AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services –...

13
AM TLD Governance AM TLD Governance The role of ITC/AMNIC The role of ITC/AMNIC

Transcript of AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services –...

Page 1: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

AM TLD GovernanceAM TLD Governance

The role of ITC/AMNICThe role of ITC/AMNIC

Page 2: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

AMNIC public servicesAMNIC public services DNS

Whois

WWW

Other services – e-mail, NTP, cDNS, RIPE Atlas

Database - behind of scene

Page 3: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

DNS Zone file management

Slaves – diversity, reliability, security

DNSSEC

IANA

Page 4: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

DNSSEC pros

Authentication of origin

Record's non-existence verification

DANE/TLSA !

No MITM and cache poisoning anymore

Page 5: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

DNSSEC cons

Additional maintenance tasks

Target for DDoS - larger responses, more CPU load and RAM

usage

Increased cost of errors

Page 6: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

Back to other services

Whois - standard and web interfaces

Web interfaces to database updates

NTP stratum 1 server - ntp.amnic.net

member of pool.ntp.org cDNS - an instance of anycast cloud

E-mail - other way to communicate

Page 7: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

Hardware, connectivity, etcHardware, connectivity, etc

Two datacentres

Two power sources

Two upstream NSPs

Page 8: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

Datacentres

Server per service - virtualization

Database streaming replication

Total logging

Backup to opposite DC

Internal anycasting

Page 9: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

Upstreams

Connected to local exchanges

Native IPv6

Multihomed, with large capacity

Page 10: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

Power

Good UPS systems

Reliable switching between sources

Page 11: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

Disaster recovery

Recovery from backup

Migration to alive database

Migration to alive datacentre

Page 12: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

What to improve

Power generator system in main DC

Paid escrow service out of country

Global anycasting of DNS

Page 13: AM TLD Governance The role of ITC/AMNIC. AMNIC public services DNS Whois WWW Other services – e-mail, NTP, cDNS, RIPE Atlas Database - behind of scene.

Questions? Suggestions ?

Hrant Dadivanyan at [email protected]