Ukuqagela ukungqubuzana kwebhizinisi ekuxhumekeni kwenethiwekhi

Ukuqagela ukungqubuzana kwebhizinisi ekuxhumekeni kwenethiwekhi
Ukungqubuzana kwebhizinisi kwaphakama ngoJuni 10.06.2019, XNUMX ngenxa yokwenyuka kwezindleko zokulethwa kwama-SMS kubasebenzisi benethiwekhi ye-VimpelCom nge-Mail.RU Group. Njengempendulo, I-Mail.RU Group iyeke “ukusebenzela” iziteshi eziqondile ze-IP yaseRussia kunethiwekhi ye-VimpelCom.

Ngezansi ukuhlaziya okufushane kwesimo ngokombono kanjiniyela wenethiwekhi.

Update: 14.06.2019/18/45 XNUMX:XNUMX - ukugcizelelwa kwemizila yaseRussia eya kunethiwekhi ye-VimpelCom, iziphetho zilungisiwe, incazelo yengeziwe U-Sergei Kubasov (CIO VKontakte).
Update: 14.06.2019/19/48 XNUMX:XNUMX - incazelo yengezwe yendlela yokukhawulela ukusatshalaliswa kwemizila eduze komzila “omfushane” waseRussia onqamula i-Rostelecom, MTS, RETN.NET..


Isingeniso:
I-VimpelCom inohlelo oluzimele lwe-AS3216, zonke ezinye (8402 - i-Intanethi yasekhaya, i-16345 - i-Intanethi yeselula) zitholakala ngemuva kwe-3216.

I-Mail.RU Group - izinhlelo ezizimele AS47541, AS47542 kanye ne-AS47764. I-generator yokuqukethwe eyinhloko yi-47542, okuthiwa. CDN VKONTAKTE (amamuvi, umculo). Zonke izinhlelo ezizimele zizimele zodwa (kusukela endaweni yohlelo oluzimele lwangaphandle).

Okokuqala, ake sibheke isimo kunethiwekhi ye-VimpelCom. Kulokhu kuzosisiza Ukubheka i-Glass Vimpelcom.

Ake sibheke uhlelo lokuqala oluzimele - AS47541.

 2914 47541
    79.104.32.251 (metric 10500) (79.104.32.251)
      Origin IGP, metric 30, localpref 87, valid, internal, best, group-best, import-candidate, import suspect
      Received Path ID 0, Local Path ID 1, version 2865394342
      Community: 2914:410 2914:1214 2914:2213 2914:3200 3216:3000 3216:3103 47541:1 47541:40000 47541:50078

I-AS-PATH iqukethe izinhlelo ezimbili ezizimele - i-2914 (NTT) ne-47541 (VKONTAKTE-SPB-AS).
I-localpref metric isethelwe ku-87, okuthi ngokuya ngencazelo ku-RIPE DB yento AS3216 ehambisana nokubuka kwamazwe ngamazwe.

...
amazwibela: Imizila yontanga yamazwe ngamazwe ithola izintandokazi zendawo ku
ukuphawula: ububanzi be-81-89.
...

Ulwazi olufanayo luqinisekiswa imiphakathi 3216:3000 kanye 3216:3103 (umthombo: I-RIPE DB ye-AS3216):

...
amazwibela: 3216:3000 Kutholwe ku-uplink yamazwe ngamazwe noma kontanga, ngokukhethekile:
...
amazwibela: 3216:3103 AMS-IX
...

Okusho ukuthi, i-VimpelCom ibona indlela eya ku-VKontakte ngokusebenzisa i-European junction.

Ake sibheke enye inethiwekhi ye-VKontakte - 47542 (VKONTAKTE-MSK-CDN-AS).

Konke kuyefana.

 2914 47541
    79.104.32.251 (metric 10500) (79.104.32.251)
      Origin IGP, metric 30, localpref 87, valid, internal, best, group-best, import-candidate, import suspect
      Received Path ID 0, Local Path ID 1, version 2865394338
      Community: 2914:410 2914:1214 2914:2213 2914:3200 3216:3000 3216:3103 47541:1 47541:40000 47541:50078

Kuthiwani nge-Mail.ru ngokwayo? Ake sibheke i-AS47764 (mailru-as).

 3356 47764
    194.67.0.215 (metric 10501) (194.67.0.215)
      Origin IGP, metric 0, localpref 77, valid, internal, best, group-best, import-candidate
      Received Path ID 0, Local Path ID 1, version 2867605667
      Community: 3216:3000 3216:3007 3356:2 3356:22 3356:100 3356:123 3356:519 3356:2094 47764:1 47764:40000 47764:50077 

I-VimpelCom ibona i-Mail.ru nge-as3356 (uplink Level3, Tier1 operator). Lolu lwazi luqinisekiswa yi-localpref 77:

...
ukuphawula: Imizila ye-Uplink ithola okuthandwayo kwendawo ebangeni lama-71-79.
ukuphawula: Ukubuyekezwa Kokugcina: February 2012...

kanye nomphakathi (3216:3000 kanye no-3216:3007):

...
amazwibela: 3216:3000 Kutholwe ku-uplink yamazwe ngamazwe noma kontanga, ngokukhethekile:
...
amazwi: 3216:3007 Level 3 Communications
...

Kusukela olwazini olutholiwe kuyacaca ukuthi ithrafikhi esuka kunethiwekhi ye-VimpelCom eya ku-VKontakte ne-MailRu isakazwa ngezixhumanisi zaseYurophu ngokuvumelana nemizila etholwe nge-protocol ye-BGP. Azikho ezinye izindlela ngoxhumano lwasekhaya lwesiRashiya ku-Looking Glass. Azikho izinyathelo ezitholiwe zokuqondisa kabusha ithrafikhi ngokuzenzisa ngemizila ebonakala imbi kakhulu.

I-Mail.ru Group iyibona kanjani inethiwekhi ye-VimpelCom?
Asisebenzise ithuba Ukubheka Ingilazi nguMailov.

Kusuka kuma-routers asuka ku-AS47764 (mailru-as):

  Path #6: Received by speaker 0
  Advertised to peers (in unique update groups):
    188.93.60.188   
  1299 1299 1273 3216 3216
    217.20.147.250 (metric 100) from 217.20.147.250 (217.20.147.253)
      Origin IGP, metric 500, localpref 200, valid, internal, best, group-best
      Received Path ID 0, Local Path ID 0, version 1172721494
      Community: 1299:20000 47764:701 47764:41100 47764:41108 47764:50077

I-AS-PATH iqukethe i-AS1299 (i-Telia, i-opharetha ye-Tier1, i-Mail.RU uplink) kanye ne-as1273 (i-Vodafon, i-opharetha ye-Tier1, i-VimpelCom uplink).

I-LocalPreference 200 iyindinganiso yokuxhumana kwangaphandle kwe-Mail.ru (https://net.mail.ru/bgp.html), futhi i-MED 500 ihambisana nakho konke okungatholakali ekuxhumaneni okuqondile, hhayi kuma-IX, hhayi kontanga .

Kodwa kungani ingekho imizila yendawo ngokusebenzisa opharetha be-telecom baseRussia ???
Zikhona, kodwa okubalulekile kwazo “akuyona indinganiso”!
Nansi indlela nge-Rostelecom (as12389):

  Path #1: Received by speaker 0
  Not advertised to any peer
  12389 3216
    46.61.178.149 from 46.61.178.149 (213.59.207.79)
      Origin IGP, metric 500, localpref 199, valid, external
      Received Path ID 0, Local Path ID 0, version 0
      Community: 3216:2001 3216:2999 3216:4100 12389:5 12389:6 12389:1100 12389:1105 12389:1277 47764:701 47764:41100 47764:41104 47764:50077
      Origin-AS validity: not-found

Lapha nge-Megafon (as31133):

  Path #2: Received by speaker 0
  Not advertised to any peer
  31133 3216
    78.25.77.41 from 78.25.77.41 (10.222.253.97)
      Origin IGP, metric 500, localpref 199, valid, external
      Received Path ID 0, Local Path ID 0, version 0
      Community: 3216:2001 3216:2999 3216:4100 31133:300 31133:46170 47764:701 47764:41100 47764:41105 47764:50077
      Origin-AS validity: not-found

Lapha nge-RETN.NET:

  Path #3: Received by speaker 0
  Not advertised to any peer
  9002 9002 3216
    87.245.253.24 from 87.245.253.24 (87.245.225.1)
      Origin IGP, metric 500, localpref 199, valid, external
      Received Path ID 0, Local Path ID 0, version 0
      Community: 9002:9002 9002:64667 47764:701 47764:41100 47764:41101 47764:50077
      Origin-AS validity: not-found

Futhi ngisho nange-MTS!

  Path #5: Received by speaker 0
  Not advertised to any peer
  8359 3216
    212.188.61.105 from 212.188.61.105 (195.34.52.77)
      Origin IGP, metric 500, localpref 199, valid, external
      Received Path ID 0, Local Path ID 0, version 0
      Community: 8359:200 8359:609 8359:5012 47764:701 47764:41100 47764:41103 47764:50077
      Origin-AS validity: not-found

Imethrikhi ye-localpref yale mizila yaseRussia ibukelwa phansi, okungukuthi, imizila mibi kakhulu uma iqhathaniswa neyangaphandle!

Ngaphezu kwalokho, kukhona ukuvinjelwa ngasohlangothini lwe-Mail.Ru Group ukusatshalaliswa kweziqalo zakho ku-VimpelCom ngokusebenzisa opharetha baseRussia!

I-RETN.NET (http://lg.retn.net/):
Izimemezelo ezivela ku-Mail.RU Group zibonisa umphakathi 3216:65535.
Ukuhoxiswa ku-LG RETN.NETinet.0: 762737 izindawo, 1734826 imizila (762708 esebenzayo, 222780 holddown, 277 kufihliwe)
94.100.176.0/20 (1 okufakiwe, oku-1 kumenyezelwe)
*BGP Okuncamelayo: 170/-201
...
...
AS indlela: 47764 I
Indlela ye-AS: Irekhodiwe
Imiphakathi: 3216:65535 9002:64667 9002:65530
...

I-VimpelCom ayamukeli imizila emakwe umphakathi onjalo kunethiwekhi yayo. Ingcaphuno evela ku-RIPE DB ku-AS3216:
...
remarks: Internal comminuties are assigned only internally.
remarks: They are in range 3216:0000-3216:4999 and 3216:6000-3216:65535
remarks: and are always deleted from incoming updates at the border
remarks: routers.
...

Ekuqondeni kwe-Rostelecom (http://lg.ip.rt.ru), i-Mail.RU Group inikeza imizila efanayo esuka emphakathini 12389:8350.
Ukuhoxiswa kwe-LG Rostelecom94.100.176.0/20 nge-217.107.65.1 ku-eth0.9 [sr2 2019-06-13] * (100/?) [AS47764i]
Uhlobo: I-BGP unicast univ
BGP.imvelaphi: IGP
BGP.as_path: 47764
BGP.next_hop: 213.59.207.78
BGP.med: 0
BGP.local_pref: 850
BGP.umphakathi: (12389,1) (12389,1100) (12389,1105) (12389,1277) (12389,8350) (12389,8380) (47764,1) (47764,40000).
BGP.originator_id: 213.59.207.78
BGP.cluster_list: 95.167.88.79 95.167.88.49 95.167.88.17

Ngokusho kokufakiwe kwe-RIPE DB kwento ethi12389, lo mphakathi usho ukuthi “ungakhangisi kunethiwekhi ye-as3216”:...
remarks: | 12389:835y When advertising to GoldenTelecom (AS3216) |
...
remarks: | ...y=0 - do not advertise |
...

Ngokufanayo ku-MTS (http://lg.mtu.ru):Ukuhoxiswa ku-LG MTSUkufakwa kwetafula lomzila le-BGP kwe-94.100.176.0/20, inguqulo 161717219
Izindlela: (2 ezitholakalayo, ezihamba phambili #1, okuzenzakalelayo kwethebula)
I-Multipath: eBGP
Ikhangiswe kumaqembu wokuvuselela:
6
47764, (yamukelwe futhi yasetshenziswa)
195.34.52.77 (metric 16) kusukela ku-195.34.52.181 (195.34.52.181)
Umsuka we-IGP, imetric 0, localpref 140, evumelekile, yangaphakathi, ehamba phambili
Umphakathi: 8359:2120 8359:2150 8359:5500 8359:55277
Umsunguli: 195.34.52.77, Uhlu Lweqoqo: 83.59.83.59
47764, (yamukelwe futhi yasetshenziswa)
195.34.52.77 (metric 16) kusukela ku-195.34.52.182 (195.34.52.182)
Umsuka we-IGP, imetric 0, localpref 140, evumelekile, yangaphakathi
Umphakathi: 8359:2120 8359:2150 8359:5500 8359:55277
Umsunguli: 195.34.52.77, Uhlu Lweqoqo: 83.59.2.77

Umphakathi 8359:2120 usho ukuthi:...
remarks: 8359:212x when announcing to Sovam (Beeline)
...
remarks: x=0 - do not announce
...

Awukwazi ukubheka izimemezelo ze-Mail.RU Group eziqonde e-Megafon - eyakamuva ayinayo i-Looking Glass.

Ake sibheke i-AS47541 (VKONTAKTE-SPB-AS).

Okukhiphayo kukhulu kakhulu.

 Router: a9922-e-5
Command: show ip bgp 81.211.56.202


Last switch-over Thu Apr  5 04:25:09 2018: 1 year, 10 weeks, 6 hours, 9 minutes ago

Fri Jun 14 10:34:20.791 MSK
BGP routing table entry for 81.211.0.0/17
Versions:
  Process           bRIB/RIB  SendTblVer
  Speaker          913059757   913059757
Last Modified: May 21 05:20:38.536 for 1y03w
Paths: (6 available, best #4)
  Advertised to update-groups (with more than one peer):
    0.2 
  Advertised to peers (in unique update groups):
    188.93.60.188   
  Path #1: Received by speaker 0
  Not advertised to any peer
  1299 1273 3216 3216
    87.240.191.235 (metric 31) from 87.240.191.235 (87.240.191.235)
      Origin IGP, metric 5000, localpref 150, valid, internal
      Received Path ID 0, Local Path ID 0, version 0
      Community: 1273:12752 1299:431 1299:4000 1299:20000 1299:20002 1299:20200 3216:2001 3216:2999 3216:4100 47541:701 47541:41100 47541:41111 47541:50078
  Path #2: Received by speaker 0
  Not advertised to any peer
  1299 1273 3216 3216
    87.240.191.248 (metric 31) from 87.240.191.248 (87.240.191.248)
      Origin IGP, metric 5000, localpref 150, valid, internal
      Received Path ID 0, Local Path ID 0, version 0
      Community: 1273:12752 1299:431 1299:4000 1299:20000 1299:20002 1299:20200 3216:2001 3216:2999 3216:4100 47541:701 47541:41100 47541:41111 47541:50078
  Path #3: Received by speaker 0
  Not advertised to any peer
  174 6762 3216 3216
    87.240.191.249 (metric 31) from 87.240.191.249 (87.240.191.249)
      Origin IGP, metric 5000, localpref 150, valid, internal
      Received Path ID 0, Local Path ID 0, version 0
      Community: 174:21100 174:22005 47541:701 47541:41100 47541:41108 47541:50078
  Path #4: Received by speaker 0
  Advertised to update-groups (with more than one peer):
    0.2 
  Advertised to peers (in unique update groups):
    188.93.60.188   
  174 6762 3216 3216
    149.6.169.113 from 149.6.169.113 (38.28.1.236)
      Origin IGP, metric 5000, localpref 150, valid, external, best, group-best
      Received Path ID 0, Local Path ID 0, version 913059757
      Community: 174:21100 174:22005 47541:701 47541:41100 47541:41108 47541:50078
      Origin-AS validity: not-found
  Path #5: Received by speaker 0
  Not advertised to any peer
  1273 1273 3216 3216
    195.89.114.197 from 195.89.114.197 (195.2.1.107)
      Origin IGP, metric 5005, localpref 150, valid, external
      Received Path ID 0, Local Path ID 0, version 0
      Community: 1273:12752 3216:2001 3216:2999 3216:4100 47541:701 47541:41100 47541:41110 47541:50078
      Origin-AS validity: not-found
  Path #6: Received by speaker 0
  Not advertised to any peer
  3356 3356 3216 3216 3216
    213.242.69.69 from 213.242.69.69 (4.69.177.130)
      Origin IGP, metric 5000, localpref 150, valid, external
      Received Path ID 0, Local Path ID 0, version 0
      Community: 3216:2001 3216:2999 3216:4100 3356:2 3356:22 3356:100 3356:123 3356:503 3356:2067 47541:701 47541:41100 47541:41107 47541:50078
      Origin-AS validity: not-found

I-AS-PATH ikhomba ku-AS174 - Cogent (Mail.RU uplink, Tier1), bese kuba ngu-AS6762 - Telecom Italia (VimpelCom uplink). I-Local Preference ingu-150 yonke indawo, kodwa lokhu kusebenza kuwo wonke amalunga angaphandle, kungakhathaliseki ukuthi yikuphi izinqubomgomo ezibhaliwe.

Ake sibheke i-AS47542 (VKONTAKTE-MSK-CDN-AS).

 Router: mx960-m9-0
Command: op lg-sh-bgp prefix 81.211.56.202


0.0.0.0/0                LP:151       MED:        NH:87.240.191.222  AS path: 47541 I
Communities: 
Accepted Best

 
0.0.0.0/0                LP:151       MED:        NH:95.142.204.251  AS path: 47541 I
Communities: 
Accepted
Inactive-reason: Interior > Exterior > Exterior via Interior

Futhi kusukela kumzila wesibili:

 Router: mx960-m9-1
Command: op lg-sh-bgp prefix 81.211.56.202


0.0.0.0/0                LP:151       MED:        NH:87.240.191.224  AS path: 47541 I
Communities: 
Accepted Best

 
0.0.0.0/0                LP:151       MED:        NH:95.142.204.250  AS path: 47541 I
Communities: 
Accepted
Inactive-reason: Interior > Exterior > Exterior via Interior

Imizila ezenzakalelayo kuphela (0.0.0.0/0). Lesi simo sachazwa isisebenzi se-Mail.RU Group ukuhaha, engimbonga ngakho. Ngamafuphi: ingxenye yaseMoscow yenethiwekhi ye-VKontakte iyingxenye ye-caching (futhi ayikhiqizi), umsebenzi wayo uwukukhuphula isivinini sokulayisha sokuqukethwe okuthandwayo, okudingekayo. Ukunakekela abasebenzisi, yebo.

Uma ungekho umzila oya kunethiwekhi ethile, khona-ke le nethiwekhi ayinikezwa amaseva e-caching. Lokhu kusho ukuthi ukulungiselelwa kwesivinini sokulanda akusebenzi, futhi abasebenzisi bayahlupheka. Kodwa lapha sidinga ukugcizelela ukuthi abasebenzisi akubona abethu kuphela, kodwa nalabo beVimpelCom.

Iziphetho:

  1. Kusuka ku-VimpelCom, ithrafikhi ebheke ku-Mail.RU Group isatshalaliswa ngokwemvelo. Akukho ukuqondisa kabusha okwenziwa ngokukhohlisa Okuncamelayo Kwasendaweni okutholiwe
  2. I-Mail.RU Group ibheka ukukhohlisa ngeziqalo ze-VimpelCom. Imizila ekhona ebheke kunethiwekhi ye-VimpelCom ngokusebenzisa ama-opharetha aseRussia inezinto eziza kuqala eziphansi uma ziqhathaniswa nemizila edlula opharetha be-Tier1 bangaphandle.
  3. Abaphathi bomphakathi be-BGP bangeziwe emizileni edluliselwa kuma-opharetha aseRussia (MTS, Rostelecom, RETN.NET) yi-Mail.RU Group ukunciphisa ukusabalala kwabo ku-VimpelCom.

Kungani i-Mail.RU Group ibeka phambili imizila edlula eYurophu? Kungani i-Mail.RU Group ivimbela ukuxhumana okufushane kwasekhaya kwaseRussia ne-VimpelCom?

Ingabe ishibhile kubo? Shayela ithrafikhi ngeziteshi zakwamanye amazwe futhi ukhokhele ama-Tirvans ngemali yangaphandle?
Noma ingabe sikhona isifiso sokushayela ithrafikhi kude ukuze ukuyithatha kungabi lula kangako, huh?
Lokhu akwaziwa unjiniyela wenethiwekhi...

Source: www.habr.com

Thenga ukusingathwa okuthembekile kwamasayithi anokuvikelwa kwe-DDoS, amaseva e-VPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekile ngokuvikelwa kwe-DDoS, amaseva e-VPS VDS | ProHoster