[113611] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: IXP

daemon@ATHENA.MIT.EDU (Ivan Pepelnjak)
Fri Apr 17 14:40:08 2009

From: "Ivan Pepelnjak" <ip@ioshints.info>
To: "'Elmar K. Bins'" <elmi@4ever.de>,
	"'Sharlon R. Carty'" <me@sharloncarty.net>
Date: Fri, 17 Apr 2009 20:39:17 +0200
In-Reply-To: <20090417142128.GM29526@ronin.4ever.de>
Cc: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org

> > I like would to know what are best practices for an 
> internet exchange. 
> > I have some concerns about the following; Can the IXP 
> members use RFC 
> > 1918 ip addresses for their peering?
> 
> No. Those IP addresses will at least appear on traceroutes; 
> also, it might not be such a good idea to use the same RFC1918 space
> (accidentally) on different IXPs. This will get your skin 
> crawling (thing IGP, or at least config databases)... IXPs 
> can usually get a v4 and a v6 block for their peering grid easily.

Anyone with a decently configured firewall would block IP packets with
source address from RFC1918 coming from the Internet. Your IXP would appear
as a black hole in traceroute printout because the ICMP replies sent from
the IXP IP addresses would be blocked.

A while ago I've described a few more caveats in an article (see
http://blog.ioshints.info/2008/08/private-ip-addresses-in-public-networks.ht
ml).

Ivan
 
http://www.ioshints.info/about
http://blog.ioshints.info/



home help back first fref pref prev next nref lref last post