Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
presentation
Jun 2009
11
Agenda
Need to develop an alternate solution for supporting Internet Direct & other services (SIA,
NBIG, BEW…) relying on GIBN today
GIBNv2 : Pilot test in Caracs 3
GIBN Architecture Evolution : Internet support on IGN
> Possible solutions considered :
- Keep dedicated Internet network : discarded due to massive investment required to replace
current CS75xx)
- Use of OTI network limited due to OTI network coverage (29 cities in 11 countries ) and
inappropriate high-end platforms to support low-speed GIBN connections
Solution retained is to rely on IGN to provide access / aggregation layer for Internet
services leveraging current infrastructure
> IGN will be turned into Multiservice network (supporting Internet + IPVPN)
> Internet gateways:
- Will support the Peering and Transit connections
- Will provide Internet access to the shared IGN Internet VRF through the PE-ASBR
- Will be deployed outside IGN AS (seen as a CE from IGN) using current GIBN ASes
> Access PE :
- Creation of a new VRF “internet_shared VRF” on all IGN PEs that will be supporting internet customers
(solution compliant with security constraints thanks to VRF isolation / no Internet in GRT)
- Customers requiring Internet Direct will be meshed to the shared “internet_shared VRF”
> PE-ASBR:
- Will support interconnection with Internet gateways
- Internet gateway meshed in a specific VRF ‘internet_gibn_gateway VRF’ on these PE-ASBR
- May also support access PE function
> Introduction of a new C3 class in the IGN backbone CoS model for Internet traffic
- Solution already implemented on RAEI
- Internet traffic with IP Precedence 0 mapped into C3 class
GIBN AS
Internet GW Internet GW Regional
Regional
Peering iBGP Peering
PE-ASBR PE-ASBR
PE-ASBR
Internet GW Local
Peering
Access PE PE-ASR/
Access PE
CPE (Static)
CPE (BGP)
IGN
CPE (Static)
- Dismantlement of GIBN
•Migration of non-customer connections (IDAR/LAN Server…)
Target is to phase-out GIBN by mid/end 2010
> During the phase 1 we will have customers connected to both GIBN and
IGN infrastructure
> Traffic flow for customers connected to GIBN and other GIBN
customers, peering partners and transit providers will remain unchanged
> Traffic between a customer connected to IGN and a customer connected
to GIBN will go through the IGW-PE-ASBR interco
Country A
Internet cust
on IGN
IGW
Country C Access Country B
PE
internet_sha
red VRF
internet_sha internet_gib
Internet cust Access red VRF n_gateway PE-ASBR
on IGN PE IGN VRF
internet_sha
red VRF Internet cust
Access on IGN
PE
GIBN GIBN
Region 2 Region 1
GIBN Cust
Country A
Country C
IGW
IGW
IAR
IAR
IGW Country B
GIBN Cust PE-ASBR
PE-ASBR internet_gib
n_gateway
internet_gib VRF
n_gateway internet_gib
VRF n_gateway PE-ASBR
IGN VRF
internet_sha
red VRF
Access Internet cust
PE on IGN
GIBN GIBN
Region 2 Region 1
Global Transit
PE-ASBR PE-ASBR
internet_gib internet_gib
n_gateway n_gateway
VRF VRF
IGN internet_sha
red VRF
internet_gib
n_gateway
Internet cust
VRF PE-ASBR on IGN
+Access PE
IAR/ICR
We will keep
domestic traffic from GIBN
Country B
going to Global
transit IGW
GIBNv2 : Pilot test in Caracs 14
GIBN Cust
Traffic flows: IGN customer to GIBN customer between countries
with or without transit/peering where RTD will be impacted if
routing using default route
> In cases following the default route for IGN customer to GIBN customer traffic between two countries will lead to an unacceptable
RTD increase, on this cases we will make an exception and allow the advertisement of GIBN routes for this country into IGN,
limiting the propagation of this routes within IGN only to the countries that will otherwise suffer an unacceptable RTD increase.
Global Transit
PE-ASBR
PE-ASBR
internet_gib internet_gib
n_gateway n_gateway
VRF VRF
internet_gib internet_sha
n_gateway red VRF
Access PE
VRF
PE-ASBR
IGW
Internet cust
GIBN on IGN
Country A
IGW
PE-ASBR
internet_gib
n_gateway
VRF
internet_gib
n_gateway
IGW VRF
internet_sha
internet_sha
red VRF
PE-ASBR red VRF
Access PE
Access PE
Internet cust
GIBN on IGN
Country B
Internet cust
Country C on IGN
> Traffic will be transported over IGN to the PE-ASBR in the country hosting the
local/regional transit/peering connection.
Global Transit
Country A
IGW IGW
internet_gib internet_gib
n_gateway n_gateway
PE-ASBR VRF VRF
Regional Transit IGW +Access PE internet_gib
and/or n_gateway
VRF
Peering internet_sha IGN
red VRF
Access PE
PE-ASBR
internet_s
+Access PE
hared VRF
internet_gib
internet_sha
n_gateway
red VRF
VRF IGW
Internet cust
GIBN on IGN
All Internet routes on IGN VRF Importing RT1 VRF permits only CT1 and CT3 (from
(As seen on IGN RR) and RT3 within the RT1 & RT3 routes, RT2 routes
are not considered)
> After all (or most) customers in a country have been migrated to IGN,
aggregates will also be migrated to IGN:
- Country aggregate and sub country aggregate will be generated from the
“internet_shared VRF”
- Regional and Global aggregates will be generated from the
“internet_gibn_gateway”
26
26
GIBNv2 Pilot : customer Digitel in VE
> Customer requirements : GE access with 100Mbps Internet in Caracas
(requiring major upgrade on GIBN)
> Solution proposed (under implementation)
- Customer to be connected on newly deployed BCCS810 (CS76xx)
- 2xGE Interconnections of PE-ASBR (ESR) with GIBN Head Routers in JAE & JAO for
Transit traffic
- FE Interconnection of PE-ASBR BCCS810 with GIBN IAR in CCS for local tfc
> Will allow better utilization of OC12 circuit on BCCS500 (Without the need of
deploying new AGN AToM links)
> Current status:
- Physical interconnection between BJAO411-BJAO518 (GE) completed
- Physical interconnection between BJAE411-BJAE518 (GE) completed
- Physical interconnection between BCCS305-BCCS810 (FE) completed
> The interconnection between BCCS305 and BCCS810 is needed to avoid traffic from a
CCS internet cust connected to GIBN going through Atlanta to reach a CCS internet
customer connected to IGN
> New customer access circuit is under deployment by local carrier
BJAE411 BJAO411
GE9/0 GE2/0
GE1/0/0 GE2/0/0
BJAO518
BJAO518
GE2/2/0
GIBN IGN
BCCS810 KCCS510
Digitel CE
FE8/1/0
BCCS403
FE1/0/0
BCCS423 BCCS305
eBGP
Set LP=110 & CT=6505:9100
eBGP
-SAM customer RT
-Permit IGN originated PI, PA & RL & Aggr with -SAM Aggregate RT
nominal LP (i.e no <ASN>:80/110)
Filtering via import route-map
Set LP=120 & CT=6505:9100 BJAE518 BJAO518
-Deny GIBN originated routes
internet_gib internet_gib -Permit IGN originated PI, PA, RL
IMPORT Rules
RTs to be imported
n_gateway GIBN n_gateway & Aggr routes from VE
-Global cust and aggregate RTs VRF VRF EXPORT Rules
-Export PI,PA & RL of VE GIBN
- SAM cust RT
connected cust
-The SAM default route RT IGN interne
tag with SAM cust RT
Filtering via import route-map internet t_gibn
-Deny GIBN originated PI, PA & RL (with the BCCS810à BCCS305 advertisements _share _gatew
exception VE GIBN cust routes) -Deny GIBN originated routes d VRF ay VRF BCCS305à BCCS810 advertisements
-Permit global IGN originated PI, PA & RL & -Advertise CCS IGN cust PI, PA & RL -Deny IGN originated routes
Aggr Set CT=6505:9100 -Advertise CCS GIBN cust PI, PA & RL
-Permit primary and backup 0/0 -Advertise CCS IGN originated Aggr BCCS810 Set CT=6505:9200
eBGP
EXPORT Rules Set CT=6505:9100 Incoming filtering on BCCS305 side
-Export PI,PA & RL of cust connected to this Incoming filtering on BCCS810 side -Deny GIBN originated routes
PE -Deny IGN originated routes -Permit CCS IGN originated PI, PA & RL
tag with global & SAM cust route RTs -Permit CCS GIBN originated PI, PA & RL with with Inter-AS tag (<ASN>:80)
- Export the VE country Aggregates Inter-AS tag (<ASN>:80) BCCS305 Set LP=80 & CT=6505:9100
tag with global & SAM Aggr route RTs Set LP=80 & CT=6505:9200 -Permit CCS IGN originated PI, PA & RL
-Permit CCS GIBN originated PI, PA & RL with with MCS backup tag (<ASN>:110)
MCS backup tag (<ASN>:110) Set LP=110 & CT=6505:9100
Set LP=110 & CT=6505:9200 -Permit IGN originated PI, PA & RL &
-Permit CCS GIBN originated PI, PA & RL with Aggr with nominal LP (i.e no <ASN>:80/
nominal LP (i.e no <ASN>:80/110) 110)
Set LP=120 & CT=6505:9200 Set LP=120 & CT=6505:9100
GIBNv2 : Pilot test in Caracs 29
GIBNv2 CCS Pilot: Traffic flows
OAKBB1 FTLD
NAM GIBN AS 5511 ATLCR3
Cust
BJAE518
BJAO518
IGN
Digitel
BCCS810
GIBN GIBN
NAM NAM BCCS305
Transit and/or
peering IMPORT Rules
RTs to be imported
-SAM customer RT
-SAM Aggregate RT
BJAO411 Filtering via import route-map
-Deny GIBN originated routes
BJAO518 -Permit IGN originated PI, PA, RL
EXPORT Rules & Aggr routes from all SAM
-Export 0/0 countries
internet_gib
tag with SAM default route RT
n_gateway
VRF
IGN
GIBN
IMPORT Rules
RTs to be imported
-SAM customer RT
-SAM Aggregate RT
BCCS305 Filtering via import route-map
-Deny GIBN originated routes
EXPORT Rules BCCS810 -Permit IGN originated PI, PA, RL
-Export PI,PA & RL of VE GIBN connected cust & Aggr routes from VE
tag with SAM cust RT internet_gib
n_gateway
VRF
IGN
GIBN
Internet cust
on IGN
EXPORT Rules
-Export PI,PA & RL of cust connected
to this PE IMPORT Rules
tag with global & SAM cust route RTs RTs to be imported
- Export the VE country Aggregates -Global cust and aggregate RTs
tag with global & SAM Aggr route RTs - SAM cust RT
BCCS810
-The SAM default route RT
Filtering via import route-map
internet_sha -Deny GIBN originated PI, PA & RL (with the
red VRF exception VE GIBN cust routes)
-Permit global IGN originated PI, PA & RL &
Aggr
IGN -Permit primary and backup 0/0
GIBN
OTI Transit
eBGP
Note: There are no SAM internet customers or Set LP=80 & CT=6505:9100
peering in JAO, BJAO411 will onl advertise 0/0 to -Permit IGN originated PI, PA & RL with
BJAO518 MCS backup tag (<ASN>:110)
BJAO518
Set LP=110 & CT=6505:9100
-Permit IGN originated PI, PA & RL & Aggr
internet_gib with nominal LP (i.e no <ASN>:80/110)
n_gateway Set LP=120 & CT=6505:9100
VRF Note: BJAO411 will accept routes from all
countries in SAM
IGN
GIBN
OTI Transit
BJAO518à BJAO411 advertisements
-Deny GIBN originated routes
-Advertise IGN cust PI, PA & RL
Set CT=6505:9100 BJAO411
-Advertise IGN originated Aggr Incoming filtering on BJAO518 side
Set CT=6505:9100 -Deny IGN originated routes
eBGP
Note: BJAO518 will advertises cust and Aggr -Permit Default route
routes from all the region to BJAO411 Set LP=120 & CT=6505:9200
Note: There are no SAM internet customers
or peering in JAO, BJAO518 will only
BJAO518
receive 0/0 from BJAO411
internet_gib
n_gateway
VRF
IGN
GIBN
eBGP
Set LP=80 & CT=6505:9100
-Advertise CCS GIBN cust PI, PA & RL -Permit CCS IGN originated PI, PA & RL
Set CT=6505:9200 with MCS backup tag (<ASN>:110)
BCCS810 Set LP=110 & CT=6505:9100
-Permit IGN originated PI, PA & RL & Aggr
internet_gib with nominal LP (i.e no <ASN>:80/110)
n_gateway Set LP=120 & CT=6505:9100
VRF Note: For all cases above only the routes
from CCS will be allowed
IGN
GIBN