routing Registry Looking Glass, news, etc 13 13 13 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 3 Exchange Two routers for redundancy ISPs use dual routers for redundancy or loadsharing Offer services for the common good Internet portals and search engines DNS TLD, News, NTP servers Routing Registry and Looking Glass 14 14 14 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 3 Exchange Requires neutral IXP management usually funded equally by IXP participants 24x7 cover, support, value add services BGP configuration skills essential Secure and neutral location Configuration private address space if non-transit and no value add services ISPs and IXP require AS 15 15 15 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 3 Exchange Network Security Considerations Core IXP router(s) require strong security, preferably with BGP neighbour authentication Management routers require TACACS+ authentication, vty security IXP services must be behind router(s) with strong filters 16 16 16 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 versus Layer 3 Layer 3 IXP team requires good BGP knowledge Rely on 3rd party for BGP configuration Less freedom on who peers with whom Could potentially compete with IXP membership Easier to distribute over wide area 17 17 17 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 2 versus Layer 3 Layer 2 IXP team does not need routing knowledge Easy to get started More complicated to distribute over wide area ISPs free to set up peering agreements with each other as they wish 18 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Transit Exchanges 19 19 19 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Transit IXPs Provides local Internet exchange facility to members Also provides transit to Internet or upstream ISP Usually operated as a commercial service Usually layer 3 design 20 20 20 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Layer 3 Transit Exchange ISP 1 ISP 2 ISP 3 IXP Management Network ISP 5 ISP 4 Transit Routers IXP Routers IXP Services: TLD DNS, Routing Registry Looking Glass, news, etc Internet ISP 21 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops IXP Design Considerations 22 22 22 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Routing and Address Space ISP border routers should not be configured with default route or carry full Internet routing table Use private addresses if possible public address space means IXP network could be leaked to Internet which may be undesirable 23 23 23 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Hardware Dont mix port speeds if 10Mbps and 100Mbps connections available, terminate on different switches (L2 IXP) Dont mix transports if terminating ATM PVCs and G/F/Ethernet, terminate on different devices Insist that IXP participants bring their own router moves buffering problem off the IXP security is responsibility of the ISP, not the IXP 24 24 24 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Services Offered Services offered should not compete with member ISPs (basic IXP) e.g. web hosting at an IXP is a bad idea unless all members agree to it IXP operations should make performance and throughput statistics available to members 25 25 25 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Services to Offer TLD DNS the country IXP could host the countrys top level DNS e.g. UK. TLD is hosted at LINX in London Usenet News Usenet News is high volume could save bandwidth to all IXP members 26 26 26 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Services to Offer Route Collector All IXP members peer with the route collector Route collector shows the reachability information available at the exchange Requires a simple router with large memory Looking Glass one way of making the Route Collector routes available for global view public or members only access 27 27 27 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Services to Offer Route Server Reduces admin burden on IXP member routers only BGP session is with Route Server Route Server supplies all paths it knows to the IXP member routers no best path selection Can use private AS Route Server software does not prepend its AS to the AS path RSd (from Merit Network) commonly used 28 28 28 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Services to Offer Network Time Protocol Locate a stratum 1 time source (GPS receiver, atomic clock, etc) at IXP Multicast Provide MBONE and other multicast services for the common good 29 29 29 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Services to Offer Routing Registry Routing Registry is used to register the routing policy of the IXP membership documenting peering relationships auto-configuring of peer routers Alternative is to use the public Internet Routing Registry (IRR) 30 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops IXP Design Summary 31 31 31 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Summary L2 IXP most commonly deployed typically based around ethernet or ATM switches L3 IXP nowadays generally a marketing concept used by wholesale ISPs doesnt offer the same flexibility as L2 32 2003, Cisco Systems, Inc. All rights reserved. Cisco ISP Workshops Internet Exchange Point Design ISP/IXP Workshops ISP/IXP Workshops