Professional Documents
Culture Documents
Service Providers
Philip Smith <pfs@cisco.com>
<pfs@cisco.com>
RIPE 40, Prague
AS 100
A C
AS 100 AS 101
B D
A C
DMZ
AS 100 Network AS 101
B D
AS 102
AS 100 AS 101
C
Router C in AS101
interface ethernet 1/0/0
ip address 222.222.10.1 255.255.255.240
router bgp 101
network 220.220.16.0 mask 255.255.240.0
neighbor 222.222.10.2 remote-as 100
neighbor 222.222.10.2 prefix-list RouterA in
neighbor 222.222.10.2 prefix-list RouterA out
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 11
Internal BGP (iBGP)
AS 100
D
A
B
• Topology independent E
• Each iBGP speaker must peer
with every other iBGP speaker
in the AS
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 13
Peering to Loop-Back Address
AS 100
Router B
interface loopback 0
ip address 215.10.7.2 255.255.255.255
router bgp 100
network 220.220.5.0
neighbor 215.10.7.1 remote-as 100
neighbor 215.10.7.1 update-source loopback0
neighbor 215.10.7.3 remote-as 100
neighbor 215.10.7.3 update-source loopback0
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 15
BGP Attributes
Recap
Presentation_ID
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 16
AS-Path
• Sequence of ASes a
AS 200 AS 100
route has traversed 170.10.0.0/16 180.10.0.0/16
150.10.1.1 150.10.1.2
iBGP C
AS 200
150.10.0.0/16 A B
eBGP AS 300
150.10.0.0/16 150.10.1.1
160.10.0.0/16 150.10.1.1
iBGP Loopback
C 220.1.254.3/32
Loopback B
220.1.254.2/32
AS 300
D
220.1.1.0/24 220.1.254.2
220.1.2.0/23 220.1.254.3
Next hop is ibgp router loopback address
Recursive route look-up
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 19
Third Party Next Hop
AS 200
192.68.1.0/24 150.1.1.3
C
150.1.1.1
• eBGP between Router A
and Router C
150.1.1.3
• eBGP between Router A
150.1.1.2 150.1.1.3
and Router B
A B • 192.68.1/24 prefix has next
AS 202
AS 201 hop address of 150.1.1.3 –
192.68.1.0/24
this is passed on to
Router C instead of
150.1.1.2
AS 100
160.10.0.0/16
AS 200 AS 300
D 500 800 E
A B
160.10.0.0/16 500
AS 400
> 160.10.0.0/16 800
C
• Local to an AS – non-transitive
Default local preference is 100
• Used to influence BGP path selection
determines best path for outbound
traffic
• Path with highest local preference
wins
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 25
Local Preference
• Configuration of Router B:
router bgp 400
neighbor 220.5.1.1 remote-as 300
neighbor 220.5.1.1 route-map local-pref in
!
route-map local-pref permit 10
match ip address prefix-list MATCH
set local-preference 800
!
ip prefix-list MATCH permit 160.10.0.0/16
AS 200
A B
192.68.1.0/24
AS 201
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 27
Multi-Exit Discriminator
• Inter-AS – non-transitive
• Used to convey the relative preference
of entry points
determines best path for inbound traffic
• Configuration of Router B:
router bgp 400
neighbor 220.5.1.1 remote-as 200
neighbor 220.5.1.1 route-map set-med out
!
route-map set-med permit 10
match ip address prefix-list MATCH
set metric 1000
!
ip prefix-list MATCH permit 192.68.1.0/24
ISP 2
160.10.0.0/16 300:1
X 170.10.0.0/16 300:1
200.10.0.0/16 AS 400
F
E
200.10.0.0/16 300:9
D ISP 1
AS 300
160.10.0.0/16 300:1 C 170.10.0.0/16 300:1
A B
AS 100 AS 200
160.10.0.0/16 170.10.0.0/16
• no-export
do not advertise to eBGP peers
• no-advertise
do not advertise to any peer
• local-AS
do not advertise outside local AS (only used
with confederations)
170.10.X.X D
A
170.10.0.0/16
AS 100 AS 200 G
B E
C F
• AS100 announces aggregate and subprefixes
aim is to improve loadsharing by leaking subprefixes
• Subprefixes marked with no-export community
• Router G in AS200 does not announce prefixes with no-
export community set
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 34
BGP Path Selection
Algorithm
Why is this the best path?
Presentation_ID
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 35
BGP Path Selection
Algorithm
• Do not consider path if no route to next
hop
• Do not consider iBGP path if not
synchronised (Cisco IOS)
• Highest weight (local to router)
• Highest local preference (global within
AS)
• Prefer locally originated route
• Shortest AS path
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 36
BGP Path Selection
Algorithm (continued)
• Lowest origin code
IGP < EGP < incomplete
• Lowest Multi-Exit Discriminator (MED)
If bgp deterministic-med, order the paths
before comparing
If bgp always-compare-med, then compare for
all paths
otherwise MED only considered if paths are
from the same AS (default)
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 37
BGP Path Selection
Algorithm (continued)
• Prefer eBGP path over iBGP path
• Path with lowest IGP metric to next-hop
• Lowest router-id (originator-id for reflected
routes)
• Shortest Cluster-List
Client must be aware of Route Reflector
attributes!
• Lowest neighbour IP address
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 38
Applying Policy with
BGP
Control!
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 39
Applying Policy with BGP
• Applying Policy
Decisions based on AS path, community or the
prefix
Rejecting/accepting selected routes
Set attributes to influence path selection
• Tools:
Prefix-list (filter prefixes)
Filter-list (filter ASes)
Route-maps and communities
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 40
Policy Control
Prefix List
• Filter routes based on prefix
• Inbound and Outbound
router bgp 200
neighbor 220.200.1.1 remote-as 210
neighbor 220.200.1.1 prefix-list PEER-IN in
neighbor 220.200.1.1 prefix-list PEER-OUT out
!
ip prefix-list PEER-IN deny 218.10.0.0/16
ip prefix-list PEER-IN permit 0.0.0.0/0 le 32
ip prefix-list PEER-OUT permit 215.7.0.0/16
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 41
Policy Control
Filter List
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 51
BGP Capabilities
• Documented in RFC2842
• Capabilities parameters passed in BGP
open message
• Unknown or unsupported capabilities
will result in NOTIFICATION message
• Current capabilities are:
0 Reserved [RFC2842]
1 Multiprotocol Extensions for BGP-4 [RFC2858]
2 Route Refresh Capability for BGP-4 [RFC2918]
3 Cooperative Route Filtering Capability []
4 Multiple routes to a destination capability [RFC3107]
64 Graceful Restart Capability []
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 52
BGP Capabilities Negotiation
192.168.100.0/24
BGP:
BGP: 192.168.100.2
192.168.100.2 open
open active,
active, local
local address
address 192.168.100.1
192.168.100.1
BGP:
BGP: 192.168.100.2
192.168.100.2 went
went from
from Active
Active to
to OpenSent
OpenSent
BGP:
BGP: 192.168.100.2
192.168.100.2 sending
sending OPEN,
OPEN, version
version 44
BGP:
BGP: 192.168.100.2
192.168.100.2 OPEN
OPEN rcvd,
rcvd, version
version 44
BGP:
BGP: 192.168.100.2
192.168.100.2 rcv
rcv OPEN
OPEN w/
w/ option
option parameter
parameter type:
type: 2,
2, len:
len: 66
BGP:
BGP: 192.168.100.2
192.168.100.2 OPEN
OPEN has
has CAPABILITY
CAPABILITY code:
code: 1,
1, length
length 44
BGP:
BGP: 192.168.100.2
192.168.100.2 OPEN
OPEN has
has MP_EXT
MP_EXT CAP
CAP for
for afi/safi:
afi/safi: 1/1
1/1
BGP:
BGP: 192.168.100.2
192.168.100.2 rcv
rcv OPEN
OPEN w/
w/ option
option parameter
parameter type:
type: 2,
2, len:
len: 66
BGP:
BGP: 192.168.100.2
192.168.100.2 OPEN
OPEN has
has CAPABILITY
CAPABILITY code:
code: 1,
1, length
length 44
BGP:
BGP: 192.168.100.2
192.168.100.2 OPEN
OPEN has
has MP_EXT
MP_EXT CAP
CAP for
for afi/safi:
afi/safi: 1/2
1/2
BGP:
BGP: 192.168.100.2
192.168.100.2 went
went from
from OpenSent
OpenSent toto OpenConfirm
OpenConfirm
BGP:
BGP: 192.168.100.2
192.168.100.2 went
went from
from OpenConfirm
OpenConfirm to to Established
Established
• Dynamic Reconfiguration
• Peer groups
• Route flap damping
• Route Reflectors & Confederations
Presentation_ID
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 58
Soft Reconfiguration
Problem:
• Hard BGP peer clear required after every
policy change because the router does
not store prefixes that are denied by a
filter
• Hard BGP peer clearing consumes CPU
and affects connectivity for all networks
Solution:
• Soft-reconfiguration
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 59
Soft Reconfiguration
discarded
peer normal BGP in
process accepted
soft “BGP in
table”
received BGP
received and used table
peer
BGP out
process
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 65
Peer Groups
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 70
Route Flap Damping
• Route flap
Going up and down of path or change in
attribute
BGP WITHDRAW followed by UPDATE = 1 flap
eBGP neighbour going down/up is NOT a flap
Ripples through the entire Internet
Wastes CPU
• Damping aims to reduce scope of route
flap propagation
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 71
Route Flap Damping
(Continued)
• Requirements
Fast convergence for normal route changes
History predicts future behaviour
Suppress oscillating routes
Advertise stable routes
• Documented in RFC2439
4000
Suppress limit
3000
Penalty
2000
Reuse limit
1000
0
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
Time
Variable damping
recommendations for ISPs
http://www.ripe.net/docs/ripe-210.html
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 76
Operation
• Examples - û
bgp dampening 30 750 3000 60
reuse-limit of 750 means maximum possible
penalty is 3000 – no prefixes suppressed as
penalty cannot exceed suppress-limit
• Examples - ü
bgp dampening 30 2000 3000 60
reuse-limit of 2000 means maximum possible
penalty is 8000 – suppress limit is easily reached
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 80
Scaling iBGP mesh
Two solutions
Route reflector – simpler to deploy and run
Confederation – more complex, corner case benefits
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 81
Route Reflector: Principle
Route Reflector
AS 100
B C
PoP3
AS 100
PoP1
PoP2
Cluster One
Cluster Two
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 87
Route Reflectors: Migration
AS 300
A
B C
AS 100
D
E G
F
AS 200
Sub-AS
65531
B
• Configuration (rtr B): Sub-AS
65532
router bgp 65532
bgp confederation identifier 200
bgp confederation peers 65530 65531
neighbor 141.153.12.1 remote-as 65530
neighbor 141.153.17.2 remote-as 65531
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 94
Route Propagation Decisions
• Same as with “normal” BGP:
From peer in same sub-AS → only to external
peers
From external peers → to all neighbors
• “External peers” refers to
Peers outside the confederation
Peers in a different sub-AS
Preserve LOCAL_PREF, MED and NEXT_HOP
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 95
Confederations (cont.)
• Example (cont.):
BGP table version is 78, local router ID is 141.153.17.1
Status codes: s suppressed, d damped, h history, * valid, >
best, i - internal
Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf Weight Path
*> 10.0.0.0 141.153.14.3 0 100 0 (65531) 1 i
*> 141.153.0.0 141.153.30.2 0 100 0 (65530) i
*> 144.10.0.0 141.153.12.1 0 100 0 (65530) i
*> 199.10.10.0 141.153.29.2 0 100 0 (65530) 1 i
Anywhere Medium
Confederations in the Yes Yes Medium
to High
Network
Route Anywhere
Reflectors in the Yes Yes Very High Very Low
Network
Most new service provider networks now deploy Route Reflectors from Day One
• DO NOT:
distribute BGP prefixes into an IGP
distribute IGP routes into BGP
use an IGP to carry customer prefixes
• YOUR NETWORK WILL NOT SCALE
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 106
Aggregation
• Configuration Example
router bgp 100
network 221.10.0.0 mask 255.255.224.0
neighbor 222.222.10.1 remote-as 101
neighbor 222.222.10.1 prefix-list out-filter out
!
ip route 221.10.0.0 255.255.224.0 null0
!
ip prefix-list out-filter permit 221.10.0.0/19
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 112
Receiving Prefixes from
downstream peers
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 120
Injecting prefixes into iBGP
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 127
iBGP and IGPs
• BGP customers
Offer max 3 types of feeds (easier than
custom configuration per peer)
Use communities
• Static customers
Use communities
• Differentiate between different types of
prefixes
Makes eBGP filtering easy
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 135
BGP Customer Aggregation
Guidelines
• Define at least three peer groups:
cust-default—send default route only
cust-cust—send customer routes only
cust-full —send full Internet routes
• Identify routes via communities e.g.
100:4100=customers; 100:4500=peers
• Apply passwords per neighbour
• Apply inbound & outbound prefix-list per
neighbour
RIPE 40 www.cisco.com
© 2001, Cisco Systems, Inc. 136
BGP Customer Aggregation
Your AS CORE
CIDR Block: 10.0.0.0/8
Route Reflector
Aggregation Router
(RR Client)
Client Peer Group
AS 100
B A
A
• Router A has a process ID of 100 .1
6.0.1.1 6.0.1.2
AS 1 FF
AS 2
2.0.0.0/8 D E 6.0.0.0/8
AS 2
D $$$$$ The Internet
C
5.1.1.1 Peering NAP
$
5.1.1.2 5.1.1.3
eBGP
B A
Router A points static
AS 1 default to Router C and all
AS 3
outbound traffic goes over
AS2’s uplink!
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 151
Troubleshooting –
Examples
• Missing routes
• Route Oscillation
• Routing Loops
• Troubleshooting hints
R3
R1
R2
AS 3
AS 4
AS 12
• Watch for:
table version number incrementing rapidly
number of networks/paths or external/internal
routes changing.
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 157
Route Oscillation –
Troubleshooting
Pick up a bgp route from the RIB that is less than a minute
old and watch what happens with the routing/bgp table …
R3#show ip route 156.1.0.0
Routing entry for 156.1.0.0/16
Known via "bgp 3", distance 200, metric 0
Routing Descriptor Blocks:
* 1.1.1.1, from 1.1.1.1, 00:00:53 ago
Route metric is 0, traffic share count is 1
AS Hops 2, BGP network version 474
R3#
BGP: scanning routing tables
BGP: ip nettable_walker 142.108.0.0/16 calling revise_route
RT: del 142.108.0.0 via 1.1.1.1, bgp metric [200/0]
BGP: revise route installing 142.108.0.0/16 -> 142.108.10.2
RT: add 142.108.0.0/16 via 142.108.10.2, bgp metric [200/0]
BGP: nettable_walker 156.1.0.0/16 calling revise_route
RT: del 156.1.0.0 via 1.1.1.1, bgp metric [200/0]
BGP: revise route installing 156.1.0.0/16 -> 142.108.10.2
RT: add 156.1.0.0/16 via 142.108.10.2, bgp metric [200/0]
RouterA
AS 2
AS 1
• Initial State
Path 1 beats Path 2 – Lower MED
RIPE 40
Path 3 beats Path 1 – Lower Router-ID
www.cisco.com 167
© 2001, Cisco Systems, Inc.
Inconsistent Route Selection
RouterA#sh ip bgp 10.0.0.0
BGP routing table entry for 10.0.0.0/8, version 40
Paths: (3 available, best #3, advertised over IBGP, EBGP)
1 10
1.1.1.1 from 1.1.1.1
Origin IGP, metric 0, localpref 100, valid, internal
3 10
2.2.2.2 from 2.2.2.2
Origin IGP, metric 20, localpref 100, valid, internal
3 10
3.3.3.3 from 3.3.3.3
Origin IGP, metric 30, valid, external, best
RIPE 40
maximum-paths 6
© 2001, Cisco Systems, Inc. www.cisco.com 177
Routing Loop – Solution
• “maximum-paths” tells the router to reset the
NEXT_HOP to himself
R3 sets NEXT_HOP to 3.3.3.3
• Forces traffic to come to him so he can load-
balance
• Is typically used for multiple eBGP sessions to an
AS
Be careful when using in Confederations!!
• Need to make R2 prefer the path from R1 to prevent
the routing loop
Make IGP metric to 1.1.1.1 better than IGP metric to 4.4.4.4
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 178
Troubleshooting Tips
• Basic Assumptions
MUST announce assigned address block to
Internet
MAY also announce subprefixes –
reachability is not guaranteed
RIR minimum allocation is /20
several ISPs filter RIR blocks on this boundary
called “Net Police” by some
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 192
Multihoming Scenarios
• Stub network
• Multi-homed stub network
• Multi-homed network
• Configuration Options
AS101
AS100
AS65530
AS100
AS100
193.1.34.0/24 65003
corporate network B
193.2.35.0/24
with several A
regions and
connections to the 193.1.32.0/22 1880
E B
D
Link two
C
A1 AS 65534
AS 109 B1
E D A2 AS 65534
B2
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 216
Two links to different ISPs
(with redundancy)
• Announce /19 aggregate on each link
• Split /19 and announce as two /20s,
one on each link
basic inbound loadsharing
• When one link fails, the announcement
of the /19 aggregate via the other ISP
ensures continued connectivity
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 217
Two links to different ISPs
(with redundancy)
Internet
A
AS 109 AS 108
C D
AS 107
AS 109 AS 108
C D
AS 107
• Router A Configuration
router bgp 107
network 221.10.0.0 mask 255.255.224.0
neighbor 222.222.10.1 remote-as 109
neighbor 222.222.10.1 prefix-list default in
neighbor 222.222.10.1 prefix-list aggregate out
!
ip prefix-list aggregate permit 221.10.0.0/19
• Router B Configuration
router bgp 107
network 221.10.0.0 mask 255.255.224.0
network 221.10.16.0 mask 255.255.240.0
neighbor 220.1.5.1 remote-as 108
neighbor 220.1.5.1 prefix-list default in
neighbor 220.1.5.1 prefix-list subblocks out
neighbor 220.1.5.1 route-map routerD out
!
..next slide..
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 227
Service Provider
Multihoming
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 231
One Upstream, One Local
Peer
C
Local Peer
AS108
A
AS 109
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 238
One Upstream, Local
Exchange Point
• Announce /19 aggregate to every
neighbouring AS
• Accept default route only from
upstream
Either 0.0.0.0/0 or a network which can
be used as default
• Accept all routes from IXP peers
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 239
One Upstream, Local
Exchange Point
Upstream ISP
AS107
IXP
C
A
AS 109
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 246
Two Upstreams
Upstreams,, One Local
Peer
Upstream ISP
AS107 Upstream ISP
AS106
C
Local Peer
AS108 D
A
AS 109
• Router A
Same routing configuration as in
example with one upstream and one
local peer
Same hardware configuration
• Router D Configuration
router bgp 109
network 221.10.0.0 mask 255.255.224.0
neighbor 222.222.10.5 remote-as 106
neighbor 222.222.10.5 prefix-list rfc1918-deny in
neighbor 222.222.10.5 prefix-list my-block out
!
ip prefix-list my-block permit 221.10.0.0/19
! See earlier in presentation for RFC1918 list
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 270
Two Upstreams
Upstreams,, One
Regional and One Local Peer
• Announce /19 aggregate on each link
• Accept default route only from
upstreams
Either 0.0.0.0/0 or a network which can
be used as default
• Accept all routes from local peer
• Accept all routes from regional peer
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 271
Two Upstreams, One
Regional and One Local Peer
Upstream ISP
AS107 Upstream ISP
Regional Peer
AS110 AS106
C
Local Peer B
AS108 D
A
AS 109
• Router A
Same routing configuration as in
previous examples
Same hardware configuration
• Configuration of Router B
Take local AS from the regional peer
Also take regional peer’s customer and
other ASes they give
Local and regional traffic stays in the
region
The two upstreams use similar
configuration to previously, loadsharing as
required.
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 275
Service Provider
Multihoming
Two US upstreams, two regional
upstreams, and local peers
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 276
US and Regional Upstreams
Upstreams,,
Local Peers
• Announce /19 aggregate on each link
• Accept partial/default routes from upstreams
For default, use 0.0.0.0/0 or a network which can be
used as default
• Accept all routes from local peer
• Accept all partial routes from regional
upstreams
• This is more complex, but a very typical
scenario
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 277
US and Regional Upstreams,
Local Peers
Upstream ISP
AS107 Upstream ISP
Regional Upstream
AS110 AS106
C
Local Peer B
AS108 D
A
AS 109
Regional Upstream
F E
Local Peers AS111
IXP
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 288
Disconnected Backbone
IXP
City One
D
IXP
City Two
Upstream C Upstream
IXP
AS108 City Three AS110
City Four
IXP
A
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 296
IDC Multihoming
• IDCs typically are not registry members so
don’t get their own address block
Situation also true for small ISPs and
“Enterprise Networks”
• Smaller address blocks being announced
Address space comes from both upstreams
Should be apportioned according to size of
circuit to upstream
• Outbound traffic paths matter
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 297
Two Upstreams, Two Local
Peers – IDC
Upstream ISP
AS107 Upstream ISP
Local Peer
AS106
AS110 C
Local Peer B
AS108 AS 109 D
A
IDC core
• Router C configuration
In: Accept partial routes from AS107
e.g. ^107_[0-9]+$
In: Ask for a route to use as default
set local preference on default to 80
Out: Send /24, and send /23 with AS-PATH
prepend of one AS
• Router D configuration
In: Ask for a route to use as default
Leave local preference of default at 100
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 305
Why Overseas Collocation?
• Common Scenario:
AS107 has collocate space in the US
AS108 and AS109 are transit
providers for AS107
AS107 is also present at the local
exchange point for regional peers
H AS107
Transoceanic
link to domestic A AS112
F
network G
B
C D
AS108
AS110
AS109
Transit Providers
• AS107
Router A is dedicated to peering at local
IXP
Router G is dedicated to links with the
transit providers
Router H is dedicated to the transoceanic
link
RIPE 40
..next slide
© 2001, Cisco Systems, Inc. www.cisco.com 318
Collocation
Router G Configuration
router bgp 107
neighbor ibgp peer-group
neighbor ibgp remote-as 107
neighbor ibgp update-source loopback 0
neighbor 221.0.0.1 peer-group ibgp
neighbor 221.0.0.1 description Router A - US Local IXP
neighbor 221.0.0.1 prefix-list myprefixes out
neighbor 221.0.0.3 peer-group ibgp
neighbor 221.0.0.3 description Router H - transoceanic router
neighbor 221.0.0.4 peer-group ibgp
neighbor 221.0.0.4 description Router at HQ
..next slide
RIPE 40 © 1999,
2000, Cisco Systems, Inc. www.cisco.com 327
Case Study
Requirements (1)
• ISP wants:
Symmetric routing and equal link utilisation
in and out (as close as possible)
international circuits are expensive
Has two 2600 border routers with 64Mbytes
memory
Cannot afford to upgrade memory or hardware on
border routers or internal routers
• “Philip, make it work, please”
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 329
Case Study
Upstream ISP
Upstream ISP
AS5400
AS2516
A B
AS 17660
ISP Core
• Refinement
Did not need any
First cut worked, seeing on average
600kbps inbound on each circuit
Does vary according to time of day, but this
is as balanced as it can get, given customer
profile
J
!
prefix-list default-route permit 0.0.0.0/0
prefix-list out-filter permit 202.144.128.0/19
!
ip as-path access-list 2 permit _2516$
ip as-path access-list 2 deny .*
ip as-path access-list 3 permit ^$
!
route-map as2516-out permit 10
set as-path prepend 17660
!
Router A to AS5400
Router B to AS2516
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 343
Case Study Summary
• RFC1998
• Examples of SP applications
• Informational RFC
• Describes how to implement loadsharing and
backup on multiple inter-AS links
BGP communities used to determine local preference in
upstream’s network
• Gives control to the customer
• Simplifies upstream’s configuration
simplifies network operation!
• Supporting RFC1998
many ISPs do, more should
check AS object in the Internet
Routing Registry
if you do, insert comment in AS object
in the IRR
RIPE 40 © 2001,
2000, Cisco Systems, Inc. www.cisco.com 354
Two links to the same ISP
primary
C
A
AS 109 AS 65534
E B
D
backup
RIPE 40 © 2001,
2000, Cisco Systems, Inc. www.cisco.com 363
Background
AS110
AS 109 AS 108
C D
AS 107
A B
• 109:122
traffic in AS109 comes directly to you
traffic in AS110 sent to AS109 rather than
best path
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 366
Examples
AS110
AS 109 AS 108
C D
AS 107
A B
• 109:121
traffic in AS109 comes directly to you
traffic in AS110 sent to AS108 rather than
best path
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 367
Examples
• 109:3
prepend any announcements to peers of
AS109 with 109_109_109
“AS109 is my backup transit AS”
• 109:20
Don’t announce outside upstream’s
customer base
“AS109 provides local connections only”
109:21 is very similar
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 368
Service Providers use
of Communities
Some working examples
RIPE 40 © 2001,
2000, Cisco Systems, Inc. www.cisco.com 369
Some ISP Examples
• ISPs create communities to give
customers bigger routing policy control
• Public policy is usually listed in the IRR
Following examples are all in the IRR
• Consider creating communities to give
policy control to customers
Reduces technical support burden
Reduces the amount of router
reconfiguration, and the chance of
mistakes
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 370
Some ISP Examples
Connect.com.au
aut-num: AS2764
as-name: ASN-CONNECT-NET
descr: connect.com.au pty ltd
admin-c: CC89
tech-c: MP151
remarks: Community Definition
remarks: ------------------------------------------------
remarks: 2764:1 Announce to "domestic" rate ASes only
remarks: 2764:2 Don't announce outside local POP
remarks: 2764:3 Lower local preference by 25
remarks: 2764:4 Lower local preference by 15
remarks: 2764:5 Lower local preference by 5
remarks: 2764:6 Announce to non customers with "no-export"
remarks: 2764:7 Only announce route to customers
remarks: 2764:8 Announce route over satellite link
notify: routing@connect.com.au
mnt-by: CONNECT-AU
changed: mrp@connect.com.au 19990506
source: CCAIR
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 371
Some ISP Examples
UUNET Europe
aut-num: AS702
as-name: AS702
descr: UUNET - Commercial IP service provider in Europe
remarks: -------------------------------------------------------------
remarks: UUNET uses the following communities with its customers:
remarks: 702:80 Set Local Pref 80 within AS702
remarks: 702:120 Set Local Pref 120 within AS702
remarks: 702:20 Announce only to UUNET AS'es and UUNET customers
remarks: 702:30 Keep within Europe, don't announce to other UUNET AS's
remarks: 702:1 Prepend AS702 once at edges of UUNET to Peers
remarks: 702:2 Prepend AS702 twice at edges of UUNET to Peers
remarks: 702:3 Prepend AS702 thrice at edges of UUNET to Peers
remarks: Details of UUNET's peering policy and how to get in touch with
remarks: UUNET regarding peering policy matters can be found at:
remarks: http://www.uu.net/peering/
remarks: --------------------------------------------------------------
mnt-by: UUNET-MNT
changed: eric-apps@eu.uu.net 20010928
source: RIPE
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 372
Some ISP Examples
Concert Europe
aut-num: AS5400
as-name: CIPCORE
descr: Concert European Core Network
remarks: Communities scheme:
remarks: The following BGP communities can be set by Concert BGP
remarks: customers to affect announcements to major peerings.
remarks:
remarks: Community to Community to
remarks: Not announce To peer: AS prepend 5400
remarks:
remarks: 5400:1000 European peers 5400:2000
remarks: 5400:1001 Ebone (AS1755) 5400:2001
remarks: 5400:1002 Eunet (AS286) 5400:2002
remarks: 5400:1003 Unisource (AS3300) 5400:2003
<snip>
remarks: 5400:1100 US peers 5400:2100
notify: peertech@concert.net
mnt-by: CIP-MNT
source: RIPE
RIPE 40 © 2001, Cisco Systems, Inc. www.cisco.com 373
BGP for Internet Service
Providers