SlideShare a Scribd company logo
1 of 24
www.internetsociety.org
Best Current Operational Practices (BCOP) –
updates and status from around the world
ION Tokyo | Tokyo, Japan | 17 November 2014
Chris Grundemann
BCOP | February 2013
What’s a BCOP?
Best Current Operational Practice
•A living document describing the best
operational practices currently agreed on by
subject matter experts
•Vetted and periodically reviewed by the global
network engineering community (GNEC)
BCOP | February 2013
The Problem
• Operational knowledge tends to be “tribal”
• Presentations, hallway conversations, internal
documents, in someone’s head…
• Technology, tools, and practices change over time…
• There are hundreds of operational forums
globally
• Archives stored in different formats, some searchable,
rarely have speech text or video, no vetting, and state
unknown.
• How do I find up-to-date, relevant
information when I need it?
BCOP | February 2013
The BCOP Solution
Open, Transparent, Bottom-up, and Community led
 Community driven, community written, community vetted Best
Current Operational Practices from an open forum, list, and
publicly searchable site.
 Community written and approved Development Process for
BCOPs
 Everyone is welcome to participate
80/20 model
BCOP | February 2013
BCOP activity around the world:
http://www.internetsociety.org/deploy360/about/bcop/
•Africa region: A BCOP group was started under AfNOG,
lead by Douglas Onyango
•Asia: BCOP Task Force started at JANOG, co-chaired by
Seiichi Kawamura and Yoshinobu Matsuzaki, NZNOG
BCOP starting up, lead by Dean Pemberton
• No whole-region effort started yet
•Europe: RIPE BCOP Task Force created, co-chaired by
Benno Overeider and Jan Žorž
•Latin America: A BCOP Task Force was started under
LACNOG, lead by Luis Balbinot and Pedro R Torres Jr.
•North America: NANOG BCOP Committee established,
co-chaired by Aaron Hughes and Chris Grundemann
BCOP | February 2013
AfNOG BCOP
First introduced in May of 2013
Held a BoF in Abidjan at AfriNIC19
Most recent BoF at AIS/AfriNIC 20 in Djibouti (June
2014).
Current focus:
•Put in place a mailing list
• Using http://www.afnog.org/mailinglist.php for now
•Create an online BCOP document repository
•Development of two or more drafts
•A session at AFRINIC 21 in Mauritius (Nov 2014).
BCOP | February 2013
AfNOG BCOP documents in the works:
“IPv6 questions/answers cheat sheet specific to
Africa”
Contributors: Alfred Arouna
•Aims to consolidate common questions and best
answers in a kind of IPv6 questions/answers cheat
sheet specific to Africa.
BCOP | February 2013
RIPE BCOP
RIPE BCOP Task Force charter page:
http://www.ripe.net/ripe/groups/tf/best-current-operational-p
Mailing-list:
https://www.ripe.net/mailman/listinfo/bcop
BCOP | February 2013
RIPE BCOP documents in the works:
“IPv6 troubleshooting for residential helpdesks”
Contributors: Lee Howard, John Jason Brzozowski, David Freedman, Jason
Fesler, Tim Chown, Sander Steffann, Chris Grundemann, Jen Linkova, Chris
Tuska, Daniel Breuer, Jan Žorž
•Starting point for technical support staff at ISPs or
enterprise IT helpdesks
•Addresses the “fear of the unknown” problem at
many organizations
•Provides a solid first step for front-line support
personnel.
BCOP | February 2013
RIPE BCOP documents in the works:
Protocol default values
+ Cryptographical
considerations?
+ ZSK/KSK split or CSK?
+ When to rollover?
+ Values for signature validities,
re-sign, refresh, …
+ NSEC or NSEC3?
+ If NSEC3, when to resalt?
Key management
+ Generation: Number of
participants?
+ Delivery: Integrity checks?
Audit trail?
+ Storage: Online or offline? HSM
or not?
+ Usage: Who can use? How to
(de)activate?
“DNSSEC operational practices for authoritative
name servers”
Contributors: Matthijs Mekking
Available software
+ Standalone solutions: OpenDNSSEC, BIND, Knot, …
+ Combinations: ldnsutils + NSD, …
+ Closed source: Microsoft DNS, Nominum, ...
BCOP | February 2013
RIPE BCOP documents in the works:
Definitions:
Interconnection types
• Direct interconnection
• IXP Peering
• IXP Route-server
• Multihop
AS relationships
• Transit / Customer (leaf)
• Transit / Small transit
• Peering
Recommendations:
AS relationship dependent
• TCP-Authentication
• AS-PATH filtering
• Prefixes filtering (route objects)
• Max-prefix
• Private AS removing
General recommendations
• Martians filtering
• Bogons filtering
• Default route filtering
• Log
• Graceful restart
“BGP Best Current Operational Practices”
Contributors: Pierre Lorinquer, Observatory Team (G. Valadon, M. Feuillet, F.
Contat) and operators Association Kazar, France-IX, Jaguar Network, Neo
Telecoms, Orange, RENATER, SFR
BCOP | February 2013
LACNOG BCOP
The group has asked for a webpage under the LACNOG
umbrella.
Mailing List: https://mail.lacnic.net/mailman/listinfo/bcop
The group still has to decide on primary language of the
produced documents (Spanish/Portuguese/English).
They recently held a BoF at LACNOG 2014 / LACNIC 22
in Santiago, Chile (October 2014)
BCOP | February 2013
LACNOG BCOP documents in the works:
“LacNOG BCOP Development Process
document”
Contributors: Pedro R. Torres Jr., Luis Balbinot
•A development process is important for capture the
Best Current Operational Practices in
documentation format that is uniform and easy to
read.
•LacNOG BCOP TF decided to set the format and
procedure first and then start capturing the Best
Current Operational Practices into documents.
BCOP | February 2013
NANOG BCOP
Charter and Members:
http://nanog.org/governance/bcop
Published BCOPs (ratified):
http://bcop.nanog.org/index.php/Ratified_BCOPs
Draft BCOPs (in progress):
http://bcop.nanog.org/index.php/BCOP_Drafts
Mailing List:
http://mailman.nanog.org/mailman/listinfo/bcop
BCOP | February 2013
NANOG BCOP documents in the works:
“Public Peering Exchange Participant”
Contributors: Shawn Hsiao, Erik Muller
•This BCOP aims to update current “Public Peering
Exchange" BCOP
• Add IXP route handling advice
• Remove information pertaining to the operation of an exchange into a
separate document, and re-focus the document toward exchange
participants
• Other updates as needed
BCOP | February 2013
NANOG BCOP documents in the works:
“eBGP Configuration”
Contributors: Bill Armstrong, Nina Bargisen, Brian Schleeper, Umair Arshad,
Mannan Venkatesan, Courtney Smith, Raghav Bhargava, Karsten Thomann
•This BCOP aims to provide a singular, consistent
view of industry standard eBGP interconnection
methodologies
•This BCOP will also document pre and post turn-up
validation practices and IRR Etiquette
•The primary focus of this BCOP is eBGP know-how
BCOP | February 2013
NANOG BCOP documents in the works:
“Ethernet OAM”
Contributors: Mark Calkins, Jean-Francois Levesque, Voitek Kozack
•This BCOP aims to provide insight into how
Ethernet OAM is best deployed within todays
service provider networks.
•This BCOP will try to capture current and emerging
best practices for uses of Ethernet OAM
technologies.
•The primary focus is on a basic understanding of
EOAM technologies.
BCOP | February 2013
NANOG BCOP documents in the works:
“Anti-DDoS”
Contributors: Yardiel Fuentes, Rich Compton, Prabhu Gurumurthy, John W,
Damon Fortune
•This BCOP aims to share practices which have
performed in production environments as a guide
on what to do before, during, and after a DDoS/DoS
attack.
•This BCOP document focuses on providing, in a
vendor-agnostic framework, guidelines at the
different stage of dealing with DDoS/DoS attacks
BCOP | February 2013
NANOG BCOP documents in the works:
“Anti-Spoofing”
Contributors: Aaron Hughes, et. al.
•Intent is to provide more detailed operator input on
workarounds for known vendor bugs in vendor
equipment
•Focus on detailed configuration information from a
variety of common vendors and architectural
scenarios for the ISP and Enterprise spaces
BCOP | February 2013
JANOG BCOP Group
JANOG has started a BCOP Task Force with Seiichi
Kawamura and Yoshinobu Matsuzaki co-chairing it.
Documents in progress:
•eBGP best practices
• http://www.janpg.gr.jp/doc/janog-comment/bcop-ebgp.txt
•How to plan, build, and run a conference WiFi network
BCOP | February 2013
Potential Topics for Additional BCOPs
http://www.internetsociety.org/deploy360/about/bcop/topics/
•How to test your network performance
•How to check your visibility from global Internet
•De-Aggregation: strict filtering /48s out of /32
•How are operators using IRR?
•IPv6 enterprise network renumbering scenarios,
considerations, and methods
•DNS Policies
•Email Policies
•ICMP Filtering
•… (we need more suggestions)
BCOP | February 2013
Next Steps
Where are we going from here?
•Continue to bootstrap new efforts as needed
•Develop new BCOP documents
• Lots of low-hanging fruit
•Review and update existing BCOP documents
•Start thinking & talking about Global coordination
BCOP | February 2013
Get Involved Today!
Join this grass-roots effort at the ground floor!
•Contribute to an existing draft
•Offer ideas for new drafts
•Kick off a new document
•Start a local or regional BCOP effort
• Email deploy360@isoc.org for more information
www.internetsociety.org
Deploy360@ISOC.org
Chris Grundemann
Jan Žorž
Internet Society Deploy360
Programmehttp://www.internetsociety.org/depl
oy360/
Thank
You!

More Related Content

What's hot

BCOP BoF
BCOP BoFBCOP BoF
BCOP BoFAPNIC
 
TWNIC OPM 2015: Network Operator Groups
TWNIC OPM 2015: Network Operator GroupsTWNIC OPM 2015: Network Operator Groups
TWNIC OPM 2015: Network Operator GroupsAPNIC
 
Best Current Operational Practice (BCOP) - Updates from around the world
Best Current Operational Practice (BCOP) - Updates from around the worldBest Current Operational Practice (BCOP) - Updates from around the world
Best Current Operational Practice (BCOP) - Updates from around the worldBangladesh Network Operators Group
 
About the IETF: Presentation for the University of Botswana
About the IETF: Presentation for the University of BotswanaAbout the IETF: Presentation for the University of Botswana
About the IETF: Presentation for the University of BotswanaInternet Society
 
ION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRSION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRSDeploy360 Programme (Internet Society)
 
IGF MAG Update
IGF MAG UpdateIGF MAG Update
IGF MAG UpdateAPNIC
 
Multistakeholder_Model-Histories-Trends-Recent Developments
Multistakeholder_Model-Histories-Trends-Recent DevelopmentsMultistakeholder_Model-Histories-Trends-Recent Developments
Multistakeholder_Model-Histories-Trends-Recent DevelopmentsEdwin A. Opare
 
OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...
OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...
OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...FINOS
 
Internet Governance: Why does it matter to Bangladesh?
Internet Governance: Why does it matter to Bangladesh?Internet Governance: Why does it matter to Bangladesh?
Internet Governance: Why does it matter to Bangladesh?APNIC
 

What's hot (20)

BCOP BoF
BCOP BoFBCOP BoF
BCOP BoF
 
TWNIC OPM 2015: Network Operator Groups
TWNIC OPM 2015: Network Operator GroupsTWNIC OPM 2015: Network Operator Groups
TWNIC OPM 2015: Network Operator Groups
 
ION Malta - Closing Slides
ION Malta - Closing SlidesION Malta - Closing Slides
ION Malta - Closing Slides
 
Best Current Operational Practice (BCOP) - Updates from around the world
Best Current Operational Practice (BCOP) - Updates from around the worldBest Current Operational Practice (BCOP) - Updates from around the world
Best Current Operational Practice (BCOP) - Updates from around the world
 
ION Hangzhou - An IETF Journey for CNNIC
ION Hangzhou - An IETF Journey for CNNICION Hangzhou - An IETF Journey for CNNIC
ION Hangzhou - An IETF Journey for CNNIC
 
About the IETF: Presentation for the University of Botswana
About the IETF: Presentation for the University of BotswanaAbout the IETF: Presentation for the University of Botswana
About the IETF: Presentation for the University of Botswana
 
IETF Talk
IETF TalkIETF Talk
IETF Talk
 
ION Sri Lanka - Opening Slides
ION Sri Lanka - Opening SlidesION Sri Lanka - Opening Slides
ION Sri Lanka - Opening Slides
 
ION Durban - MANRS Introduction
ION Durban - MANRS IntroductionION Durban - MANRS Introduction
ION Durban - MANRS Introduction
 
ION Durban - Introduction to ISOC Gauteng Chapter
ION Durban - Introduction to ISOC Gauteng ChapterION Durban - Introduction to ISOC Gauteng Chapter
ION Durban - Introduction to ISOC Gauteng Chapter
 
ION Durban - Opening Slides
ION Durban - Opening SlidesION Durban - Opening Slides
ION Durban - Opening Slides
 
ION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRSION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRS
 
ION Hangzhou - Keynote: Collaborative Security and an Open Internet
ION Hangzhou - Keynote: Collaborative Security and an Open InternetION Hangzhou - Keynote: Collaborative Security and an Open Internet
ION Hangzhou - Keynote: Collaborative Security and an Open Internet
 
ISOC Engagement Activities
ISOC Engagement ActivitiesISOC Engagement Activities
ISOC Engagement Activities
 
ION Hangzhou - Opening Remarks
ION Hangzhou - Opening RemarksION Hangzhou - Opening Remarks
ION Hangzhou - Opening Remarks
 
IGF MAG Update
IGF MAG UpdateIGF MAG Update
IGF MAG Update
 
Multistakeholder_Model-Histories-Trends-Recent Developments
Multistakeholder_Model-Histories-Trends-Recent DevelopmentsMultistakeholder_Model-Histories-Trends-Recent Developments
Multistakeholder_Model-Histories-Trends-Recent Developments
 
IPv6 and Telecom: IPv4 Is FInally Running Out. Now What?
IPv6 and Telecom: IPv4 Is FInally Running Out. Now What?IPv6 and Telecom: IPv4 Is FInally Running Out. Now What?
IPv6 and Telecom: IPv4 Is FInally Running Out. Now What?
 
OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...
OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...
OSSF 2018 - Overcoming Compliance Barriers to Open Source Collaboration Infra...
 
Internet Governance: Why does it matter to Bangladesh?
Internet Governance: Why does it matter to Bangladesh?Internet Governance: Why does it matter to Bangladesh?
Internet Governance: Why does it matter to Bangladesh?
 

Similar to ION Tokyo: Best Current Operational Practices (BCOP) Update, Chris Grundemann

Douglas_onyango bcop-update-isoc
Douglas_onyango bcop-update-isocDouglas_onyango bcop-update-isoc
Douglas_onyango bcop-update-isocAFRINIC
 
Introduction to PeeringDB by Arnold Nipper
Introduction to PeeringDB by Arnold NipperIntroduction to PeeringDB by Arnold Nipper
Introduction to PeeringDB by Arnold NipperMyNOG
 
How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...APNIC
 
Create great cncf user base from lessons learned from other open source com...
Create great cncf user base from   lessons learned from other open source com...Create great cncf user base from   lessons learned from other open source com...
Create great cncf user base from lessons learned from other open source com...Krishna-Kumar
 
The Dark Side of Digital Preservation: Distributed Digital Preservation
The Dark Side of Digital Preservation: Distributed Digital PreservationThe Dark Side of Digital Preservation: Distributed Digital Preservation
The Dark Side of Digital Preservation: Distributed Digital PreservationEducopia
 
COBWEB technology platform and future development needs
COBWEB technology platform and future development needsCOBWEB technology platform and future development needs
COBWEB technology platform and future development needsEDINA, University of Edinburgh
 
IPv6 Observatory outomes
IPv6 Observatory outomesIPv6 Observatory outomes
IPv6 Observatory outomesFabrice Clari
 
COBWEB technology platform and future development needs, ISPRA 2016
COBWEB technology platform and future development needs, ISPRA 2016COBWEB technology platform and future development needs, ISPRA 2016
COBWEB technology platform and future development needs, ISPRA 2016COBWEB Project
 
Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...
Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...
Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...Lee Calcote
 
Toolbox Collaboration Setup For Research Ppt Final
Toolbox Collaboration Setup For Research Ppt FinalToolbox Collaboration Setup For Research Ppt Final
Toolbox Collaboration Setup For Research Ppt FinalFITT
 

Similar to ION Tokyo: Best Current Operational Practices (BCOP) Update, Chris Grundemann (20)

Douglas_onyango bcop-update-isoc
Douglas_onyango bcop-update-isocDouglas_onyango bcop-update-isoc
Douglas_onyango bcop-update-isoc
 
ION Toronto - Best Current Operational Practices Update
ION Toronto - Best Current Operational Practices UpdateION Toronto - Best Current Operational Practices Update
ION Toronto - Best Current Operational Practices Update
 
ION Ljubljana - Aaron Hughes: Best Current Operational Practices
ION Ljubljana - Aaron Hughes: Best Current Operational PracticesION Ljubljana - Aaron Hughes: Best Current Operational Practices
ION Ljubljana - Aaron Hughes: Best Current Operational Practices
 
ION Belfast - Opening Slides - Chris Grundemann
ION Belfast - Opening Slides - Chris GrundemannION Belfast - Opening Slides - Chris Grundemann
ION Belfast - Opening Slides - Chris Grundemann
 
Introductory Presentation of bdNOG
Introductory Presentation of bdNOGIntroductory Presentation of bdNOG
Introductory Presentation of bdNOG
 
Introduction to PeeringDB by Arnold Nipper
Introduction to PeeringDB by Arnold NipperIntroduction to PeeringDB by Arnold Nipper
Introduction to PeeringDB by Arnold Nipper
 
Orchestration, Automation and Virtualisation (OAV) in GÉANT
Orchestration, Automation and Virtualisation (OAV) in GÉANT Orchestration, Automation and Virtualisation (OAV) in GÉANT
Orchestration, Automation and Virtualisation (OAV) in GÉANT
 
ION Islamabad - Opening Remarks
ION Islamabad - Opening RemarksION Islamabad - Opening Remarks
ION Islamabad - Opening Remarks
 
NISO Standards Update, Seamless Access, ALA Midwinter
NISO Standards Update, Seamless Access, ALA MidwinterNISO Standards Update, Seamless Access, ALA Midwinter
NISO Standards Update, Seamless Access, ALA Midwinter
 
ION Bucharest - ISOC & Deploy360 overview
ION Bucharest - ISOC & Deploy360 overviewION Bucharest - ISOC & Deploy360 overview
ION Bucharest - ISOC & Deploy360 overview
 
How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...
 
NISO Webinar: Getting to the Right Content: Link Resolvers and Knowledgebases
NISO Webinar: Getting to the Right Content: Link Resolvers and KnowledgebasesNISO Webinar: Getting to the Right Content: Link Resolvers and Knowledgebases
NISO Webinar: Getting to the Right Content: Link Resolvers and Knowledgebases
 
Create great cncf user base from lessons learned from other open source com...
Create great cncf user base from   lessons learned from other open source com...Create great cncf user base from   lessons learned from other open source com...
Create great cncf user base from lessons learned from other open source com...
 
The Dark Side of Digital Preservation: Distributed Digital Preservation
The Dark Side of Digital Preservation: Distributed Digital PreservationThe Dark Side of Digital Preservation: Distributed Digital Preservation
The Dark Side of Digital Preservation: Distributed Digital Preservation
 
COBWEB technology platform and future development needs
COBWEB technology platform and future development needsCOBWEB technology platform and future development needs
COBWEB technology platform and future development needs
 
IPv6 Observatory outomes
IPv6 Observatory outomesIPv6 Observatory outomes
IPv6 Observatory outomes
 
COBWEB technology platform and future development needs, ISPRA 2016
COBWEB technology platform and future development needs, ISPRA 2016COBWEB technology platform and future development needs, ISPRA 2016
COBWEB technology platform and future development needs, ISPRA 2016
 
Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...
Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...
Create Great CNCF User-Base from Lessons Learned from Other Open Source Commu...
 
Toolbox Collaboration Setup For Research Ppt Final
Toolbox Collaboration Setup For Research Ppt FinalToolbox Collaboration Setup For Research Ppt Final
Toolbox Collaboration Setup For Research Ppt Final
 
ION Costa Rica Opening Slides
ION Costa Rica Opening SlidesION Costa Rica Opening Slides
ION Costa Rica Opening Slides
 

More from Deploy360 Programme (Internet Society)

More from Deploy360 Programme (Internet Society) (20)

ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success StoriesION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
 
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter PresentationION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
 
ION Belgrade - IETF Update
ION Belgrade - IETF UpdateION Belgrade - IETF Update
ION Belgrade - IETF Update
 
ION Belgrade - Opening Slides
ION Belgrade - Opening SlidesION Belgrade - Opening Slides
ION Belgrade - Opening Slides
 
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
 
ION Belgrade - Closing Slides
ION Belgrade - Closing SlidesION Belgrade - Closing Slides
ION Belgrade - Closing Slides
 
AusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRSAusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRS
 
ION Malta - IETF Update
ION Malta - IETF UpdateION Malta - IETF Update
ION Malta - IETF Update
 
ION Malta - MANRS Introduction
ION Malta - MANRS IntroductionION Malta - MANRS Introduction
ION Malta - MANRS Introduction
 
ION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSECION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSEC
 
ION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLSION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLS
 
ION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & AccountabilityION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & Accountability
 
ION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: FinlandION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: Finland
 
ION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 TransitionION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 Transition
 
ION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for youION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for you
 
ION Malta - Opening Slides
ION Malta - Opening SlidesION Malta - Opening Slides
ION Malta - Opening Slides
 
ION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internetION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internet
 
ION Durban - What's Happening at the IETF?
ION Durban - What's Happening at the IETF?ION Durban - What's Happening at the IETF?
ION Durban - What's Happening at the IETF?
 
ION Durban - NAT64/DNS64 Experiments and the NAT64Check Tool
ION Durban - NAT64/DNS64 Experiments and the NAT64Check ToolION Durban - NAT64/DNS64 Experiments and the NAT64Check Tool
ION Durban - NAT64/DNS64 Experiments and the NAT64Check Tool
 
ION Durban - Closing Slides
ION Durban - Closing SlidesION Durban - Closing Slides
ION Durban - Closing Slides
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024The Digital Insurer
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024SynarionITSolutions
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 

Recently uploaded (20)

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 

ION Tokyo: Best Current Operational Practices (BCOP) Update, Chris Grundemann

  • 1. www.internetsociety.org Best Current Operational Practices (BCOP) – updates and status from around the world ION Tokyo | Tokyo, Japan | 17 November 2014 Chris Grundemann
  • 2. BCOP | February 2013 What’s a BCOP? Best Current Operational Practice •A living document describing the best operational practices currently agreed on by subject matter experts •Vetted and periodically reviewed by the global network engineering community (GNEC)
  • 3. BCOP | February 2013 The Problem • Operational knowledge tends to be “tribal” • Presentations, hallway conversations, internal documents, in someone’s head… • Technology, tools, and practices change over time… • There are hundreds of operational forums globally • Archives stored in different formats, some searchable, rarely have speech text or video, no vetting, and state unknown. • How do I find up-to-date, relevant information when I need it?
  • 4. BCOP | February 2013 The BCOP Solution Open, Transparent, Bottom-up, and Community led  Community driven, community written, community vetted Best Current Operational Practices from an open forum, list, and publicly searchable site.  Community written and approved Development Process for BCOPs  Everyone is welcome to participate 80/20 model
  • 5. BCOP | February 2013 BCOP activity around the world: http://www.internetsociety.org/deploy360/about/bcop/ •Africa region: A BCOP group was started under AfNOG, lead by Douglas Onyango •Asia: BCOP Task Force started at JANOG, co-chaired by Seiichi Kawamura and Yoshinobu Matsuzaki, NZNOG BCOP starting up, lead by Dean Pemberton • No whole-region effort started yet •Europe: RIPE BCOP Task Force created, co-chaired by Benno Overeider and Jan Žorž •Latin America: A BCOP Task Force was started under LACNOG, lead by Luis Balbinot and Pedro R Torres Jr. •North America: NANOG BCOP Committee established, co-chaired by Aaron Hughes and Chris Grundemann
  • 6. BCOP | February 2013 AfNOG BCOP First introduced in May of 2013 Held a BoF in Abidjan at AfriNIC19 Most recent BoF at AIS/AfriNIC 20 in Djibouti (June 2014). Current focus: •Put in place a mailing list • Using http://www.afnog.org/mailinglist.php for now •Create an online BCOP document repository •Development of two or more drafts •A session at AFRINIC 21 in Mauritius (Nov 2014).
  • 7. BCOP | February 2013 AfNOG BCOP documents in the works: “IPv6 questions/answers cheat sheet specific to Africa” Contributors: Alfred Arouna •Aims to consolidate common questions and best answers in a kind of IPv6 questions/answers cheat sheet specific to Africa.
  • 8. BCOP | February 2013 RIPE BCOP RIPE BCOP Task Force charter page: http://www.ripe.net/ripe/groups/tf/best-current-operational-p Mailing-list: https://www.ripe.net/mailman/listinfo/bcop
  • 9. BCOP | February 2013 RIPE BCOP documents in the works: “IPv6 troubleshooting for residential helpdesks” Contributors: Lee Howard, John Jason Brzozowski, David Freedman, Jason Fesler, Tim Chown, Sander Steffann, Chris Grundemann, Jen Linkova, Chris Tuska, Daniel Breuer, Jan Žorž •Starting point for technical support staff at ISPs or enterprise IT helpdesks •Addresses the “fear of the unknown” problem at many organizations •Provides a solid first step for front-line support personnel.
  • 10. BCOP | February 2013 RIPE BCOP documents in the works: Protocol default values + Cryptographical considerations? + ZSK/KSK split or CSK? + When to rollover? + Values for signature validities, re-sign, refresh, … + NSEC or NSEC3? + If NSEC3, when to resalt? Key management + Generation: Number of participants? + Delivery: Integrity checks? Audit trail? + Storage: Online or offline? HSM or not? + Usage: Who can use? How to (de)activate? “DNSSEC operational practices for authoritative name servers” Contributors: Matthijs Mekking Available software + Standalone solutions: OpenDNSSEC, BIND, Knot, … + Combinations: ldnsutils + NSD, … + Closed source: Microsoft DNS, Nominum, ...
  • 11. BCOP | February 2013 RIPE BCOP documents in the works: Definitions: Interconnection types • Direct interconnection • IXP Peering • IXP Route-server • Multihop AS relationships • Transit / Customer (leaf) • Transit / Small transit • Peering Recommendations: AS relationship dependent • TCP-Authentication • AS-PATH filtering • Prefixes filtering (route objects) • Max-prefix • Private AS removing General recommendations • Martians filtering • Bogons filtering • Default route filtering • Log • Graceful restart “BGP Best Current Operational Practices” Contributors: Pierre Lorinquer, Observatory Team (G. Valadon, M. Feuillet, F. Contat) and operators Association Kazar, France-IX, Jaguar Network, Neo Telecoms, Orange, RENATER, SFR
  • 12. BCOP | February 2013 LACNOG BCOP The group has asked for a webpage under the LACNOG umbrella. Mailing List: https://mail.lacnic.net/mailman/listinfo/bcop The group still has to decide on primary language of the produced documents (Spanish/Portuguese/English). They recently held a BoF at LACNOG 2014 / LACNIC 22 in Santiago, Chile (October 2014)
  • 13. BCOP | February 2013 LACNOG BCOP documents in the works: “LacNOG BCOP Development Process document” Contributors: Pedro R. Torres Jr., Luis Balbinot •A development process is important for capture the Best Current Operational Practices in documentation format that is uniform and easy to read. •LacNOG BCOP TF decided to set the format and procedure first and then start capturing the Best Current Operational Practices into documents.
  • 14. BCOP | February 2013 NANOG BCOP Charter and Members: http://nanog.org/governance/bcop Published BCOPs (ratified): http://bcop.nanog.org/index.php/Ratified_BCOPs Draft BCOPs (in progress): http://bcop.nanog.org/index.php/BCOP_Drafts Mailing List: http://mailman.nanog.org/mailman/listinfo/bcop
  • 15. BCOP | February 2013 NANOG BCOP documents in the works: “Public Peering Exchange Participant” Contributors: Shawn Hsiao, Erik Muller •This BCOP aims to update current “Public Peering Exchange" BCOP • Add IXP route handling advice • Remove information pertaining to the operation of an exchange into a separate document, and re-focus the document toward exchange participants • Other updates as needed
  • 16. BCOP | February 2013 NANOG BCOP documents in the works: “eBGP Configuration” Contributors: Bill Armstrong, Nina Bargisen, Brian Schleeper, Umair Arshad, Mannan Venkatesan, Courtney Smith, Raghav Bhargava, Karsten Thomann •This BCOP aims to provide a singular, consistent view of industry standard eBGP interconnection methodologies •This BCOP will also document pre and post turn-up validation practices and IRR Etiquette •The primary focus of this BCOP is eBGP know-how
  • 17. BCOP | February 2013 NANOG BCOP documents in the works: “Ethernet OAM” Contributors: Mark Calkins, Jean-Francois Levesque, Voitek Kozack •This BCOP aims to provide insight into how Ethernet OAM is best deployed within todays service provider networks. •This BCOP will try to capture current and emerging best practices for uses of Ethernet OAM technologies. •The primary focus is on a basic understanding of EOAM technologies.
  • 18. BCOP | February 2013 NANOG BCOP documents in the works: “Anti-DDoS” Contributors: Yardiel Fuentes, Rich Compton, Prabhu Gurumurthy, John W, Damon Fortune •This BCOP aims to share practices which have performed in production environments as a guide on what to do before, during, and after a DDoS/DoS attack. •This BCOP document focuses on providing, in a vendor-agnostic framework, guidelines at the different stage of dealing with DDoS/DoS attacks
  • 19. BCOP | February 2013 NANOG BCOP documents in the works: “Anti-Spoofing” Contributors: Aaron Hughes, et. al. •Intent is to provide more detailed operator input on workarounds for known vendor bugs in vendor equipment •Focus on detailed configuration information from a variety of common vendors and architectural scenarios for the ISP and Enterprise spaces
  • 20. BCOP | February 2013 JANOG BCOP Group JANOG has started a BCOP Task Force with Seiichi Kawamura and Yoshinobu Matsuzaki co-chairing it. Documents in progress: •eBGP best practices • http://www.janpg.gr.jp/doc/janog-comment/bcop-ebgp.txt •How to plan, build, and run a conference WiFi network
  • 21. BCOP | February 2013 Potential Topics for Additional BCOPs http://www.internetsociety.org/deploy360/about/bcop/topics/ •How to test your network performance •How to check your visibility from global Internet •De-Aggregation: strict filtering /48s out of /32 •How are operators using IRR? •IPv6 enterprise network renumbering scenarios, considerations, and methods •DNS Policies •Email Policies •ICMP Filtering •… (we need more suggestions)
  • 22. BCOP | February 2013 Next Steps Where are we going from here? •Continue to bootstrap new efforts as needed •Develop new BCOP documents • Lots of low-hanging fruit •Review and update existing BCOP documents •Start thinking & talking about Global coordination
  • 23. BCOP | February 2013 Get Involved Today! Join this grass-roots effort at the ground floor! •Contribute to an existing draft •Offer ideas for new drafts •Kick off a new document •Start a local or regional BCOP effort • Email deploy360@isoc.org for more information
  • 24. www.internetsociety.org Deploy360@ISOC.org Chris Grundemann Jan Žorž Internet Society Deploy360 Programmehttp://www.internetsociety.org/depl oy360/ Thank You!