Skip to Content.
Sympa Menu

ntacpeering - Re: R&E route policy with other NRENs

Subject: NTAC Peering Working Group

List archive

Re: R&E route policy with other NRENs


Chronological Thread 
  • From: Nicholas Buraglio <>
  • To: David Farmer <>
  • Cc: Michael H Lambert <>,
  • Subject: Re: R&E route policy with other NRENs
  • Date: Sat, 07 Apr 2018 23:02:31 +0000
  • Ironport-phdr: 9a23:xSiUix1rgyatyMpMsmDT+DRfVm0co7zxezQtwd8ZseMQLPad9pjvdHbS+e9qxAeQG9mDsLQc06L/iOPJYSQ4+5GPsXQPItRndiQuroEopTEmG9OPEkbhLfTnPGQQFcVGU0J5rTngaRAGUMnxaEfPrXKs8DUcBgvwNRZvJuTyB4Xek9m72/q99pHPbQhEniaxba9vJxiqsAvdsdUbj5F/Iagr0BvJpXVIe+VSxWx2IF+Yggjx6MSt8pN96ipco/0u+dJOXqX8ZKQ4UKdXDC86PGAv5c3krgfMQA2S7XYBSGoWkx5IAw/Y7BHmW5r6ryX3uvZh1CScIMb7Vq4/Vyi84Kh3SR/okCYHOCA/8GHLkcx7kaZXrAu8qxBj34LYZYeYP+d8cKzAZ9MXXWVOXshTWCxbAo2yYYgBAfcfM+lEtITyvUcCoAGkCAWwGO/iyDlFjWL2060g1OQhFBnL0hQhH90SsHTUq9H1O70JUeuo0aTI0C/DYOlZ2Tf56YjIdQ0qrPaXUrJta8re00YvFwfEjlWXsoHqISiV2v4Ls2eF8+ptTOSigHMppQF2pzig3MYsio/Ri44L11zJ9D91zJg7KNC4UkJ3f8CoHZpKuy2GL4d7Td0uT3trtSs00LEKpJC2cSoQxJg73xLSZOKLf5KL7x/tTuqdPDl1iXF/dL6jnxq+71WsxvHmWsWqylpHoTBJnsXUunwQ0xHe5dKLRuVy80qgwzqC0wHe5vtYLUwsiKbXNZ4szqQumpYPsknPBCD7lUvsgKOKbkko5/ak5uT9brn4upORNJV4hw7xP6g0hsCyB/kzPAsWX2WD5Oiwyr7u8Vf3TblQgfA6j7PVvZLHKcgDpKO0DBVZ3ps95xu/FTur08oUkWMaIF9BfB+KiZXiNUvUL/DiF/i/hkyhkDd1yPDCOb3sGpvNIWbMnbv7ebZy8EpcxBA8zdBY+ZJYErABIPTtVU/trNHUEwE1Pg+uz+vpEtlw2Z4SVXiND6OEKK/StEWH5uMrI+mCfo8VvzP9JuA+6P7zl382g1Adfa2o3ZsQc323AO9mL1+fYXXyntcNCX0KsRYmTOz2lF2CViZeZ3CuX60m+j47EJypApnZRoCshryB0zy2HplXZmBdFlCMCmnke5+FW/cKdCKdPNVhkjoaWri9VYMtzw+huxLny+kvEu2B1iQGtJ6r+tFv4uDJ3UU8/CZxAt61zmSLCWx4gzVbfTIu2LFDphl3102K3qx5hNRVDppV6u8afB09MMv6zud6DNT7QUrrY82AR1KnRZ3yCywrR901wtgmbl07Hdi+2EOQlxG2CqMYwuTYTKc/9bjRij2of55w

This is an interesting and likely unintentional issue. I can drive this discussion with the NREN community and perhaps suss out some details (and perhaps work out some policy or agreement). 

nb

On Sat, Apr 7, 2018 at 11:19 AM David Farmer <> wrote:
To be clear I'm not saying it is inappropriate UBUNTU or RENU to have a GGC in their R&E route table, I think that is a great idea for them. However, what I am saying, is that Internet2 should not accept such routes from them. Furthermore, in most cases, we should not advertise such routes to them either. The intent of services like GGC, Akamai, and anycast generally, is to service users as topologically close as possible. Accepting these routes from other NRENs into the Internet2 R&E route table, which most participants local-pref over regular Internet routes, or advertising these routes to other NRENS, defeats that intent and degrades Internet performance, which runs counter to Internet2's goals.

In the case of GGC and Akamai for sure, it would be more effective for Internet2 work with Google and Akamai to get service node placed in developing NRENs than to provide routing for these services. 

Thanks.

On Sat, Apr 7, 2018 at 10:30 AM, Michael H Lambert <> wrote:
In the same vein, I noticed last week that CUDI was leaking PNWGP and CENIC routes (and perhaps others) into the R&E network.  The result was a likely violation of Internet2 AUPs and not just bad routing practices.  The Internet2 NOC put a filter in at least for those ASNs and was reaching out to CUDI.  This was probably the result of broken configuration because the AS paths were "11537 CUDI X Y CUDI Z".

Michael

David Farmer wrote:
FYI, I just sent the following note the Internet2 NOC.  I think we need a set of ASNs that should not be accepted from other NRENs, This should include things like GGC nodes, DNS Root Server anycast nodes, AS112 nodes, global transit providers, etc...

There are several HE(AS6939) routes being leaked into the R&E route table.

*> 42.83.137.0/24 <http://42.83.137.0/24>     146.57.255.241        2735    202      0 11537 22388 7660 4641 4641 6939 24785 8763 8763 8763 8763 24151 i
*> 42.83.138.0/24 <http://42.83.138.0/24>     146.57.255.241        2735    202      0 11537 22388 7660 4641 4641 6939 28917 39134 15835 24406 i
*> 125.208.43.0/24 <http://125.208.43.0/24>    146.57.255.241        2735    202      0 11537 22388 7660 4641 4641 6939 28917 39134 15835 24406 i
*> 125.208.44.0/24 <http://125.208.44.0/24>    146.57.255.241        2735    202      0 11537 22388 7660 4641 4641 6939 28917 39134 15835 24406 i
*> 194.246.96.0/24 <http://194.246.96.0/24>    146.57.255.241        2735    202      0 11537 22388 7660 4641 4641 6939 24785 8763 31529 i
*> 210.2.4.0/24 <http://210.2.4.0/24>       146.57.255.241        2735     202      0 11537 22388 7660 4641 4641 6939 28917 39134 15835 24406 i
*> 216.235.226.0/24 <http://216.235.226.0/24>   146.57.255.241        2142    202      0 11537 40220 11164 6939 26202 i

Thanks

---------- Forwarded message ----------
From: *David Farmer* < <mailto:>>
Date: Sat, Apr 7, 2018 at 9:54 AM
Subject: RENU advertising GGC node
To: Internet2 NOC < <mailto:>>


RENU is advertising a GGC node via UBUNTU into the Internet2 R&E route table. Please stop accepting these routes from them. As these routes are in the R&E route table they were overriding at least one route (104.237.191.0/24 <http://104.237.191.0/24>) I learn from a GGC node in Minneapolis. I have dealt with this in my local route policy, but I suspect others may have an issue too.

Note AS36040 is the ASN Google uses for GGC nodes;
https://peeringdb.com/net/4319
https://peering.google.com/#/options/peering

*> 104.237.175.0/24 <http://104.237.175.0/24>   146.57.255.241        2749    202      0 11537 36944 327687 36040 i
*> 104.237.191.0/24 <http://104.237.191.0/24>   146.57.255.241        2749    202      0 11537 36944 327687 36040 i

Thanks.

--

--
===============================================
David Farmer <mailto:>
Networking & Telecommunication Services
Office of Information Technology
University of Minnesota
2218 University Ave SE        Phone: 612-626-0815
Minneapolis, MN 55414-3029   Cell: 612-812-9952
===============================================



--
Michael H Lambert, GigaPoP Manager             Phone: +1 412 268-4960
Pittsburgh Supercomputing Center/3ROX          FAX:   +1 412 268-5832
300 S Craig St, Pittsburgh, PA  15213 USA     




--
===============================================
David Farmer              
Networking & Telecommunication Services
Office of Information Technology
University of Minnesota  
2218 University Ave SE        Phone: 612-626-0815
Minneapolis, MN 55414-3029   Cell: 612-812-9952
===============================================
--
---
Nick Buraglio
Energy Sciences Network; AS293
Lawrence Berkeley National Laboratory

+1 (510) 995-6068



Archive powered by MHonArc 2.6.19.

Top of Page