project fenix by nix.cz tomas marsalek apricot 2015 fukuoka, 3. 3. 2015

12
Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

Upload: rodger-bryant

Post on 17-Jan-2016

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

Project FENIXby NIX.CZ

Tomas Marsalek

APRICOT 2015Fukuoka, 3. 3. 2015

Page 2: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

NIX.CZ introduction

• Neutral platform• 5 data centers in Prague• 123 connected networks• 41 international networks• 360 Gbps peek data flow• Project FENIX

Page 3: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

FENIX

• Reaction to DOS attacks in 3/20134 days long

• Multiple CZ targetsmedia, banks, cell phone operators, Seznam.cz (CZ “Google”)

• Source of attacks out of CZ• Nothing from CZ• Through upstream and NIX.CZ• No response source

Page 4: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

FENIX

• Club of “trustworthy” companies• Technical tool “Secure VLAN”• Czech eyeballs can connect to local content

home banking, media, email …

• Island modelast resort

• Faster than regulations• High joining criteria

Page 5: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

FENIXorganization rules

• End user terms and conditionsspam, attacks

• 24x7 technical conditionsno IVR

• CSIRT teamlisted by Trusted Introducer, Terena

• Active participation• Recommendation from 2 members, no veto

Page 6: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

FENIXtechnical rules

• BCP-38/SAC004 – granularity /24 (/48)• RTBH filtering using RS• IPv6, DNSSEC• Full redundancy on NIX.CZ• Network monitoring (MRTG, NetFlow, ...)• Control plane policy RFC6192• DNS, NTP, SNMP amplification protection• Security incident time <30min• BGP – TCP MD5

Page 7: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

FENIXstart

• 6 founding companies – January 2014Active 24CESNET (NREN)CZ.NICDial TelecomSeznam.czTelefonica Czech Republic (incumbent operator)

• NIX.CZ supervisor over rules

Page 8: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015
Page 9: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

Year of FENIX

• 3 new members• Technical implementation• RTBH testing• Brand name announcement• Micro web site fe.nix.cz• Island mode test

Page 10: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

Members of FENIX

• New candidates

Page 11: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

FENIX at Slovakia

• Take over of SITELiX• CSIRT.SK discusions• More info at Peering Day • www.peeringday.eu

Page 12: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

Follow us

.. and at www.nix.cz