1/7
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
---|
No study sessions yet.
Internet is a network of autonomous networks and BGP is how we communicate between those autonomous networks
BGP stands for Border Gateway Protocol
allows us to find the best route on the internet from source IP to best IP in network
between domains of networks
BGP vulnerabilities lead to…
able to spoof BGP traffic
Blocking access to certain sites
impersonating website via IP addresses
BGP is honestly a huge pain b/c it priorities money
So there are like multiple relationships
Peer to Peer
free
I promise to pass your traffic to anotehr network i nexchange you do the same
Customer0service
you pay or i pay you to pass my traffic
usually ISP is always going to prioritize money and do customer service instead
figures out best provider through this
We figure out the “routes” via AS
Some act as multhomed AS in the sense that they connect between multiple AS
Stub AS
on the periphery of the network
Transit AS
passes traffic to other ASs
at least two connections
BGP Table
Okay, so how BGP routers work in general
Use TCP and basically send keep alive messages to other routers periodically
This is to make sure that there’s like a good log of available paths from outer routers
we want to know the best path yippie so we use a BGP table
if we find a new best path, BGP update
Originator in AS path is always going to be rightmost
BGP rule, must NEVER have a valley in the based routing
We don’t want that b/c you’re gonna get super charged
and you could get overwhelmed b/c the other provider or network might be like, oh this is free and then pass traffic you can’t manage to you
Cases you want to run BGP
Multiple of the routers will computer BGP routing
BOrder router could bea route for BGP speaker
Attacks for BGP based on the fact that it runs on TCP
DoS
0- we establish a new TCP connection that we think is legitimate, update everything
BGP route flapping
where like there’s this one route that you’re getting and it’s new and better than what yo uahve, but it’s actually fake, but you’ve sent the update so now the routes in the area are kind of unreliable