16
S Hiding OSPF Transit-only Networks Yi Yang IETF 79

Hiding OSPF Transit-only Networks Yi Yang IETF 79

Embed Size (px)

Citation preview

S

Hiding OSPFTransit-only Networks

Yi YangIETF 79

What are transit-only networks?

Why to hide them?

Infrastructure security

Plus, downsize routing table and speed up convergence

How to hide them?

Point-to-Point networks

Broadcast networks

Non-Broadcast networks

LS Age = 0LS Type = 1LS ID = 1.1.1.1Adv. Router = 1.1.1.1Number of Links = 2

Link ID = 2.2.2.2Link Data = 10.1.1.1Type = 1Metric = 10

Link ID= 10.1.1.0Link Data = 255.255.255.252Type = 3Metric = 10

Point-to-Point

10.1.1.0/30.1

1.1.1.1

.2

2.2.2.2

LS Age = 0LS Type = 1LS ID = 2.2.2.2Adv. Router = 2.2.2.2Number of Links = 2

Link ID = 1.1.1.1Link Data = 10.1.1.2Type = 1Metric = 10

Link ID= 10.1.1.0Link Data = 255.255.255.252Type = 3Metric = 10

LS Age = 0LS Type = 1LS ID = 1.1.1.1Adv. Router = 1.1.1.1Number of Links = 1

Link ID = 2.2.2.2Link Data = 10.1.1.1Type = 1Metric = 10

Point-to-Point

10.1.1.0/30.1

1.1.1.1

.2

2.2.2.2

LS Age = 0LS Type = 1LS ID = 2.2.2.2Adv. Router = 2.2.2.2Number of Links = 1

Link ID = 1.1.1.1Link Data = 10.1.1.2Type = 1Metric = 10

Broadcast

10.2.2.0/24

.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.5

LS Age = 0LS Type = 2LS ID = 10.2.2.5Adv. Router = 5.5.5.5Network Mask = 255.255.255.0Attached Router = 3.3.3.3Attached Router = 4.4.4.4Attached Router = 5.5.5.5

Broadcast

10.2.2.0/24

.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.5

LS Age = 0LS Type = 2LS ID = 10.2.2.5Adv. Router = 5.5.5.5Network Mask = 255.255.255.255Attached Router = 3.3.3.3Attached Router = 4.4.4.4Attached Router = 5.5.5.5

Non-Broadcast: NBMA

Use /32 subnet mask, similar to Broadcast

Non-Broadcast: P2MP

10.3.3.0/24

.6

6.6.6.6

.7

7.7.7.7

.8

8.8.8.8

LS Age = 0LS Type = 1LS ID = 6.6.6.6Adv. Router = 6.6.6.6Number of Links = 3

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

Link ID= 10.3.3.0Link Data = 255.255.255.0Type = 3Metric = 0

Non-Broadcast: P2MP

10.3.3.0/24

.6

6.6.6.6

.7

7.7.7.7

.8

8.8.8.8

LS Age = 0LS Type = 1LS ID = 6.6.6.6Adv. Router = 6.6.6.6Number of Links = 2

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

OSPFv3

Remove IPv6 Prefixes from the intra-area-prefix-LSAs

Next Step

END

Backward Compatibility: Broadcast

10.2.2.0/24

.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.5

LS Age = 0LS Type = 2LS ID = 10.2.2.5Adv. Router = 5.5.5.5Network Mask = 255.255.255.255Attached Router = 3.3.3.3Attached Router = 4.4.4.4Attached Router = 5.5.5.5

Backward Compatibility: Broadcast

10.2.2.0/24

.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.51.1.1.1

7.7.7.7 8.8.8.8

Host B

Host A2.2.2.2

Upgraded Not-upgraded-yet