Benchmarking for CoPP draft-shishio-bmwg-copp-00 Shishio Tsuchiya

Slides:



Advertisements
Similar presentations
Basic BGP Data Plane Convergence Benchmarking draft-papneja-bgp-basic-dp-convergence-01 Rajiv Papneja, Susan Hares, Bhavani Parise, Mohan Nanduri, Jay.
Advertisements

Release 5.1, Revision 0 Copyright © 2001, Juniper Networks, Inc. Advanced Juniper Networks Routing Module 9: Static Routes & Routing Table Groups.
1 IP Forwarding Relates to Lab 3. Covers the principles of end-to-end datagram delivery in IP networks.
IP Forwarding Relates to Lab 3.
Chapter 6: Static Routing
RIP V2 W.lilakiatsakun.  RFC 2453 (obsoletes –RFC 1723 /1388)  Extension of RIP v1 (Classful routing protocol)  Classless routing protocol –VLSM is.
Dynamic Tunnel Management Protocol for IPv4 Traversal of IPv6 Mobile Network Jaehoon Jeong Protocol Engineering Center, ETRI
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 The Routing Table: A Closer Look Routing Protocols and Concepts – Chapter.
Routing Security Capabilities draft-zhao-opsec-routing-capabilities-02.txt OPSEC WG, IETF #66.
CSCE 515: Computer Network Programming Chin-Tser Huang University of South Carolina.
Security of wireless ad-hoc networks. Outline Properties of Ad-Hoc network Security Challenges MANET vs. Traditional Routing Why traditional routing protocols.
Routing and Routing Protocols Introduction to Static Routing.
Draft-novak-bmwg-ipflow-meth-05.txt IP Flow Information Accounting and Export Benchmarking Methodology
1 IP Forwarding Relates to Lab 3. Covers the principles of end-to-end datagram delivery in IP networks.
IETF 90: VNF PERFORMANCE BENCHMARKING METHODOLOGY Contributors: Sarah Muhammad Durrani: Mike Chen:
Guide to TCP/IP, Third Edition
Distance Vector Routing Protocols W.lilakiatsakun.
1 IP Forwarding Relates to Lab 3. Covers the principles of end-to-end datagram delivery in IP networks.
IP Forwarding.
PC1 LAN GW SP RTR1 SP RTR2 DST 4 * 25 ms 21 ms dst [ ] 4. A third packet is sent with TTL=3, which decrements at each hop, and expires after RTR2,
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 The Routing Table: A Closer Look Routing Protocols and Concepts – Chapter 8.
Staff AAA. Radius is not an ISP AAA Option RADIUS TACACS+ Kerberos.
Proposal for new Working Group Item: Core Router Software Accelerated Life Testing (draft-poretsky-routersalt-term-00.txt) Authors: Scott Poretsky, Avici.
24/10/2015draft-novak-bmwg-ipflow-meth- 03.txt 1 IP Flow Information Accounting and Export Benchmarking Methodology
Vic Liu Lingli Deng Dapeng Liu China Mobile Speaker: Vic Liu China Mobile Gap Analysis on Virtualized Network Test draft-liu-dclc-gap-virtual-test-00.
IGP Data Plane Convergence draft-ietf-bmwg-dataplane-conv-meth-14.txt draft-ietf-bmwg-dataplane-conv-term-14.txt draft-ietf-bmwg-dataplane-conv-app-14.txt.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 6: Static Routing Routing and Switching Essentials.
Networks and Protocols CE Week 7b. Routing an Overview.
1 TCP/IP based TML (Transport Mapping Layer) for ForCES Protocol Hormuzd Khosravi Shuchi Chawla Furquan Ansari Jon Maloy 62 nd IETF Meeting, Minneapolis.
Chapter 9 Cisco IOS Firewall. IOS Firewall  Stateful packet-filter firewall that runs on a router  Provides firewall capabilities and normal routing.
Guidance for Running Multiple IPv6 Prefixes (draft-liu-v6ops-running-multiple-prefixes-02) Bing Liu, Sheng Jiang (Speaker), Yang Bo IETF91
1 Requirements for Internet Routers (Gateways) and Hosts Relates to Lab 3. (Supplement) Covers the compliance requirements of Internet routers and hosts.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 6: Static Routing Routing and Switching Essentials.
Cisco Systems Networking Academy S2 C 12 Routing Protocols.
1 Multicast Routing Blackhole Avoidance draft-asati-pim-multicast-routing-blackhole-avoid-00 Rajiv Asati Mike McBride IETF 72, Dublin.
Reshad Rahman, Editor.  Adrian Farrel OldDog Consulting  Tony Li Ericsson  David Ward Francois LeFaucheur Ashok Narayanan Cisco.
Describe basic routing concepts. Routers Interconnect Networks Router is responsible for forwarding packets from network to network, from the original.
IGP Data Plane Convergence draft-ietf-bmwg-dataplane-conv-meth-15.txt draft-ietf-bmwg-dataplane-conv-term-15.txt draft-ietf-bmwg-dataplane-conv-app-15.txt.
1 IGP Data Plane Convergence Benchmarking draft-ietf-bmwg-igp-dataplane-conv-app-01.txt draft-ietf-bmwg-igp-dataplane-conv-term-01.txt draft -ietf-bmwg-igp-dataplane-conv-meth-01.txt.
28 July BGP Data-Plane Benchmarking Applicable to Modern Routers Ilya Varlashkin Rajiv Papneja Bhavani Parise presented by Grégory CAUCHIE.
23Mar BGP Data-Plane Benchmarking Applicable to Modern Routers Rajiv Papneja Ilya Varlashkin Bhavani Parise Dean Lee Sue Hares.
1 IETF-70 draft-akhter-bmwg-mpls-meth MPLS Benchmarking Methodology draft-akhter-bmwg-mpls-meth-03 IETF 70 Aamer Akhter / Rajiv Asati /
1 IGP Data Plane Convergence Benchmarking draft-ietf-bmwg-igp-dataplane-conv-app-00.txt draft-ietf-bmwg-igp-dataplane-conv-term-00.txt draft -ietf-bmwg-igp-dataplane-conv-meth-00.txt.
A Fragmentation Strategy for Generic Routing Encapsulation (GRE)
1 Authors: Scott Poretsky, Quarry Technologies Shankar Rao, Qwest Communications 60th IETF Meeting – San Diego Accelerated Stress Benchmarking draft-ietf-bmwg-acc-bench-term-03.txt.
Authors: Scott Poretsky, Quarry Technologies Brent Imhoff, LightCore
Booting up on the Home Link
draft-white-i2rs-use-case-02
Homenet Architecture Discussion
Ingress Filtering, Site Multihoming, and Source Address Selection
Link-State Routing Protocols
100% REAL EXAM QUESTIONS ANSWERS
Chapter 2: Static Routing
FAR: A Fault-avoidance Routing Method for Data Center Networks with Regular Topology Please send.
Internet Control Message Protocol (ICMP)
IP Forwarding Relates to Lab 3.
Chapter 2: Static Routing
MPLS Network Carry Voice Real Time Protocol (RTP)
Internet Control Message Protocol (ICMP)
Link-State Routing Protocols
IS-IS Flooding Reduction in MSDC
Link-State Routing Protocols
The Routing Table: A Closer Look
Networking and Network Protocols (Part2)
IP Forwarding Relates to Lab 3.
Computer Networks ARP and RARP
Figure 6.11 Configuration for Example 4
Computer Networks Protocols
Sécurisation au niveau 2 pour certains matériels Cisco
IPFRR WITH FAST NOTIFICATION
Presentation transcript:

Benchmarking for CoPP draft-shishio-bmwg-copp-00 Shishio Tsuchiya

RFC6192 CoPP Control Plane Protection Protect router's control plane from undesired or malicious traffic | Router Control | | Plane | | | Router Control Plane Protection | | | Forwarding | Interface X ==[ Plane ]== Interface Y Figure 1: Router Control Plane Protection

Background Business: Router less service Consumer: FTTH/DDoS Data center: Large Scale ARP/NDP, DDOS Test by themself, no standard

2. Test setup 2.1. Topology DUT connect to Router/Attack Emulator/Traffic Generator | | | DUT | | | | | | | Router Control | | | | Plane | | | | | | | | | Router Control | | Plane Protection | | | | | | Attack | | | | Emulator |---|---[ | | | | Forwarding | | |---[ Plane ]---|----| Router |---+ | | | | | | | | | Traffic | | Generator |

2.2. Network Configure IGP/OSPS between DUT and Router DUT configure CoPP if needed

3. Test procedure 3.1. Attack Packet Attack Emulator : send packets to DUT to confirm influence of CoPP Test duration time should be grater than hold time between UUT and Router Attack Emulator

Attack Packet exampleexpect action Typicalfragment/ip option/ ICMP ttl exceed drop/rate-limit Routing Protocol from trust network BGP/OSPFaccept but rate-limit would be preferred Routing Protocol from untrust network BGP/OSPFdrop Control Packet from trust network ARP/NDP/ICMP/ICMPv6 accept but rate-limit would be preferred Control Packet from un- trust network ARP/NDP/ICMP/ICMPv6drop/rate-limit Management Packet from trust network NTP/SSH/Telnet/Radius/D NS/DHCP accept/rate-limit Management Packet from un-trust network NTP/SSH/Telnet/Radius/D NS/DHCP drop undefined packetsIPX/Appletalkdrop Will update in detail in future version

Test result | Attack | Attack | Attack | Loss of packets on | | | rate[pps/bps] | duration time | traffic generator | | - | - | - | - | CPU Utilization of DUT will be added

Ask to WG Is the draft useful for the WG? Any idea of the scenario – test procedure – confirmation of stability