8 GP 3 (utonomous System) GP(order Gateway Protocol) GP GP GP 1 ISP 1 KI 2516 SO-NET 2527 IIJ 2497 ON 4713 WIE 2500 GP (order Gateway Protocol) ISP External GP ( ) 2516 7660 2500 4717 4767 ( ) 1 1 2 2 4 E 3 1
LOOP! LOOP! GP telnet@foundry1.fujisawa#show ip bgp route Total number of GP Routes: 91216 Status :GGREGTE :EST b:not-instlle-est :ONFE_EGP :MPE E:EGP H:HISTORY I:IGP L:LOL M:MULTIPTH S:SUPPRESSE Prefix Next Hop Metric LocPrf Weight Status 1 4.78.32.0/21 203.178.136.15 9041 100 0 I _PTH: 6461 14361 29748 2 4.78.32.0/21 203.178.136.15 9041 100 0 I _PTH: 6461 14361 29748 3 4.78.32.0/21 203.178.136.15 9041 100 0 I _PTH: 6461 14361 29748 4 4.78.32.0/21 203.178.136.15 9041 100 0 I _PTH: 6461 14361 29748 5 6.1.0.0/16 203.178.136.15 100 100 0 I _PTH: 7660 11537 668 1455 6461 OVENET 14361 HopOne 29748 arpathia Hosting 1455 N-YUM 668 REN 11537 ILENE 2
IPv4GP 156000(2003 12 ) 2002 8 8 ( ) GP http://bgp.potaroo.net/ Punching hole ISP ISP () /24 /2430,000 IP ISP /16 /18 ISP Punching Hole 203.178.136.0/19 JPNI 203.178.143.0/24 ISP X 203.178.143.0/24 203.178.136.0/21 ISP ISP 203.178.143.0/24 (ISP) ( ) (ISP) ( ) () (1/2) 1 2 1 (ISP) ( ) 2 (ISP) ( ) 1 (ISP) GP ( ) GP OSPF RIP 3
( ) 2 (ISP) GP ( ) GP OSPF RIP (2/2) ISP () ( ) (ISP) () () WIE GP (ISP) () () WIE NS ISP PN www.apan.net ISP lter.net <ccz00 6:33pm ~ >traceroute www.ucdavis.edu traceroute to www.ucdavis.edu (169.237.104.199), 30 hops max, 40 byte packets 1 gw2-v1-1 (133.27.4.2) 1 ms 0 ms 0 ms 2 fw1-1 (133.27.3.12) 0 ms fw1-2 (133.27.3.18) 1 ms 0 ms 3 wide-keio-p2p-gbe-1 (133.27.1.245) 1 ms 1 ms 1 ms 4 foundry2.otemachi.wide.ad.jp (203.178.138.227) 2 ms 2 ms 2 ms 5 tpr3-ge0-0-0-7.jp.apan.net (203.181.249.18) 2 ms 2 ms 2 ms 6 tpr2-ge-0-1-0-4.jp.apan.net (203.181.248.237) 2 ms 2 ms 2 ms 7 transpac-la-tpr2.jp.apan.net (203.181.248.129) 106 ms 106 ms 106 ms 8 hpr-lax-gsr1--abilene-l-10ge.cenic.net (137.164.25.2) 106 ms 106 ms 106 ms 9 dc-lax-dc1--lax-hpr1-ge.cenic.net (137.164.22.12) 106 ms 106 ms 106 ms 10 dc-sac-dc1--lax-dc1-pos.cenic.net (137.164.22.127) 115 ms 115 ms 115 ms 11 dc-oak-dc2--csac-dc1-ge.cenic.net (137.164.22.110) 119 ms 117 ms 117 ms 12 dc-ucd--oak-dc2-ge.cenic.net (137.164.24.226) 119 ms 119 ms 119 ms 13 ucd-area0.ucdavis.edu (128.120.0.113) 119 ms 119 ms 119 ms 14 area0-area13.ucdavis.edu (128.120.0.122) 119 ms 119 ms 120 ms ccz00 7:14pm ~ >traceroute www.cisco.com traceroute to www.cisco.com (198.133.219.25), 30 hops max, 40 byte packets 1 gw2-v1-1 (133.27.4.2) 1 ms 1 ms 0 ms 2 fw1-1 (133.27.3.12) 1 ms fw1-2 (133.27.3.18) 1 ms 0ms 3 wide-keio-p2p-gbe-1 (133.27.1.245) 1 ms 1 ms 1 ms 4 foundry4.otemachi.wide.ad.jp (203.178.138.241) 2 ms 2 ms 2 ms 5 cisco1.losngeles.wide.ad.jp (203.178.138.129) 111 ms 111 ms 111 ms 6 500.POS4-2.GW8.LX4.LTER.NET (208.222.9.225) 111 ms 111 ms 111 ms 7 106.at-0-1-0.L1.LX4.LTER.NET (152.63.114.98) 111 ms 112 ms 112 ms 8 0.so-1-0-0.TL1.LX9.LTER.NET (152.63.115.142) 113 ms 113 ms 113 ms 9 0.so-5-0-0.TL1.SL2.LTER.NET (152.63.1.33) 126 ms 126 ms 126 ms 10 0.so-1-1-0.XL1.SJ2.LTER.NET (152.63.50.153) 129 ms 129 ms 129 ms 11 POS1-0.XR1.SJ2.LTER.NET (152.63.56.138) 129 ms 129 ms 129 ms 12 191.TM6-0.GW5.SJ2.LTER.NET (152.63.48.141) 129 ms 129 ms 130 ms 13 ciscosys-gw1.customer.alter.net (65.208.80.242) 130 ms 130 ms 130 ms 14 sjce-dirty-gw1.cisco.com (128.107.239.89) 128 ms 129 ms 128 ms 15 sjck-sdf-ciod-gw2.cisco.com (128.107.239.102) 130 ms 129 ms 130 ms 16 www.cisco.com (198.133.219.25) 129 ms 130 ms GP GP _PTH _PTH : 2500 2500 2500 4717 ME (Multi Exit iscriminator) Local Preference Tier1: ISP Tier2: Tier1 ISP Tier 2 Tier 1 Transit Tier 2 Peer Tier 2 Tier 1 Peer Tier 2 4
GP GP GP GP ( RIP, OSPF, IS-IS) IPNS 1.5Mbps(NTT igital ccess 1500) 8Mbps 10 8Mbps * 10 = 80Mbps?? (1/2) TP End-End k ISP 10Mbps ISP Mbps 1Mbps SL 8M 5
運用回線のモニタ NSの対外トラフィック SNMP 133.27.0.0/16 NS全体で平均数 Mbps IN,OUTのMX値 Simple Network Management Protocol ルータ スイッチから情報を収集 取得するデータはMIに基づく MI (Management Information ase) 標準化されたデータフォーマット MRTG http://people.ee.ethz.ch/~oetiker/webtools/mrtg/ 2系列のデータを描画 IN MX: 16.3 Mb/s verage: 8.0 Mb/s OUT MX: 30.2 Mb/s verage: 5.6 Mb/s 外からの攻撃 ウィルスの影響 送信bit 数 受信bit数など 他の用途にも使える IN MX: 23.4 Mb/s OUT MX: 26.5 Mb/s 一日 一週間 一ヶ月 一年ごとのグラフ 定期的にログをサマリ verage: 8.5 Mb/s verage: 7.0 Mb/s year ログサイズが大きくならない 詳細なデータは抜けていく IN MX: 147.1 Mb/s verage: 13.0 Mb/s OUT MX: 116.9 Mb/s verage: 11.8 Mb/s KEIOの対外トラフィック 131.113.0.0/16 WIEネットワークの対外線 NS以外の慶応全体 トランジットを購入したISP IN MX: 40.3 Mb/s verage: 7.5 Mb/s OUT MX: 42.8 Mb/s verage: 10.1 Mb/s ほぼNSと同等 学術ネットワークを トランジット Uunet (lternet) NEWE (KI) NSPIXP (IX)に参加 国内ISPとピア PN IN MX: 22.2 Mb/s verage: 8.2 Mb/s OUT MX: 36.7 Mb/s verage: 12.1 Mb/s WIE year 慶応 NS IN MX: 71.6 Mb/s verage: 8.5 Mb/s OUT MX: 106.4 Mb/s verage: 13.1 Mb/s WIE Externalの埋まり具合 WIE Externalの埋まり具合 Uunet (購入) IN MX: 16.5 Mb/s verage: 11.2 Mb/s OUT MX: 29.0 Mb/s verage: 1.1 Mb/s IN MX: 17.8 Mb/s verage: 13.0 Mb/s OOU MX: 2.9 Mb/s verage: 8.9 Mb/s NSPIXP2 (国内とpeer) KI 購入 IN MX: 17.7 Mb/s verage: 4.8 Mb/s OUT MX: 13.0 Mb/s verage: 7.4 Mb/s IN MX: 15.3 Mb/s verage: 5.7 Mb/s OUT MX: 15.4 Mb/s verage: 7.2 Mb/s IN MX: 164.1 Mb/s verage: 71.2 Mb/s OUT MX: 195.8 Mb/s verage: 131.3Mb/s IN MX: 144.1 Mb/s verage: 66.5 Mb/s OUT MX: 196.2 Mb/s verage: 133.8 Mb/s PN (学術) IN MX: 43.2 Mb/s verage: 15.8 Mb/s OUT MX: 21.1 Mb/s verage: 6.0 Mb/s IN MX: 42.2 Mb/s verage: 15.2 Mb/s OUT MX: 19.6 Mb/s verage: 5.3 Mb/s 6
NSPIXP2 IX 60 ( ) PS (it Per Second) PPS (Packet Per Seconda) RTT(Round Trip Time) < 100ms + NI (access-list) Routing Processor (Hardware) Network Interface Routing Engine (Software) Switching Interface Routing Processor (Hardware) Network Interface 7
Packet Forwarding I(pplication Specific Integrated ircuit) =I Packet Forwarding L2/L3 IP 100Mbps! 1500byte 1500byte = 12,000bit 100,000,000/12,000 = 8333 PPS 100byte 6.7Mbps 100Mbps isco 2620/21 ( ) 25,000pps IOS 2WN Ethernet,, IM( ) isco 2650/51XM () 80MHz PU 40,000pps isco 12012 ( ) 60Gbps 12 S3O-48/STM-16 11 44Mpps isco 12416 () 320 Gbps 16 10 Gbps http://www.cisco.com/japanese/warp/public/ 3/jp/product/hs/routers/c12000/index.shtml http://www.cisco.com/japanese/warp/public/3 /jp/product/hs/routers/c2600/prodlit/2600d_ds.shtml http://www.cisco.com/japanese/warp/ public/3/jp/product/hs/ifmodule/adap/oc192/ Layer3 Foundry FastIron Edge Switch () FES2402 6.6 Mpps 24 10/100ase-TX + 2 2 & 3 FES4802: 10.2 Mpps 48 10/100ase-TX + 2 3 FES9604: 20.4 Mpps 96 10/100ase-TX + 4 3 Smartbit Router Tester http://advanced.comms.agilent.com/routertester/ UP http://advanced.comms.agilent.com/routertester/ 8
SNMP PPS (I) 3 TP Monitor Plus http://hp.vector.co.jp/authors/v032928/ TP ----- 2003/11/21 18:43:45 ----- 0 02 04 15.88 K 40.08 K 0.12 K/s 0.32 K/s 0.00 K/s 0.01 K/s ----- 2003/11/21 18:43:55 ----- 0 02 14 16.09 K 40.35 K 0.12 K/s 0.30 K/s 0.00 K/s 0.00 K/s http://hp.vector.co.jp/authors/v032928/img/tcpmon130.jpg TP Monitor (1) TP Monitor TP Monitor (2) TP Monitor (3) 1Kbps TP Monitor (4) (60) TP Monitor 9