SlideShare ist ein Scribd-Unternehmen logo
1 von 56
Downloaden Sie, um offline zu lesen
Marek Isalski – marek @ faelix.net – @maznu
faelix limited – https://faelix.net/ – @faelix
KEEPING YOUR RACK COOL
WITH ONE "/IP ROUTE RULE"
THE END
QUESTIONS ETC?
NOT SO FAST…
;-)
KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE"
HOW FAELIX ARRIVED AT THIS IDEA
▸ Part 1:
▸ About our network and what we do
▸ Our experience using MikroTik at the provider edge
▸ Part 2:
▸ Zero filter rules! :-)
MIKROTIK AT THE
PROVIDER EDGE
PART 1:
KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE"
ABOUT FAELIX
▸ Mostly-hosting ISP
▸ Security, social issues, environment
▸ Based in Manchester, UK = local footprint
▸ ≈50% of servers in Geneva, CH = excellent energy efficiency
▸ Multi-homed, multi-site, autonomous system: AS41495
EYEBALLS VS CONTENT
SINGLE VS MULTI
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
MULTI-HOMED
▸ Organise "transit" from upstream providers
▸ Talk BGP with them, announcements + get sent routing tables
▸ Maybe you get "default only"…
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
MULTI-HOMED
▸ Organise "transit" from upstream providers
▸ Talk BGP with them, announcements + get sent routing tables
▸ …or maybe you get "full tables"
▸ >600k IPv4 routes, >30k IPv6 routes
▸ That's a lot of routes!
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
OUR MIGRATION TO MIKROTIK ROUTEROS
▸ Quagga + BIRD on servers running Linux solid for >6 years ❤
▸ 2015: we wanted to do an upgrade… 📈
▸ We love the energy efficiency of MikroTik CCR… 💚
▸ No "NSA/GCHQ inside"… 😍
▸ Can we use RouterOS? 🤔
▸ + BIRD on servers running Linux? 🐧
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
TWO ROUTING SYSTEMS?
▸ Early version of BIRD segfaulted, withdrew announcements
▸ Quagga kept on running, we did not vanish from DFZ
▸ Are we sure RouterOS BGP is going to cope?
▸ What is support going to be like? Debugging?
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
OVERALL EXPERIENCE
▸ Some weird behaviour occasionally…
▸ NTP leap second bug = hard crash
▸ Disable VLAN interface before
changing its physical interface orVID
▸ Support are helpful and fast;
anecdotally, as responsive as the "big
name" vendors
▸ Debugging time = get friendly with
RouterOS command-line
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
THE GOOD THE BAD
▸ £700 + 70W routes >10Gbit/s
▸ BGP feels familiar afteryears
of experience of Quagga
▸ Consultants out there if you
need them; training & quals
▸ MikroTik now "go to" choice
for CPE, wireless, etc…
▸ Vendor interop good (beware
of extra options in RouterOS)
▸ Watchdog not good enough,
IPMI-style OOB hard reboot?
▸ BGP converge & FIB is slow on
CCRwith 2M+ routes
▸ Routing filters don't always
work first time (enable/disable)
▸ Switch VLAN setup feels like
raw config of merchant silicon
▸ "RouterOS 7"
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
FAELIX'S TIPS
▸ CHR, hardware is economical = no excuses for network lab
▸ Consider leap-frogging RouterOS releases in production
▸ layer-3 > layer-2, MikroTik affordability = dream come true
▸ Full routing tables get into FIB a lot quicker on x86 than on tile
▸ oxidized + syslog = configs in git + logs in one place
▸ snmp + graphite + grafana = netops visibility, cool dashboards
▸ BCP38 + MANRS + abuse-c = be excellent to each other
MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE
PLUGS
▸ http://uknof.org.uk/ = packet pushers of the UK (and beer)
▸ http://netmcr.uk/ = packet pushers of Manchester (and beer)
BEER-TO-PEER NETWORKING
FIREWALLING WITH
ZERO FILTER RULES!
PART 2:
U WOT M8?
you, right now
ZERO FILTER FIREWALLS
ssh
SMTP / IMAP / POP
VOIP
Drupal
WordPress
IPsec
L2TP
ZERO FILTER FIREWALLS
SHIT HAPPENS
▸ Your networkwill get scanned
▸ ssh, DDoS amplification, open proxies…
▸ You might have forgotten something
▸ Is your management network isolated?
▸ Your customers will do things you don't expect
▸ e.g. SNMP or DNS on CPE open to Internet
▸ Software has bugs
That is one big
pile of shit!
omg wtf loadavg bbq
SECURITY IS HARD
every infosec professional ever
ZERO FILTER FIREWALLS
START WITH THE LOW-
HANGING FRUIT…
GOAL:
THE NEXT CROP!
AND WHEN THEY'RE PICKED…
LOGS + DATA
STEP 1:
FAIL2BAN
STEP 2:
WWW
Cat GIF Blog
make DJT
root again!
apache
logs
fail2ban
ZERO FILTER FIREWALLS
FAIL2BAN
▸ Follow log file, if line matches "filter" then performs "action"
▸ Great for blocking brute force (ssh, etc)
▸ MikroTikwiki + forum have examples for RouterOS
▸ Send logs via syslog to a VM for analysis
▸ fail2ban connects to RouterOS with ssh and blocks using:
▸ add new /ip firewall filter (ok)
▸ add new /ip firewall address-list (better)
ZERO FILTER FIREWALLS
FAIL2BAN
▸ Quick, cheap, easy
▸ Make your own or find rules to block
web, VoIP, and other nasty traffic
▸ Attackerwill move on to another
target pretty quickly when DROPped
▸ Next target might still be in your
network, still traffic across your
backbone
▸ Can we put attacking IPs on a
network-wide "naughty step"?
BLOCK AT THE
PROVIDER EDGE
STEP 3:
Edge Router
WWW
Cat GIF Blog
make DJT
root again!
apache
logs
fail2ban
slurry
spreader
AMQP
ROSAPI
ZERO FILTER FIREWALLS
BLOCKING AT THE PROVIDER EDGE
▸ Lots of flows, lots of PPS, lots of attacking addresses
▸ /ip firewall filter uses each set of rules sequentially = O(n)
▸ /ip firewall address-list is a hash-table ≈ O(1)
▸ Using AMQP to get addresses added to block lists on all routers
in three data-centres
▸ We already had RabbitMQ across our network for other
infrastructure needs
FALSE POSITIVES
STEP 4:
WWW
Cat GIF Blog
apache
logs
fail2banslurry
spreader
AMQP
passwords
are hard
Edge Router
ROSAPI
FALSE POSITIVES
STEP 4:
WWW
Cat GIF Blog
apache
logs
fail2banslurry
spreader
AMQP
passwords
are hard
Edge Router
DNAT!
ROSAPI
FALSE POSITIVES
STEP 4:
WWW
Cat GIF Blog
apache
logs
fail2banslurry
spreader
AMQP
passwords
are hard
Edge Router
ROSAPI
ZERO FILTER FIREWALLS
DESTINATION NAT
▸ Send bad traffic to a VM serving the "blocked" message:
▸ /ip firewall nat src-address-list=shitpit action=dst-nat
CONN
TRACK!
tl;dr: ah, crap
ZERO FILTER FIREWALLS
BLOCKING AT THE PROVIDER EDGE
▸ Lots of flows, lots of PPS, lots of attacking addresses
▸ /ip firewall filter uses each set of rules sequentially = O(n)
▸ /ip firewall address-list is a hash-table ≈ O(1)
▸ Using AMQP to get addresses added to block lists on all routers
in three data-centres
▸ We already had RabbitMQ across our network for other
infrastructure needs
ZERO FILTER FIREWALLS
BLOCKING AT THE PROVIDER EDGE
▸ Lots of flows…
▸ …so use a mangle rule so routers only track bad traffic?
▸ No! We want to build something we can understand.
MULTI-
HOMED!
tl;dr: ah, crap2
TRAFFIC HAS MULTIPLE PATHS
IN AND OUT OF OUR NETWORK
PROBLEM:
Edge Router
Edge Router
Edge Router
Edge Router
Edge Router
TRAFFIC HAS MULTIPLE PATHS
IN AND OUT OF OUR NETWORK
PROBLEM:
Edge Router
Edge Router
Edge Router
Edge Router
Edge Router
TRAFFIC HAS MULTIPLE PATHS
IN AND OUT OF OUR NETWORK
PROBLEM:
Edge Router
Edge Router
Edge Router
Edge Router
Edge Router
what is this?
TRAFFIC HAS MULTIPLE PATHS
IN AND OUT OF OUR NETWORK
PROBLEM:
Edge Router
Edge Router
Edge Router
Edge Router
Edge Router
bro, do u even
conntrack?
ZERO FILTER FIREWALLS
WON'T CONNTRACK, CAN'T NAT
▸ Lots of flows
▸ Can't share conntrack across RouterOS devices
▸ Would be nice forVRRP-type HA default gateways?
▸ We don't want to even ifwe could: lots of flows!
▸ And don't want to mangle to ignore good flows…
▸ …and mangle to make return traffic go the right way.
▸ "Are we there yet!?"
KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE"
MULTIPLE ROUTING TABLES
▸ /ip route add gateway=203.0.113.113 routing-mark=shitpit
▸ /ip route rule add routing-mark=shitpit table=shitpit
▸ /ip firewall mangle add chain=prerouting passthrough=yes

action=mark-routing new-routing-mark=shitpit

src-address-list=shitpit
▸ /ip firewall address-list add list=shitpit

address=192.0.2.69/32 timeout=1m
/IP ROUTE RULE
STEP 5:
Edge Router
fail2ban
spreader
make DJT
root again!
WWW
Cat GIF Blog
slurry
AMQP
apache
logs
…AND STAY OUT!
STEP 6:
Edge Router
fail2ban
spreader
make DJT
root again!
slurry
AMQP
YOUR NEXT CROP OF
LOW-HANGING FRUIT
STEP 7:
Edge Router
fail2ban
spreader
make DJT
root again!
WWW
Cat GIF Blog
slurry
AMQP
apache
logs
M
O
RE
RULES!
EXTRA CREDIT
STEP 8:
Edge Router
fail2ban
spreader
make DJT
root again!
slurry
AMQP
Edge Router
fail2ban
slurry
spreader
AMQP
make DJT
root again!
DNS RBL
badips.com
fastnetmon
VIPs
snort
KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE"
REFERENCES
▸ fail2ban = tail log files, filter them, perform actions
▸ fastnetmon = DDoS detection with data from /ip traffic-flow
▸ portsentry = am I being portscanned?
▸ mod_security + OWASP = Web Application Firewall
▸ snort = intrusion detection system
▸ GIFs from devopsreactions, securityreactions, honestnetworker
KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE"
CONCLUSION
▸ /ip route add gateway=203.0.113.113 routing-mark=shitpit
▸ /ip route rule add routing-mark=shitpit table=shitpit
▸ /ip firewall mangle add chain=prerouting passthrough=yes

action=mark-routing new-routing-mark=shitpit

src-address-list=shitpit
▸ /ip firewall address-list add list=shitpit

address=192.0.2.69/32 timeout=1m
e: marek@faelix.net
t: @maznu
w: https://faelix.net/
THANKS FOR LISTENING!
ANY QUESTIONS?

Weitere ähnliche Inhalte

Was ist angesagt?

Best practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protectionBest practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protectionWestermo Network Technologies
 
Kubernetes networking-made-easy-with-open-v switch
Kubernetes networking-made-easy-with-open-v switchKubernetes networking-made-easy-with-open-v switch
Kubernetes networking-made-easy-with-open-v switchInfraEngineer
 
Cisco CCNA-Router on Stick
Cisco CCNA-Router on StickCisco CCNA-Router on Stick
Cisco CCNA-Router on StickHamed Moghaddam
 
OpenStack DVR_What is DVR?
OpenStack DVR_What is DVR?OpenStack DVR_What is DVR?
OpenStack DVR_What is DVR?Yongyoon Shin
 
Cisco CCNA- NAT Configuration
Cisco CCNA- NAT ConfigurationCisco CCNA- NAT Configuration
Cisco CCNA- NAT ConfigurationHamed Moghaddam
 
Things I wish I had known about IPv6 before I started
Things I wish I had known about IPv6 before I startedThings I wish I had known about IPv6 before I started
Things I wish I had known about IPv6 before I startedFaelix Ltd
 
Morphology of Modern Data Center Networks - YaC 2013
Morphology of Modern Data Center Networks - YaC 2013Morphology of Modern Data Center Networks - YaC 2013
Morphology of Modern Data Center Networks - YaC 2013Cumulus Networks
 
20141102 VyOS 1.1.0 and NIFTY Cloud New Features
20141102 VyOS 1.1.0 and NIFTY Cloud New Features20141102 VyOS 1.1.0 and NIFTY Cloud New Features
20141102 VyOS 1.1.0 and NIFTY Cloud New Features雄也 日下部
 
SF Kubernetes Meetup Lightning Talk
SF Kubernetes Meetup Lightning TalkSF Kubernetes Meetup Lightning Talk
SF Kubernetes Meetup Lightning TalkRomana Project
 
第53回WIT研究会におけるリアルタイム映像配信 -技術編-
第53回WIT研究会におけるリアルタイム映像配信 -技術編-第53回WIT研究会におけるリアルタイム映像配信 -技術編-
第53回WIT研究会におけるリアルタイム映像配信 -技術編-Toshimitsu YAMAGUCHI
 
Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501robertguerra
 
How to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco RoutersHow to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco RoutersSolarWinds
 
2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...
2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...
2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...Shuichi Ohkubo
 

Was ist angesagt? (15)

Best practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protectionBest practices for using VPNs for easy network-to-network protection
Best practices for using VPNs for easy network-to-network protection
 
Kubernetes networking-made-easy-with-open-v switch
Kubernetes networking-made-easy-with-open-v switchKubernetes networking-made-easy-with-open-v switch
Kubernetes networking-made-easy-with-open-v switch
 
Cisco CCNA-Router on Stick
Cisco CCNA-Router on StickCisco CCNA-Router on Stick
Cisco CCNA-Router on Stick
 
OpenStack DVR_What is DVR?
OpenStack DVR_What is DVR?OpenStack DVR_What is DVR?
OpenStack DVR_What is DVR?
 
Cisco CCNA- NAT Configuration
Cisco CCNA- NAT ConfigurationCisco CCNA- NAT Configuration
Cisco CCNA- NAT Configuration
 
Things I wish I had known about IPv6 before I started
Things I wish I had known about IPv6 before I startedThings I wish I had known about IPv6 before I started
Things I wish I had known about IPv6 before I started
 
Nat
NatNat
Nat
 
Morphology of Modern Data Center Networks - YaC 2013
Morphology of Modern Data Center Networks - YaC 2013Morphology of Modern Data Center Networks - YaC 2013
Morphology of Modern Data Center Networks - YaC 2013
 
Indicaciones nota 4
Indicaciones nota 4Indicaciones nota 4
Indicaciones nota 4
 
20141102 VyOS 1.1.0 and NIFTY Cloud New Features
20141102 VyOS 1.1.0 and NIFTY Cloud New Features20141102 VyOS 1.1.0 and NIFTY Cloud New Features
20141102 VyOS 1.1.0 and NIFTY Cloud New Features
 
SF Kubernetes Meetup Lightning Talk
SF Kubernetes Meetup Lightning TalkSF Kubernetes Meetup Lightning Talk
SF Kubernetes Meetup Lightning Talk
 
第53回WIT研究会におけるリアルタイム映像配信 -技術編-
第53回WIT研究会におけるリアルタイム映像配信 -技術編-第53回WIT研究会におけるリアルタイム映像配信 -技術編-
第53回WIT研究会におけるリアルタイム映像配信 -技術編-
 
Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501
 
How to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco RoutersHow to Configure NetFlow v5 & v9 on Cisco Routers
How to Configure NetFlow v5 & v9 on Cisco Routers
 
2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...
2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...
2015.7.17 JANOG36 BGP Flowspec Interoperability Test @ Interop Tokyo 2015 Sho...
 

Ähnlich wie Keeping Your Rack Cool with One IP Route Rule

MikroTik & RouterOS
MikroTik & RouterOSMikroTik & RouterOS
MikroTik & RouterOSFaelix Ltd
 
DoS and DDoS mitigations with eBPF, XDP and DPDK
DoS and DDoS mitigations with eBPF, XDP and DPDKDoS and DDoS mitigations with eBPF, XDP and DPDK
DoS and DDoS mitigations with eBPF, XDP and DPDKMarian Marinov
 
High Availability Architecture for Legacy Stuff - a 10.000 feet overview
High Availability Architecture for Legacy Stuff - a 10.000 feet overviewHigh Availability Architecture for Legacy Stuff - a 10.000 feet overview
High Availability Architecture for Legacy Stuff - a 10.000 feet overviewMarco Amado
 
IPVS for Docker Containers
IPVS for Docker ContainersIPVS for Docker Containers
IPVS for Docker ContainersBob Sokol
 
[En] IPVS for Docker Containers
[En] IPVS for Docker Containers[En] IPVS for Docker Containers
[En] IPVS for Docker ContainersAndrey Sibirev
 
Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Keisuke Takahashi
 
DDos, Peering, Automation and more
DDos, Peering, Automation and moreDDos, Peering, Automation and more
DDos, Peering, Automation and moreInternet Society
 
DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)
DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)
DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)Igalia
 
IPv6 enterprise security - The NAT Returns
IPv6 enterprise security - The NAT ReturnsIPv6 enterprise security - The NAT Returns
IPv6 enterprise security - The NAT ReturnsSanjeev Gupta
 
IETF 106 - Default IPv6 Local Only Addressing for Non-Internet Devices
IETF 106 - Default IPv6 Local Only Addressing for Non-Internet DevicesIETF 106 - Default IPv6 Local Only Addressing for Non-Internet Devices
IETF 106 - Default IPv6 Local Only Addressing for Non-Internet DevicesMark Smith
 
Rete di casa e raspberry pi - Home network and Raspberry Pi
Rete di casa e raspberry pi - Home network and Raspberry Pi Rete di casa e raspberry pi - Home network and Raspberry Pi
Rete di casa e raspberry pi - Home network and Raspberry Pi Daniele Albrizio
 
Bastion jump hosts with Teleport
Bastion jump hosts with TeleportBastion jump hosts with Teleport
Bastion jump hosts with TeleportFaelix Ltd
 
Bh fed-03-kaminsky
Bh fed-03-kaminskyBh fed-03-kaminsky
Bh fed-03-kaminskyDan Kaminsky
 
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...arnaudsoullie
 
Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501robertguerra
 
Chef on SmartOS
Chef on SmartOSChef on SmartOS
Chef on SmartOSEric Saxby
 
Kamailio with Docker and Kubernetes
Kamailio with Docker and KubernetesKamailio with Docker and Kubernetes
Kamailio with Docker and KubernetesPaolo Visintin
 
Neutron Network Namespaces and IPtables--A Technical Deep Dive
Neutron Network Namespaces and IPtables--A Technical Deep DiveNeutron Network Namespaces and IPtables--A Technical Deep Dive
Neutron Network Namespaces and IPtables--A Technical Deep DiveMirantis
 
OpenStack Havana over IPv6
OpenStack Havana over IPv6OpenStack Havana over IPv6
OpenStack Havana over IPv6Shixiong Shang
 
10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfsk
10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfsk10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfsk
10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfskJuraj Hantak
 

Ähnlich wie Keeping Your Rack Cool with One IP Route Rule (20)

MikroTik & RouterOS
MikroTik & RouterOSMikroTik & RouterOS
MikroTik & RouterOS
 
DoS and DDoS mitigations with eBPF, XDP and DPDK
DoS and DDoS mitigations with eBPF, XDP and DPDKDoS and DDoS mitigations with eBPF, XDP and DPDK
DoS and DDoS mitigations with eBPF, XDP and DPDK
 
High Availability Architecture for Legacy Stuff - a 10.000 feet overview
High Availability Architecture for Legacy Stuff - a 10.000 feet overviewHigh Availability Architecture for Legacy Stuff - a 10.000 feet overview
High Availability Architecture for Legacy Stuff - a 10.000 feet overview
 
IPVS for Docker Containers
IPVS for Docker ContainersIPVS for Docker Containers
IPVS for Docker Containers
 
[En] IPVS for Docker Containers
[En] IPVS for Docker Containers[En] IPVS for Docker Containers
[En] IPVS for Docker Containers
 
Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5
 
DDos, Peering, Automation and more
DDos, Peering, Automation and moreDDos, Peering, Automation and more
DDos, Peering, Automation and more
 
DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)
DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)
DIY Internet: Snappy, Secure Networking with MinimaLT (JSConf EU 2013)
 
IPv6 enterprise security - The NAT Returns
IPv6 enterprise security - The NAT ReturnsIPv6 enterprise security - The NAT Returns
IPv6 enterprise security - The NAT Returns
 
IETF 106 - Default IPv6 Local Only Addressing for Non-Internet Devices
IETF 106 - Default IPv6 Local Only Addressing for Non-Internet DevicesIETF 106 - Default IPv6 Local Only Addressing for Non-Internet Devices
IETF 106 - Default IPv6 Local Only Addressing for Non-Internet Devices
 
Rete di casa e raspberry pi - Home network and Raspberry Pi
Rete di casa e raspberry pi - Home network and Raspberry Pi Rete di casa e raspberry pi - Home network and Raspberry Pi
Rete di casa e raspberry pi - Home network and Raspberry Pi
 
Bastion jump hosts with Teleport
Bastion jump hosts with TeleportBastion jump hosts with Teleport
Bastion jump hosts with Teleport
 
Bh fed-03-kaminsky
Bh fed-03-kaminskyBh fed-03-kaminsky
Bh fed-03-kaminsky
 
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...
Introduction to Industrial Control Systems : Pentesting PLCs 101 (BlackHat Eu...
 
Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501Installation of pfSense on Soekris 6501
Installation of pfSense on Soekris 6501
 
Chef on SmartOS
Chef on SmartOSChef on SmartOS
Chef on SmartOS
 
Kamailio with Docker and Kubernetes
Kamailio with Docker and KubernetesKamailio with Docker and Kubernetes
Kamailio with Docker and Kubernetes
 
Neutron Network Namespaces and IPtables--A Technical Deep Dive
Neutron Network Namespaces and IPtables--A Technical Deep DiveNeutron Network Namespaces and IPtables--A Technical Deep Dive
Neutron Network Namespaces and IPtables--A Technical Deep Dive
 
OpenStack Havana over IPv6
OpenStack Havana over IPv6OpenStack Havana over IPv6
OpenStack Havana over IPv6
 
10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfsk
10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfsk10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfsk
10. th cncf meetup - Routing microservice-architectures-with-traefik-cncfsk
 

Kürzlich hochgeladen

Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Servicesexy call girls service in goa
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.soniya singh
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsstephieert
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Delhi Call girls
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...tanu pandey
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...Diya Sharma
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts servicevipmodelshub1
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersDamian Radcliffe
 
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With RoomVIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Roomishabajaj13
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girlsstephieert
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607dollysharma2066
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Roomdivyansh0kumar0
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceDelhi Call girls
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Sheetaleventcompany
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Callshivangimorya083
 

Kürzlich hochgeladen (20)

Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
 
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girls
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With RoomVIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girls
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
 
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Defence Colony Delhi 💯Call Us 🔝8264348440🔝
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Rohini 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
 

Keeping Your Rack Cool with One IP Route Rule

  • 1. Marek Isalski – marek @ faelix.net – @maznu faelix limited – https://faelix.net/ – @faelix KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE"
  • 4. KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE" HOW FAELIX ARRIVED AT THIS IDEA ▸ Part 1: ▸ About our network and what we do ▸ Our experience using MikroTik at the provider edge ▸ Part 2: ▸ Zero filter rules! :-)
  • 6.
  • 7. KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE" ABOUT FAELIX ▸ Mostly-hosting ISP ▸ Security, social issues, environment ▸ Based in Manchester, UK = local footprint ▸ ≈50% of servers in Geneva, CH = excellent energy efficiency ▸ Multi-homed, multi-site, autonomous system: AS41495
  • 10. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE MULTI-HOMED ▸ Organise "transit" from upstream providers ▸ Talk BGP with them, announcements + get sent routing tables ▸ Maybe you get "default only"…
  • 11. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE MULTI-HOMED ▸ Organise "transit" from upstream providers ▸ Talk BGP with them, announcements + get sent routing tables ▸ …or maybe you get "full tables" ▸ >600k IPv4 routes, >30k IPv6 routes ▸ That's a lot of routes!
  • 12. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE OUR MIGRATION TO MIKROTIK ROUTEROS ▸ Quagga + BIRD on servers running Linux solid for >6 years ❤ ▸ 2015: we wanted to do an upgrade… 📈 ▸ We love the energy efficiency of MikroTik CCR… 💚 ▸ No "NSA/GCHQ inside"… 😍 ▸ Can we use RouterOS? 🤔 ▸ + BIRD on servers running Linux? 🐧
  • 13. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE TWO ROUTING SYSTEMS? ▸ Early version of BIRD segfaulted, withdrew announcements ▸ Quagga kept on running, we did not vanish from DFZ ▸ Are we sure RouterOS BGP is going to cope? ▸ What is support going to be like? Debugging?
  • 14. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE OVERALL EXPERIENCE ▸ Some weird behaviour occasionally… ▸ NTP leap second bug = hard crash ▸ Disable VLAN interface before changing its physical interface orVID ▸ Support are helpful and fast; anecdotally, as responsive as the "big name" vendors ▸ Debugging time = get friendly with RouterOS command-line
  • 15. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE THE GOOD THE BAD ▸ £700 + 70W routes >10Gbit/s ▸ BGP feels familiar afteryears of experience of Quagga ▸ Consultants out there if you need them; training & quals ▸ MikroTik now "go to" choice for CPE, wireless, etc… ▸ Vendor interop good (beware of extra options in RouterOS) ▸ Watchdog not good enough, IPMI-style OOB hard reboot? ▸ BGP converge & FIB is slow on CCRwith 2M+ routes ▸ Routing filters don't always work first time (enable/disable) ▸ Switch VLAN setup feels like raw config of merchant silicon ▸ "RouterOS 7"
  • 16. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE FAELIX'S TIPS ▸ CHR, hardware is economical = no excuses for network lab ▸ Consider leap-frogging RouterOS releases in production ▸ layer-3 > layer-2, MikroTik affordability = dream come true ▸ Full routing tables get into FIB a lot quicker on x86 than on tile ▸ oxidized + syslog = configs in git + logs in one place ▸ snmp + graphite + grafana = netops visibility, cool dashboards ▸ BCP38 + MANRS + abuse-c = be excellent to each other
  • 17. MIKROTIK HARDWARE AND ROUTEROS AT THE PROVIDER EDGE PLUGS ▸ http://uknof.org.uk/ = packet pushers of the UK (and beer) ▸ http://netmcr.uk/ = packet pushers of Manchester (and beer) BEER-TO-PEER NETWORKING
  • 19. U WOT M8? you, right now ZERO FILTER FIREWALLS
  • 20. ssh SMTP / IMAP / POP VOIP Drupal WordPress IPsec L2TP
  • 21. ZERO FILTER FIREWALLS SHIT HAPPENS ▸ Your networkwill get scanned ▸ ssh, DDoS amplification, open proxies… ▸ You might have forgotten something ▸ Is your management network isolated? ▸ Your customers will do things you don't expect ▸ e.g. SNMP or DNS on CPE open to Internet ▸ Software has bugs
  • 22. That is one big pile of shit!
  • 23.
  • 25. SECURITY IS HARD every infosec professional ever ZERO FILTER FIREWALLS
  • 26. START WITH THE LOW- HANGING FRUIT… GOAL:
  • 27. THE NEXT CROP! AND WHEN THEY'RE PICKED…
  • 29. FAIL2BAN STEP 2: WWW Cat GIF Blog make DJT root again! apache logs fail2ban
  • 30. ZERO FILTER FIREWALLS FAIL2BAN ▸ Follow log file, if line matches "filter" then performs "action" ▸ Great for blocking brute force (ssh, etc) ▸ MikroTikwiki + forum have examples for RouterOS ▸ Send logs via syslog to a VM for analysis ▸ fail2ban connects to RouterOS with ssh and blocks using: ▸ add new /ip firewall filter (ok) ▸ add new /ip firewall address-list (better)
  • 31. ZERO FILTER FIREWALLS FAIL2BAN ▸ Quick, cheap, easy ▸ Make your own or find rules to block web, VoIP, and other nasty traffic ▸ Attackerwill move on to another target pretty quickly when DROPped ▸ Next target might still be in your network, still traffic across your backbone ▸ Can we put attacking IPs on a network-wide "naughty step"?
  • 32. BLOCK AT THE PROVIDER EDGE STEP 3: Edge Router WWW Cat GIF Blog make DJT root again! apache logs fail2ban slurry spreader AMQP ROSAPI
  • 33. ZERO FILTER FIREWALLS BLOCKING AT THE PROVIDER EDGE ▸ Lots of flows, lots of PPS, lots of attacking addresses ▸ /ip firewall filter uses each set of rules sequentially = O(n) ▸ /ip firewall address-list is a hash-table ≈ O(1) ▸ Using AMQP to get addresses added to block lists on all routers in three data-centres ▸ We already had RabbitMQ across our network for other infrastructure needs
  • 34. FALSE POSITIVES STEP 4: WWW Cat GIF Blog apache logs fail2banslurry spreader AMQP passwords are hard Edge Router ROSAPI
  • 35. FALSE POSITIVES STEP 4: WWW Cat GIF Blog apache logs fail2banslurry spreader AMQP passwords are hard Edge Router DNAT! ROSAPI
  • 36. FALSE POSITIVES STEP 4: WWW Cat GIF Blog apache logs fail2banslurry spreader AMQP passwords are hard Edge Router ROSAPI
  • 37. ZERO FILTER FIREWALLS DESTINATION NAT ▸ Send bad traffic to a VM serving the "blocked" message: ▸ /ip firewall nat src-address-list=shitpit action=dst-nat
  • 39. ZERO FILTER FIREWALLS BLOCKING AT THE PROVIDER EDGE ▸ Lots of flows, lots of PPS, lots of attacking addresses ▸ /ip firewall filter uses each set of rules sequentially = O(n) ▸ /ip firewall address-list is a hash-table ≈ O(1) ▸ Using AMQP to get addresses added to block lists on all routers in three data-centres ▸ We already had RabbitMQ across our network for other infrastructure needs
  • 40. ZERO FILTER FIREWALLS BLOCKING AT THE PROVIDER EDGE ▸ Lots of flows… ▸ …so use a mangle rule so routers only track bad traffic? ▸ No! We want to build something we can understand.
  • 42. TRAFFIC HAS MULTIPLE PATHS IN AND OUT OF OUR NETWORK PROBLEM: Edge Router Edge Router Edge Router Edge Router Edge Router
  • 43. TRAFFIC HAS MULTIPLE PATHS IN AND OUT OF OUR NETWORK PROBLEM: Edge Router Edge Router Edge Router Edge Router Edge Router
  • 44. TRAFFIC HAS MULTIPLE PATHS IN AND OUT OF OUR NETWORK PROBLEM: Edge Router Edge Router Edge Router Edge Router Edge Router what is this?
  • 45. TRAFFIC HAS MULTIPLE PATHS IN AND OUT OF OUR NETWORK PROBLEM: Edge Router Edge Router Edge Router Edge Router Edge Router bro, do u even conntrack?
  • 46. ZERO FILTER FIREWALLS WON'T CONNTRACK, CAN'T NAT ▸ Lots of flows ▸ Can't share conntrack across RouterOS devices ▸ Would be nice forVRRP-type HA default gateways? ▸ We don't want to even ifwe could: lots of flows! ▸ And don't want to mangle to ignore good flows… ▸ …and mangle to make return traffic go the right way. ▸ "Are we there yet!?"
  • 47.
  • 48. KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE" MULTIPLE ROUTING TABLES ▸ /ip route add gateway=203.0.113.113 routing-mark=shitpit ▸ /ip route rule add routing-mark=shitpit table=shitpit ▸ /ip firewall mangle add chain=prerouting passthrough=yes
 action=mark-routing new-routing-mark=shitpit
 src-address-list=shitpit ▸ /ip firewall address-list add list=shitpit
 address=192.0.2.69/32 timeout=1m
  • 49. /IP ROUTE RULE STEP 5: Edge Router fail2ban spreader make DJT root again! WWW Cat GIF Blog slurry AMQP apache logs
  • 50. …AND STAY OUT! STEP 6: Edge Router fail2ban spreader make DJT root again! slurry AMQP
  • 51. YOUR NEXT CROP OF LOW-HANGING FRUIT STEP 7: Edge Router fail2ban spreader make DJT root again! WWW Cat GIF Blog slurry AMQP apache logs M O RE RULES!
  • 52. EXTRA CREDIT STEP 8: Edge Router fail2ban spreader make DJT root again! slurry AMQP
  • 53. Edge Router fail2ban slurry spreader AMQP make DJT root again! DNS RBL badips.com fastnetmon VIPs snort
  • 54. KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE" REFERENCES ▸ fail2ban = tail log files, filter them, perform actions ▸ fastnetmon = DDoS detection with data from /ip traffic-flow ▸ portsentry = am I being portscanned? ▸ mod_security + OWASP = Web Application Firewall ▸ snort = intrusion detection system ▸ GIFs from devopsreactions, securityreactions, honestnetworker
  • 55. KEEPING YOUR RACK COOL WITH ONE "/IP ROUTE RULE" CONCLUSION ▸ /ip route add gateway=203.0.113.113 routing-mark=shitpit ▸ /ip route rule add routing-mark=shitpit table=shitpit ▸ /ip firewall mangle add chain=prerouting passthrough=yes
 action=mark-routing new-routing-mark=shitpit
 src-address-list=shitpit ▸ /ip firewall address-list add list=shitpit
 address=192.0.2.69/32 timeout=1m
  • 56. e: marek@faelix.net t: @maznu w: https://faelix.net/ THANKS FOR LISTENING! ANY QUESTIONS?