Unexpected traffic in LHCONE ?

Slides:



Advertisements
Similar presentations
Release 5.1, Revision 0 Copyright © 2001, Juniper Networks, Inc. Advanced Juniper Networks Routing Module 9: Static Routes & Routing Table Groups.
Advertisements

KIT – University of the State of Baden-Wuerttemberg and National Research Center of the Helmholtz Association Steinbuch Centre for Computing (SCC)
Discussion Monday ( ). ver length 32 bits data (variable length, typically a TCP or UDP segment) 16-bit identifier header checksum time to live.
TCOM 509 – Internet Protocols (TCP/IP) Lecture 06_b Subnetting,Supernetting, CIDR IPv6 Instructor: Dr. Li-Chuan Chen Date: 10/06/2003 Based in part upon.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Introduction to IPv4 Introduction to Networks.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
1 [Lab] 6to4 Tunnels. 2 Pre-requisite Reading RFC 3056 – Connection of IPv6 Domains via IPv4 Clouds Y. Hei and K. Yamazaki, " Traffic analysis and worldwide.
Chapter 21 Exercises 1. A router forwards packets between networks. (Given a destination host address, it must be able to figure out which network that.
Network Layer4-1 Hierarchical Routing scale: with 200 million destinations: r can’t store all dest’s in routing tables! r routing table exchange would.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—2-1 BGP Transit Autonomous Systems Monitoring and Troubleshooting IBGP in a Transit AS.
Chapter 4: Network Layer 4. 1 Introduction 4.2 Virtual circuit and datagram networks 4.3 What’s inside a router 4.4 IP: Internet Protocol –Datagram format.
CEG3185 Tutorial 7 Routers and Routing. IP Address An Internet Protocol address (IP address) is a numerical label assigned to each device (e.g., computer,
CS 164: Global Internet Slide Set In this set... More about subnets Classless Inter Domain Routing (CIDR) Border Gateway Protocol (BGP) Areas with.
11- IP Network Layer4-1. Network Layer4-2 The Internet Network layer forwarding table Host, router network layer functions: Routing protocols path selection.
Chapter 2 Internet Protocol DoD Model Four layers: – Process/Application layer – Host-to-Host layer – Internet layer – Network Access layer.
Network Layer Moving datagrams. How do it know? Tom-Tom.
CCNA Introduction to Networking 5.0 Rick Graziani Cabrillo College
Internet Technologies and Applications
IP (Internet Protocol) –the network level protocol in the Internet. –Philosophy – minimum functionality in IP, smartness at the end system. –What does.
1 IP: putting it all together Part 2 G53ACC Chris Greenhalgh.
Network Tools TCP/IP interface configuration query - MAC (HW) address and IP address – Linux - /sbin/ifconfig – MS Windows – ipconfig/all 1.
1 Computer Communication & Networks Lecture 22 Network Layer: Delivery, Forwarding, Routing (contd.)
The Hebe-jebes (or He-B-GPs): Understanding the Roles of EBGP, IBGP and an IGP Using Lab 7-4, IBGP, Next Hop and Synchronization Rick Graziani Cabrillo.
TCOM 515 IP Routing. Syllabus Objectives IP header IP addresses, classes and subnetting Routing tables Routing decisions Directly connected routes Static.
1 Internet Control Message Protocol (ICMP) Used to send error and control messages. It is a necessary part of the TCP/IP suite. It is above the IP module.
© 2012 Juniper Networks, Inc. All rights reserved. | | Worldwide Education Services Chapter 2: Routing Fundamentals Junos Routing Essentials.
1 Objectives Identify the basic components of a network Describe the features of Internet Protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6)
CCNP Network Route IPV-6 Part-I IPV6 Addressing: IPV-4 is 32-BIT, IPV-6 is 128-BIT IPV-6 are divided into 8 groups. Each is 4 Hex characters. Each group.
A Measurement Study on the Impact of Routing Events on End-to-End Internet Path Performance Feng Wang 1, Zhuoqing Morley Mao 2 Jia Wang 3, Lixin Gao 1,
CIDR Classless Inter Domain Routing Give the IP address space some breathing room! Basic idea: allocate the remaining IP addresses in variable-size blocks.
Network Layer4-1 Datagram networks r no call setup at network layer r routers: no state about end-to-end connections m no network-level concept of “connection”
Lesson 2 – IP Addressing IP Address (IPv4 – Version 4) Private and Public Address Brief Introduction to IPv6 – Version 6.
1 | Bruno Hoeft, KIT / AutoKNF - LHC(OPN/ONE), 06/17/13 | Karlruhe Institute of Technology (KIT) Bruno Hoeft (KIT/SCC) AutoKNF – status June 2013.
Review of IPv4 Routing Veena S, MCA Dept, PESIT Mar 09-10, 2013.
1 Lecture, November 20, 2002 Message Delivery to Processes Internet Addressing Address resolution protocol (ARP) Dynamic host reconfiguration protocol.
1 Lecture 11 Routing in Virtual Circuit Networks Internet Addressing.
1 Objectives Identify the basic components of a network Describe the features of Internet Protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6)
CHAPTER 6: STATIC ROUTING Static Routing 2 nd semester
Border Gateway Protocol. Intra-AS v.s. Inter-AS Intra-AS Inter-AS.
1 | Bruno Hoeft, TNC2012 | Karlruhe Institute of Technology (KIT) Bruno Hoeft (KIT/SCC) Co-Authors: Kostas Stamos (CTI), Tangui Coulouarn (UNI-C)
Computer Networks 0110-IP Gergely Windisch
Network Layer IP Address.
CSE 421 Computer Networks. Network Layer 4-2 Chapter 4: Network Layer r 4. 1 Introduction r 4.2 Virtual circuit and datagram networks r 4.3 What’s inside.
Network Overview. Protocol Protocol (network protocols) - a special set of rules that define communication between two or more devices on a network.
Routing in the Internet
14 – Inter/Intra-AS Routing
Homework 4 Out: Fri 2/24/2017 In: Fri 3/10/2017.
Working at a Small-to-Medium Business or ISP – Chapter 6
LHC[OPN/ONE]  IPv6  status
Chapter 6 Delivery & Forwarding of IP Packets
COMP2322 Lab 5 IP Steven Lee March 22, 2017.
Ipv6 addressing Chapter 5d.
Addressing the Network – IPv4
Homework 4 Out: Fri 2/26/2016 In: Fri 3/11/2016.
COMPUTER NETWORKS CS610 Lecture-33 Hammad Khalid Khan.
Chapter 2: Static Routing
Chapter 2: Static Routing
Static Routing 1st semester
© 2006 ITT Educational Services Inc.
Part 4: Network Layer Part B: The Internet Routing Protocols
Ct1304 Lecture#4 IPV4 Addressing Asma AlOsaimi.
Charles Warren and Ben Kangas
Working at a Small-to-Medium Business or ISP – Chapter 6
COMP/ELEC 429/556 Introduction to Computer Networks
Static Routing 2nd semester
Computer Networks Protocols
[Lab] 6to4 Tunnels.
Lecture#3-IPV4 Addressing
Presentation transcript:

Unexpected traffic in LHCONE ? Bruno Hoeft / KIT Kars Ohrenberg / DESY

LHCONE Bruno Hoeft / Kars Ohrenberg – LHCONE – KEK – 17st Oct. 17

Data exchange only between connected sites Cidr exchange via BGP LHCONE policy VPN Data exchange only between connected sites Cidr exchange via BGP Follow the aup Participating collaborations Scope of sites/nodes Roles and Responsibilities Bruno Hoeft / Kars Ohrenberg – LHCONE – KEK – 17st Oct. 17

LHCONE miss-routed At DESY / KIT / ASGC Data from non LHCONE received Multiple captures over 4 to 24 hours KIT  135 ipv4 (/24 ?) subnets + 16 ipv6 (/64 ?) subnets incl. private addresses (10.x.x.x, 172.16.x.x, 192.168.x.x) DESY  203 ipv4 (/24 ?) subnets + 26 ipv6 (/64 ?) subnets incl. private addresses Limited averlapping only at DESY and KIT (approx. 15%) ASGC  reported miss-routed data Ports: icmp pcsync-https (8443), domain (53), 20000-25000 eyetv (2170) … Only a vage suggestion : AMS-IX Bruno Hoeft / Kars Ohrenberg – LHCONE – KEK – 17st Oct. 17

Reverse check of KIT/DESY most source addresses (no private addr.) „reachable“ (ping) Packets not routed to LHCONE traceroute from DESY/KIT not via LHCONE Bruno Hoeft / Kars Ohrenberg – LHCONE – KEK – 17st Oct. 17

Suggestions: how to avoide Avoiding (only some ideas): Sites configure routing AUP acordingly Reverse path forwarding (RPF) check at sites/NREN At Reginal internet registries hosted LHCONE prefix table NREN controlled and mantained table … Bruno Hoeft / Kars Ohrenberg – LHCONE – KEK – 17st Oct. 17

Questions Suggestions Discussion Bruno Hoeft / Kars Ohrenberg – LHCONE – KEK – 17st Oct. 17

UNI-Mainz to ASGC [root@f01-120-126-e ~]# traceroute 117.103.103.71 -I traceroute to 117.103.103.71 (117.103.103.71), 30 hops max, 60 byte packets 1 192.108.68.2 (192.108.68.2) 0.613 ms 0.775 ms 0.979 ms 2 * * * 3 * * * 4 cr-fra2-hundredgige0-9-0-1-704.x-win.dfn.de (188.1.153.65) 3.042 ms 3.116 ms 3.272 ms 5 geant-lhcone-gw.mx1.fra.de.geant.net (62.40.126.184) 2.917 ms 2.948 ms 2.953 ms 6 62.40.126.229 (62.40.126.229) 20.562 ms 20.735 ms 20.709 ms 7 asgc-lhcone-gw.ams.nl.geant.net (62.40.126.230) 20.092 ms 20.128 ms 20.173 ms 8 e-1-3.r0.chi.asgc.net (117.103.111.202) 121.144 ms 121.170 ms 121.184 ms 9 e-1-2.r2.tpe.asgc.net (117.103.111.206) 303.109 ms 303.001 ms 302.998 ms 10 * * * 11 f-arc02.grid.sinica.edu.tw (117.103.103.71) 303.004 ms 303.001 ms 302.997 ms [root@mgftp1 ~]# traceroute -I 117.103.103.71  1  g1341-ms3d-1.zdv.Uni-Mainz.DE (134.93.168.125)  1.086 ms  1.743 ms  2.401 ms  2  134.93.255.177 (134.93.255.177)  0.341 ms  0.376 ms  0.449 ms  3  g1341-0033-1.zdv.Uni-Mainz.DE (134.93.254.5)  0.720 ms  0.780 ms  0.839 ms  4  g-uni-mz-1.rlp-net.net (217.198.241.33)  3.293 ms  3.560 ms  3.714 ms  5  g-uni-klinik-mz-1.rlp-net.net (217.198.241.6)  1.693 ms  1.926 ms  2.121 ms  6  g-interxion-1.rlp-net.net (217.198.240.101)  0.985 ms  0.924 ms  0.939 ms  7  te-0-0-6-561.core1.fra1.ix.f.man-da.net (82.195.78.5)  1.014 ms  0.938 ms  1.136 ms  8  te-0-2-0.peer1.sara.ams.man-da.net (82.195.67.90)  6.305 ms  6.214 ms  6.222 ms  9  * * * 10  e-1-3.r0.chi.asgc.net (117.103.111.202)  103.192 ms  103.175 ms  103.161 ms 11  e-1-2.r2.tpe.asgc.net (117.103.111.206)  289.224 ms  289.224 ms  289.219 ms 12  v3967.n7k.tpe.asgc.net (117.103.111.233)  286.798 ms  285.475 ms  285.456 ms 13  f-arc02.grid.sinica.edu.tw (117.103.103.71)  289.221 ms  289.210 ms  289.190 ms Bruno Hoeft / Kars Ohrenberg – LHCONE – KEK – 17st Oct. 17