Responsible Edge Policies

Analysis
Aug 6, 20073 mins

Avi Freedman long ago described a route advertisement as a promise to deliver packets to the advertised destination. I’ve liked that adage so much that I’ve used it over the years in numerous networking classes and have even quoted it in one of my books.

There’s a lot behind that little statement: You are expected to live up to your promises, so if you promise to deliver packets to a destination you must perform due diligence to insure that you really can. Likewise, you must be sure that you do not make a promise that you cannot keep: Make sure you do not advertise a destination that you cannot route packets to.

Yet on the Internet, autonomous systems frequently make promises they cannot keep, and that’s at the heart of a number of big network outages. A recent example of this is the brief but well-publicized Yahoo outage a month ago. Hanaro Telecom, a South Korean Internet Service Provider, advertised a /14 prefix to Level 3 Communications that caused packets destined for Yahoo and several other destinations to be incorrectly routed to Hanaro, where they were blackholed.

It’s unfair to call this incident the “Yahoo outage,” because Yahoo was only a victim, not a culprit, in the incident. The general public of course does not know about or care about BGP routing errors; they only know they couldn’t get to Yahoo, and blamed the company for the problem.

It’s also a little unfair to blame Level 3, although many have. While their router should not have accepted the bad advertisement (and I don’t know why it did), Level 3 has one of the best filtering practices around; they put tremendous effort into their edge filters, where many operators have minimal filtering policies or none at all.

It’s even unfair to blame the poor soul at Hanaro who made the configuration error causing the bad advertisement. People make mistakes.

Rather, the fault apparently lies with Hanaro’s outgoing filtering policies. If the right filters had been in place, it is unlikely that a bad route would have made it out to the public.

Discussion of filtering practices and policies seem to dwell heavily on what advertisements are accepted at the edge of the network, and this is only right: If you leave your door wide open, you’ve got to bear some liability for who comes wandering in. But even if every household in the neighborhood leaves its doors unlocked, you still have a fundamental responsibility to be a good neighbor and not take advantage.

Likewise, if you advertise routes to a neighbor, do it responsibly: Implement outgoing filters that insure you are not advertising anything you should not advertise, that might hurt not only your neighbor but—as in the Yahoo incident—an entirely innocent bystander.

Surprisingly, such “good neighbor policies” are far from common; more common, from what I’ve seen, is an attitude that if a neighbor is accepting routes from you, they do so at their own risk. Proper precautions, it seems to many operators, is the other guy’s problem.

Over the next few posts, I’d like to discuss best practices at the network edge both for incoming and outgoing filters, some tools for implementing responsible edge policy, and some work being done to improve the reliability of BGP route exchange.