Protecting your
peering edge.
Graham Beneke
AfPIF 2015
#include std-disclaimer
IXP
Peer 3
Peer 1
Peer 2ISP
Expect to receive
traffic not destined
to your network.
You will need to protect your network!
FIB: NET_GREEN
NET_BLUE
NET_RED
FIB: NET_GREEN
NET_RED
IX
Route Reflector Client
Route Reflector
Peering Router
IXP
route-map filter-to-my-peering-router
match criteria only_my_customers
permit only_my_customers
Whom are you
protecting against?
IX
FIB: NET_GREEN
NET_BLUE
NET_RED
FIB: NET_GREEN
NET_RED
No valid 0/0
Partial
Routes
iACLs
1 32
• BGP advertisement
classification
• QoS Policy Propagation
via BGP (QPPB).
Step 1: Tag peer
prefixes uniquely within
BGP and FIB tables


- peer prefixes set with
community attribute (P)
and tag (P)
- customer prefixes are
set with community
attribute (C) and tag (C)
route-policy qosgroup_map
if community matches-any
set qos-group 7
elseif community matches-a
then
set qos-group 2
else
set qos-group 1
endifend-policy
router bgp <your ASN>
address-family ipv4 unicast
table-policy qosgroup_map
Step 2: Tag external packets at peering locations based
upon longest prefix match within FIB:


- tag (P) for packets received from peer and destined to a
prefix in the FIB with tag (P),
- tag (C) for packets received from peer and destined to a
prefix in the FIB with tag (C).
int Gig 0/0
ipv4 bgp policy propagation input qos-group destination
ISP forwards or discards packets that ingress peering
interconnects based upon associated packet tag value:
- Packets with tag (P) are discarded

- Packets with tag (C) are forwarded
a
end-cla
!
class-map match-any
match qos-group 7
end-class-map
!
policy-map qppb_set_dscp
class TWO
set dscp af21
!
class EXT
police rate 1000000 bps burst
31250 bytes peak-burst 31250 bytes
conform-action drop
Step 3 (Packet
classification via MQC):
int Gig 0/0
ipv4 bgp policy propagation input qos-group destination
service-policy input qppb_set_dscp
handouts available for
IOS, IOS-XR and JunOS
• Hardware
forwarding
platform.
• Classification
is a key
requirement.
graham@inx.net.za

More Related Content

PDF
DDos, Peering, Automation and more
PDF
High Speed Fiber Services and Challenges to the Core Network by Seiichi Kawamura
PDF
How Data Center Traffic is Changing Your Network by KC Lim
PPTX
Barriers to content production & distribution in Africa
PPTX
IPv6 @ Cloudflare
PDF
TIME Journey to the SPACE
PDF
DDOS Mitigation Experience from IP ServerOne by CL Lee
PDF
The Path to a Programmable Network
DDos, Peering, Automation and more
High Speed Fiber Services and Challenges to the Core Network by Seiichi Kawamura
How Data Center Traffic is Changing Your Network by KC Lim
Barriers to content production & distribution in Africa
IPv6 @ Cloudflare
TIME Journey to the SPACE
DDOS Mitigation Experience from IP ServerOne by CL Lee
The Path to a Programmable Network

What's hot (20)

PDF
The OTT Challenge - Eric Leung
PPTX
In Search of Low Cost Bandwidth
PDF
MyIX Updates by Raja Mohan
PDF
Next Generation DDoS Services – can we do this with NFV? - CF Chui
PPTX
Gambia IXP Experience
PDF
MyIX Updates
PPT
Angani Cloud – Impact of peering in Africa
PDF
Combating DDoS and why peering is important in Asia
PDF
WINS: Peering and IXPs
PDF
Engineering The New IP Transport
PDF
Prof. Danny Raz, Director, Bell Labs Israel, Nokia
PDF
Ken Liao, Senior Associate VP, Faraday
PDF
12 (IDNOG02) SGIX and Singapore Internet Landscape by Kerk Chun Sing
PDF
IPv6 in the Telco Cloud and 5G
PDF
Service Provider Architectures for Tomorrow by Chow Khay Kid
PDF
03 - IDNOG04 - Hideyuki Sasaki (BBIX) - Introducing Internet Culture To The O...
PDF
Multicast QUIC for video content delivery
PPTX
CDN Cache Distribution through RINEX
PPSX
WEGO2
PPTX
Pure-Play Virtualization for Rural Broadband
The OTT Challenge - Eric Leung
In Search of Low Cost Bandwidth
MyIX Updates by Raja Mohan
Next Generation DDoS Services – can we do this with NFV? - CF Chui
Gambia IXP Experience
MyIX Updates
Angani Cloud – Impact of peering in Africa
Combating DDoS and why peering is important in Asia
WINS: Peering and IXPs
Engineering The New IP Transport
Prof. Danny Raz, Director, Bell Labs Israel, Nokia
Ken Liao, Senior Associate VP, Faraday
12 (IDNOG02) SGIX and Singapore Internet Landscape by Kerk Chun Sing
IPv6 in the Telco Cloud and 5G
Service Provider Architectures for Tomorrow by Chow Khay Kid
03 - IDNOG04 - Hideyuki Sasaki (BBIX) - Introducing Internet Culture To The O...
Multicast QUIC for video content delivery
CDN Cache Distribution through RINEX
WEGO2
Pure-Play Virtualization for Rural Broadband
Ad

Viewers also liked (20)

PPTX
BGP and Traffic Engineering with Akamai
PDF
CARTELLE ESATTORIALI VIA PEC
PDF
Optimal-Care-Checklist-MSM-Patient_JLH
PDF
Equinix IP Address Renumbering in Singapore and Sydney
PDF
Xcode install Guide
PDF
EY - Letter of recommendation
PDF
Winning in Malaysia
PDF
Bando startup innovative
PDF
La Toscana che innova - intervento di Albino Caporale
PPT
Peering introductions-2
PPTX
De la realization de KINIX a la Viabilite et Attraction
PDF
Africa IXP Survey Report
PDF
Africa IETF Initiative
PDF
IXP Panel: Presentation by DECIX
PDF
MainOne at Glance
PDF
IPv6 Rollout to the mass market
PDF
Keynote Speech 2: “New Market Evaluation Strategy Guide”
PDF
Internet Measurements Infrastructure at KENET
PDF
Keynote Speech 1: “Promoting Content in Africa”
BGP and Traffic Engineering with Akamai
CARTELLE ESATTORIALI VIA PEC
Optimal-Care-Checklist-MSM-Patient_JLH
Equinix IP Address Renumbering in Singapore and Sydney
Xcode install Guide
EY - Letter of recommendation
Winning in Malaysia
Bando startup innovative
La Toscana che innova - intervento di Albino Caporale
Peering introductions-2
De la realization de KINIX a la Viabilite et Attraction
Africa IXP Survey Report
Africa IETF Initiative
IXP Panel: Presentation by DECIX
MainOne at Glance
IPv6 Rollout to the mass market
Keynote Speech 2: “New Market Evaluation Strategy Guide”
Internet Measurements Infrastructure at KENET
Keynote Speech 1: “Promoting Content in Africa”
Ad

Similar to Protecting your Peering Edge (20)

PDF
PLNOG 4: Klaudiusz Staniek - Efficient Technique for Enforcing Internet Peeri...
PDF
SGNOG2 - Using communities for multihoming ISP workshop
PPT
Bgp 1232073634451868-3
PDF
Route Leak Prevension with BGP Community
PDF
Improving the peering business case with RPKI
PDF
MANRS for Network Operators
PPT
bgp.ppt
PDF
Border Gateway Protocol (BGP) Security, LKNOG 8
PPTX
Ericsson_5G NSA Planning and design Worksho_CustomerGCU presentation_Q319.pptx
PDF
BGP Security Best Practices that Matter, presented at PHNOG 2025
PPTX
slides-87-mpls-12[19].pptx
PDF
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...
PPTX
10 routing-bgp
PPTX
8 - Configuring a VPRN Nokia Router.pptx
PDF
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpec
PPT
Configuraciones con BGP Juniper 4.bgp-1232073634451868-3.ppt
PPT
PDF
Scripting on Routers - NANOG 47
PPT
Chapter14ccna
PPT
Chapter14ccna
PLNOG 4: Klaudiusz Staniek - Efficient Technique for Enforcing Internet Peeri...
SGNOG2 - Using communities for multihoming ISP workshop
Bgp 1232073634451868-3
Route Leak Prevension with BGP Community
Improving the peering business case with RPKI
MANRS for Network Operators
bgp.ppt
Border Gateway Protocol (BGP) Security, LKNOG 8
Ericsson_5G NSA Planning and design Worksho_CustomerGCU presentation_Q319.pptx
BGP Security Best Practices that Matter, presented at PHNOG 2025
slides-87-mpls-12[19].pptx
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...
10 routing-bgp
8 - Configuring a VPRN Nokia Router.pptx
Обеспечение безопасности сети оператора связи с помощью BGP FlowSpec
Configuraciones con BGP Juniper 4.bgp-1232073634451868-3.ppt
Scripting on Routers - NANOG 47
Chapter14ccna
Chapter14ccna

More from Internet Society (20)

PPTX
IXP growth challenges in West Africa: The Ghana Experience
PPTX
IXP growth challenges in Central Africa
PPTX
Benin IX: 3 Years After!
PPT
IXP growth challenges in Côte D’Ivoire
PPTX
IXP Masterclass
PPTX
PeeringDB Updates
PPTX
Peering Personals #2
PPTX
Keynote Presentation : “80/20 by 2020”
PPT
International Bandwidth and Pricing Trends in Sub-Sahara Africa
PPTX
Interconnection Evolution
PPTX
Peering Personals #1
PPTX
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa
PPTX
Looking for Latency Clusters in Africa's internet
PPT
Fantsuam: Ideas for the sustainability of Community Networks
PDF
Mawingu: Ideas for the sustainability of Community Networks
PPTX
Zenzeleni Networks Update Report
PPTX
Canadian Victory Garden: Overview of an Off Grid Solution
PPTX
TVWS use case in Kenya
PPTX
TVWS use case in Malawi
PPTX
C3: Ideas for the sustainability of Community Networks
IXP growth challenges in West Africa: The Ghana Experience
IXP growth challenges in Central Africa
Benin IX: 3 Years After!
IXP growth challenges in Côte D’Ivoire
IXP Masterclass
PeeringDB Updates
Peering Personals #2
Keynote Presentation : “80/20 by 2020”
International Bandwidth and Pricing Trends in Sub-Sahara Africa
Interconnection Evolution
Peering Personals #1
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa
Looking for Latency Clusters in Africa's internet
Fantsuam: Ideas for the sustainability of Community Networks
Mawingu: Ideas for the sustainability of Community Networks
Zenzeleni Networks Update Report
Canadian Victory Garden: Overview of an Off Grid Solution
TVWS use case in Kenya
TVWS use case in Malawi
C3: Ideas for the sustainability of Community Networks

Recently uploaded (20)

PPTX
t_and_OpenAI_Combined_two_pressentations
PPTX
Internet Safety for Seniors presentation
PPTX
TITLE DEFENSE entitle the impact of social media on education
PDF
Exploring VPS Hosting Trends for SMBs in 2025
PPTX
Reading as a good Form of Recreation
PPTX
AI_Cyberattack_Solutions AI AI AI AI .pptx
PDF
Course Overview and Agenda cloud security
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PPTX
Database Information System - Management Information System
PPTX
Cyber Hygine IN organizations in MSME or
PPTX
KSS ON CYBERSECURITY INCIDENT RESPONSE AND PLANNING MANAGEMENT.pptx
PPTX
Introduction to cybersecurity and digital nettiquette
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PPTX
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
PDF
The Evolution of Traditional to New Media .pdf
PDF
Containerization lab dddddddddddddddmanual.pdf
PPT
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
PDF
Top 8 Trusted Sources to Buy Verified Cash App Accounts.pdf
PPTX
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
PPTX
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
t_and_OpenAI_Combined_two_pressentations
Internet Safety for Seniors presentation
TITLE DEFENSE entitle the impact of social media on education
Exploring VPS Hosting Trends for SMBs in 2025
Reading as a good Form of Recreation
AI_Cyberattack_Solutions AI AI AI AI .pptx
Course Overview and Agenda cloud security
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
Database Information System - Management Information System
Cyber Hygine IN organizations in MSME or
KSS ON CYBERSECURITY INCIDENT RESPONSE AND PLANNING MANAGEMENT.pptx
Introduction to cybersecurity and digital nettiquette
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
The Evolution of Traditional to New Media .pdf
Containerization lab dddddddddddddddmanual.pdf
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
Top 8 Trusted Sources to Buy Verified Cash App Accounts.pdf
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd

Protecting your Peering Edge