policy
Differences
This shows you the differences between two versions of the page.
| Previous revision | |||
| — | policy [2025/11/22 22:57] (current) – noc | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ===== Peering ===== | ||
| + | |||
| + | ==== Autonomous System Number ==== | ||
| + | AS53062 | ||
| + | |||
| + | ==== Peering Policy ==== | ||
| + | We have an open peering policy, and we welcome the opportunity to establish peering connections with any BGP operator, in an effort to improve the experience of our users. | ||
| + | |||
| + | ==== Peering Information ==== | ||
| + | |ASN|AS53062| | ||
| + | |Suggested IPv4 Prefix Limit|4500| | ||
| + | |Suggested IPv6 Prefix Limit|2500| | ||
| + | |PeeringDB|http:// | ||
| + | |||
| + | ==== Contact Information ==== | ||
| + | |NOC Contact|< | ||
| + | |Peering Contact|< | ||
| + | |||
| + | ===== BGP Session Request or Prefix Release ===== | ||
| + | Requests for BGP sessions or prefix releases must be made via email, following the templates at the link below: | ||
| + | |||
| + | [[http:// | ||
| + | |||
| + | ===== BGP Policies ===== | ||
| + | |||
| + | ==== Internet Routing Registry ==== | ||
| + | We keep our aut-num, as-set, route, and route6 objects updated in the IRR **ALTDB** database through **MAINT-AS53062** | ||
| + | |||
| + | < | ||
| + | #aut-num | ||
| + | whois -h whois.radb.net AS53062 | ||
| + | #as-set | ||
| + | whois -h whois.radb.net AS-53062 | ||
| + | #route | ||
| + | whois -h whois.radb.net -i origin AS53062 -T route | ||
| + | #route6 | ||
| + | whois -h whois.radb.net -i origin AS53062 -T route6 | ||
| + | </ | ||
| + | |||
| + | https:// | ||
| + | |||
| + | |||
| + | ==== BGP Session Types ==== | ||
| + | ^ PROFILE ^ DESCRIPTION ^ LOCAL_PREF ^ | ||
| + | | Internal | originated prefixes | 7000 | | ||
| + | | Custumers | **IN**: accept_customer_prefix_aspath_list(); | ||
| + | | Private Network Interconections (PNIs) | **IN**: Routes received in the session will **by default** be announced to our customers and our traffic exchange connections, | ||
| + | | Internet Exchange Points (IXPs) | **IN**: Routes received in the session are placed in our routing table with the LOCAL_PREF defined in the column to the right and are used for traffic forwarding. \\ **OUT**: We announce our prefixes and customer prefixes according to our traffic engineering definitions. | 4000 | | ||
| + | | Upstreams | **IN**: reject_bogon_asns(); | ||
| + | |||
| + | * LOCAL_PREF is standard for each session type and cannot be changed through communities. | ||
| + | * All sessions with the same neighboring AS will be adjusted for the same type of session. (e.g.: a customer cannot be peering and transit at the same time, it is either one or the other). | ||
| + | |||
| + | ==== MED ==== | ||
| + | |||
| + | Customers with multiple eBGP sessions with us may use the MED (Multi-Exit Discriminator) attribute to indicate their preferred ingress path between different circuits. This allows traffic entering our network to be directed to the desired circuit according to the MED values advertised by the customer. By default, lower MED values are preferred. | ||
| + | |||
| + | ==== BGP Communities ==== | ||
| + | |||
| + | === RPKI (Resource Public Key Infrastructure) === | ||
| + | ^ Attribute ^ Internal Name ^ | ||
| + | |53062:601 | rpki_valid | | ||
| + | |53062:602 | rpki_invalid | | ||
| + | |53062:603 | rpki_unknown | | ||
| + | |||
| + | Notes: | ||
| + | * Invalid prefixes are rejected | ||
| + | |||
| + | === Blackhole Community === | ||
| + | ^ Attribute ^ Internal Name ^ Description ^ | ||
| + | |53062:666 | blackhole | Redirects /32 prefix traffic to NULL0 and propagates the route to the internet | | ||
| + | |53062:665 | blackhole_internal | Redirects /32 prefix traffic to NULL0 without propagating it to the internet (For internal use only; customers cannot use it) | | ||
| + | |||
| + | |||
| + | Notes: | ||
| + | * We only accept /32 prefixes in Blackhole. | ||
| + | * The customer must tag the /32 prefix with community 53062:666 | ||
| + | |||
| + | === DDoS Mitigation Service === | ||
| + | * The service works by monitoring potential traffic anomalies. When an anomaly is identified, primary triggers are activated to specifically filter the anomalous flow. | ||
| + | * Secondary triggers may take blackhole action. | ||
| + | * No community tagging is required for the mitigation service. | ||
| + | * The service is not standard. It must be contracted. | ||
| + | |||
| + | ^ Attribute ^ Internal Name ^ Description ^ | ||
| + | |53062:669 | ddos_filter_diversion | This community is informational only and indicates that the prefix was redirected to a mitigation center. | | ||
| + | |53062:670 | fs_rib_only | This community prevents a flowspec rule from being installed on the FIB of the ASN routers. | | ||
| + | |||
| + | |||
| + | |||
| + | === Internal Communities === | ||
| + | |||
| + | We tag all internal routes, from our customers, our upstreams, traffic exchange points, and private peerings using communities, | ||
| + | |||
| + | ^ Attribute ^ Internal Name ^ Description ^ | ||
| + | |Internal||| | ||
| + | |- 53062:10080 | mark_ourprefixes | Our prefixes | ||
| + | |Customers||| | ||
| + | |- 53062:10020 | mark_customers | Prefixes learned from a Customer | ||
| + | |Upstreams||| | ||
| + | |- 53062:10072 | mark_upstreams | Prefixes learned from an Upstream | ||
| + | |- - 53062:10074 | mark_level3 | ||
| + | |- - 53062:10075 | mark_internexa | Prefixes learned via Internexa | ||
| + | |- - 53062:10155 | mark_openx | ||
| + | |- - 53062:10087 | mark_sparkle | ||
| + | |- - 53062:10094 | mark_tim | ||
| + | |- - 53062:10120 | mark_algar | ||
| + | |- - 53062:10132 | mark_angolacables | ||
| + | |- - 53062:10166 | mark_cogent | ||
| + | |- - 53062:10212 | mark_edgeuno | ||
| + | |- - 53062:10257 | mark_globenet | ||
| + | |- - 53062:10307 | mark_vivo | ||
| + | |- - 53062:10323 | mark_eletronet | ||
| + | |- - 53062:10334 | mark_ufinet | ||
| + | |Internet Exange Points||| | ||
| + | |- 53062:10037 | mark_ixps | ||
| + | |- - 53062:10039 | mark_ixbrsc | ||
| + | |- - 53062:10043 | mark_ixbrsp | ||
| + | |- - 53062:10047 | mark_ixbrpr | ||
| + | |- - 53062:10062 | mark_ixbrrs | ||
| + | |- - 53062:10116 | mark_ixbrbnu | ||
| + | |- - 53062:10135 | mark_ixbrpgo | ||
| + | |- - 53062:10151 | mark_ixbrfoz | ||
| + | |- - 53062:10160 | mark_ixbrrj | ||
| + | |- - 53062:10190 | mark_ixbrcgr | ||
| + | |- - 53062:10216 | mark_ixbrdf | ||
| + | |- - 53062:10234 | mark_ixbrcac | ||
| + | |- - 53062:10238 | mark_ixbrmgf | ||
| + | |- - 53062:10249 | mark_ixbrmg | ||
| + | |- - 53062:10281 | mark_ixbrsjc | ||
| + | |- - 53062:10315 | mark_ixbrce | ||
| + | |- - 53062:10327 | mark_ixbrcba | ||
| + | |- - 53062:10350 | mark_ixbrvta | ||
| + | |Private Network Interconections (PNIs)||| | ||
| + | |- 53062:10077 | mark_pnis | ||
| + | |- - 53062:10053 | mark_trocasdetrafego | Prefixes learned from PNI category " | ||
| + | |- - 53062:10055 | mark_facebookpni | ||
| + | |- - 53062:10170 | mark_twitchpni | ||
| + | |- - 53062:10172 | mark_steampni | ||
| + | |- - 53062:10174 | mark_verizonpni | ||
| + | |- - 53062:10176 | mark_amazonpni | ||
| + | |- - 53062:10178 | mark_cloudflarepni | ||
| + | |- - 53062:10180 | mark_netflixpni | ||
| + | |- - 53062:10098 | mark_googlepni | ||
| + | |- - 53062:10199 | mark_cdn77pni | ||
| + | |- - 53062:10202 | mark_maxihostpni | ||
| + | |- - 53062:10220 | mark_akamaipni | ||
| + | |- - 53062:10230 | mark_stackpathpni | ||
| + | |- - 53062:10199 | mark_i3dpni | ||
| + | |- - 53062:10261 | mark_tiktokpni | ||
| + | |- - 53062:10268 | mark_microsoftpni | ||
| + | |- - 53062:10276 | mark_tencentcdnpni | ||
| + | |- - 53062:10285 | mark_globopni | ||
| + | |- - 53062:10294 | mark_fastlypni | ||
| + | |- - 53062:10303 | mark_gamersclubpni | ||
| + | |||
| + | | CDNs ||| | ||
| + | |- - 53062:10209 | mark_clouflarepop | ||
| + | |||
| + | |||
| + | === Propagation Control === | ||
| + | |||
| + | Some customers (depending on the contract) can control the propagation of their announcements by tagging their prefixes with the following communities: | ||
| + | |||
| + | ^ Attribute ^ Internal Name ^ Description ^ | ||
| + | |Customers ||| | ||
| + | |- 53062:50036 | no_export_to_customers | Do not announce to any customer | ||
| + | |Upstreams ||| | ||
| + | |- 53062:50024 | no_export_to_upstreams | Do not announce to any Upstream | | ||
| + | |- - 53062:50026 | no_export_to_level3 | ||
| + | |- - 53062:50027 | no_export_to_internexa | Do not announce to Internexa | ||
| + | |- - 53062:50066 | no_export_to_openx | ||
| + | |- - 53062:50090 | no_export_to_sparkle | ||
| + | |- - 53062:50095 | no_export_to_tim | ||
| + | |- - 53062:50121 | no_export_to_algar | ||
| + | |- - 53062:50131 | no_export_to_angolacables | ||
| + | |- - 53062:50167 | no_export_to_cogent | ||
| + | |- - 53062:50195 | no_export_to_embratel | ||
| + | |- - 53062:50213 | no_export_to_edgeuno | ||
| + | |- - 53062:50258 | no_export_to_globenet | ||
| + | |- - 53062:50308 | no_export_to_vivo | ||
| + | |- - 53062:50324 | no_export_to_eletronet | ||
| + | |- - 53062:50335 | no_export_to_ufinet | ||
| + | |Internet Exange Points||| | ||
| + | |- 53062:50038 | no_export_to_ixps | ||
| + | |- - 53062:50040 | no_export_to_ixbrsc | ||
| + | |- - 53062:50044 | no_export_to_ixbrsp | ||
| + | |- - 53062:50048 | no_export_to_ixbrpr | ||
| + | |- - 53062:50063 | no_export_to_ixbrrs | ||
| + | |- - 53062:50119 | no_export_to_ixbrbnu | ||
| + | |- - 53062:50138 | no_export_to_ixbrpgo | ||
| + | |- - 53062:50154 | no_export_to_ixbrfoz | ||
| + | |- - 53062:50163 | no_export_to_ixbrrj | ||
| + | |- - 53062:50193 | no_export_to_ixbrcgr | ||
| + | |- - 53062:50219 | no_export_to_ixbrdf | ||
| + | |- - 53062:50237 | no_export_to_ixbrcac | ||
| + | |- - 53062:50241 | no_export_to_ixbrmgf | ||
| + | |- - 53062:50252 | no_export_to_ixbrmg | ||
| + | |- - 53062:50283 | no_export_to_ixbrsjc | ||
| + | |- - 53062:50316 | no_export_to_ixbrce | ||
| + | |- - 53062:50330 | no_export_to_ixbrcba | ||
| + | |- - 53062:50352 | no_export_to_ixbrvta | ||
| + | |CDNs||| | ||
| + | |- 53062:50001 | no_export_to_cdns | ||
| + | |- - 53062:50005 | no_export_to_fna | ||
| + | |- - 53062:50002 | no_export_to_ggc | ||
| + | |- - 53062:50014 | no_export_to_oca | ||
| + | |- - 53062:50083 | no_export_to_akamaibox | Do not announce to Akamai CDN | | ||
| + | |- - 53062:50207 | no_export_to_clouflarepop | ||
| + | |- - 53062:50273 | no_export_to_mcc | ||
| + | |Private Network Interconections (PNIs)||| | ||
| + | |- 53062:50051 | no_export_to_pnis | ||
| + | |- - 53062:50052 | no_export_to_trocasdetrafego | Do not announce to PNI category " | ||
| + | |- - 53062:50056 | no_export_to_facebookpni | ||
| + | |- - 53062:50171 | no_export_to_twitchpni | ||
| + | |- - 53062:50173 | no_export_to_steampni | ||
| + | |- - 53062:50175 | no_export_to_verizonpni | ||
| + | |- - 53062:50177 | no_export_to_amazonpni | ||
| + | |- - 53062:50179 | no_export_to_cloudflarepni | ||
| + | |- - 53062:50181 | no_export_to_netflixpni | ||
| + | |- - 53062:50100 | no_export_to_googlepni | ||
| + | |- - 53062:50201 | no_export_to_cdn77pni | ||
| + | |- - 53062:50204 | no_export_to_maxihostpni | ||
| + | |- - 53062:50221 | no_export_to_akamaipni | ||
| + | |- - 53062:50231 | no_export_to_stackpathpni | ||
| + | |- - 53062:50254 | no_export_to_i3dpni | ||
| + | |- - 53062:50262 | no_export_to_tiktokpni | ||
| + | |- - 53062:50269 | no_export_to_microsoftpni | ||
| + | |- - 53062:50277 | no_export_to_tencentcdnpni | ||
| + | |- - 53062:50286 | no_export_to_globopni | ||
| + | |- - 53062:50295 | no_export_to_fastlypni | ||
| + | |- - 53062:50304 | no_export_to_gamersclubpni | ||
| + | |||
| + | * Use our [[# | ||
| + | |||
| + | **Attention: | ||
| + | It is important to understand that " | ||
| + | |||
| + | ===== Looking Glass ===== | ||
| + | |||
| + | This tool allows routing (BGP protocol) queries and reachability and response time tests. | ||
| + | ^ Address ^ Protocol ^ Notes ^ | ||
| + | | http:// | ||
| + | | telnet:// | ||
| + | |||
| + | ===== Inter-Network Operation Center Dial By Autonomous System Number ===== | ||
| + | |||
| + | Our team can be reached through the iNOC-DBA project | ||
| + | |||
| + | Hotline Phone: **53062*100** | ||
| + | |||
| + | http:// | ||
| + | http:// | ||
| + | |||
| + | ===== MANRS ===== | ||
| + | https:// | ||
| + | https:// | ||
| + | |||
| + | --- NOC Version: 2024062601 | ||
| + | --- Author: Marcelo Balbinot | ||
