hiding ospf transit-only networks

16
S Hiding OSPF Transit-only Networks Yi Yang IETF 79

Upload: bertha

Post on 18-Feb-2016

42 views

Category:

Documents


2 download

DESCRIPTION

Hiding OSPF Transit-only Networks. Yi Yang IETF 79. What are transit-only networks?. W hy to hide them?. Infrastructure security Plus, downsize routing table and speed up convergence . How to hide them?. Point-to-Point networks Broadcast networks Non-Broadcast networks. Point-to-Point. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Hiding OSPF Transit-only Networks

S

Hiding OSPFTransit-only Networks

Yi YangIETF 79

Page 2: Hiding OSPF Transit-only Networks

What are transit-only networks?

Page 3: Hiding OSPF Transit-only Networks

Why to hide them?

Infrastructure security Plus, downsize routing table and speed up

convergence

Page 4: Hiding OSPF Transit-only Networks

How to hide them?

Point-to-Point networks Broadcast networks Non-Broadcast networks

Page 5: Hiding OSPF Transit-only Networks

LS Age = 0LS Type = 1LS ID = 1.1.1.1Adv. Router = 1.1.1.1Number of Links = 2

Link ID = 2.2.2.2Link Data = 10.1.1.1Type = 1Metric = 10

Link ID= 10.1.1.0Link Data = 255.255.255.252Type = 3Metric = 10

Point-to-Point

10.1.1.0/30.1

1.1.1.1

.2

2.2.2.2

LS Age = 0LS Type = 1LS ID = 2.2.2.2Adv. Router = 2.2.2.2Number of Links = 2

Link ID = 1.1.1.1Link Data = 10.1.1.2Type = 1Metric = 10

Link ID= 10.1.1.0Link Data = 255.255.255.252Type = 3Metric = 10

Page 6: Hiding OSPF Transit-only Networks

LS Age = 0LS Type = 1LS ID = 1.1.1.1Adv. Router = 1.1.1.1Number of Links = 1

Link ID = 2.2.2.2Link Data = 10.1.1.1Type = 1Metric = 10

Point-to-Point

10.1.1.0/30.1

1.1.1.1

.2

2.2.2.2

LS Age = 0LS Type = 1LS ID = 2.2.2.2Adv. Router = 2.2.2.2Number of Links = 1

Link ID = 1.1.1.1Link Data = 10.1.1.2Type = 1Metric = 10

Page 7: Hiding OSPF Transit-only Networks

Broadcast

10.2.2.0/24.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.5

LS Age = 0LS Type = 2LS ID = 10.2.2.5Adv. Router = 5.5.5.5Network Mask = 255.255.255.0Attached Router = 3.3.3.3Attached Router = 4.4.4.4Attached Router = 5.5.5.5

Page 8: Hiding OSPF Transit-only Networks

Broadcast

10.2.2.0/24.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.5

LS Age = 0LS Type = 2LS ID = 10.2.2.5Adv. Router = 5.5.5.5Network Mask = 255.255.255.255Attached Router = 3.3.3.3Attached Router = 4.4.4.4Attached Router = 5.5.5.5

Page 9: Hiding OSPF Transit-only Networks

Non-Broadcast: NBMA

Use /32 subnet mask, similar to Broadcast

Page 10: Hiding OSPF Transit-only Networks

Non-Broadcast: P2MP

10.3.3.0/24

.6

6.6.6.6

.7

7.7.7.7

.8

8.8.8.8

LS Age = 0LS Type = 1LS ID = 6.6.6.6Adv. Router = 6.6.6.6Number of Links = 3

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

Link ID= 10.3.3.0Link Data = 255.255.255.0Type = 3Metric = 0

Page 11: Hiding OSPF Transit-only Networks

Non-Broadcast: P2MP

10.3.3.0/24

.6

6.6.6.6

.7

7.7.7.7

.8

8.8.8.8

LS Age = 0LS Type = 1LS ID = 6.6.6.6Adv. Router = 6.6.6.6Number of Links = 2

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

Link ID = 7.7.7.7Link Data = 10.3.3.6Type = 1Metric = 10

Page 12: Hiding OSPF Transit-only Networks

OSPFv3

Remove IPv6 Prefixes from the intra-area-prefix-LSAs

Page 13: Hiding OSPF Transit-only Networks

Next Step

Page 14: Hiding OSPF Transit-only Networks

END

Page 15: Hiding OSPF Transit-only Networks

Backward Compatibility: Broadcast

10.2.2.0/24.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.5

LS Age = 0LS Type = 2LS ID = 10.2.2.5Adv. Router = 5.5.5.5Network Mask = 255.255.255.255Attached Router = 3.3.3.3Attached Router = 4.4.4.4Attached Router = 5.5.5.5

Page 16: Hiding OSPF Transit-only Networks

Backward Compatibility: Broadcast

10.2.2.0/24.3

3.3.3.3

.4

4.4.4.4

.5

5.5.5.51.1.1.1

7.7.7.7 8.8.8.8

Host B

Host A2.2.2.2

Upgraded Not-upgraded-yet