DENOG18

Maybe it is time to consider layer 3 internet exchanges

Internet exchanges have presented as shared layer 2 networks for thirty years. I will show the mechanisms that silently blackhole exchange traffic or forward it to the wrong port: missing or incorrect neighbour entries, and unknown unicast flooding. In each case BGP stays established to the route servers and nothing reports a fault.

A large exchange stated in writing that it gives no guarantee traffic sent to a peering LAN goes to, and only to, the port of the network it was meant for, and that it knows of no exchange that does. I do not know how many members expect that answer.

The rest of the industry has spent years dismantling large layer 2 domains in favour of routed ones. Perhaps it is time for internet exchanges to forward at layer 3, rather than running a layer 2 forwarding domain with a route server making routing decisions.

In many cases this needs no new hardware. The switches already used to build exchange fabrics forward at layer 2 and at layer 3 at line rate. Route scale is where careful consideration is needed.

The shape of a layer 3 internet exchange switch is already commonplace: each PNI switch a CDN or ISP operates is a routed exchange with several settlement-free peers and one customer on it.

Running at layer 3 gives participants complete isolation between ports, the same model that already applies to every other upstream connection that networks buy. RTBH works at the exchange rather than depending on a peer to honour it. Debugging becomes possible from the participant side, because traceroute shows the exchange hop.

The speaker’s profile picture
James Rice

James Rice is the founder and technical director of Jump Networks Ltd (AS8943), a UK ISP and transit provider in London Docklands. He has been operating public peering since the 1990s, and in October 2001, as the operator of LONAP, turned off unknown unicast flooding on member ports. He has been active in RIPE circles since 2001, and most recently gave a case study on peering LAN mis-forwarding at RIPE 92 in Edinburgh. His long standing interest is in making sure traffic goes where it is meant to go.