<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Christoph Blecker &#187; Networking</title>
	<atom:link href="http://www.toph.ca/category/technology/networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.toph.ca</link>
	<description>Growing up in the Internet Age</description>
	<lastBuildDate>Sat, 20 Feb 2010 09:57:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>The Internet Revealed: A film about IXPs</title>
		<link>http://www.toph.ca/2010/02/20/the-internet-revealed-a-film-about-ixps/</link>
		<comments>http://www.toph.ca/2010/02/20/the-internet-revealed-a-film-about-ixps/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 09:57:51 +0000</pubDate>
		<dc:creator>Toph</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[peer1]]></category>
		<category><![CDATA[the internet]]></category>
		<category><![CDATA[tier 1]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.toph.ca/?p=204</guid>
		<description><![CDATA[I was passed a link to this video the other day. It&#8217;s over simplified of course, but it breaks down a bit of the basics as far as how the backbone of the internet works, and what I do all day .]]></description>
			<content:encoded><![CDATA[<p>I was passed a link to this video the other day. It&#8217;s over simplified of course, but it breaks down a bit of the basics as far as how the backbone of the internet works, and what I do all day <img src='http://www.toph.ca/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p><object width="480" height="295"><param name="movie" value="http://www.youtube.com/v/a5837LcDHfE&#038;hl=en&#038;fs=1&#038;rel=0&#038;hd=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/a5837LcDHfE&#038;hl=en&#038;fs=1&#038;rel=0&#038;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="295"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.toph.ca/2010/02/20/the-internet-revealed-a-film-about-ixps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>California here we come, right back where we started from..</title>
		<link>http://www.toph.ca/2009/03/21/california-here-we-come-right-back-where-we-started-from/</link>
		<comments>http://www.toph.ca/2009/03/21/california-here-we-come-right-back-where-we-started-from/#comments</comments>
		<pubDate>Sat, 21 Mar 2009 15:26:20 +0000</pubDate>
		<dc:creator>Toph</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[data centre]]></category>
		<category><![CDATA[industry analysis]]></category>
		<category><![CDATA[juniper]]></category>
		<category><![CDATA[project california]]></category>
		<category><![CDATA[servers]]></category>

		<guid isPermaLink="false">http://www.toph.ca/?p=124</guid>
		<description><![CDATA[Cisco&#8217;s (NASDAQ:CSCO) new Unified Computing System (also known as Project California) is a very interesting piece of technology. In a nutshell, what they&#8217;re trying to do is reduce and unify all the equipment needed to run a server infrastructure into one box. Server hardware itself, server-attached storage (also known as a SAN or Storage Area [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco&#8217;s (<a href="http://www.google.ca/finance?q=NASDAQ:CSCO">NASDAQ:CSCO</a>) new <a href="http://newsroom.cisco.com/dlls/2009/prod_031609.html">Unified Computing System</a> (also known as Project California) is a very interesting piece of technology. In a nutshell, what they&#8217;re trying to do is reduce and unify all the equipment needed to run a server infrastructure into one box. Server hardware itself, server-attached storage (also known as a SAN or Storage Area Network), and network backbone (routing/switching devices) would all integrate into &#8220;blades&#8221; that lock into a high-speed backplane. Through this single unified system, they are able to employ virtualization of the actual &#8220;server&#8221; instances across the smaller and more efficient blades.</p>
<p>They have taken their knowledge in and expertise in networking and used it to create a high-speed switching/routing backplane that is 10 Gigabit-per-second Ethernet capable. Through it, administrators can consolidate the both the local-area network (LAN) connections, SAN, and high-speed clustering connections all into one. Cisco is hoping that by integrating all these devices into one, that it will simply administration and provisioning due to the virtualized nature of the product, reduce costs by consolidating duplicated hardware, increase energy efficiency and lower cooling costs with a unified chassis, among other things. They have also partnered with VMWare (<a href="http://www.google.ca/finance?q=NYSE:VMW">NYSE:VMW</a>), who is already and industry leader in virtualization technologies, for both their press announcement and to help them develop the underlying tech.</p>
<p>So far, I&#8217;ve seen mixed reactions from the industry. Traditionally, Cisco has partnered with the major computer manufactures as they had largely complimentary markets and very little overlap. However, this move is a clear indication that Cisco is dropping the gloves and wants to take on the big manufactueres directly. IBM (<a href="http://www.google.ca/finance?q=NYSE:IBM">NASDAQ:IBM</a>), HP (<a href="http://www.google.ca/finance?q=NYSE:HPQ">NAQDAQ:HPQ</a>), Dell (<a href="http://www.google.ca/finance?q=NASDAQ:DELL">NASDAQ:DELL</a>), and Sun Microsystems (<a href="http://www.google.ca/finance?q=NASDAQ:JAVA">NASDAQ:JAVA</a>) are the four major incumbents in this sector, and they might just have something to be worried about. Cisco has a lot of financial resources to invest into this project, and with the economy in it&#8217;s current state, companies are always looking for tech that is going to lower their Total Cost of Ownership (or TCO).</p>
<p>Cisco isn&#8217;t the only player to get into this market though. Their primary rival in the network room is Juniper Networks (<a href="http://www.google.ca/finance?q=NASDAQ:JNPR">NASDAQ:JNPR</a>), and they <a href="http://www.juniper.net/us/en/company/press-center/press-releases/2009/pr_2009_02_24-12_00.html">announced</a> last month a similar project to integrate the various devices in the data centre together. However, it appears Cisco has a lead on them as far as bringing the product to market. Juniper is taking a slightly different approach, though.. they are actually in talks to partner with the major server manufacturers to bring this technology to market. Juniper has also indicated that it is looking to re-invent a best-of-breed technology in their product, and not necessarily be forced to stick with current tech and standards.</p>
<p>Same technology, but two different approaches. It will be also interesting to see if Cisco&#8217;s repositioning and determination to take on the entire project themselves will increase their share of the larger tech market, or if it could weaken their incumbent position on top of the networking sector.</p>
<p><em>PEER1 Networks employs both best-of-breed Cisco and Juniper networks equipment throughout their network infrastructure.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.toph.ca/2009/03/21/california-here-we-come-right-back-where-we-started-from/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Collateral Damage</title>
		<link>http://www.toph.ca/2008/06/29/collateral-damage/</link>
		<comments>http://www.toph.ca/2008/06/29/collateral-damage/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 06:42:13 +0000</pubDate>
		<dc:creator>Toph</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[toph on the web]]></category>

		<guid isPermaLink="false">http://www.toph.ca/?p=24</guid>
		<description><![CDATA[I recently wrote an article for ypigsfly, one of our partners who is developing a state of the art DDoS shield product. It&#8217;s designed to protect your web site and severs from being taken offline by an attacker. My article centers around the fact that your site doesn&#8217;t even have to be the intended target [...]]]></description>
			<content:encoded><![CDATA[<p>I recently wrote an article for <a href="http://www.ypigsfly.com/">ypigsfly</a>, one of our partners who is developing a state of the art DDoS shield product. It&#8217;s designed to protect your web site and severs from being taken offline by an attacker. My article centers around the fact that your site doesn&#8217;t even have to be the intended target to feel the affects of a DDoS attack.</p>
<p>You can take a look at the article, <a href="http://www.ypigsfly.com/index.php/noc-notes/34-noc-notes/116-collateral-damage-how-your-website-can-be-brought-down-by-a-denial-of-service-attack-without-being-the-target">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.toph.ca/2008/06/29/collateral-damage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Pakistan caused Youtube to drop off the net</title>
		<link>http://www.toph.ca/2008/02/29/how-pakistan-caused-youtube-to-drop-off-the-net/</link>
		<comments>http://www.toph.ca/2008/02/29/how-pakistan-caused-youtube-to-drop-off-the-net/#comments</comments>
		<pubDate>Fri, 29 Feb 2008 22:51:41 +0000</pubDate>
		<dc:creator>Toph</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.toph.ca/2008/02/29/how-pakistan-caused-youtube-to-drop-off-the-net/</guid>
		<description><![CDATA[BGP (Border Gateway Protocol) is the core protocol that runs the internet infrastructure. It&#8217;s a de-centralized protocol, meaning that no one server or core controls the internet. It&#8217;s designed to establish &#8220;peering&#8221; type relationships as well as &#8220;upstream&#8221; type relationships between different providers. There are three primary tiers of IP network providers: -Tier 1: Providers [...]]]></description>
			<content:encoded><![CDATA[<p>BGP (<a href="http://en.wikipedia.org/wiki/Border_Gateway_Protocol">Border Gateway Protocol</a>) is the core protocol that runs the internet infrastructure. It&#8217;s a de-centralized protocol, meaning that no one server or core controls the internet. It&#8217;s designed to establish &#8220;peering&#8221; type relationships as well as &#8220;upstream&#8221; type relationships between different providers. There are three primary tiers of IP network providers:<br />
-Tier 1: Providers that are very large, usually own a large IP network with their own fiber, and only establish &#8220;peering&#8221; relationships with other providers (peering is to provide access to each other&#8217;s networks with no money changing hands).<br />
-Tier 2: Providers of varying size networks that establish large amounts of peering relationships, but also rely on &#8220;upstream&#8221; relationships to Tier 1 providers (upstream is to provide the lower tier provider with routes to the entire internet, with the lower tier provider paying for access to this service)<br />
-Tier 3: Smaller or private providers that only establish upstream relationships with higher tier providers.</p>
<p>All of this works around the concept of BGP &#8216;prefixes&#8217;. These are simply routes that are transmitted across a &#8216;point-to-point&#8217; session between two routers. A BGP prefix is usually written in slash notation (10.0.0.0/8), and describes the AS (Autonomous System) numbers of the network path that prefix has to travel through, as well as a route to that network. Like any other form of subnet routing, routers can receive multiple routes through to a particular IP or network. This allows redundancy, as well as the router to choose the shortest path through to that destination. There are many things that factor into these routing decisions, but the two we&#8217;re going to focus on is specificity of the route and AS path length.</p>
<p>Now my earlier example of 10.0.0.0/8 is a very large route. It&#8217;s a route to all the addresses in-between 10.0.0.0 and 10.255.255.255. Lets say your router calculates a route to this network that has 3 AS networks in-between. Now another router starts advertising a BGP route to 10.0.0.0/16. This is a route to just 10.0.0.0-10.0.255.255; a much smaller group of addresses. Now I&#8217;m really over simplifying the routing decision, but for the sake of explanation, in many cases this new route would take preference as it is routing to a more specific group of addresses.</p>
<p>This is exactly what happened to YouTube. YouTube was advertising a prefix of 208.65.152.0/22. The Pakistani government decided to block YouTube (see <a href="http://www.cbc.ca/money/story/2008/02/24/pakistan-youtube.html">news article</a>) for what is says is &#8220;anti-islamic&#8221; content. The WAY they did this, was by getting the major Pakistani ISP, Pakistan Telecom, to advertise a more specific BGP route of 208.65.152.0/24. This caused all traffic in the ISP to pick up the new route, which told the router to drop the traffic.</p>
<p>Now how this spread is even more interesting. Due to the nature of BGP, prefixes are handed off in peering sessions between two routers. PCCW Global Crossing (3491) is a Tier 1 IP network provider that provides upstream services to Pakistan Telecom (17557). However, they were not conducting proper filtering of the routes that Pakistan Telecom was providing up to PCCW in their direct relationship. Once the routes are accepted by PCCW, they are then labeled as routes coming from PCCW and any other provider that trusts PCCW would get those routes. Very quickly this caused all YouTube traffic to be redirected into Pakistan Telecom, where their routers dropped the traffic. Not only did they succeed in cutting off YouTube from Pakistan, but they cut it off for the world.<br />
<a href="http://cache.toph.ca/uploads/2008/02/pakistan-route.jpg"><img src="http://cache.toph.ca/uploads/2008/02/pakistan-route.jpg" alt="YouTube Traffic routing to Pakistan" border="0" width="450" height="272" /></a></p>
<p>Very quickly, PCCW noticed the large redirection of traffic to Pakistan Telecom, and had to terminate their BGP session with Pakistan Telecom to cut off the route from taking effect. This effectively cut off Pakistan from the rest of the internet while PCCW worked to filter out the malicious route.<br />
<a href="http://cache.toph.ca/uploads/2008/02/youtube-route.jpg"><img src="http://cache.toph.ca/uploads/2008/02/youtube-route.jpg" alt="YouTube routing restored" border="0" width="450" height="272" /></a></p>
<p>This isn&#8217;t the first time something like this has happened, and there isn&#8217;t a lot in place to prevent it from happening again. The nature of BGP is insecure, and the routers mainly go on a trust relationship that every provider is going to filter on the outside borders of their network and that inter-network traffic routes can be trusted.</p>
<p>It&#8217;s really cool when you start to grasp some of these concepts and how they work. A little over 2 months ago I had no clue what BGP even stood for, let alone that it routes the entire internet.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.toph.ca/2008/02/29/how-pakistan-caused-youtube-to-drop-off-the-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Good Game, Savvis.</title>
		<link>http://www.toph.ca/2008/02/28/good-game-savvis/</link>
		<comments>http://www.toph.ca/2008/02/28/good-game-savvis/#comments</comments>
		<pubDate>Thu, 28 Feb 2008 15:07:10 +0000</pubDate>
		<dc:creator>Toph</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[savvis]]></category>
		<category><![CDATA[tier 1]]></category>

		<guid isPermaLink="false">http://www.toph.ca/2008/02/28/good-game-savvis/</guid>
		<description><![CDATA[PEER1 runs a redundant network utilizing 4 Tier 1 upstream providers. One of these providers, Savvis, had a major network fault last night. I started getting reports from customers that they are either unable to access their server, or their server was unable to access the internet outside the PEER1 network. After a bunch of [...]]]></description>
			<content:encoded><![CDATA[<p>PEER1 runs a <a href="http://peer1.com/infrastructure/network.php">redundant network</a> utilizing 4 Tier 1 upstream providers. One of these providers, <a href="http://www.savvis.net/">Savvis</a>, had a major network fault last night. I started getting reports from customers that they are either unable to access their server, or their server was unable to access the internet outside the PEER1 network. After a bunch of diagnosis, I was able to trace the issue to our Savvis transit upstreams in the east coast.</p>
<p>I then checked a very handy service called <a href="http://www.internetpulse.net/">Internet Pulse</a>, and discovered that Savvis was having network issues pretty much all over North America.<br />
<a href="http://cache.toph.ca/uploads/2008/02/savvis-outage.jpg"><img src="http://cache.toph.ca/uploads/2008/02/savvis-outage.jpg" alt="Savvis Network Issues" border="0" width="450" height="262" /></a></p>
<p>Fantastic. However, with the help of the Engineering department, we were quickly able to react, and redirect traffic out the other upstreams, avoiding Savvis where possible. Most providers, no matter how big or small, will have network issues, faults, and generally not nice stuff happen to them.. However what makes the difference between the decent networks, and the great networks (like PEER1) is the ability to react quickly to changes in the structure of the network and minimize latency, packet loss, and downtime.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.toph.ca/2008/02/28/good-game-savvis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
