30
Operation TF

Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Embed Size (px)

Citation preview

Page 1: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Operation TF

Page 2: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

まとめ• 発表の目的

– Operator TFの円滑な議事進行

• 議題、提案点その他– 次のスライドを参照願います

• 結論– アナウンス– スケジュールや手法、役割分担など具体的な実行計画を伴う合意

Page 3: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Agenda

• UDL Operation

• UDL 13Mbps bandwidth extension

• IPv4 Routing on UDL

• Other Routing Issues

• New network design in SFC

• Security

Page 4: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

UDL Operation

Page 5: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Topics• Report

– UDL13Mbps extension and UDstation installation done– Keio establish maintenance contracet with UDcast for UDstation and UDbox– Backup UDstation and UDboxes will arrive soon

• Backup UDStation box– Coming Soon– TBD Later

• MTU 1500 on UDL– MTU 1452 on UDL should be legacy (SONY Feed problem)– TBD Later

• Issues on UDstation 13Mbps Performance– Configuration is 13Mbps but actual output by MRTG is around 10Mbps– TBD Later

• IPv4 routing on UDL– Install Private IPv4 for routing on the UDL (schedule and design)– TBD Later

Page 6: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Backup UDstation and UDbox

• Expected arrival date

• Direction of operation

• Expected topology including backup UDstation

Page 7: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

MTU 1500 on UDL

• Current status– 1500 on sfc-udl-feed and ITB

• ospf6dでは ipv6 ospf6 mtu 1452

– 1452 on others– OSPFv2 with ITB is okay– OSPFv3 with all uses if mtu 1452 definition in ospf6d.conf

• AI3 Meeting後に Operator Meetingを開催して変更をします。– 各サイトの RRにて、 UDL I/FのMTUを 1500に変更します。– スケジュール未定– TSペイロード長を考慮したMTUを設定

Page 8: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Issues on UDStation 13Mbps Performance

Page 9: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

UDStation 13Mbps Performance

• TCP tests on UDL:– Multiple wget sessions on SFC RO2:

• web server is sfc-cpu, output is /dev/null• MTU is 1500

• Output is around 10Mbps (less than smartbit results)

Page 10: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Comparing the ResultsTCP Throughput

0

2

4

6

8

10

12

1 2 3 4 5

Attempts

Thro

ughp

ut (M

bps)

udboxsonyboxiperf TCP results:

Around 11Mbps

Wget results:Around 10Mbps

MRTGSfc-udl-feed:bge1

Page 11: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Testing direction and announcement

• Do more tests to confirm– iperf vs wget– Smartbit UDP vs iperf UDP

• If wget or iperf is less than Smartbit:– Why?– Contact UDcast?

• Use tcpdump, then gets more accurate number

• UDL maybe blocked for testing

Page 12: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

IPv4 routing on UDL

Page 13: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Routing for AIT and ITB

• BDL bandwidth changes due to UDL 13Mbps migration– SFC-ITB and SFC-AIT are 128kbps

• OSPFv2 is running on UDL• Neighbor: ITB, AIT should be neighbor, too.• Prefer routes via UDL than BDL

Page 14: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Install Private IPv4 for routing on the UDL

• Background

• Discussion

• Design

• Schedule

Page 15: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Other Routing Issues

Page 16: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

SFC installed a Cisco Router

• SFC installed Cisco with 5 I/Fs

• Show current status and changes made in the routing /topology

Page 17: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Connection to WIDE Fujisawa NOC

AI3 switchWIDE switch

gsr1.fujisawa

sfc-gate

202.249.26.1142001:d30:101:4::2

202.249.26.1132001:d30:101:4::1

100-TXTaggedVLAN:31,49,140

foundry1S3/23

fa0/1

fa0/29

sfc-c7200

202.249.26.1152001:d30:101:4::3

1G-SXTaggedVLAN:31,49,140

Cisco 12000

202.249.26.1162001:d30:101:4::4

?

?

BGP backup BGP backupBGP MAIN

BGP MAIN

?

gi0/2

gi0/1 vlan 200gi0/2 vlan 140gi0/3 vlan 49fa5/0 vlan 31

Page 18: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

M6bone

• Current status:– Tunnel with RENATER using sfc-c7200-gate– Failure on advertising AI3 prefix to RENATER

• Trouble shooting is on-going

• Next:– Move c7200 to AI3 rack– BGP peers Fujisawa cisco 12000– Push APAN-JP and TEIN2 to activate PIM-S

M and MBGP

Page 19: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

FreeBSD-specific Issues

• Routing socket issue FreeBSD 4.10 ~– Kernel doesn’t inform all route deletes if too

many deletes in a small period• Ex: route flush

– Result: Zebra doesn’t reinstall all routes deleted by, e.g., route flush

• Husni patched zebra code– Already run on some routers in AI3– Should let others know

Page 20: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Multicast Routing: XORP Issues

• SOI Asia is using XORP 1.1– Some bugs. E.g.: doesn’t update MRIB if ther

e are changes in kernel

• Should upgrade to XORP 1.3 + patches– Unpatched XORP 1.3 has next-hop interface

problem in MRIB

Page 21: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

AI3 SFC NetworkMiddle-term Design

Page 22: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Todos for preparation

• Show the final topology

• Show the intermediate topology for the near future (Change topology with current cisco) and discuss routing and addressing

Page 23: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

sfc-ro1-gate

sfc-ro2-gate

sfc-udbox sfc-udbox2

C-band BDLs

C-band BDLs

sfc-bridge

WIDEWIDENSPIXP6NSPIXP6APANAPAN

NAISTNAIST

sfc-gate sfc-gate2

Sfc-udl-feed

Page 24: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Generic Requirement

• Less operational cost and more stability– Integrate some PC routers to Cisco routers– Distinguish challenge and stable operation (ex. sfc-udl

-feed)

• Capability of fiber optic connections in backbone• Redundancy against hardware troubles

– Backup for core routers– Backup for UDstation

• Interoperability between challenge and stabile operation IPv6 deployment

Page 25: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Less operational cost and more stability

• Integrate some PC routers to Cisco routers– Decrease the risk for hardware trouble

• Trials with PC router like sfc-udl-feedv.s backup using Cisco router– Need to clear out the minimum interoperability

between challenge and stable operation

Page 26: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Capability of fiber optic connections in backbone

• For the future operation, routers and switches connecting to the backbone may need gigabit Ethernet interface

Page 27: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Redundancy against hardware troubles

• Duplicate some important routing entities– sfc-gate– sfc-udl-feed– sfc-sat– sfc-udstation

Page 28: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

IPv6 deployment

• Server upgrade– WEB Cache– DNS– SOI-Asia applications?

• Routing in the UDL network– IPv6 for all SOI-Asia partners– Private IPv4 for a part of partners

• BDL partners

• IPv6-only connection for new RO sites

Page 29: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

Security

Page 30: Operation TF. –Operator TF – Agenda UDL Operation UDL 13Mbps bandwidth extension IPv4 Routing on UDL Other Routing Issues New network design in SFC Security

– Unsrat Open Proxy– Show and confirm the ai3 security policy