[8411] in Commercialization & Privatization of the Internet

home help back first fref pref prev next nref lref last post

Re: Russian chemists harmed by ANS-CIX dispute?

daemon@ATHENA.MIT.EDU (Lars Poulsen)
Thu Nov 18 10:13:26 1993

Date: Thu, 18 Nov 93 12:41:59 +0100
From: lars@eskimo.cph.cmc.com (Lars Poulsen)
To: peter@goshawk.lanl.gov
In-Reply-To: <199311172106.OAA07420@goshawk.lanl.gov>
Cc: com-priv@psi.com

In com-priv message <199311172106.OAA07420@goshawk.lanl.gov> you write
   to Gordon Cook:
PF> It is not sufficient for a network R to be connected to a provider S
PF> that is CIX connected for R to have CIX connectivity.  If customer C of
PF> R wants CIX connectivity then R must also be a  CIX member.  
PF> CIX members can augment their Internet connectivity by peering with N
PF> directly or peer with some other network M which peers with N.

Peter, I don't think Gordon is the only one who is confused about this.
The above reply is a little too terse for me. (I am not sure that I
understand the undefined quantity N or the constraints on network R).

Let me try to guess and perform the substitutions for the specific
case:

	In order for network R (Moscow Chemistry Institute) to have CIX
	connectivity, not only must they be connected to a provider S
	(SprintNet) with CIX connectivity, but network R (Moscow Chemistry
	Institute) must also be a CIX member.

	In order for network R (Chemical Abstracts) to have CIX connectivity,
	not only must they be connected to a provider S (OARnet) with CIX
	connectivity, but network R (Chemical abstracts) must also be a CIX
	member.

Does not seem right.  Lets try again. Introducing a defined class of
network, called a mid-level, and constrain network R to be a mid-level.

	In order for network R (SprintNet) to have CIX connectivity,
	not only must they be connected to a provider S (SprintNet)
	with CIX connectivity, but network R (SprintNet) must also be
	a CIX member.

	In order for network R (OARnet) to have CIX connectivity, not only must
	they be connected to a provider S (ANS) with CIX connectivity, but
	network R (OARnet) must also be a CIX member.

Much better.

We now have defined
	Customers (may be hosts or networks)
	Mid-levels
	Transit Networks
	CIX

There are three things here that are confusing:
(1) The distinction between "mid-levels" and "transit networks".
(2) The distinction between CIX connectivity and CIX membership.
(3) We want to give AUP compliant networks a "free ride" to CIX.

As NSFnet moves away from the role as "the core", the game has changed.
It used to be that it was obvious that one wanted to connect to NSF
attached places. This is no longer the overwhelming issue. CIX is now
the place to get to.

Until now, policy restrictions were imposed by Merit on behalf of NSF
and the goal was to enforce a liberal interpretation of the NSF-AUP.
Nobody else could do very much about policy, because you needed to
pass traffic to the AUP-compliant core network, and you could not
distinguish between NSF destinations and ANS CO+RE destinations,
because they were traversing the same "autonomous system".

The deployment of BGP routing has allowed the evaluation of policy
over the entire path, rather than just for the last AS in the path.
This means that CIX is now able to enforce the the NSF AUP (very
loosely: "packets may go through NSFnet if and only if they are going
to an R&E-only destination") as well their own AUP, "packets may go
through here only if they are going through a CIX member before or
after they go through here".

I see nothing wrong with this. This is common sense from CIX. To do
anything else, would be to give ANS a free CIX membership.

The real issue is buried in the fine print: The CIX "AUP" is not exactly
as stated above. CIX would probably not allow ANS to join and thereby
allow free carriage to all regionals entering CIX through ANS. So the
fine print is in the definition of what exactly *is* CIX's "AUP", and to
the extent this definition includes the word mid-level, what does this
mean.

My interest in this is not theoretical. The BGP deployment has created
many situations where I have connectivity from California via CERFnet,
but not from Copenhagen via ALTERnet, and it is very hard to find out
	- whether the problem is transient (link down or overloaded) or
	  policy-induced
	- where the problem is located (my end or the other end at
	  fault)

Gordon's question was: I understand that Sprint is a CIX member, and
this should suffice to get their subscribers to CIX. If Sprint can get
to CAS via CIX and OARnet, why can't Sprint's customer get there ?
The real answer is probably that OARnet is not a CIX member, so the
problem is on the OARnet/CAS end.

The NOCs are good at debugging bad links, but have not yet learned
how to troubleshoot policy problems. ("Looks good from here, and RIPE
says it looks good in their database; call back if it persists after
their next policy propagation cycle.")

I am sure that any misconceptions in the above will be pointed out
right away.
-- 
/ Lars Poulsen			Internet E-mail: lars@CMC.COM
  CMC Network Products		Phone: (011-) +45-31 49 81 08
  Hvidovre Strandvej 72 B	Telefax:      +45-31 49 83 08
  DK-2650 Hvidovre, DENMARK	Internets: designed and built while you wait

home help back first fref pref prev next nref lref last post