This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+35 -35
View File
@@ -7,7 +7,7 @@ This is about **resource management**
- **Supply** - Available link capacity on path
- **Demand** - Host transmitting and receiving traffic
- **Elastic** - capacity reduces -> demand is scaled back
- Hosts stop sending / send less
- Hosts stop sending / send less
- **Inelastic** - applications can’t handle this
TCP manages resource usage based on observed loss and latency
@@ -19,8 +19,8 @@ If capacity > demand, there is no need for quality of service
If capacity < demand, we need to keep queuing minimal
- As queuing directly impacts latency, jitter and loss
- In stable networks
- **Jitter**: The difference in delays, a measure of stability
- In stable networks
- **Jitter**: The difference in delays, a measure of stability
#### IP Type of Service
@@ -59,76 +59,76 @@ Precedence
### Differentiated Services (DiffServ)
- Operates on *traffic aggregates*
- Label packets with desired class via ToS
- Routers apply different queuing as operator sees fit
- Label packets with desired class via ToS
- Routers apply different queuing as operator sees fit
- Four service classes, or *per-hop behaviour*
- **Default**: best effort
- No QoL applied
- **Expedited Forwarding**: low delay, loss & jitter
- **Assured Forwarding**: low loss if within rate
- **Class Selector**: use ToS precedence bits
- **Default**: best effort
- No QoL applied
- **Expedited Forwarding**: low delay, loss & jitter
- **Assured Forwarding**: low loss if within rate
- **Class Selector**: use ToS precedence bits
##### Problems
- End to end semantics
- End-to-end semantics
- Mapping to service level agreement
- If an internet company sells a network with a certain speed, this might have legal repercussions if QoS are enacted
- If an internet company sells a network with a certain speed, this might have legal repercussions if QoS is enacted
- Mapping to application demands
### Integrated Services (IntServ)
- Operates on explicitly signalled *flows*
- Think phone switchboards
- The network signals exactly what it can and can’t do to the destination nodes
- Think phone switchboards
- The network signals exactly what it can and can’t do to the destination nodes
- Flow setup specifies some quality of service
- Routers perform **C**onnection **A**dmission **C**ontrol
- CDA can accept and reject traffic based on whether or not the route/path is available
- CDA can accept and reject traffic based on whether or not the route/path is available
##### Problems
- Complexity
- Hard to scale
- Hard to scale
- Mapping requirements to parameters
- This was easier when ATM did it as they owned all the infrastructure
- Whereas now it is difficult to map across all different companies
- This was easier when ATM did it as they owned all the infrastructure
- Whereas now it is difficult to map across all different companies
- Per-flow state
- Extremely difficult
- Extremely difficult
## NAT
### Address Shortages
**IPv4** supports 32 bit addresses
**IPv4** supports 32-bit addresses
- 95% allocated already (440,000 netblocks)
**IPv6** supports 128-bit address
**IPv6** supports 128-bit addresses
- Loads of addresses :white_check_mark:
- Routing protocols need to ported :negative_squared_cross_mark:
- Routing protocols need to be ported :negative_squared_cross_mark:
- Associated services needing to move :negative_squared_cross_mark:
### Network Address Translation
Because IPv6 did not magically solve address shortage problem and not all routers are ipv6 aware, we had to rely on NAT.
Because IPv6 did not magically solve the address shortage problem and not all routers are IPv6-aware, we had to rely on NAT.
- Private Addressing, `RFC1918`
- `172.16/12`, `192.168/16`, `10/8`
- Devices with these local IPs should never be externally routed
- Not for security reasons - just for getting more addresses
- `172.16/12`, `192.168/16`, `10/8`
- Devices with these local IPs should never be externally routed
- Not for security reasons - just for getting more addresses
- Traditional NAT, `RFC3022` is the standard
- Use private addresses internally (within the local network)
- Map into a (small) set of routable addresses
- Use source ports to distinguish connections
- For large scale **carrier grade NAT** [`RFC6598`] on `100.64/10`
- Use private addresses internally (within the local network)
- Map into a (small) set of routable addresses
- Use source ports to distinguish connections
- For large-scale **carrier-grade NAT** [`RFC6598`] on `100.64/10`
#### Implementation
- Requires IP, TCP/UDP header rewriting
- Addresses, ports and checksums all need to be recalculated
- Addresses, ports and checksums all need to be recalculated
- Behaviours
- Network Address Translation
- Network Address and Port Translation
- Network Address Translation
- Network Address and Port Translation
###### Full Cone
@@ -136,7 +136,7 @@ Because IPv6 did not magically solve address shortage problem and not all router
ea:ep - NAT address : NAT port
```
When client receives packet from server 1 `da:dp`, the NAT translates the NAT address `ea:ep` to the clients internet address and port `ia:ip`.
When the client receives a packet from server 1 `da:dp`, the NAT translates the NAT address `ea:ep` to the client's internet address and port `ia:ip`.
###### Address Restricted Cone NAT
@@ -148,4 +148,4 @@ If the router receives a packet from a bad IP or bad port, it will be dropped.
###### Symmetric NAT
Here the internal address is obfuscated from the external servers, same client can use different ports for different communications.
Here, the internal address is obfuscated from the external servers. The same client can use different ports for different communications.