4 ms·
Looking at their prefix right now I see them behind Hurricane Electric prepended 3 times. They ought to filter/sever that out give HEs "we treat peers as custom
by kitteh 6y ago
Looking at their prefix right now I see them behind Hurricane Electric prepended 3 times. They ought to filter/sever that out give HEs "we treat peers as customers" offensive routing policy. Unless that's what they want :/
- Jonnax 6y agoWhat do you mean by "we treat peers as customers"?
- est31 6y agoThat they don't offer peering for free but charge for it. The idea of peering is that both sides gain from it as they reduce the traffic routed through middlemen like level3. So you both go to internet exchanges like DE-CIX, and pay a basic fee that you may participate in the exchange but you get all the connectivity to other ISPs from that exchange. But some ISPs don't do that and require you to peer in one of their own datacenters, requiring you to pay them money. You are now their customer instead of a partner. A big German partially government owned ISP did this for a while until they finally gave up a few years ago.
- welterde 6y agoHE doesn't charge for peering though. The complaint was that HE was leaking peer routes to other peers per default, which is normally only done if you are a customer (which can be nice if you want this, but can lead to sub-optimal routing if you don't want this).
- sprayk 6y agowhere can I find more information on HE's "we treat peers as customers" routing policy?
- kitteh 6y agoSo this is something they're not very open about, but you'll learn the hard way. Years ago Hurricane Electric would setup settlement free peers to be downstream customers in order to inflate their IPv6 footprint. Years ago HE was trying really hard to be the largest IPv6 transit provider in terms of prefixes and ASNs behind them in order to get some of the larger networks to peer with them ("we have X percent of the IPv6 internet"). To their credit it actually worked with a few. As for the goofy routing: if you were an IPv6 peer they'd announce you to their a large amount of their other peers (normally you don't announce peers to transit or peers - just to customers). This led to lots of sub-optimal routing scenarios and you'd have to ask them to knock it off and treat you like a real peer. So yeah cool you get free transit kinda, but the goofy routing isn't worth it for a lot of folks. This plus their long history of lack of filtering their transit customers and enabling lots of route hijacks really gave them a bad reputation. Their recent news about deploying RPKI is a bit of fake news: it's not real RPKI and doesn't address the issues with their customers.
- wbl 6y agoSo HE would carry the traffic for free between peers? That sounds very generous of them!
- iso1631 6y agoThat's what I thought, but I don't play in that playpen Wouldn't you just have an inbound filter to only allow HE ASes? Or do you also want to reach other ASes that pay HE for upstream service, but are multi-homed so exist in their own AS?
- kitteh 6y agoThere's two ways to think about this problem: routes advertised and routes received. Received: So for the most part people implement zero or just minimal filters on routes received from peers. They might drop a set of ASNs they consider large that would be indicative of a leak. Some may go the extra distance and even do IRR filtering. But for the most part people are fairly permissive in what they accept from peers Advertised: Here's the catch. You announce routes to HE and they're propagating it to networks you don't anticipate. This pulls in traffic from other HE peers you weren't expecting. You don't really have much controls here. You can try to prepend but remember it's the other leaked peers of HE that will generally set a better local pref to HE (by virtue of being a peer) so your prepends won't do anything.