BGP » Historique » Version 188
Laurent GUERBY, 27/06/2017 12:25
1 | 20 | Laurent GUERBY | {{>toc}} |
---|---|---|---|
2 | 20 | Laurent GUERBY | |
3 | 1 | Laurent GUERBY | h1. BGP |
4 | 1 | Laurent GUERBY | |
5 | 175 | Laurent GUERBY | h2. Liens |
6 | 175 | Laurent GUERBY | |
7 | 1 | Laurent GUERBY | Nous utilisons BIRD sous Linux comme routeur BGP |
8 | 1 | Laurent GUERBY | |
9 | 1 | Laurent GUERBY | http://bird.network.cz/ |
10 | 1 | Laurent GUERBY | |
11 | 184 | Laurent GUERBY | simulation de l'internet |
12 | 184 | Laurent GUERBY | https://www.nsec.io/ |
13 | 184 | Laurent GUERBY | https://github.com/nsec/the-internet |
14 | 184 | Laurent GUERBY | |
15 | 185 | Laurent GUERBY | https://www.franceix.net/fr/technical/blackholing/ |
16 | 185 | Laurent GUERBY | BLACKHOLE Community https://tools.ietf.org/html/rfc7999 |
17 | 185 | Laurent GUERBY | |
18 | 14 | Laurent GUERBY | blog bgp http://www.renesys.com/blog/ |
19 | 15 | Laurent GUERBY | flowspec http://www.slideshare.net/sfouant/an-introduction-to-bgp-flow-spec |
20 | 16 | Laurent GUERBY | DFZ = Default Free Zone archive http://archive.routeviews.org/ |
21 | 17 | Laurent GUERBY | http://www.ripe.net/data-tools/stats/ris/routing-information-service |
22 | 65 | Laurent GUERBY | https://stat.ripe.net/widget/announced-prefixes |
23 | 17 | Laurent GUERBY | http://pch.net/resources/data/routing-tables/archive/ |
24 | 17 | Laurent GUERBY | http://pch.net/resources/data/routing-tables/mrt-bgp-updates/ |
25 | 18 | Laurent GUERBY | http://www.nanog.org/meetings/archive/ |
26 | 52 | Laurent GUERBY | http://tools.ietf.org/html/draft-lapukhov-bgp-routing-large-dc-02 |
27 | 14 | Laurent GUERBY | |
28 | 43 | Laurent GUERBY | http://inside.godaddy.com/inside-story-happened-godaddy-com-sept-10-2012/ |
29 | 43 | Laurent GUERBY | |
30 | 67 | Laurent GUERBY | liste des communautés des opérateurs http://onesc.net/communities/ via http://www.bortzmeyer.org/7153.html |
31 | 66 | Laurent GUERBY | |
32 | 55 | Laurent GUERBY | http://tools.ietf.org/html/rfc4271#section-9.1 BGP route decision process |
33 | 55 | Laurent GUERBY | |
34 | 29 | Laurent GUERBY | http://www.ipbcop.org/ |
35 | 29 | Laurent GUERBY | IP Best Current Operational Practices Documented best practices for Engineers by Engineers |
36 | 29 | Laurent GUERBY | |
37 | 30 | Laurent GUERBY | BGP best practices ANSSI |
38 | 30 | Laurent GUERBY | https://www.sstic.org/media/SSTIC2012/SSTIC-actes/influence_des_bonnes_pratiques_sur_les_incidents_b/SSTIC2012-Article-influence_des_bonnes_pratiques_sur_les_incidents_bgp-contat_valadon_nataf_2.pdf |
39 | 62 | Laurent GUERBY | http://www.ssi.gouv.fr/fr/bonnes-pratiques/recommandations-et-guides/securite-des-reseaux/le-guide-des-bonnes-pratiques-de-configuration-de-bgp.html |
40 | 64 | Laurent GUERBY | http://tools.ietf.org/html/draft-ietf-opsec-bgp-security-01 |
41 | 179 | Laurent GUERBY | http://www.ssi.gouv.fr/uploads/2014/10/rapport_observatoire_2015.pdf |
42 | 30 | Laurent GUERBY | |
43 | 37 | Laurent GUERBY | https://www.ams-ix.net/technical/specifications-descriptions/ams-ix-route-servers |
44 | 37 | Laurent GUERBY | |
45 | 39 | Laurent GUERBY | these LAAS BGP http://www.laas.fr/1-31360-Detail-Soutenance-de-these.php?id=600 |
46 | 41 | Laurent GUERBY | http://www.laas.fr/1-31706-Publications.php?author=7738 |
47 | 1 | Laurent GUERBY | http://www.net.t-labs.tu-berlin.de/papers/OMUPMO-OOSICP-11.pdf |
48 | 42 | Laurent GUERBY | http://hal.archives-ouvertes.fr/docs/00/60/53/83/PDF/dVirt-virtual_platform.pdf |
49 | 42 | Laurent GUERBY | http://hal.archives-ouvertes.fr/docs/00/48/70/74/PDF/Poster_SIGCOMM2010_philippe.pdf |
50 | 40 | Laurent GUERBY | |
51 | 44 | Laurent GUERBY | Le monde sur BGP http://reseaux.blog.lemonde.fr/2012/11/04/routage-enjeu-cyberstrategie/ |
52 | 44 | Laurent GUERBY | |
53 | 45 | Laurent GUERBY | coupure free wanadoo http://www.journaldunet.com/solutions/0301/030122_freeft.shtml |
54 | 45 | Laurent GUERBY | |
55 | 46 | Laurent GUERBY | tsunami Japon 2011 et BGP : http://archive.psg.com/111206.conext-quake.pdf |
56 | 46 | Laurent GUERBY | |
57 | 47 | Laurent GUERBY | Session is up on telnet:route-views.routeviews.org username rviews |
58 | 47 | Laurent GUERBY | |
59 | 48 | Laurent GUERBY | BGP book http://www.bortzmeyer.org/files/bgp.html |
60 | 48 | Laurent GUERBY | |
61 | 49 | Laurent GUERBY | Cyclops is able to detect several forms of route hijack attacks http://cyclops.cs.ucla.edu/ |
62 | 50 | Laurent GUERBY | BGPmon monitors the routing of your prefixes and alerts you in case of an 'interesting' path chang http://www.bgpmon.net/ |
63 | 49 | Laurent GUERBY | |
64 | 53 | Laurent GUERBY | http://jointtransit.nl/prices.html |
65 | 53 | Laurent GUERBY | |
66 | 54 | Laurent GUERBY | http://blog.cloudflare.com/the-ddos-that-knocked-spamhaus-offline-and-ho |
67 | 54 | Laurent GUERBY | |
68 | 51 | Laurent GUERBY | * taille table de routage http://bgp.potaroo.net/ |
69 | 1 | Laurent GUERBY | |
70 | 65 | Laurent GUERBY | * BGP in 2011 Geoff Huston APNIC http://iepg.org/2011-11-ietf82/2011-11-13-bgp2011.pdf |
71 | 56 | Laurent GUERBY | |
72 | 57 | Laurent GUERBY | * http://pages.cs.wisc.edu/~plonka/netgear-sntp/ |
73 | 57 | Laurent GUERBY | |
74 | 58 | Laurent GUERBY | * http://www.afnic.fr/fr/l-afnic-en-bref/actualites/actualites-generales/7114/show/l-observatoire-sur-la-resilience-de-l-internet-francais-publie-son-rapport-2012.html |
75 | 58 | Laurent GUERBY | |
76 | 59 | Laurent GUERBY | * http://www.ris.ripe.net/dashboard/2a01:6600:8000::/40 |
77 | 59 | Laurent GUERBY | |
78 | 60 | Laurent GUERBY | * http://www.bortzmeyer.org/6996.html |
79 | 60 | Laurent GUERBY | ** RFC 6996 : Autonomous System (AS) Reservation for Private Use |
80 | 60 | Laurent GUERBY | ** http://www.iana.org/assignments/as-numbers |
81 | 60 | Laurent GUERBY | |
82 | 61 | Laurent GUERBY | * Look for TRACEROUTE by SRCGUARDIAN in the Play Store. It needs network access only... Doesn't do TCP but does ICMP and UDP traceroutes and displays ASN as well ... |
83 | 61 | Laurent GUERBY | |
84 | 63 | Laurent GUERBY | * http://www.team-cymru.org/Services/Bogons/bgp.html |
85 | 63 | Laurent GUERBY | ** http://www.team-cymru.org/Services/Bogons/bgp-examples.html#bird-full |
86 | 175 | Laurent GUERBY | |
87 | 175 | Laurent GUERBY | * 3D looking glass http://as2914.net/#/ |
88 | 63 | Laurent GUERBY | |
89 | 177 | Laurent GUERBY | * https://labs.ripe.net/Members/emileaben/has-the-routability-of-longer-than-24-prefixes-changed |
90 | 177 | Laurent GUERBY | |
91 | 183 | Laurent GUERBY | * https://github.com/pavel-odintsov/fastnetmon |
92 | 183 | Laurent GUERBY | ** FastNetMon - A high performance DoS/DDoS load analyzer built on top of multiple packet capture engines (NetFlow, IPFIX, sFLOW, SnabbSwitch, netmap, PF_RING, PCAP). |
93 | 183 | Laurent GUERBY | ** What can we do? We can detect hosts in our networks sending or receiving large volumes of packets/bytes/flows per second. We can call an external script to notify you, switch off a server, or blackhole the client. |
94 | 183 | Laurent GUERBY | |
95 | 186 | Laurent GUERBY | * https://www.redpill-linpro.com/sysadvent/2016/12/09/slimming-routing-table.html |
96 | 186 | Laurent GUERBY | |
97 | 187 | Matthieu Herrb | * http://www.bortzmeyer.org/1997.html sur les communautés BGP |
98 | 187 | Matthieu Herrb | |
99 | 188 | Laurent GUERBY | * https://radar.qrator.net/as-rating#connectivity/1 |
100 | 188 | Laurent GUERBY | ** https://radar.qrator.net/as197422 |
101 | 188 | Laurent GUERBY | |
102 | 182 | Laurent GUERBY | h2. Baker-s Dozen |
103 | 182 | Laurent GUERBY | |
104 | 181 | Laurent GUERBY | * Baker's Dozen BGP transit players |
105 | 181 | Laurent GUERBY | ** http://research.dyn.com/2008/12/winners-and-losers-for-2008/ |
106 | 181 | Laurent GUERBY | ** http://research.dyn.com/2009/12/a-bakers-dozen-in-2009/ |
107 | 181 | Laurent GUERBY | ** http://research.dyn.com/2011/01/a-bakers-dozen-2010-edition/ |
108 | 181 | Laurent GUERBY | ** http://research.dyn.com/2012/02/a-bakers-dozen-2011-edition/ |
109 | 181 | Laurent GUERBY | ** http://research.dyn.com/2012/02/a-bakers-dozen-2012-edition/ |
110 | 181 | Laurent GUERBY | ** http://research.dyn.com/2012/02/a-bakers-dozen-2013-edition/ |
111 | 181 | Laurent GUERBY | ** http://research.dyn.com/2012/02/a-bakers-dozen-2014-edition/ |
112 | 181 | Laurent GUERBY | ** http://research.dyn.com/2016/04/a-bakers-dozen-2015-edition/ |
113 | 182 | Laurent GUERBY | *** https://cdn.vpls.com/wp-content/uploads/WP033-Bakers-Dozen-2015.pdf |
114 | 180 | Laurent GUERBY | |
115 | 171 | Laurent GUERBY | h1. Bird |
116 | 171 | Laurent GUERBY | |
117 | 171 | Laurent GUERBY | h2. Link local IPv6 static route |
118 | 171 | Laurent GUERBY | |
119 | 171 | Laurent GUERBY | <pre> |
120 | 171 | Laurent GUERBY | protocol direct { |
121 | 171 | Laurent GUERBY | interface "eth0"; |
122 | 171 | Laurent GUERBY | } |
123 | 171 | Laurent GUERBY | |
124 | 171 | Laurent GUERBY | protocol static { |
125 | 171 | Laurent GUERBY | route 2001:db8::/32 via fe80::1%eth0; |
126 | 171 | Laurent GUERBY | } |
127 | 171 | Laurent GUERBY | </pre> |
128 | 171 | Laurent GUERBY | |
129 | 172 | Laurent GUERBY | h2. Gitoyen BIRD config |
130 | 172 | Laurent GUERBY | |
131 | 172 | Laurent GUERBY | https://code.ffdn.org/gitoyen/bird-config/ |
132 | 171 | Laurent GUERBY | |
133 | 176 | Laurent GUERBY | Et autres outils dont le blackholing automatique : https://code.ffdn.org/org/gitoyen |
134 | 176 | Laurent GUERBY | |
135 | 173 | Laurent GUERBY | h2. Misc BIRD Links |
136 | 173 | Laurent GUERBY | |
137 | 173 | Laurent GUERBY | * zeromq integration https://github.com/samrussell/bird/tree/zmqintegration |
138 | 174 | Laurent GUERBY | * https://www.netdev01.org/docs/prabhu-linux_ipv4_ipv6_inconsistencies_talk_slides.pdf |
139 | 173 | Laurent GUERBY | |
140 | 178 | Baptiste Jonglez | h1. mrtdump |
141 | 178 | Baptiste Jonglez | |
142 | 178 | Baptiste Jonglez | mrtdump est un format standard pour représenter et stocker des données BGP (table de routage, messages BGP) : https://tools.ietf.org/html/rfc6396 |
143 | 178 | Baptiste Jonglez | |
144 | 178 | Baptiste Jonglez | h2. Dump mrtdump avec Bird |
145 | 178 | Baptiste Jonglez | |
146 | 178 | Baptiste Jonglez | h3. Dump de tous les messages BGP échangés avec les pairs |
147 | 178 | Baptiste Jonglez | |
148 | 178 | Baptiste Jonglez | <pre> |
149 | 178 | Baptiste Jonglez | mrtdump "/tmp/mrtdump-messages"; |
150 | 178 | Baptiste Jonglez | mrtdump protocols {messages}; |
151 | 178 | Baptiste Jonglez | </pre> |
152 | 178 | Baptiste Jonglez | |
153 | 178 | Baptiste Jonglez | Cf. doc bird : http://bird.network.cz/?get_doc&f=bird-3.html#ss3.2 |
154 | 178 | Baptiste Jonglez | |
155 | 178 | Baptiste Jonglez | Pour "rotate" le fichier de dump, changer le nom du fichier dans la configuration bird et faire `birdc configure`. |
156 | 178 | Baptiste Jonglez | |
157 | 178 | Baptiste Jonglez | h3. Dump de la table de routage BGP |
158 | 178 | Baptiste Jonglez | |
159 | 178 | Baptiste Jonglez | Ce n'est pas encore possible mais en développement dans Bird, cf. branche *mrtdump* upstream. |
160 | 178 | Baptiste Jonglez | |
161 | 178 | Baptiste Jonglez | Doc : https://gitlab.labs.nic.cz/labs/bird/commit/11fabd2d6b8bc3d6ca86acd3b62fe4deeb4b91b7 |
162 | 178 | Baptiste Jonglez | |
163 | 178 | Baptiste Jonglez | h2. Sources de données mrtdump publiques |
164 | 178 | Baptiste Jonglez | |
165 | 178 | Baptiste Jonglez | * RIS (Routing Information Service) : |
166 | 178 | Baptiste Jonglez | |
167 | 178 | Baptiste Jonglez | * routes BGP collectées par le RIPE depuis plusieurs points d'échanges (16 collecteurs en tout) |
168 | 178 | Baptiste Jonglez | * données collectées et archivées depuis 2001 |
169 | 178 | Baptiste Jonglez | * https://www.ripe.net/analyse/internet-measurements/routing-information-service-ris/routing-information-service-ris |
170 | 178 | Baptiste Jonglez | * données en libre accès https://www.ripe.net/analyse/internet-measurements/routing-information-service-ris/ris-raw-data |
171 | 178 | Baptiste Jonglez | |
172 | 178 | Baptiste Jonglez | * Routeviews : |
173 | 178 | Baptiste Jonglez | |
174 | 178 | Baptiste Jonglez | * même idée, mais moins centré sur l'Europe (projet mené par des américains) |
175 | 178 | Baptiste Jonglez | * http://www.routeviews.org/ |
176 | 178 | Baptiste Jonglez | * données en libre accès ftp://archive.routeviews.org/ |
177 | 178 | Baptiste Jonglez | |
178 | 178 | Baptiste Jonglez | h2. Exploitation des données mrtdump |
179 | 178 | Baptiste Jonglez | |
180 | 178 | Baptiste Jonglez | * outil historique : *bgpdump* https://bitbucket.org/ripencc/bgpdump/wiki/Home |
181 | 178 | Baptiste Jonglez | * plus récent : *bgpstream* https://bgpstream.caida.org/ https://github.com/CAIDA/bgpstream https://pypi.python.org/pypi/pybgpstream |
182 | 178 | Baptiste Jonglez | |
183 | 178 | Baptiste Jonglez | bgpstream est plutôt fait pour récupérer automatiquement les données de RIS et Routeviews (d'ailleurs parfois ça ne marche pas super bien...). C'est aussi possible de lire des fichiers mrtdump locaux, par exemple avec les bindings python : |
184 | 178 | Baptiste Jonglez | |
185 | 178 | Baptiste Jonglez | <pre> |
186 | 178 | Baptiste Jonglez | from _pybgpstream import BGPStream, BGPRecord, BGPElem |
187 | 178 | Baptiste Jonglez | record = BGPRecord() |
188 | 178 | Baptiste Jonglez | stream = BGPStream() |
189 | 178 | Baptiste Jonglez | stream.set_data_interface("singlefile") |
190 | 178 | Baptiste Jonglez | stream.set_data_interface_option("singlefile", "rib-file", myfilename) |
191 | 178 | Baptiste Jonglez | # Add additional filters here |
192 | 178 | Baptiste Jonglez | stream.start() |
193 | 178 | Baptiste Jonglez | # etc (cf. tutorial bgpstream) |
194 | 178 | Baptiste Jonglez | </pre> |
195 | 178 | Baptiste Jonglez | |
196 | 178 | Baptiste Jonglez | |
197 | 38 | Laurent GUERBY | h1. TouIX et GIX |
198 | 38 | Laurent GUERBY | |
199 | 38 | Laurent GUERBY | http://touix.net |
200 | 38 | Laurent GUERBY | http://wikilulu.net/doku.php?id=articles:gix-howto |
201 | 38 | Laurent GUERBY | |
202 | 3 | Laurent GUERBY | h1. Evolutions de la conf BGP |
203 | 3 | Laurent GUERBY | |
204 | 3 | Laurent GUERBY | * http://lists.tetaneutral.net/pipermail/technique/2011-December/000118.html |
205 | 3 | Laurent GUERBY | |
206 | 5 | Laurent GUERBY | TODO: |
207 | 6 | Laurent GUERBY | * mise en place d'un gestionaire de version style git au moins pour documentation |
208 | 5 | Laurent GUERBY | * Comment gerer les password MD5 du fichier de conf (les garder secrets tout en publiant le reste) |
209 | 5 | Laurent GUERBY | * Atelier ? |
210 | 7 | Laurent GUERBY | ** Laurent GUERBY |
211 | 9 | Raphaël Durand | ** Solarus |
212 | 10 | Raphaël Durand | ** Ajouter son nom... |
213 | 4 | Laurent GUERBY | |
214 | 13 | Laurent GUERBY | Alternative a MP BGP |
215 | 13 | Laurent GUERBY | http://tools.ietf.org/html/draft-ietf-idr-bgp-multisession-06 |
216 | 13 | Laurent GUERBY | |
217 | 31 | Laurent GUERBY | Add Path |
218 | 31 | Laurent GUERBY | http://tools.ietf.org/html/draft-ietf-idr-add-paths-07 |
219 | 31 | Laurent GUERBY | support in bird ? http://marc.info/?l=bird-users&m=134409996129466&w=2 |
220 | 31 | Laurent GUERBY | |
221 | 2 | Laurent GUERBY | h1. Liens |
222 | 2 | Laurent GUERBY | |
223 | 2 | Laurent GUERBY | * http://www.cl.cam.ac.uk/~tgg22/talks/BGP_TUTORIAL_ICNP_2002.ppt |
224 | 11 | Laurent GUERBY | * http://www.menog.net/menog-meetings/menog5/presentations/smith-32bit-asn-update.pdf |
225 | 12 | Laurent GUERBY | * AS4 http://www.rfc-editor.org/rfc/rfc4893.txt |
226 | 19 | Laurent GUERBY | * bonnes pratiques incidents BGP |
227 | 19 | Laurent GUERBY | ** https://www.sstic.org/media/SSTIC2012/SSTIC-actes/influence_des_bonnes_pratiques_sur_les_incidents_b/SSTIC2012-Slides-influence_des_bonnes_pratiques_sur_les_incidents_bgp-contat_valadon_nataf.pdf |
228 | 35 | Laurent GUERBY | * test ping plus UDP http://www.broadband-forum.org/technical/download/TR-143.pdf |
229 | 2 | Laurent GUERBY | |
230 | 1 | Laurent GUERBY | h1. Configuration Toulouse |
231 | 1 | Laurent GUERBY | |
232 | 1 | Laurent GUERBY | <pre> |
233 | 1 | Laurent GUERBY | router id 91.224.148.2; |
234 | 1 | Laurent GUERBY | define myas = 197422; |
235 | 1 | Laurent GUERBY | |
236 | 1 | Laurent GUERBY | |
237 | 1 | Laurent GUERBY | protocol device { |
238 | 1 | Laurent GUERBY | scan time 10; |
239 | 1 | Laurent GUERBY | primary "eth0" 91.224.148.3; |
240 | 1 | Laurent GUERBY | } |
241 | 1 | Laurent GUERBY | |
242 | 1 | Laurent GUERBY | protocol static static_bgp { |
243 | 1 | Laurent GUERBY | import all; |
244 | 1 | Laurent GUERBY | route 91.224.148.0/23 reject; |
245 | 1 | Laurent GUERBY | } |
246 | 1 | Laurent GUERBY | |
247 | 1 | Laurent GUERBY | |
248 | 1 | Laurent GUERBY | protocol kernel{ |
249 | 1 | Laurent GUERBY | import all; |
250 | 1 | Laurent GUERBY | export all; |
251 | 1 | Laurent GUERBY | } |
252 | 1 | Laurent GUERBY | |
253 | 1 | Laurent GUERBY | |
254 | 1 | Laurent GUERBY | function avoid_martians() |
255 | 1 | Laurent GUERBY | prefix set martians; |
256 | 1 | Laurent GUERBY | { |
257 | 1 | Laurent GUERBY | martians = [ 169.254.0.0/16+, 172.16.0.0/12+, 192.168.0.0/16+, 10.0.0.0/8+, 224.0.0.0/4+, 240.0.0.0/4+ ]; |
258 | 1 | Laurent GUERBY | |
259 | 1 | Laurent GUERBY | # Avoid 0.0.0.0/X |
260 | 1 | Laurent GUERBY | if net.ip = 0.0.0.0 then return false; |
261 | 1 | Laurent GUERBY | |
262 | 1 | Laurent GUERBY | # Avoid too short and too long prefixes |
263 | 1 | Laurent GUERBY | if (net.len < 8) || (net.len > 24) then return false; |
264 | 1 | Laurent GUERBY | |
265 | 1 | Laurent GUERBY | # Avoid RFC1918 networks |
266 | 1 | Laurent GUERBY | if net ~ martians then return false; |
267 | 1 | Laurent GUERBY | return true; |
268 | 1 | Laurent GUERBY | } |
269 | 1 | Laurent GUERBY | |
270 | 1 | Laurent GUERBY | filter bgp_OUT { |
271 | 1 | Laurent GUERBY | if (net ~ [91.224.148.0/23]) then accept; |
272 | 1 | Laurent GUERBY | else reject; |
273 | 1 | Laurent GUERBY | } |
274 | 1 | Laurent GUERBY | |
275 | 1 | Laurent GUERBY | |
276 | 1 | Laurent GUERBY | protocol bgp TOUIX { |
277 | 1 | Laurent GUERBY | local as myas; |
278 | 1 | Laurent GUERBY | neighbor 91.213.236.1 as 47184; |
279 | 1 | Laurent GUERBY | preference 200; |
280 | 1 | Laurent GUERBY | import where avoid_martians(); |
281 | 1 | Laurent GUERBY | export filter bgp_OUT; |
282 | 1 | Laurent GUERBY | } |
283 | 1 | Laurent GUERBY | |
284 | 1 | Laurent GUERBY | protocol bgp JAGUAR { |
285 | 1 | Laurent GUERBY | local as myas; |
286 | 1 | Laurent GUERBY | neighbor 31.172.233.1 as 30781; |
287 | 1 | Laurent GUERBY | preference 50; |
288 | 1 | Laurent GUERBY | import where avoid_martians(); |
289 | 1 | Laurent GUERBY | export filter bgp_OUT; |
290 | 1 | Laurent GUERBY | } |
291 | 1 | Laurent GUERBY | |
292 | 1 | Laurent GUERBY | protocol bgp TETANEUTRAL { |
293 | 1 | Laurent GUERBY | local as myas; |
294 | 1 | Laurent GUERBY | neighbor 91.224.148.2 as myas; |
295 | 1 | Laurent GUERBY | preference 100; |
296 | 1 | Laurent GUERBY | import where avoid_martians(); |
297 | 1 | Laurent GUERBY | export all; |
298 | 1 | Laurent GUERBY | } |
299 | 1 | Laurent GUERBY | </pre> |
300 | 20 | Laurent GUERBY | |
301 | 33 | Laurent GUERBY | h1. IRR |
302 | 33 | Laurent GUERBY | |
303 | 33 | Laurent GUERBY | * From nanog: |
304 | 33 | Laurent GUERBY | http://www.clarksys.com/blog/2009/09/02/using-irr-with-level3/ |
305 | 33 | Laurent GUERBY | whois -h filtergen.level3.net "RIPE::YOUR-AS-SET -searchpath=RIPE;ARIN;RADB -recurseok -warnonly" |
306 | 33 | Laurent GUERBY | |
307 | 20 | Laurent GUERBY | h1. Blackholing |
308 | 20 | Laurent GUERBY | |
309 | 160 | Laurent GUERBY | h2. DECIX |
310 | 160 | Laurent GUERBY | |
311 | 160 | Laurent GUERBY | http://de-cix.net/products-services/de-cix-frankfurt/blackholing/ |
312 | 160 | Laurent GUERBY | |
313 | 24 | Laurent GUERBY | h2. Attaques |
314 | 24 | Laurent GUERBY | |
315 | 24 | Laurent GUERBY | * 20120629 http://lists.tetaneutral.net/pipermail/technique/2012-July/000406.html |
316 | 36 | Laurent GUERBY | * http://blog.cloudflare.com/65gbps-ddos-no-problem |
317 | 24 | Laurent GUERBY | |
318 | 1 | Laurent GUERBY | h2. URPF |
319 | 34 | Laurent GUERBY | |
320 | 65 | Laurent GUERBY | blacklister une/plusieures sources est relativement complexe à mettre en place sur une petite infrastructure car nécessite la mise en place de l'URPF (Unicast Reverse Path Forwarding). |
321 | 34 | Laurent GUERBY | |
322 | 34 | Laurent GUERBY | http://www.cisco.com/web/about/security/intelligence/ipv6_rtbh.html |
323 | 34 | Laurent GUERBY | |
324 | 20 | Laurent GUERBY | h2. RFC3882 |
325 | 1 | Laurent GUERBY | |
326 | 22 | Laurent GUERBY | * http://www.ietf.org/rfc/rfc3882.txt |
327 | 1 | Laurent GUERBY | community AS:666 sur annonce /32 pour balckhole par AS upstream |
328 | 1 | Laurent GUERBY | |
329 | 22 | Laurent GUERBY | * doc CISCO |
330 | 22 | Laurent GUERBY | http://www.cisco.com/web/about/security/intelligence/blackhole.pdf |
331 | 22 | Laurent GUERBY | |
332 | 28 | Laurent GUERBY | h2. RFC1997 |
333 | 28 | Laurent GUERBY | |
334 | 28 | Laurent GUERBY | * http://www.ietf.org/rfc/rfc1997.txt |
335 | 28 | Laurent GUERBY | BGP Communities Attribute |
336 | 28 | Laurent GUERBY | |
337 | 28 | Laurent GUERBY | * doc CISCO |
338 | 28 | Laurent GUERBY | http://www.cisco.com/web/about/ac123/ac147/archived_issues/ipj_6-2/bgp_communities.html |
339 | 28 | Laurent GUERBY | |
340 | 22 | Laurent GUERBY | h2. BIRD |
341 | 22 | Laurent GUERBY | |
342 | 22 | Laurent GUERBY | * http://www.mail-archive.com/bird-users@atrey.karlin.mff.cuni.cz/msg01998.html |
343 | 1 | Laurent GUERBY | |
344 | 24 | Laurent GUERBY | h2. Absolight |
345 | 24 | Laurent GUERBY | |
346 | 65 | Laurent GUERBY | * communauté 29608:65001 sur /24..32 IPv4 et /41..128 IPv6 => blackhole |
347 | 65 | Laurent GUERBY | * test 20120703 IPv4 et IPv6, ça marche et convergence très rapide |
348 | 24 | Laurent GUERBY | |
349 | 22 | Laurent GUERBY | h2. GIXE |
350 | 1 | Laurent GUERBY | |
351 | 65 | Laurent GUERBY | * communauté 31576:666 sur /32 => blackhole |
352 | 65 | Laurent GUERBY | * test 20120703 => marche pas encore, signalé et dev a faire coté GIXE pour autoriser les /32 |
353 | 1 | Laurent GUERBY | |
354 | 1 | Laurent GUERBY | h2. Jaguar |
355 | 22 | Laurent GUERBY | |
356 | 24 | Laurent GUERBY | * https://extranet.jaguar-network.com/app/public/index.php?cmd=bgp-policy |
357 | 65 | Laurent GUERBY | * demande 20120702 : pas de communauté blackhole actuellement, en reflexion |
358 | 65 | Laurent GUERBY | * déploiement de matériel arbor networks, reglage a affiner (pas de detection d'attaque) |
359 | 22 | Laurent GUERBY | |
360 | 27 | Laurent GUERBY | h2. Gitoyen |
361 | 27 | Laurent GUERBY | |
362 | 65 | Laurent GUERBY | * demande 20120704 sur la liste, réponse 20120717 |
363 | 28 | Laurent GUERBY | * Tata http://noc.easycolocate.nl/Teleglobe_bgp_comm.pdf |
364 | 65 | Laurent GUERBY | *** => black-hole route (host route or shorter prefix within customer’s RIR registred assignment) 64999:0 |
365 | 28 | Laurent GUERBY | * Ielo whois AS29075 => 29075:0 Null-route/Blackhole |
366 | 32 | Laurent GUERBY | * https://pad.ilico.org/p/cleanup-bgp-gitoyen |
367 | 22 | Laurent GUERBY | |
368 | 22 | Laurent GUERBY | h2. France-IX |
369 | 22 | Laurent GUERBY | |
370 | 25 | Laurent GUERBY | * community plan : https://apps.db.ripe.net/whois/lookup/ripe/aut-num/AS51706.html |
371 | 26 | Laurent GUERBY | * TODO tester |
372 | 22 | Laurent GUERBY | |
373 | 22 | Laurent GUERBY | h2. Equinix-IX |
374 | 1 | Laurent GUERBY | |
375 | 26 | Laurent GUERBY | * community plan : https://ix.equinix.com/ixp/mlpeCommunityInfo |
376 | 26 | Laurent GUERBY | * TODO tester |
377 | 22 | Laurent GUERBY | |
378 | 1 | Laurent GUERBY | h2. TouIX |
379 | 22 | Laurent GUERBY | |
380 | 26 | Laurent GUERBY | * demande acces switch et route server 20120702 |
381 | 22 | Laurent GUERBY | * TODO |
382 | 1 | Laurent GUERBY | |
383 | 1 | Laurent GUERBY | h2. Hurricane Electric |
384 | 1 | Laurent GUERBY | |
385 | 26 | Laurent GUERBY | * http://www.he.net/adm/ |
386 | 1 | Laurent GUERBY | * http://www.he.net/adm/blackhole.html |
387 | 1 | Laurent GUERBY | * TODO tester |
388 | 28 | Laurent GUERBY | |
389 | 28 | Laurent GUERBY | h2. Sfinx |
390 | 28 | Laurent GUERBY | |
391 | 28 | Laurent GUERBY | * http://www.renater.fr/route-servers-bgp?lang=fr |
392 | 28 | Laurent GUERBY | * whois AS1304 => |
393 | 28 | Laurent GUERBY | remarks: 1304:65281 = Apply NO-EXPORT community |
394 | 28 | Laurent GUERBY | remarks: 1304:65282 = Apply NO-ADVERTISE community |
395 | 161 | Laurent GUERBY | |
396 | 161 | Laurent GUERBY | h2. Cogent |
397 | 161 | Laurent GUERBY | |
398 | 166 | Laurent GUERBY | h3. Docs |
399 | 166 | Laurent GUERBY | |
400 | 161 | Laurent GUERBY | * http://www.cogentco.com/files/docs/customer_service/guide/global_cogent_customer_user_guide.pdf |
401 | 162 | Laurent GUERBY | ** communautés page 21-22 |
402 | 169 | Laurent GUERBY | * http://www.onesc.net/communities/as174/ |
403 | 170 | Laurent GUERBY | * https://www.nanog.org/mailinglist/mailarchives/old_archive/2005-03/msg00465.html |
404 | 166 | Laurent GUERBY | * https://www.nanog.org/meetings/nanog45/presentations/Sunday/RAS_traceroute_N45.pdf |
405 | 1 | Laurent GUERBY | |
406 | 162 | Laurent GUERBY | France / Benelux: |
407 | 162 | Laurent GUERBY | +33 1 49 03 1818 (Hotline) |
408 | 162 | Laurent GUERBY | +33 1 49 03 1803 (fax) |
409 | 162 | Laurent GUERBY | fr-support@cogentco.com (maintenance and repair) |
410 | 162 | Laurent GUERBY | bnl-support@cogentco.com (maintenance and repair)) |
411 | 162 | Laurent GUERBY | billingeu@cogentco.com (billing, customer care) |
412 | 162 | Laurent GUERBY | All Customers in Europe can also contact the European Cogent Customer Support team |
413 | 162 | Laurent GUERBY | using the generic email address for Europe: eu-support@cogentco.com |
414 | 162 | Laurent GUERBY | |
415 | 164 | Laurent GUERBY | Livré comme demandé sur rocade optique Fullsave : |
416 | 164 | Laurent GUERBY | Livré sur TLS01.CB.KD-05/A.To02.03&04 (tiroir optique N°2, fibre 03&04). |
417 | 165 | Laurent GUERBY | Cogent physical port te0/0/2/3-rcr11.tls01 |
418 | 164 | Laurent GUERBY | |
419 | 163 | Laurent GUERBY | Order ID/Service ID: 1-166108500 |
420 | 163 | Laurent GUERBY | Service Type: EU_L3_ON_10GE_BURST |
421 | 163 | Laurent GUERBY | Commitment: 1000.0 MBps |
422 | 163 | Laurent GUERBY | Service Address: 125 bis ch du Sang de Serp |
423 | 163 | Laurent GUERBY | livraison dans baie Fullsave / salle LAP Te0/0/2/3 rcr01.tls01 -- > TLS01.CB.KD-05/A.To02.03&04 |
424 | 163 | Laurent GUERBY | Toulouse, FR France 31000 |
425 | 163 | Laurent GUERBY | Your service acceptance date is 27-May-2014 and your billing start date is 27-May-2014 |
426 | 163 | Laurent GUERBY | |
427 | 163 | Laurent GUERBY | Order ID/Service ID: 1-166108524 |
428 | 163 | Laurent GUERBY | Service Type: EU_L3_ON_IPV6DSTACK_FLAT |
429 | 163 | Laurent GUERBY | Commitment: 0.0 MBps |
430 | 163 | Laurent GUERBY | Service Address: 125 bis ch du Sang de Serp |
431 | 163 | Laurent GUERBY | IPv6s fort port order 1-166108500 |
432 | 163 | Laurent GUERBY | Toulouse, FR France 31000 |
433 | 163 | Laurent GUERBY | Your service acceptance date is 27-May-2014 and your billing start date is 27-May-2014 |
434 | 163 | Laurent GUERBY | |
435 | 163 | Laurent GUERBY | Order ID/Service ID: 1-166108512 |
436 | 163 | Laurent GUERBY | Service Type: EU_L0_ON_XCFIBER_FLAT |
437 | 163 | Laurent GUERBY | Commitment: 0.0 MBps |
438 | 163 | Laurent GUERBY | Service Address: 125 bis ch du Sang de Serp |
439 | 163 | Laurent GUERBY | Te0/0/2/3 rcr01.tls01 -- > TLS01.CB.KD-05/A.To02.03&04 port order 1-166108500 |
440 | 163 | Laurent GUERBY | Toulouse, FR France 31000 |
441 | 163 | Laurent GUERBY | Your service acceptance date is 27-May-2014 and your billing start date is 27-May-2014 |
442 | 162 | Laurent GUERBY | |
443 | 162 | Laurent GUERBY | h3. Config initiale BGP Cogent |
444 | 162 | Laurent GUERBY | |
445 | 161 | Laurent GUERBY | <pre> |
446 | 161 | Laurent GUERBY | root@h7:~# cat /etc/bird/bird.conf |
447 | 161 | Laurent GUERBY | router id 149.11.58.74; |
448 | 161 | Laurent GUERBY | |
449 | 161 | Laurent GUERBY | define myas = 197422; |
450 | 161 | Laurent GUERBY | |
451 | 161 | Laurent GUERBY | timeformat base iso long; |
452 | 161 | Laurent GUERBY | timeformat log iso long; |
453 | 161 | Laurent GUERBY | timeformat protocol iso long; |
454 | 161 | Laurent GUERBY | timeformat route iso long; |
455 | 161 | Laurent GUERBY | |
456 | 161 | Laurent GUERBY | log "/var/log/bird/bird-20140527.log" all; |
457 | 161 | Laurent GUERBY | |
458 | 161 | Laurent GUERBY | debug commands 2; |
459 | 161 | Laurent GUERBY | |
460 | 161 | Laurent GUERBY | debug protocols { states, events }; |
461 | 161 | Laurent GUERBY | |
462 | 161 | Laurent GUERBY | protocol device { |
463 | 161 | Laurent GUERBY | scan time 10; |
464 | 161 | Laurent GUERBY | } |
465 | 161 | Laurent GUERBY | |
466 | 161 | Laurent GUERBY | protocol kernel { |
467 | 161 | Laurent GUERBY | import all; |
468 | 161 | Laurent GUERBY | export all; |
469 | 161 | Laurent GUERBY | learn; |
470 | 161 | Laurent GUERBY | } |
471 | 161 | Laurent GUERBY | |
472 | 161 | Laurent GUERBY | filter bgp_OUT { |
473 | 167 | Laurent GUERBY | if (net ~ [91.224.148.0/23, 80.67.182.0/24, 89.234.156.0/23]) then { |
474 | 167 | Laurent GUERBY | accept; |
475 | 167 | Laurent GUERBY | } |
476 | 161 | Laurent GUERBY | reject; |
477 | 161 | Laurent GUERBY | } |
478 | 161 | Laurent GUERBY | |
479 | 161 | Laurent GUERBY | filter bgp_IN_PEERING { |
480 | 161 | Laurent GUERBY | accept; |
481 | 161 | Laurent GUERBY | } |
482 | 161 | Laurent GUERBY | |
483 | 161 | Laurent GUERBY | protocol bgp COGENT_TLS00 { |
484 | 161 | Laurent GUERBY | local as myas; |
485 | 161 | Laurent GUERBY | neighbor 149.11.58.73 as 174; |
486 | 161 | Laurent GUERBY | import filter bgp_IN_PEERING; |
487 | 161 | Laurent GUERBY | export filter bgp_OUT; |
488 | 161 | Laurent GUERBY | } |
489 | 161 | Laurent GUERBY | root@h7:~# cat /etc/bird/bird6.conf |
490 | 161 | Laurent GUERBY | router id 149.11.58.74; |
491 | 161 | Laurent GUERBY | |
492 | 161 | Laurent GUERBY | define myas = 197422; |
493 | 161 | Laurent GUERBY | |
494 | 161 | Laurent GUERBY | timeformat base iso long; |
495 | 161 | Laurent GUERBY | timeformat log iso long; |
496 | 161 | Laurent GUERBY | timeformat protocol iso long; |
497 | 161 | Laurent GUERBY | timeformat route iso long; |
498 | 161 | Laurent GUERBY | |
499 | 161 | Laurent GUERBY | log "/var/log/bird/bird6-20140527.log" all; |
500 | 161 | Laurent GUERBY | |
501 | 161 | Laurent GUERBY | debug commands 2; |
502 | 161 | Laurent GUERBY | |
503 | 161 | Laurent GUERBY | debug protocols { states, events }; |
504 | 161 | Laurent GUERBY | |
505 | 161 | Laurent GUERBY | listen bgp v6only; |
506 | 161 | Laurent GUERBY | |
507 | 161 | Laurent GUERBY | protocol device { |
508 | 161 | Laurent GUERBY | scan time 10; |
509 | 161 | Laurent GUERBY | } |
510 | 161 | Laurent GUERBY | |
511 | 161 | Laurent GUERBY | protocol kernel { |
512 | 161 | Laurent GUERBY | import all; |
513 | 161 | Laurent GUERBY | export all; |
514 | 161 | Laurent GUERBY | learn; |
515 | 161 | Laurent GUERBY | } |
516 | 161 | Laurent GUERBY | |
517 | 161 | Laurent GUERBY | filter bgp_OUT_6 { |
518 | 168 | Laurent GUERBY | if (net ~ [2a01:6600:8000::/40]) then { |
519 | 168 | Laurent GUERBY | accept; |
520 | 168 | Laurent GUERBY | } |
521 | 161 | Laurent GUERBY | reject; |
522 | 161 | Laurent GUERBY | } |
523 | 161 | Laurent GUERBY | |
524 | 161 | Laurent GUERBY | filter bgp_IN_PEERING_6 { |
525 | 161 | Laurent GUERBY | accept; |
526 | 161 | Laurent GUERBY | } |
527 | 161 | Laurent GUERBY | |
528 | 161 | Laurent GUERBY | protocol bgp COGENT_TLS00_6 { |
529 | 161 | Laurent GUERBY | local as myas; |
530 | 161 | Laurent GUERBY | neighbor 2001:978:2:68::8:1 as 174; |
531 | 161 | Laurent GUERBY | import filter bgp_IN_PEERING_6; |
532 | 161 | Laurent GUERBY | export filter bgp_OUT_6; |
533 | 161 | Laurent GUERBY | } |
534 | 161 | Laurent GUERBY | </pre> |