Re: IPv6 Allocation Policy
"Craig A. Huegen" <[email protected]>
| Newsgroups | gmane.org.apnic.global-v6 |
|---|---|
| Message-ID | <Pine.WNT.4.44.0305191615370.1844-100000@chuegen-w2k04.amer.cisco.com> |
On Mon, 19 May 2003, Pekka Savola wrote: > > Because I pay ISP's to bring traffic to me. If I announce the /32 > > everywhere, then I have to build and manage my own Internet backbone to > > carry the traffic globally (in parallel with my internal/clean WAN). That > > amounts to paying two service providers to carry the traffic where I need > > it. > > I don't quite understand this, so I take it there may be some unstated > assumptions here. > > You mean that if you have two physically separate sites with each e.g. /33 > block, and would announce the /32 block at both points, you would have to > have more extensive & expensive internal WAN (carrying the other half, /33 > to the other physical location) to the -- and your WAN could not handle > it? > > This seems to call for separate addresses to separate sites under > different ISPs. Oh.. that was called PA. This company I know has 5 primary Internet route points, one for the west coast of the US, one for the east coast of the US, one in western Europe, one in Australia, and one in northern Asia. Each has a minimum of 2 providers, some have 4. If this company advertises the /32 from each SP at each route point, traffic is going to jump to that company at the first possible point. This particular company has the greatest majority of its traffic arriving at the west coast of the US. BGP doesn't exactly have the best intelligence when it comes to network proximity, so there are cases when a European ISP might end up sending traffic to this company's western US presence only to have the company's WAN backhaul it to Europe for its final destination. So, in essence it calls for separate addressing to separate sites with multiple ISP's at the same site. This company uses PA space when only one provider is present at a site (smaller access points). A secondary problem is stateful firewalls. In order to admit traffic related to a connection, stateful firewalls need to see the outbound traffic, or have some mechanism to share state. In large networks, this state sharing may use a very significant amount of bandwidth. By using controlled announcements as mentioned above (and matching address space to where the site's default route is located), symmetry is created and expensive long-haul WAN bandwidth does not have to be used to share this state. /cah -- Craig A. Huegen, Chief Network Architect C i s c o S y s t e m s IT Transport, Network Technology & Design || || Cisco Systems, Inc., 400 East Tasman Drive || || San Jose, CA 95134, (408) 526-8104 |||| |||| email: [email protected] CCIE #2100 ..:||||||:..:||||||:.. _______________________________________________ global-v6 mailing list [email protected] http://mailman.apnic.net/mailman/listinfo/global-v6