Projet

Général

Profil

BGP » Historique » Version 29

Laurent GUERBY, 18/07/2012 18:11

1 20 Laurent GUERBY
{{>toc}}
2 20 Laurent GUERBY
3 1 Laurent GUERBY
h1. BGP
4 1 Laurent GUERBY
5 1 Laurent GUERBY
Nous utilisons BIRD sous Linux comme routeur BGP
6 1 Laurent GUERBY
7 1 Laurent GUERBY
http://bird.network.cz/
8 1 Laurent GUERBY
9 14 Laurent GUERBY
blog bgp http://www.renesys.com/blog/
10 15 Laurent GUERBY
flowspec http://www.slideshare.net/sfouant/an-introduction-to-bgp-flow-spec
11 16 Laurent GUERBY
DFZ = Default Free Zone archive http://archive.routeviews.org/
12 17 Laurent GUERBY
http://www.ripe.net/data-tools/stats/ris/routing-information-service
13 17 Laurent GUERBY
http://pch.net/resources/data/routing-tables/archive/
14 17 Laurent GUERBY
http://pch.net/resources/data/routing-tables/mrt-bgp-updates/
15 18 Laurent GUERBY
http://www.nanog.org/meetings/archive/
16 14 Laurent GUERBY
17 29 Laurent GUERBY
http://www.ipbcop.org/
18 29 Laurent GUERBY
IP Best Current Operational Practices Documented best practices for Engineers by Engineers
19 29 Laurent GUERBY
20 3 Laurent GUERBY
h1. Evolutions de la conf BGP
21 3 Laurent GUERBY
22 3 Laurent GUERBY
* http://lists.tetaneutral.net/pipermail/technique/2011-December/000118.html
23 3 Laurent GUERBY
24 5 Laurent GUERBY
TODO: 
25 6 Laurent GUERBY
* mise en place d'un gestionaire de version style git au moins pour documentation
26 5 Laurent GUERBY
* Comment gerer les password MD5 du fichier de conf (les garder secrets tout en publiant le reste)
27 5 Laurent GUERBY
* Atelier ?
28 7 Laurent GUERBY
** Laurent GUERBY
29 9 Raphaël Durand
** Solarus
30 10 Raphaël Durand
** Ajouter son nom...
31 4 Laurent GUERBY
32 13 Laurent GUERBY
Alternative a MP BGP
33 13 Laurent GUERBY
http://tools.ietf.org/html/draft-ietf-idr-bgp-multisession-06
34 13 Laurent GUERBY
35 2 Laurent GUERBY
h1. Liens
36 2 Laurent GUERBY
37 2 Laurent GUERBY
* http://www.cl.cam.ac.uk/~tgg22/talks/BGP_TUTORIAL_ICNP_2002.ppt
38 11 Laurent GUERBY
* http://www.menog.net/menog-meetings/menog5/presentations/smith-32bit-asn-update.pdf
39 12 Laurent GUERBY
* AS4 http://www.rfc-editor.org/rfc/rfc4893.txt
40 19 Laurent GUERBY
* bonnes pratiques incidents BGP
41 19 Laurent GUERBY
** https://www.sstic.org/media/SSTIC2012/SSTIC-actes/influence_des_bonnes_pratiques_sur_les_incidents_b/SSTIC2012-Slides-influence_des_bonnes_pratiques_sur_les_incidents_bgp-contat_valadon_nataf.pdf
42 2 Laurent GUERBY
43 1 Laurent GUERBY
h1. Configuration Toulouse
44 1 Laurent GUERBY
45 1 Laurent GUERBY
<pre>
46 1 Laurent GUERBY
router id 91.224.148.2;
47 1 Laurent GUERBY
define myas = 197422;
48 1 Laurent GUERBY
49 1 Laurent GUERBY
50 1 Laurent GUERBY
protocol device {
51 1 Laurent GUERBY
	scan time 10;
52 1 Laurent GUERBY
        primary "eth0" 91.224.148.3;
53 1 Laurent GUERBY
}
54 1 Laurent GUERBY
55 1 Laurent GUERBY
protocol static static_bgp {
56 1 Laurent GUERBY
	import all;
57 1 Laurent GUERBY
	route 91.224.148.0/23 reject;
58 1 Laurent GUERBY
}
59 1 Laurent GUERBY
60 1 Laurent GUERBY
61 1 Laurent GUERBY
protocol kernel{
62 1 Laurent GUERBY
	import all;
63 1 Laurent GUERBY
	export all;
64 1 Laurent GUERBY
}
65 1 Laurent GUERBY
66 1 Laurent GUERBY
67 1 Laurent GUERBY
function avoid_martians()
68 1 Laurent GUERBY
prefix set martians;
69 1 Laurent GUERBY
{
70 1 Laurent GUERBY
  martians = [ 169.254.0.0/16+, 172.16.0.0/12+, 192.168.0.0/16+, 10.0.0.0/8+, 224.0.0.0/4+, 240.0.0.0/4+ ];
71 1 Laurent GUERBY
72 1 Laurent GUERBY
  # Avoid 0.0.0.0/X
73 1 Laurent GUERBY
  if net.ip = 0.0.0.0 then return false;
74 1 Laurent GUERBY
75 1 Laurent GUERBY
  # Avoid too short and too long prefixes
76 1 Laurent GUERBY
  if (net.len < 8) || (net.len > 24) then return false;
77 1 Laurent GUERBY
78 1 Laurent GUERBY
  # Avoid RFC1918 networks
79 1 Laurent GUERBY
  if net ~ martians then return false;
80 1 Laurent GUERBY
  return true;
81 1 Laurent GUERBY
}
82 1 Laurent GUERBY
83 1 Laurent GUERBY
filter bgp_OUT {
84 1 Laurent GUERBY
	if (net ~ [91.224.148.0/23]) then accept;
85 1 Laurent GUERBY
	else reject;
86 1 Laurent GUERBY
}
87 1 Laurent GUERBY
88 1 Laurent GUERBY
89 1 Laurent GUERBY
protocol bgp TOUIX {
90 1 Laurent GUERBY
        local as myas;
91 1 Laurent GUERBY
        neighbor 91.213.236.1 as 47184;
92 1 Laurent GUERBY
        preference 200;
93 1 Laurent GUERBY
        import where avoid_martians();
94 1 Laurent GUERBY
        export filter bgp_OUT;
95 1 Laurent GUERBY
}
96 1 Laurent GUERBY
97 1 Laurent GUERBY
protocol bgp JAGUAR {
98 1 Laurent GUERBY
	 local as myas;
99 1 Laurent GUERBY
	 neighbor 31.172.233.1 as 30781;
100 1 Laurent GUERBY
	 preference 50;
101 1 Laurent GUERBY
         import where avoid_martians();
102 1 Laurent GUERBY
         export filter bgp_OUT;
103 1 Laurent GUERBY
}
104 1 Laurent GUERBY
105 1 Laurent GUERBY
protocol bgp TETANEUTRAL {
106 1 Laurent GUERBY
	local as myas;
107 1 Laurent GUERBY
	neighbor 91.224.148.2 as myas;
108 1 Laurent GUERBY
	preference 100;
109 1 Laurent GUERBY
	import where avoid_martians();
110 1 Laurent GUERBY
	export all;
111 1 Laurent GUERBY
}
112 1 Laurent GUERBY
</pre>
113 20 Laurent GUERBY
114 20 Laurent GUERBY
h1. Blackholing
115 20 Laurent GUERBY
116 24 Laurent GUERBY
h2. Attaques
117 24 Laurent GUERBY
118 24 Laurent GUERBY
* 20120629 http://lists.tetaneutral.net/pipermail/technique/2012-July/000406.html
119 24 Laurent GUERBY
120 20 Laurent GUERBY
h2. RFC3882 
121 1 Laurent GUERBY
122 22 Laurent GUERBY
* http://www.ietf.org/rfc/rfc3882.txt
123 1 Laurent GUERBY
community AS:666 sur annonce /32 pour balckhole par AS upstream
124 1 Laurent GUERBY
125 22 Laurent GUERBY
* doc CISCO
126 22 Laurent GUERBY
http://www.cisco.com/web/about/security/intelligence/blackhole.pdf
127 22 Laurent GUERBY
128 28 Laurent GUERBY
h2. RFC1997
129 28 Laurent GUERBY
130 28 Laurent GUERBY
* http://www.ietf.org/rfc/rfc1997.txt
131 28 Laurent GUERBY
BGP Communities Attribute
132 28 Laurent GUERBY
133 28 Laurent GUERBY
* doc CISCO
134 28 Laurent GUERBY
http://www.cisco.com/web/about/ac123/ac147/archived_issues/ipj_6-2/bgp_communities.html
135 28 Laurent GUERBY
136 22 Laurent GUERBY
h2. BIRD
137 22 Laurent GUERBY
138 22 Laurent GUERBY
* http://www.mail-archive.com/bird-users@atrey.karlin.mff.cuni.cz/msg01998.html
139 22 Laurent GUERBY
140 24 Laurent GUERBY
h2. Absolight
141 24 Laurent GUERBY
142 24 Laurent GUERBY
* communauté 29608:65001 sur /24..32 IPv4 et /41..128 IPv6 => blackhole
143 24 Laurent GUERBY
* test 20120703 IPv4 et IPv6, ça marche et convergence très rapide
144 24 Laurent GUERBY
145 22 Laurent GUERBY
h2. GIXE
146 22 Laurent GUERBY
147 1 Laurent GUERBY
* communauté 31576:666 sur /32 => blackhole
148 24 Laurent GUERBY
* test 20120703 => marche pas encore, signalé et dev a faire coté GIXE pour autoriser les /32
149 1 Laurent GUERBY
150 1 Laurent GUERBY
h2. Jaguar 
151 22 Laurent GUERBY
152 24 Laurent GUERBY
* https://extranet.jaguar-network.com/app/public/index.php?cmd=bgp-policy
153 22 Laurent GUERBY
* demande 20120702 : pas de communauté blackhole actuellement, en reflexion
154 22 Laurent GUERBY
* déploiement de matériel arbor networks, reglage a affiner (pas de detection d'attaque)
155 22 Laurent GUERBY
156 27 Laurent GUERBY
h2. Gitoyen
157 27 Laurent GUERBY
158 1 Laurent GUERBY
* demande 20120704 sur la liste, réponse 20120717
159 28 Laurent GUERBY
* Tata http://noc.easycolocate.nl/Teleglobe_bgp_comm.pdf
160 27 Laurent GUERBY
*** => black-hole route (host route or shorter prefix within customer’s RIR registred assignment) 64999:0
161 28 Laurent GUERBY
* Ielo  whois AS29075 => 29075:0 Null-route/Blackhole
162 22 Laurent GUERBY
163 22 Laurent GUERBY
h2. France-IX
164 22 Laurent GUERBY
165 25 Laurent GUERBY
* community plan : https://apps.db.ripe.net/whois/lookup/ripe/aut-num/AS51706.html
166 26 Laurent GUERBY
* TODO tester
167 22 Laurent GUERBY
168 22 Laurent GUERBY
h2. Equinix-IX
169 1 Laurent GUERBY
170 26 Laurent GUERBY
* community plan : https://ix.equinix.com/ixp/mlpeCommunityInfo
171 26 Laurent GUERBY
* TODO tester
172 22 Laurent GUERBY
173 1 Laurent GUERBY
h2. TouIX
174 22 Laurent GUERBY
175 26 Laurent GUERBY
* demande acces switch et route server 20120702
176 22 Laurent GUERBY
* TODO
177 1 Laurent GUERBY
178 1 Laurent GUERBY
h2. Hurricane Electric
179 1 Laurent GUERBY
180 26 Laurent GUERBY
* http://www.he.net/adm/
181 1 Laurent GUERBY
* http://www.he.net/adm/blackhole.html
182 1 Laurent GUERBY
* TODO tester
183 28 Laurent GUERBY
184 28 Laurent GUERBY
h2. Sfinx
185 28 Laurent GUERBY
186 28 Laurent GUERBY
* http://www.renater.fr/route-servers-bgp?lang=fr
187 28 Laurent GUERBY
* whois  AS1304 =>
188 28 Laurent GUERBY
remarks:        1304:65281 = Apply NO-EXPORT community
189 28 Laurent GUERBY
remarks:        1304:65282 = Apply NO-ADVERTISE community