The Fat Pipe - All Packet Pushers Pods

The Fat Pipe - All Packet Pushers Pods

By Packet PushersTechnology
Download on the App Store

The Fat Pipe - All Packet Pushers Pods episodes

  • PQ Show 78: BGP Flowspec For DoS Mitigation
    Welcome to the Packet Pushers Priority Queue. On today’s show we’re going to talk about BGP flowspec, an RFC that can be used for DoS mitigation.
    But before we dive in, let’s level set on BGP, the border gateway protocol. BGP is the routing protocol that glues the Internet together. Big, huge companies and service providers use complex BGP policies to govern traffic flowing across their networks. BGP lets you perform some clever routing tricks that you can’t really do with an interior gateway routing protocol like OSPF or EIGRP.
    And all of that is, more or less, true. To quote RFC 4271, “The primary function of a BGP speaking system is to exchange network reachability information with other BGP systems.  This network reachability information includes information on the list of Autonomous Systems (ASes) that reachability information traverses. This information is sufficient for constructing a graph of AS connectivity for this reachability, from which routing loops may be pruned and, at the AS level, some policy decisions may be enforced.”
    Okay. So RFC 4271 tells us that BGP is, primarily for telling BGP speakers what networks are reachable via what autonomous systems. And if you dig a little deeper, you find that information is learned via the exchange of NLRIs – network layer reachability information messages.
    Now, here’s the big deal with BGP. An NLRI could contain any sort of information. An NLRI doesn’t have to contain an IP prefix with reachability information. You know, a route. For instance, RFC 4684 defines NLRIs that contain route-target information. RFC 4760 talks about NLRIs for multi-protocol BGP. RFC 7432 defines NLRIs for EVPN.
    Once you realize this, BGP becomes more than just a routing protocol. BGP can be used to share all sorts of information between BGP speakers to influence their forwarding decisions.
    The topic of our conversation today is RFC 5575, BGP flowspec. BGP flowspec defines a specific BGP NLRI defining a flow. What do BGP speakers do with this flow information?
    Our guest today is Justin Ryburn, who’s going to talk us through BGP flowspec and how it can be used to mitigate DoS and DDoS attacks.
    Justin is a Consulting Engineer with Juniper Networks. He’s been with Juniper for about 9 years in both pre-sales and post-sales Engineering roles, and has about 20 years experience in networking with a primary focus on service providers and carriers.
    Show Notes:
    Section 1 – Setting Up The problem: DoS Attacks

    * Briefly, what’s a DoS attack?

    * High Level – Denial of Service attack is any attack that denies (blocks) the legitimate use of a resource.
    * There is also a term DDoS. The extra D stands for distributed and it refers to the type of attack with a widely distributed source.


    * What are the chief ways DoS attacks are defended against (and their issues)?

    * Manual call – help me, I’m being attacked!
    * D/RTBH – victim announces RTBH
    * S/RTBH – victim calls for help, NOC initiates RTBH + uRPF


    * The big deal? Every flow dies in the blackhole in destination-based filtering. A lack of granularity that kills useful traffic along with the DoS traffic. Even source-based with uRPF is not a perfect answer, although it’s better that destination-based.

    * It is better in the sense that it does not “complete the attack” like you mentioned with destination-based filtering. However, it is impractical for a truly distributed attack as the source can be hundreds or thousands of hosts.



    Section 2 – Introducing BGP Flowspec For DoS Mitigation

    * What is BGP flowspec?

    0 min
  • PQ Show 77: Location-Aware Apps With Aruba Meridian (Sponsored)
    This episode of Priority Queue, sponsored by Aruba, a Hewlett Packard Enterprise company, talks about location services. Location services are being deployed in shopping centers, stadiums, hospitals, and other public areas. They tap into wireless networks to enable people to get location-related information and services on their mobile devices.
    Traditional WLAN infrastructure is necessary for location services, but another key element is the Bluetooth Low Energy (BLE) protocol, which allows low-volume data transmissions over brief bursts instead of a continuous transmission.
    BLE has given rise to beacons – tiny Bluetooth devices that broadcasts a small amount of data at regular intervals. These beacons are so small that they can run on coin-sized batteries for 2 years.
    Placing beacons around a physical buildings allows smartphones to know where they are by hearing the BLE messages. By combining this with an app to fetch data based on the beacon and some programming, you can create location services.
    People can use their phones to find the shop they want in a large shopping mall, or get alerts that the person they want to meet is drinking coffee in the next room. Companies have new ways to generate revenue with push notifications to users.
    Julia Farina, Head of Product Marketing for Mobile Engagement at Aruba, sat down with Greg and Ethan at the Atmosphere 2016 conference to talk about location services and how the Aruba product line supports and enables these services.
    They discuss how BLE integrates with Aruba’s wireless infrastructure, examine use cases for location services, and dive into the Meridian platform for building location features into mobile applications.
    0 min
  • PQ Show 76: Understanding Aruba’s Unified Wired And Wireless Roadmap (Sponsored)
    Today’s Priority Queue show comes to you from Atmosphere 2016 Vegas – the largest community conference for enterprise mobility engineers – hosted by Aruba, a Hewlett Packard Enterprise company. Aruba has hit a $1 billion run rate for its mobility business since its acquisition by HPE, confirming the reasons behind the bold move.
    As the two organizations came together, campus and data center switching products were added to the Aruba portfolio of networking products as well, further increasing the total addressable market for the organization.
    Which brings us to the topic of today’s sponsored show with Aruba. The acquisition and the technology roadmap for the newly formed and unified networking organization cannot be viewed as simply as HPE Networking getting a new wireless LAN product line. There’s policy and management tools to consider. There’s some switching and wireless products that overlap — not everything can survive.
    Ethan Banks and Greg Ferro are joined by Michael Dickman, VP of Product Management for campus switching products at Aruba. Michael will give a detailed update regarding the progress on the integration roadmap and answer some key questions, including:
    What’s on the roadmap to integrate Aruba and HPE Networking product lines as they existed before the acquisition? What has been accomplished already? What does the unified wired and wireless networking portfolio look like?
    What are the leading software solutions for policy and network management? How is Aruba’s “mobile-first” campus and branch network architecture different from others in the networking industry? And how will the partner and customer relationships be affected? Join us to hear all about it.
    0 min
  • PQ Show 75: Talking Network Analytics And Telemetry
    Network monitoring has been in the doldrums for decades. The best protocols for network visibility that our industry has produced are SNMP, ping, and syslog. We use SNMP for metrics and ping to test availability, and syslog is an entire data source for device information. All of these have limitations.
    However, over the last few years, software defined networking has seen new ways of getting information from our devices, and new tools and techniques are emerging to help network operators get better data and make more sense out of it.
    Today we have a couple of folks to talk about the state of network monitoring and analytics. We’ll discuss why things like SNMP aren’t enough, how analytics and telemetry differ from traditional monitoring, what data sources are available, and how we can put that data to good use.
    Our guests are Avi Freedman, Founder and CEO at Kentik, and Bill Beckett, Founder and CSO at Saisei.
    Show Notes:
    A. Define Analytics & Telemetry Compared To Network Monitoring

    * I’ve got SNMP, why isn’t that enough?
    * Flexible data sources
    * What kind of data? Routing? Counters? Control-plane ‘deep’ counters like Q depth? Detailed config data (like LACP hash params+functions)?
    * How often? Streaming or pull? What about streaming?
    * Self-defined data formats
    * Network-centric or application-centric instead of device-centric or “hop by hop” performance

    B. Implementation Factors

    * OpenConfig/NetCONF/YANG
    * sFlow/NetFlow/IPFIX
    * DPI
    * Other data sources?
    * Streaming bus?
    * REST APIs

    C. Data Wrangling

    * Data platforms – one or many?
    * Streaming data buses to feed multiple tools?
    * How to interoperate?
    * How to use for multiple purposes (BI, ops, security, performance)?

    D. Use Cases

    * Debugging/root cause?  How to use the data for that?
    * Alerting and prediction over the data?
    * Security?
    * Performance?
    * Other?

    E. Visualization & Presentation

    * Viable UI design
    * UX flow and presentation
    * Onboarding
    * Business – linking performance to dollars, reducing asset values

    Links:
    PQ Show 46 – Saisei & Network Performance Enforcement – Packet Pushers
    PQ Show 71: Kentik & Real-Time Network Visibility (Sponsored) – Packet Pushers
    What is Juniper-Grafana? – GitHub
    0 min
  • PQ Show 74: Cambium Networks – Affordable PTP Wireless (Sponsored)
    Today on the Packet Pushers Priority Queue, we step out of the data center, away from the hot aisle, take out our spectrum analyzers, shoo away the pigeons, and discuss outdoor wireless. Specifically, we’re going to go after point-to-point wireless and wireless backhaul with our sponsor, Cambium Networks.
    Cambium Networks specializes in fixed outdoor wireless broadband in the unlicensed 5GHz/2.4Ghz spectrum, handling challenging wireless interference from 2 meters to 245 kilometers.
    The company connects backhaul systems, WiFi networks, video cameras and other systems.
    Our guests from Cambium are Sakid Ahmed, Senior Director of Engineering; Dmitry Moiseev, Systems Engineer; and Alex Marcham, Systems Engineer.
    Greg and Ethan dive in with their guests to talk about Cambium’s product line, including the ePMP product, which is specifically designed for outdoor use. They discuss how Cambium handles outdoor interference, including other radio signals, and uses a deterministic system to adapt modulation levels to ensure a strong signal even in noisy environments.
    And because Cambium radios are designed for point-to-point links, deployment is fairly simple and doesn’t require an expert installer. Cambium includes AES 128-bit encryption support to ensure data is encrypted in transit.
    Cambium offers cnMaestro, a cloud-based management system that provides visibility to all APs and modules. Operators can configure and manage their entire Cambium network from one place.
    Use Cases
    The primary use case for Cambium is operators providing Internet and VoIP services to home users. For instance, in a rural location, an operator can put Cambium equipment on a water tower, grain elevator or building and within a 60 degree or 90 degree sector provide broadband for hundreds of houses.
    However, the company is also seeing growing adoption for connecting surveillance cameras for warehouses and other large commercial spaces, enterprise connectivity, WiFi hotspot backhaul, and organizations connecting multiple buildings on a campus.
    Links
    Cambium has a special offer for Packet Pushers listeners. The first 25 people to register at on cambiumnetworks.com/packetpushers will each get a pair of ePMP radios, while supplies last.
    Cambium Networks
    Cambium Networks Community Forum
    0 min
  • PQ Show 73: VMware’s Martin Casado On SDN Evolution In 2016 (Sponsored)
    Our guest today is Martin Casado, General Manager of the Network and Security Business Unit (NSBU) at VMware. He joins the Packet Pushers to get nerdy about where SDN and VMware’s NSX have been, and where they’re going in 2016.
    On the business side, VMware announced this past week it has grown the NSX business to a $600 million run rate and tripled the number of paying customers year over year to 1,200. The number of customers running NSX in production has grown 5X, to more than 250.
    In this wide-ranging conversation on the transformation of networking, we hit on four main subjects:

    * SDN Evolution: We talk about how SDN discussions have moved from trying to understand the concepts to exploring business cases that drive deployment. And as network virtualization has moved into the mainstream, we dive into the relationship between physical and virtual networking.


    * Open Source: We talk about the impact of standards bodies and open source software on networking, including projects such as Open vSwitch and the Congress project, which is an effort to translate business requirements into instructions and configurations that can be implemented automatically.


    * NSX And ACI: Martin disputes the portrayal of VMware NSX and Cisco ACI as competing products. He notes both products are seeing great adoption, with many customers buying both. We talk about how NSX provides the virtualization layer, and ACI provides a robust network fabric. As both products advance, Martin anticipates that areas of overlap will shrink.


    * Distributed Network Services: When you virtualize the network, you can run functions such as firewalls and load balancers out at the edges, and spread the load of those services across multiple CPUs. This enables fine-grained provisioning and resource accounting, and will enable new capabilities and enhance the operational value of network virtualization.

    Links:
    The Packet Pushers have had several discussions with VMware around NSX, network virtualization, security, and containers. Check out these other podcasts:
    PQ Show 67: VMware NSX Everywhere With Guido Appenzeller (Sponsored)
    PQ Show 56 – VMware NSX In Production – Sponsored
    Show 161 – VMware NSX – Real World SDN – Sponsored
    0 min
  • PQ Show 72: Three Use Cases For Sonus VellOS Dynamic Path Networking (Sponsored)
    On today’s Priority Queue, sponsored by Sonus Networks, we examine three use cases for VellOS, Sonus’s product that lets customers program a network to customize it for their environments.
    Joining us from Sonus for the discussion are Dan Malek, Software Engineering Fellow; and Karl May, VP, VellOS Business Unit.
    We’ll drill into the details of three VellOS use cases, and explore both the technology aspects of the product and the business problems you can solve.
    Use Cases

    * Enterprise SD-WAN. The first use case revolves around reducing costs for enterprise WAN connectivity while also ensuring high performance for applications and network resilience, using off-the-shelf, OpenFlow-compatible switches in conjunction with the VellOS controller. Customers can mix and match carriers and connectivity types, including MPLS, dark fiber, and broadband, and choose application paths based on criteria including performance and cost.
    * Service provider interconnects. The second use case is for international carriers that are building interconnects with other providers across geographic regions. VellOS allows carriers to enforce QoS and other customer policies on a peer’s network.
    * Multitenant interconnects for colocation providers. The third use case discusses how a data center/colocation operator can install high-bandwidth interconnects that can be shared with a large number of tenants. VellOS creates a shared infrastructure that lets the operator carve up bandwidth and provide network services and requirements on demand. VellOS flow control provides multitenancy separation.

    Links:
    If you want to learn more about Sonus and VellOS, you can check out the resource page Real-time Service Quality for Unified Communications.
    You can also get more details from the blog posts QoS Done Right and Leveraging SD-WAN For Skype For Business Enterprise Voice.
    And be sure to check out other podcasts from Sonus, including Packet Pushers Weekly Show 253 and PQ Show 69: Sonus VellOS And QoE For Unified Communications (Sponsored).
    0 min
  • PQ Show 71: Kentik & Real-Time Network Visibility (Sponsored)
    Today’s podcast is sponsored by Kentik, a startup that’s just recently come out of stealth. Kentik offers real-time network visibility for service providers, Web companies, and enterprises.
    Kentik’s SaaS offering collects flows, including Netflow, sFlow, and IPFIX, as well as BGP and SNMP, and analyzes all this data to help operators determine if availability or performance problems are network-related.
    If they are, Kentik can drill into flow records to show when and where the problem started, whether it’s on an internal or external network, and other essential information to help resolve the issue.
    Customers can encrypt and upload flow records to Kentik’s service. Records are stored in a Big Data backend. A portal provides dashboards for immediate analysis of incoming data, and customers can also run SQL queries against the backend. Kentik also offers a premises version for customers uncomfortable with the SaaS option.
    Avi Freedman, CEO and co-founder of Kentik, joins the Packet Pushers to talk about how Kentik works, how the service extracts value from flow information, how Kentik compares to other visibility and monitoring products, and shares customer use cases.
    It’s a nerdy, detailed discussion on getting insight from flows and other data sources.
    0 min
  • PQ Show 70 – The HPE-Aruba Networks Merger – How Is That Going To Work?
    I was fortunate to be a guest at the HP Discover conference in December 2015, shortly after HPE announced its acquisition of Aruba. I was able to collar Ozer Dondurmacioglu from Aruba and Chris Young from HPE to talk frankly about what the merger looks like.
    Topics Covered:

    * Some history about Aruba and how they structure their go-to-market strategy.
    * What does the Aruba/HPE merger mean for customers?
    * How is the merger going internally?
    * What do we know about changes in the product portfolio at this time?

    Guests
    Ozer Dondurmacioglu @ozwifi
    Chris Young @netmanchris
    0 min
  • PQ Show 69: Sonus VellOS And QoE For Unified Communications (Sponsored)
    One of the things we like to discuss on Packet Pushers are use cases—why you’d want to use a specific technology in the real world. Today, we’re going to discuss, with our sponsor Sonus, how to enforce QoS end to end across a network to support real-time communications.
    If you’ve built a campus QoS scheme, you think in terms of DSCP marks, low-latency queuing, and so on. But the reality is these schemes are static and designed for peak loads in the hope that UC traffic doesn’t exceed those static allocations.
    So what if there was a way to build out a QoS prioritized path in real time? What if, when the call was stood up, the path between the end points had traffic prioritization configured automatically?
    Sonus’s VellOS allows us to do this and more. VellOS is a network operating system that allows you to fully automate flows through a network, so you can control bandwidth, packet marketing, MPLS values, and more to ensure voice and video calls get the highest quality available.
    On today’s show, we’re going to drill into how VellOS works, including its use of OpenFlow, and its integration with Microsoft’s UC SDN API. Joining us for today’s conversation are Kevin Isacks, VP of Engineering at Sonus; and Dan Malek, Software Engineering Fellow at Sonus.
    Learn More
    If you want to learn more about Sonus and VellOS, you can check out the resource page Real-time Service Quality for Unified Communications from Sonus.
    You can also get more details from the blog posts QoS Done Right and Leveraging SD-WAN For Skype For Business Enterprise Voice, and from Packet Pushers Weekly Show 253 with Sonus.
    0 min

About The Fat Pipe - All Packet Pushers Pods

From the publisher's feed

Everything we offer in one high bandwidth output queue. New content every weekday. High priority, low latency, jitter free. Too much technology would never be enough.

More shows like The Fat Pipe - All Packet Pushers Pods

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,492 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,087 Listeners

The Everything Feed - All Packet Pushers Pods by Packet Pushers

The Everything Feed - All Packet Pushers Pods

194 Listeners

Heavy Networking by Packet Pushers

Heavy Networking

327 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

The Daily by The New York Times

The Daily

111,799 Listeners

Tech Field Day Podcast by Tech Field Day

Tech Field Day Podcast

16 Listeners

Tech Bytes by Packet Pushers

Tech Bytes

5 Listeners

The Diary Of A CEO with Steven Bartlett by DOAC

The Diary Of A CEO with Steven Bartlett

8,527 Listeners

IPv6 Buzz by Packet Pushers

IPv6 Buzz

33 Listeners

Advent of Computing by Sean Haas

Advent of Computing

83 Listeners

Day Two DevOps by Packet Pushers

Day Two DevOps

15 Listeners

The Art of Network Engineering by Andy and Friends

The Art of Network Engineering

84 Listeners

Heavy Strategy by Packet Pushers

Heavy Strategy

27 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners

Heavy Wireless by Packet Pushers

Heavy Wireless

11 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners

Packet Protector by Packet Pushers

Packet Protector

7 Listeners

Network Automation Nerds by Packet Pushers

Network Automation Nerds

5 Listeners

Total Network Operations by Packet Pushers

Total Network Operations

4 Listeners

Technically Leadership by Packet Pushers

Technically Leadership

0 Listeners

N Is For Networking by Packet Pushers

N Is For Networking

29 Listeners

Network Automagic by Steinn Örvar

Network Automagic

0 Listeners

The Cloud Gambit by Packet Pushers

The Cloud Gambit

0 Listeners

Life In Uptime by Packet Pushers

Life In Uptime

14 Listeners