Educause Security Discussion mailing list archives

Re: Multiple ISPs and Traffic Shaping


From: Jeff Kell <jeff-kell () UTC EDU>
Date: Fri, 15 Apr 2011 13:22:56 -0400

On 4/15/2011 12:34 PM, Kundert, Robin wrote:

I am wondering if there are other institutions that have implemented a similar setup
and would be willing to share how they accomplished these goals.  As you can imagine
we are quite budget conscious and right now I'm trying to figure out how we can shape,
firewall and route traffic (BGP to steer things a bit) on each "pipe" without having
to buy multiple of each device or creating some crazy VLAN structure shuttling traffic
back and forth between buildings.


We have three provider links and five logical "peering limits" based on the BGP path of
the data.  We use a Procera and the it's BGP peering capability to have the AS path
available to make shaping decisions.

Your actual mileage may vary as the BGP path only accurately predicts the outbound path
of your data.

If you can DSCP mark your incoming traffic based on the ingress path, you can use the
DSCP values to shape your inbound path; but we are not currently doing this (the BGP
path has proven to be a reasonable approximation of inbound source).

Jeff


Current thread: