๐Ÿš€ BGP (Border Gateway Protocol)๋ž€? ์ธํ„ฐ๋„ท์„ ์›€์ง์ด๋Š” ๋ณด์ด์ง€ ์•Š๋Š” ์†! ๐ŸŒ✨

์ธํ„ฐ๋„ท์ด ์ด๋ ‡๊ฒŒ ๊ฑฐ๋Œ€ํ•œ ๊ทœ๋ชจ๋กœ ์šด์˜๋  ์ˆ˜ ์žˆ๋Š” ์ด์œ  ์ค‘ ํ•˜๋‚˜๋Š” "Border Gateway Protocol (BGP)" ๋•๋ถ„์ž…๋‹ˆ๋‹ค. ์ด ํ”„๋กœํ† ์ฝœ์€ ์ธํ„ฐ๋„ท์ƒ์˜ ๋‹ค์–‘ํ•œ ๋„คํŠธ์›Œํฌ(์ž์œจ ์‹œ์Šคํ…œ, AS)๋ฅผ ์—ฐ๊ฒฐํ•˜๊ณ  ์ตœ์ ์˜ ๊ฒฝ๋กœ๋ฅผ ์ฐพ๋„๋ก ๋„์™€์ค๋‹ˆ๋‹ค. ์˜ค๋Š˜์€ BGP๊ฐ€ ๋ฌด์—‡์ธ์ง€, ์–ด๋–ป๊ฒŒ ์ž‘๋™ํ•˜๋Š”์ง€, ๊ทธ๋ฆฌ๊ณ  ๋ณด์•ˆ ๋ฌธ์ œ์™€ ์‹ค์ œ ์‚ฌ๋ก€๊นŒ์ง€ ๊นŠ์ด ์žˆ๊ฒŒ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.


๐Ÿ“Œ ๋ชฉ์ฐจ

  1. BGP๋ž€ ๋ฌด์—‡์ธ๊ฐ€?

  2. BGP์˜ ์ฃผ์š” ํŠน์ง•

  3. BGP์˜ ๋™์ž‘ ๋ฐฉ์‹

  4. BGP Neighboring ๊ณผ์ •

  5. BGP์˜ ์žฅ์ ๊ณผ ํ•œ๊ณ„์ 

  6. BGP ๋ณด์•ˆ ๋ฌธ์ œ์™€ ํ•ด๊ฒฐ ๋ฐฉ์•ˆ

  7. BGP ์ฃผ์š” ์†์„ฑ

  8. ์‹ค์ œ BGP ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

  9. ์š”์•ฝ ๋ฐ ์˜๊ฒฌ


1. BGP๋ž€ ๋ฌด์—‡์ธ๊ฐ€?

BGP(Border Gateway Protocol)๋Š” "์ธํ„ฐ๋„ท์˜ ์šฐ์ฒด๋ถ€" ์—ญํ• ์„ ํ•˜๋Š” ๋ผ์šฐํŒ… ํ”„๋กœํ† ์ฝœ์ž…๋‹ˆ๋‹ค. ์ฆ‰, ์ธํ„ฐ๋„ท์„ ๊ตฌ์„ฑํ•˜๋Š” ์—ฌ๋Ÿฌ ๋„คํŠธ์›Œํฌ ๊ฐ„์— ๊ฒฝ๋กœ ์ •๋ณด๋ฅผ ๊ณต์œ ํ•˜๊ณ  ์ตœ์ ์˜ ๊ฒฝ๋กœ๋ฅผ ์„ ํƒํ•˜๋Š” ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

BGP์˜ ๊ฐ€์žฅ ํฐ ํŠน์ง•์€ ํŒจํ‚ท์„ ์ „๋‹ฌํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ, ๋ผ์šฐํŒ… ์ •๋ณด๋ฅผ ๊ตํ™˜ํ•˜๋Š” ํ”„๋กœํ† ์ฝœ์ด๋ผ๋Š” ์ ์ž…๋‹ˆ๋‹ค. ์ฆ‰, BGP๋Š” ์ธํ„ฐ๋„ท์ƒ์˜ ์ž์œจ ์‹œ์Šคํ…œ(Autonomous System, AS)๋“ค ๊ฐ„์— ์–ด๋–ค ๊ฒฝ๋กœ๋ฅผ ๋”ฐ๋ผ ๋ฐ์ดํ„ฐ๋ฅผ ์ฃผ๊ณ ๋ฐ›์„์ง€๋ฅผ ๊ฒฐ์ •ํ•˜๋Š” ํ•ต์‹ฌ ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.

"AS(์ž์œจ ์‹œ์Šคํ…œ)"์ด๋ž€?
์ž์œจ ์‹œ์Šคํ…œ(AS)์€ ํ•˜๋‚˜์˜ ์ธํ„ฐ๋„ท ์„œ๋น„์Šค ์ œ๊ณต์—…์ฒด(ISP)๋‚˜ ๋Œ€๊ธฐ์—…, ์ •๋ถ€๊ธฐ๊ด€ ๋“ฑ์˜ ๋…๋ฆฝ์ ์ธ ๋„คํŠธ์›Œํฌ ๊ทธ๋ฃน์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ๊ฐ AS๋Š” ๊ณ ์œ ํ•œ AS ๋ฒˆํ˜ธ(ASN, Autonomous System Number)๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ์œผ๋ฉฐ, BGP๋ฅผ ํ†ตํ•ด ๋‹ค๋ฅธ AS์™€ ๊ฒฝ๋กœ ์ •๋ณด๋ฅผ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค.


2. BGP์˜ ์ฃผ์š” ํŠน์ง•

Path Vector Protocol
BGP๋Š” ๊ฒฝ๋กœ๋ฅผ ๋ฒกํ„ฐ(ASN ๋ชฉ๋ก)๋กœ ๊ด€๋ฆฌํ•˜๋Š” Path Vector Protocol์ž…๋‹ˆ๋‹ค. ์ฆ‰, ์–ด๋–ค ๋ชฉ์ ์ง€๊นŒ์ง€ ๊ฐ€๊ธฐ ์œ„ํ•ด ๊ฑฐ์ณ์•ผ ํ•˜๋Š” AS์˜ ๋ฆฌ์ŠคํŠธ๋ฅผ ์œ ์ง€ํ•˜๋ฉฐ, ์ด๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์ตœ์ ์˜ ๊ฒฝ๋กœ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

Exterior Gateway Protocol (EGP)
BGP๋Š” ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ(๋‹ค๋ฅธ AS ๊ฐ„)์—์„œ ๋™์ž‘ํ•˜๋Š” **Exterior Gateway Protocol (EGP)**์ด๋ฉฐ, ๋‚ด๋ถ€ ๋ผ์šฐํŒ…์„ ๋‹ด๋‹นํ•˜๋Š” OSPF, RIP, EIGRP ๊ฐ™์€ **Interior Gateway Protocol (IGP)**๊ณผ ๊ตฌ๋ถ„๋ฉ๋‹ˆ๋‹ค.

TCP ๊ธฐ๋ฐ˜ ํ”„๋กœํ† ์ฝœ
BGP๋Š” ์‹ ๋ขฐ์„ฑ์ด ๋†’์€ TCP (ํฌํŠธ 179๋ฒˆ)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ผ์šฐํŒ… ์ •๋ณด๋ฅผ ์ฃผ๊ณ ๋ฐ›์Šต๋‹ˆ๋‹ค. ๋•๋ถ„์— ์†์‹ค ์—†์ด ์•ˆ์ •์ ์œผ๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ๊ตํ™˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Path Selection (๊ฒฝ๋กœ ์„ ํƒ ์•Œ๊ณ ๋ฆฌ์ฆ˜)
BGP๋Š” ๋‹จ์ˆœํžˆ ์งง์€ ๊ฒฝ๋กœ๋ฅผ ์„ ํƒํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ, ๋‹ค์–‘ํ•œ ๊ธฐ์ค€์„ ์กฐํ•ฉํ•˜์—ฌ ์ตœ์ ์˜ ๊ฒฝ๋กœ๋ฅผ ์„ ์ •ํ•ฉ๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์ธ ๊ฒฝ๋กœ ์„ ํƒ ๊ธฐ์ค€์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. 

1️⃣ "๊ฐ€์žฅ ๋†’์€ ์šฐ์„ ์ˆœ์œ„"๋ฅผ ๊ฐ€์ง„ ๊ฒฝ๋กœ
2️⃣ "AS ๊ฒฝ๋กœ๊ฐ€ ์งง์€" ๊ฒฝ๋กœ
3️⃣ "๊ฐ€์žฅ ๋‚ฎ์€ ORIGIN ๊ฐ’"์„ ๊ฐ€์ง„ ๊ฒฝ๋กœ
4️⃣ "๊ฐ€์žฅ ๋‚ฎ์€ MED ๊ฐ’"์„ ๊ฐ€์ง„ ๊ฒฝ๋กœ
5️⃣ "๊ฐ€์žฅ ๊ฐ€๊นŒ์šด IGP ๊ฑฐ๋ฆฌ"๋ฅผ ๊ฐ€์ง„ ๊ฒฝ๋กœ

๋‘ ๊ฐ€์ง€ ๋ชจ๋“œ

  • eBGP(External BGP) ๐Ÿ›️: ์„œ๋กœ ๋‹ค๋ฅธ AS ๊ฐ„ ๋ผ์šฐํŒ… ์ •๋ณด๋ฅผ ๊ตํ™˜

  • iBGP(Internal BGP) ๐Ÿ : ๊ฐ™์€ AS ๋‚ด์—์„œ BGP ๊ฒฝ๋กœ๋ฅผ ๊ณต์œ 


3. BGP์˜ ๋™์ž‘ ๋ฐฉ์‹

BGP๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ Peering(ํ”ผ์–ด๋ง)์„ ํ†ตํ•ด ์ •๋ณด๋ฅผ ๊ตํ™˜ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ›  BGP ํ”ผ์–ด๋ง ๊ณผ์ •

1️⃣ TCP ์„ธ์…˜ ์„ค์ • (Port 179)

  • BGP ๋ผ์šฐํ„ฐ ๊ฐ„์— ์—ฐ๊ฒฐ์„ ๋งบ์Œ 2️⃣ OPEN ๋ฉ”์‹œ์ง€ ์ „์†ก (BGP Open Message)

  • ๋ฒ„์ „, ASN, ํ™€๋“œํƒ€์ž„, BGP ์‹๋ณ„์ž ๊ตํ™˜ 3️⃣ Keepalive ๋ฉ”์‹œ์ง€ ์ „์†ก (BGP Keepalive Message)

  • ์„ธ์…˜ ์œ ์ง€ 4️⃣ Update ๋ฉ”์‹œ์ง€ ์ „์†ก (BGP Update Message)

  • ๊ฒฝ๋กœ ์ •๋ณด ๊ณต์œ  5️⃣ Withdraw ๋ฉ”์‹œ์ง€ ์ „์†ก (BGP Withdraw Message)

  • ๋” ์ด์ƒ ์œ ํšจํ•˜์ง€ ์•Š์€ ๊ฒฝ๋กœ ์ œ๊ฑฐ

BGP ๋ผ์šฐํ„ฐ๋Š” Update ๋ฉ”์‹œ์ง€๋ฅผ ์ฃผ๊ณ ๋ฐ›์œผ๋ฉฐ ์ง€์†์ ์œผ๋กœ ๋„คํŠธ์›Œํฌ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ๋ฐ˜์˜ํ•ฉ๋‹ˆ๋‹ค.



4. BGP Neighboring ๊ณผ์ •

๐Ÿ›  BGP Neighbor ๊ด€๊ณ„ ์ˆ˜๋ฆฝ ๊ณผ์ •

BGP ํ”ผ์–ด๋ง์ด ํ˜•์„ฑ๋˜๋Š” ๊ณผ์ •์€ ์ด 6๋‹จ๊ณ„๋กœ ๋‚˜๋‰ฉ๋‹ˆ๋‹ค.

1️⃣ Idle ์ƒํƒœ

  • BGP ํ”„๋กœ์„ธ์Šค๊ฐ€ ํ™œ์„ฑํ™”๋˜์—ˆ์ง€๋งŒ, ์•„์ง ํ”ผ์–ด๋ง์„ ์‹œ์ž‘ํ•˜์ง€ ์•Š์€ ์ƒํƒœ์ž…๋‹ˆ๋‹ค.
  • ๊ด€๋ฆฌ์ž๊ฐ€ BGP ํ”„๋กœ์„ธ์Šค๋ฅผ ์ˆ˜๋™์œผ๋กœ ํ™œ์„ฑํ™”ํ•˜๊ฑฐ๋‚˜, ๋„คํŠธ์›Œํฌ ์ด๋ฒคํŠธ๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด ๋‹ค์Œ ๋‹จ๊ณ„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

2️⃣ Connect ์ƒํƒœ

  • BGP๊ฐ€ TCP 3-way handshake๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ TCP ํฌํŠธ 179๋ฅผ ํ†ตํ•ด ์—ฐ๊ฒฐ์„ ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.
  • ์—ฐ๊ฒฐ์ด ์„ฑ๊ณตํ•˜๋ฉด Open ๋ฉ”์‹œ์ง€๋ฅผ ๋ณด๋‚ด๊ณ  OpenSent ์ƒํƒœ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  • ์‹คํŒจํ•˜๋ฉด Active ์ƒํƒœ๋กœ ์ด๋™ํ•˜์—ฌ ๋‹ค์‹œ ์—ฐ๊ฒฐ์„ ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.

3️⃣ Active ์ƒํƒœ

  • TCP ์—ฐ๊ฒฐ์„ ๋‹ค์‹œ ์‹œ๋„ํ•˜๋Š” ๋‹จ๊ณ„๋กœ, ์ผ์ • ์‹œ๊ฐ„ ๋‚ด ์—ฐ๊ฒฐ์ด ์„ฑ๋ฆฝ๋˜์ง€ ์•Š์œผ๋ฉด Idle ์ƒํƒœ๋กœ ๋Œ์•„๊ฐ‘๋‹ˆ๋‹ค.
  • ์—ฐ๊ฒฐ์ด ์„ฑ๊ณตํ•˜๋ฉด OpenSent ์ƒํƒœ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

4️⃣ OpenSent ์ƒํƒœ

  • BGP๊ฐ€ Open ๋ฉ”์‹œ์ง€๋ฅผ ์ˆ˜์‹ ํ•˜๊ณ  ๊ฒ€์ฆํ•˜๋Š” ๋‹จ๊ณ„์ž…๋‹ˆ๋‹ค.
  • Open ๋ฉ”์‹œ์ง€์—๋Š” BGP ๋ฒ„์ „, AS ๋ฒˆํ˜ธ, ํ™€๋“œ ํƒ€์ž„, BGP Identifier ๋“ฑ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.
  • ๊ฒ€์ฆ์ด ์„ฑ๊ณตํ•˜๋ฉด OpenConfirm ์ƒํƒœ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

5️⃣ OpenConfirm ์ƒํƒœ

  • Keepalive ๋ฉ”์‹œ์ง€๋ฅผ ๊ตํ™˜ํ•˜์—ฌ BGP ์„ธ์…˜์ด ์ •์ƒ์ ์œผ๋กœ ์œ ์ง€๋˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • ๊ฒ€์ฆ์ด ์™„๋ฃŒ๋˜๋ฉด Established ์ƒํƒœ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

6️⃣ Established ์ƒํƒœ

  • BGP ํ”ผ์–ด๋ง์ด ์™„๋ฃŒ๋˜์—ˆ์œผ๋ฉฐ, ์ด์ œ ๋ผ์šฐํŒ… ์ •๋ณด๋ฅผ ๊ตํ™˜ํ•˜๋Š” ๋‹จ๊ณ„์ž…๋‹ˆ๋‹ค.
  • Update ๋ฉ”์‹œ์ง€๋ฅผ ๊ตํ™˜ํ•˜๋ฉฐ BGP์˜ ์ตœ์  ๊ฒฝ๋กœ ์„ ํƒ ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ํ†ตํ•ด ๊ฒฝ๋กœ๋ฅผ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ณผ์ •์„ ํ†ตํ•ด ์•ˆ์ •์ ์ธ BGP Neighbor ๊ด€๊ณ„๊ฐ€ ์ˆ˜๋ฆฝ๋ฉ๋‹ˆ๋‹ค.


5. BGP์˜ ์žฅ์ ๊ณผ ํ•œ๊ณ„์ 

์žฅ์ 

  • ํ™•์žฅ์„ฑ์ด ๋›ฐ์–ด๋‚จ: ์ธํ„ฐ๋„ท์ฒ˜๋Ÿผ ๊ฑฐ๋Œ€ํ•œ ๋„คํŠธ์›Œํฌ์—์„œ๋„ ์•ˆ์ •์ ์œผ๋กœ ๋™์ž‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • ์ •์ฑ… ๊ธฐ๋ฐ˜ ๋ผ์šฐํŒ… ๊ฐ€๋Šฅ: ํŠน์ • ๊ฒฝ๋กœ๋ฅผ ์„ ํ˜ธํ•˜๊ฑฐ๋‚˜ ์ œํ•œํ•  ์ˆ˜ ์žˆ์–ด ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ๊ฐ€ ์œ ์—ฐํ•ฉ๋‹ˆ๋‹ค.

  • ๋„คํŠธ์›Œํฌ ์•ˆ์ •์„ฑ ์ œ๊ณต: AS ๊ฐ„ ๊ฒฝ๋กœ ๋ณ€๊ฒฝ์ด ๋ฐœ์ƒํ•ด๋„ ๋น ๋ฅด๊ฒŒ ์ ์‘ํ•˜์—ฌ ์„œ๋น„์Šค ์ง€์†์„ฑ์„ ์œ ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•œ๊ณ„์ 

  • ์ˆ˜๋ ด ์‹œ๊ฐ„์ด ๊ธธ๋‹ค: "Convergence Time(์ˆ˜๋ ด ์‹œ๊ฐ„)"์ด ๊ธธ์–ด ๋ผ์šฐํŒ… ๋ณ€ํ™”๊ฐ€ ๋ฐ˜์˜๋˜๊ธฐ๊นŒ์ง€ ์‹œ๊ฐ„์ด ๊ฑธ๋ฆฝ๋‹ˆ๋‹ค.

  • ๋ณด์•ˆ ์ทจ์•ฝ์  ์กด์žฌ: BGP ํ•˜์ด์žฌํ‚น(๊ฒฝ๋กœ ๊ฐ€๋กœ์ฑ„๊ธฐ)๊ณผ ๊ฐ™์€ ๋ณด์•ˆ ์œ„ํ˜‘์ด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.

  • ์šด์˜ ๋ถ€๋‹ด์ด ํผ: ๊ฒฝ๋กœ ์ •๋ณด๋ฅผ ์ˆ˜๋™์œผ๋กœ ์„ค์ •ํ•ด์•ผ ํ•˜๋ฏ€๋กœ ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ์ž์˜ ๋ถ€๋‹ด์ด ์ฆ๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.


6. BGP ๋ณด์•ˆ ๋ฌธ์ œ์™€ ํ•ด๊ฒฐ ๋ฐฉ์•ˆ

๐Ÿšจ BGP ๋ณด์•ˆ ์œ„ํ˜‘

1️⃣ BGP ํ•˜์ด์žฌํ‚น – ์•…์˜์ ์ธ AS๊ฐ€ ์ž˜๋ชป๋œ ๊ฒฝ๋กœ ์ •๋ณด๋ฅผ ๋ฐฐํฌํ•˜์—ฌ ํŠธ๋ž˜ํ”ฝ์„ ๊ฐ€๋กœ์ฑ„๋Š” ๊ณต๊ฒฉ
2️⃣ BGP ๋ฃจํŠธ ๋ฆฌํ”Œ๋ ‰ํ„ฐ ๊ณต๊ฒฉ – iBGP์—์„œ ํŠน์ • ๋…ธ๋“œ๋ฅผ ๊ฒฝ์œ ํ•˜๋„๋ก ์†์—ฌ์„œ ํŠธ๋ž˜ํ”ฝ์„ ์กฐ์ž‘
3️⃣ BGP ํ”ผ์–ด๋ง ํ•ดํ‚น – ํ”ผ์–ด๋ง ์„ธ์…˜์„ ๊ฐ€๋กœ์ฑ„์„œ ๋„คํŠธ์›Œํฌ ๋งˆ๋น„

๐Ÿ›ก BGP ๋ณด์•ˆ ๊ฐ•ํ™” ๋ฐฉ๋ฒ•

  • RPKI (Resource Public Key Infrastructure) ์‚ฌ์šฉํ•˜์—ฌ ์˜ฌ๋ฐ”๋ฅธ ๊ฒฝ๋กœ๋งŒ ์ธ์ฆ

  • Prefix Filtering์„ ์ ์šฉํ•˜์—ฌ ์˜ˆ์ƒ์น˜ ๋ชปํ•œ ๊ฒฝ๋กœ ๋ณ€๊ฒฝ ์ฐจ๋‹จ

  • BGP TTL Security, MD5 ์ธ์ฆ ์ ์šฉํ•˜์—ฌ ํ”ผ์–ด๋ง ๋ณด์•ˆ ๊ฐ•ํ™”


7. BGP  ์ฃผ์š” ์†์„ฑ

BGP๋Š” ๊ฒฝ๋กœ๋ฅผ ์„ ํƒํ•  ๋•Œ Path Attribute(๊ฒฝ๋กœ ์†์„ฑ)์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ€์žฅ ์ ์ ˆํ•œ ๊ฒฝ๋กœ๋ฅผ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.
์ด ๋ฌธ์„œ์—์„œ๋Š” BGP์˜ ์ฃผ์š” Path Attribute์— ๋Œ€ํ•ด ์ƒ์„ธํžˆ ์„ค๋ช…ํ•˜๊ณ , ๊ฐ ์†์„ฑ์„ ์–ธ์ œ ์–ด๋–ป๊ฒŒ ์‚ฌ์šฉํ•˜๋ฉด ์ข‹์€์ง€ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

BGP ์†์„ฑ์€ ํฌ๊ฒŒ 4๊ฐ€์ง€ ํƒ€์ž…์œผ๋กœ ๋ถ„๋ฅ˜๋ฉ๋‹ˆ๋‹ค.

๐Ÿ”นWell-Known Mandatory : ๋ชจ๋“  BGP ๋ฉ”์‹œ์ง€์— ํฌํ•จ๋˜์–ด์•ผ ํ•˜๋ฉฐ, ๋ชจ๋“  BGP ๋ผ์šฐํ„ฐ๊ฐ€ ์ดํ•ดํ•ด์•ผ ํ•˜๋Š” ์†์„ฑ (์˜ˆ. Origin, AS-path, Next-Hop)

๐Ÿ”นWell-Known Discretionary : ๋ชจ๋“  BGP ๋ผ์šฐํ„ฐ๊ฐ€ ์ดํ•ดํ•ด์•ผ ํ•˜์ง€๋งŒ, ํ•„์ˆ˜์ ์œผ๋กœ ํฌํ•จ๋  ํ•„์š”๋Š” ์—†์Œ (์˜ˆ. Local Preference, Atomic Aggregate)

๐Ÿ”นOptional Transitive : ์„ ํƒ์ ์ด๋ฉฐ, BGP ๋„ค์ด๋ฒ„์—๊ฒŒ ์ „๋‹ฌ ๊ฐ€๋Šฅ (์˜ˆ. BGP community, Aggregator)

๐Ÿ”นOptional Non-Transitive : ์„ ํƒ์ ์ด๋ฉฐ, ๋„ค์ด๋ฒ„์—๊ฒŒ ์ „๋‹ฌ๋˜์ง€ ์•Š์Œ (์˜ˆ. MED (Multi-Exit Discriminator), Originator ID, Cluster ID)


๐Ÿ“Œ BGP ๊ฒฝ๋กœ ์„ ํƒ ์‹œ ์šฐ์„ ์ˆœ์œ„

BGP๋Š” ์—ฌ๋Ÿฌ ๊ฒฝ๋กœ๊ฐ€ ์žˆ์„ ๊ฒฝ์šฐ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์†์„ฑ์„ ๊ธฐ์ค€์œผ๋กœ ๊ฒฝ๋กœ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

1. Weight (Cisco ์ „์šฉ)
2. Local Preference
3. AS Path
4. Origin
5. MED (Multi-Exit Discriminator)
6. eBGP > iBGP
7. IGP Cost to Next-Hop
8. Router ID
9. Oldest Path

1️⃣ Weight (Cisco ์ „์šฉ)

  • ์ •์˜Cisco ์ „์šฉ ์†์„ฑ์œผ๋กœ, ๋กœ์ปฌ ๋ผ์šฐํ„ฐ์—์„œ๋งŒ ํŠน์ • ๊ฒฝ๋กœ๋ฅผ ์„ ํ˜ธํ•˜๋„๋ก ์„ค์ •
  • ์ ์šฉ ๋ฐฉํ–ฅ : Outbound ํŠธ๋ž˜ํ”ฝ
  • ์ด์›ƒ(Neighbor) ๋ผ์šฐํ„ฐ์—๋Š” ์ „๋‹ฌ๋˜์ง€ ์•Š์Œ (๋กœ์ปฌ ์ „์šฉ ์†์„ฑ)
  • ๊ฐ’ ๋ฒ”์œ„ : 0 ~ 65535 (๊ธฐ๋ณธ๊ฐ’: 0, ์ง์ ‘ ํ•™์Šตํ•œ ๊ฒฝ๋กœ๋Š” 32768)
  • ๋†’์„์ˆ˜๋ก ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’์Œ
  • ํ™œ์šฉ ์˜ˆ์‹œ : ํŠน์ • ISP  (BGP Peer)๊ฒฝ๋กœ์˜ Weight ๊ฐ’์„ ๋†’๊ฒŒ ์„ค์ •ํ•˜์—ฌ ๋กœ์ปฌ ๋ผ์šฐํ„ฐ์—์„œ ํ•ด๋‹น ๊ฒฝ๋กœ๋ฅผ ์šฐ์„ ์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๋„๋ก ์œ ๋„

  • ์„ค์ • ๋ฐฉ๋ฒ• : Inbound ๊ฒฝ๋กœ ๋งต(route map)์„ ํ†ตํ•ด ์ˆ˜์‹ ํ•œ ๊ฒฝ๋กœ์˜ weight ๊ฐ’์„ ์„ค์ •ํ•˜์—ฌ ๋กœ์ปฌ ๋ผ์šฐํ„ฐ์˜ Outbound ๊ฒฝ๋กœ ์„ ํƒ์— ์˜ํ–ฅ์„ ์คŒ 

  • Weight ์„ค์ • ์˜ˆ์ œ 
// route-map์„ ํ†ตํ•ด ์„ธ๋ถ€๊ฒฝ๋กœ์—๋งŒ ์ ์šฉ
ip prefix-list PREFERRED-ROUTES permit 192.0.2.0/24

route-map SET_WEIGHT permit 10
match ip address prefix-list PREFERRED-ROUTES
set weight 400
!
router bgp 65001
neighbor 192.168.1.1 route-map SET_WEIGHT in

// neighbor์— ์ง์ ‘ ์„ค์ •ํ•˜์—ฌ ๋ชจ๋“  ๊ฒฝ๋กœ์— ๋™์ผํ•œ weight ์ 
router bgp 65001
 neighbor 10.1.1.1 remote-as 65010
 neighbor 10.1.1.1 weight 500

 neighbor 10.2.2.2 remote-as 65020
 ! weight ์„ค์ • ์•ˆํ•จ → ๊ธฐ๋ณธ๊ฐ’ 0


2️⃣  Local Preference

  • ์ •์˜AS ๋‚ด๋ถ€(iBGP)์—์„œ ๊ฒฝ๋กœ ์šฐ์„ ์ˆœ์œ„๋ฅผ ๊ฒฐ์ •. Local Preference ๊ฐ’์€ AS ๋‚ด๋ถ€(iBGP) ํ”ผ์–ด๊ฐ„์—๋งŒ ์ „ํŒŒ๋˜๋ฉฐ, AS ์™ธ๋ถ€๋กœ๋Š” ์ „์†ก๋˜์ง€์•Š์Œ. ์•„์›ƒ๋ฐ”์šด๋“œ ํŠธ๋ž˜ํ”ฝ ๊ฒฝ๋กœ ์„ ํƒ์— ์˜ํ–ฅ์„ ๋ฏธ์นจ.
  • ์ ์šฉ ๋ฐฉํ–ฅ : Outbound ํŠธ๋ž˜ํ”ฝ
  • ๊ฐ’ ๋ฒ”์œ„: 0 ~ 4294967295 (๊ธฐ๋ณธ๊ฐ’: 100)
  • ๋†’์„์ˆ˜๋ก ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’์Œ

  • ํ™œ์šฉ ์˜ˆ์‹œ: ๋ฉ€ํ‹ฐํ™ˆ๋“œ(ISP1, ISP2...) ํ™˜๊ฒฝ์—์„œ ํŠน์ • ISP๋กœ ํŠธ๋ž˜ํ”ฝ์„ ๊ธฐ๋ณธ์ ์œผ๋กœ ๋ณด๋‚ด๊ณ  ์‹ถ์„ ๋•Œ (๋ชจ๋“  iBGP ๋ผ์šฐํ„ฐ๋“ค๋„ ํŠน์ • ISP๋กœ best path ์—…๋ฐ์ดํŠธ ๋จ. Weight์—์„œ๋Š” ๋ถˆ๊ฐ€๋Šฅํ•จ. ๋‹ค๋ฅธ iBGP๋กœ ์ „ํŒŒ๋˜์ง€์•Š๊ธฐ๋•Œ๋ฌธ.)
  • Local Preference ์„ค์ • ์˜ˆ์ œ

route-map SET_LOCAL_PREF permit 10

 match ip address 10
 set local-preference 200
!
router bgp 65001
 neighbor 192.168.1.1 route-map SET_LOCAL_PREF in

3️⃣ AS Path

  • BGP ๊ฒฝ๋กœ ์—…๋ฐ์ดํŠธ ๋ฉ”์‹œ์ง€์— ํฌํ•จ๋˜๋Š” ์†์„ฑ. ํŠน์ • ๋„คํŠธ์›Œํฌ (Prefix)๊ฐ€ ์–ด๋–ค AS(Autonomous System)๋ฅผ ๊ฑฐ์ณ์™”๋Š”์ง€ ๋‚˜ํƒ€๋ƒ„.
  • ์ ์šฉ ๋ฐฉํ–ฅ : Inbound / Outbound ํŠธ๋ž˜ํ”ฝ ๋ชจ๋‘ ์ ์šฉ ๊ฐ€๋Šฅ
  • Inbound (์ˆ˜์‹ ๋œ ๊ฒฝ๋กœ์— ์ ์šฉ): ํŠน์ • AS์—์„œ ์˜จ ๊ฒฝ๋กœ๋ฅผ ์ฐจ๋‹จํ•˜๊ฑฐ๋‚˜ ์„ ํ˜ธ๋„ ์กฐ์ •
  • Outbound (๋‚ด๋ณด๋‚ด๋Š” ๊ฒฝ๋กœ์— ์ ์šฉ): AS-Path Prepend๋ฅผ ํ†ตํ•ด ํŠน์ • ๊ฒฝ๋กœ๋ฅผ ๋œ ์„ ํ˜ธํ•˜๊ฒŒ ์กฐ์ž‘
  • ์งง์„์ˆ˜๋ก ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’์Œ → BGP๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ AS-Path๊ฐ€ ๊ฐ€์žฅ ์งง์€ ๊ฒฝ๋กœ๋ฅผ ์„ ํ˜ธ
  • "192.168.1.0/24  AS-Path: 65005 65003 65001"๋ผ๋ฉด, 192.168.1.0/24 ๊ฒฝ๋กœ๋Š” AS 65001 → 65003 → 65005๋ฅผ ๊ฑฐ์ณ ์ „๋‹ฌ๋จ
  • ํ™œ์šฉ์˜ˆ์‹œ : AS 65005์—์„œ ์˜จ ๋ชจ๋“  ๊ฒฝ๋กœ๋ฅผ ์ฐจ๋‹จ (Inbound), ISP2๋ฅผ ๋ฐฑ์—… ๊ฒฝ๋กœ๋กœ ์„ค์ • (Outbound)
  • AS Path ์„ค์ • ์˜ˆ์ œ

 // AS-Path ํ•„ํ„ฐ๋ง (Inbound)

ip as-path access-list 10 deny _65005_

ip as-path access-list 10 permit .*  # ๋‚˜๋จธ์ง€ ๋ชจ๋“  ๊ฒฝ๋กœ ํ—ˆ์šฉ


route-map FILTER-AS-PATH deny 10

 match as-path 10


router bgp 65000

 neighbor 10.1.1.1 route-map FILTER-AS-PATH in


// AS-Path Prepend (Outbound)

route-map PREPEND-ISP2 permit 10

 match ip address prefix-list BACKUP-ROUTES

 set as-path prepend 65000 65000 65000  # ๋‚ด AS๋ฒˆํ˜ธ๋ฅผ ์—ฌ๋Ÿฌ ๋ฒˆ ์ถ”๊ฐ€


router bgp 65000

 neighbor 10.2.2.2 route-map PREPEND-ISP2 out


4️⃣ MED (Multi-Exit Discriminator)

  • ํŠน์ • AS(Autonomous System)๋กœ ๋“ค์–ด์˜ค๋Š” ํŠธ๋ž˜ํ”ฝ์„ ์ œ์–ดํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋˜๋ฉฐ, ํŠนํžˆ, ํ•˜๋‚˜์˜ AS์— ์—ฌ๋Ÿฌ๊ฐœ์˜ ๊ฒฝ๋กœ๊ฐ€ ์žˆ์„ ๋•Œ, ์™ธ๋ถ€ AS๊ฐ€ ํŠน์ • ๊ฒฝ๋กœ๋ฅผ ์„ ํ˜ธํ•˜๋„๋ก ์œ ๋„ํ• ๋•Œ ํ™œ์šฉ๋จ
  • ์ ์šฉ ๋ฐฉํ–ฅ : Inbound / Outbound ํŠธ๋ž˜ํ”ฝ 
  • Inbound (์ˆ˜์‹ ๋œ ๊ฒฝ๋กœ์— ์ ์šฉ): ํŠน์ • AS๋กœ๋ถ€ํ„ฐ ๋“ค์–ด์˜ค๋Š” ๊ฒฝ๋กœ์— ๋Œ€ํ•ด MED ๊ฐ’์„ ์กฐ์ •ํ•˜์—ฌ ์šฐ์„ ์ˆœ์œ„๋ฅผ ์„ค์ •
  • Outbound (๋‚ด๋ณด๋‚ด๋Š” ๊ฒฝ๋กœ์— ์ ์šฉ): ๋‚ด๊ฐ€ ํŠน์ • ๊ฒฝ๋กœ์˜ MED ๊ฐ’์„ ๋ณ€๊ฒฝํ•˜์—ฌ, ์ƒ๋Œ€ AS๊ฐ€ ํŠน์ • ๊ฒฝ๋กœ๋ฅผ ์„ ํ˜ธํ•˜๋„๋ก ์œ ๋„
  • MED ๊ฐ’์€ AS ๊ฐ„ ๋น„๊ต๊ฐ€ ๋ถˆ๊ฐ€๋Šฅ.  (์ฆ‰, AS 100๊ณผ AS 200์—์„œ ๋“ค์–ด์˜ค๋Š” ๊ฒฝ๋กœ ๊ฐ„์—๋Š” MED ๋น„๊ต๊ฐ€ ๋˜์ง€ ์•Š์Œ. ๋™์ผํ•œ AS์—์„œ ๋“ค์–ด์˜ค๋Š” ์—ฌ๋Ÿฌ ๊ฒฝ๋กœ์— ๋Œ€ํ•ด์„œ๋งŒ ๋น„๊ต ๊ฐ€๋Šฅ!
  • ํ™œ์šฉ์˜ˆ์‹œ : ํŠน์ • ISP์—์„œ ๋“ค์–ด์˜ค๋Š” ํŠธ๋ž˜ํ”ฝ ๊ฒฝ๋กœ ์กฐ์ • (Inbound), ๋ฉ€ํ‹ฐํ™ˆ(์ด์ค‘ ISP) ํ™˜๊ฒฝ์—์„œ ํŠธ๋ž˜ํ”ฝ ๋ฐธ๋Ÿฐ์‹ฑ (Outbound)
  • MED ์„ค์ • ์˜ˆ์ œ

// ์ด์ค‘ ISP ํ™˜๊ฒฝ์—์„œ ISP1์„ ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋กœ ์‚ฌ์šฉํ•˜๊ณ , ISP2๋ฅผ ๋ฐฑ์—… ๊ฒฝ๋กœ๋กœ ์‚ฌ์šฉ (Outbound ์ ์šฉ. ์ƒ๋Œ€๋ฐฉ(์™ธ๋ถ€ AS)์ด ๋‚ด๊ฐ€ ์„ค์ •ํ•œ MED ๊ฐ’์„ ๋ณด๊ณ  ํ•ด๋‹น ๊ฒฝ๋กœ๋ฅผ ๋” ์„ ํ˜ธํ•˜๋„๋ก ์œ ๋„ํ•˜๊ธฐ ๋•Œ๋ฌธ)

route-map SET_MED_ISP1 permit 10

 match ip address prefix-list OUR_NETWORKS

 set metric 50   # ๋‚ฎ์€ ๊ฐ’์ด ์šฐ์„ ์ˆœ์œ„ ๋†’์Œ


route-map SET_MED_ISP2 permit 10

 match ip address prefix-list OUR_NETWORKS

 set metric 200  # ๋†’์€ ๊ฐ’ → ๋œ ์„ ํ˜ธ๋จ


router bgp 65000

 neighbor 192.168.1.1 route-map SET_MED_ISP1 out  # ISP1์œผ๋กœ ๋ณด๋‚ด๋Š” ๊ฒฝ๋กœ

 neighbor 192.168.2.1 route-map SET_MED_ISP2 out  # ISP2๋กœ ๋ณด๋‚ด๋Š” ๊ฒฝ๋กœ


5️⃣ BGP Communities

  • BGP ์—…๋ฐ์ดํŠธ ๋ฉ”์‹œ์ง€๋ฅผ ํ†ตํ•ด ์—ฌ๋Ÿฌ AS์— ์ „๋‹ฌ๋  ์ˆ˜ ์žˆ์Œ. ํ•˜๋‚˜์˜ ๊ฒฝ๋กœ์— ์—ฌ๋Ÿฌ ๊ฐœ์˜ Community ๊ฐ’์„ ๋ถ€์—ฌ ๊ฐ€๋Šฅ.
  • AA:NN ํ˜•ํƒœ๋กœ ์‚ฌ์šฉ (์˜ˆ: 65000:100 → AS 65000์—์„œ ์ •์˜ํ•œ Community ๊ฐ’ 100)
  • Outbound (๋‚ด๋ณด๋‚ด๋Š” ๊ฒฝ๋กœ์— ์ ์šฉ) : ๋‚ด๊ฐ€ ํŠน์ • ๊ฒฝ๋กœ์— Community ๊ฐ’์„ ์ถ”๊ฐ€ํ•˜์—ฌ ๋‹ค๋ฅธ AS๊ฐ€ ํ•ด๋‹น ๊ฐ’์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์ •์ฑ…์„ ์ ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•จ
  • Inbound (์ˆ˜์‹ ๋œ ๊ฒฝ๋กœ์— ์ ์šฉ) : ๋ฐ›์€ ๊ฒฝ๋กœ์˜ Community ๊ฐ’์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํŠน์ • ์ •์ฑ…์„ ์ ์šฉ (ํ•„ํ„ฐ๋ง, ์šฐ์„ ์ˆœ์œ„ ๋ณ€๊ฒฝ ๋“ฑ)
  • BGP ์—…๋ฐ์ดํŠธ ๋ฉ”์‹œ์ง€๋ฅผ ํ†ตํ•ด ์—ฌ๋Ÿฌ AS์— ์ „๋‹ฌ๋  ์ˆ˜ ์žˆ์Œ. ํ•˜๋‚˜์˜ ๊ฒฝ๋กœ์— ์—ฌ๋Ÿฌ ๊ฐœ์˜ Community ๊ฐ’์„ ๋ถ€์—ฌ ๊ฐ€๋Šฅ.
  • AA:NN ํ˜•ํƒœ๋กœ ์‚ฌ์šฉ (์˜ˆ: 65000:100 → AS 65000์—์„œ ์ •์˜ํ•œ Community ๊ฐ’ 100)
  • ํ™œ์šฉ์˜ˆ์‹œ : Outbound (ํŠธ๋ž˜ํ”ฝ ์—”์ง€๋‹ˆ์–ด๋ง, ํŠน์ • ๊ฒฝ๋กœ ์šฐ์„ ์ˆœ์œ„ ์„ค์ •), Inbound (๊ฒฝ๋กœ ํ•„ํ„ฐ๋ง, ํŠน์ • ๊ฒฝ๋กœ ์„ ํ˜ธ)
  • Community ์„ค์ • ์˜ˆ์ œ

// AS 65000์—์„œ ๋ณด๋‚ธ ๊ฒฝ๋กœ ์ค‘ Community ๊ฐ’์ด 65000:100์ธ ๊ฒฝ๋กœ๋ฅผ ์ฐจ๋‹จ

ip community-list 10 deny 65000:100  # AS 65000์—์„œ ๋ณด๋‚ธ Community 100 ์ฐจ๋‹จ

ip community-list 10 permit any      # ๋‚˜๋จธ์ง€๋Š” ํ—ˆ์šฉ


route-map FILTER_COMMUNITY deny 10

 match community 10


router bgp 65000

 neighbor 192.168.1.1 route-map FILTER_COMMUNITY in



8. ์‹ค์ œ BGP ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

1️⃣ 2018๋…„ 4์›”: Amazon Route 53 BGP ํ•˜์ด์žฌํ‚น ์‚ฌ๊ฑด

  • ์˜ํ–ฅ์„ ๋ฐ›์€ ๊ธฐ์—…: MyEtherWallet (์•”ํ˜ธํ™”ํ ์ง€๊ฐ‘ ์„œ๋น„์Šค)
  • ๋ฐœ์ƒ ์‹œ๊ฐ„: 2018๋…„ 4์›” 24์ผ
  • ์ง€์† ์‹œ๊ฐ„: ์•ฝ 2์‹œ๊ฐ„
  • ๊ธฐ์ˆ ์  ์›์ธ: BGP ํ•˜์ด์žฌํ‚น

์ด ์‚ฌ๊ฑด์—์„œ ๊ณต๊ฒฉ์ž๋Š” BGP ํ•˜์ด์žฌํ‚น์„ ํ†ตํ•ด Amazon์˜ DNS ์„œ๋น„์Šค์ธ Route 53์˜ ํŠธ๋ž˜ํ”ฝ์„ ๊ฐ€๋กœ์ฑ˜์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด MyEtherWallet ์‚ฌ์šฉ์ž๋ฅผ ํ”ผ์‹ฑ ์‚ฌ์ดํŠธ๋กœ ์œ ๋„ํ•˜์—ฌ ์•”ํ˜ธํ™”ํ๋ฅผ ํƒˆ์ทจํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ํ•ฉ๋ฒ•์ ์ธ IP ์ฃผ์†Œ ๋ฒ”์œ„๋ฅผ ๊ฐ€์žฅํ•˜์—ฌ ์ž˜๋ชป๋œ BGP ๊ฒฝ๋กœ๋ฅผ ๊ด‘๊ณ ํ•จ์œผ๋กœ์จ ํŠธ๋ž˜ํ”ฝ์„ ์ž์‹ ๋“ค์ด ์ œ์–ดํ•˜๋Š” ์„œ๋ฒ„๋กœ ๋ฆฌ๋””๋ ‰์…˜ํ–ˆ์Šต๋‹ˆ๋‹ค.

2️⃣ 2019๋…„ 6์›”: ์œ ๋Ÿฝ ์ธํ„ฐ๋„ท ํŠธ๋ž˜ํ”ฝ ์šฐํšŒ ์‚ฌ๊ณ 

  • ์˜ํ–ฅ์„ ๋ฐ›์€ ๊ธฐ์—…: Cloudflare, Amazon, Linode ๋“ฑ
  • ๋ฐœ์ƒ ์‹œ๊ฐ„: 2019๋…„ 6์›” 6์ผ
  • ์ง€์† ์‹œ๊ฐ„: ์•ฝ 2์‹œ๊ฐ„
  • ๊ธฐ์ˆ ์  ์›์ธ: ์ž˜๋ชป๋œ BGP ๊ฒฝ๋กœ ๊ด‘๊ณ 

์Šค์œ„์Šค์˜ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ์—…์ฒด์ธ Safe Host๊ฐ€ ์ž˜๋ชป๋œ BGP ๊ฒฝ๋กœ๋ฅผ ๊ด‘๊ณ ํ•˜์—ฌ ์œ ๋Ÿฝ์˜ ์ธํ„ฐ๋„ท ํŠธ๋ž˜ํ”ฝ์ด ์ค‘๊ตญ์˜ China Telecom์„ ๊ฒฝ์œ ํ•˜๋„๋ก ๋งŒ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋กœ ์ธํ•ด Cloudflare, Amazon, Linode ๋“ฑ์˜ ์„œ๋น„์Šค์— ์ง€์—ฐ๊ณผ ์žฅ์• ๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ์ˆ ์ ์œผ๋กœ ์ด๋Š” BGP ํ”ผ์–ด ๊ฐ„์˜ ํ•„ํ„ฐ๋ง์ด ์ œ๋Œ€๋กœ ์ด๋ฃจ์–ด์ง€์ง€ ์•Š์•„ ๋ฐœ์ƒํ•œ ๋ฌธ์ œ๋กœ, ์ž˜๋ชป๋œ ๊ฒฝ๋กœ ์ •๋ณด๊ฐ€ ์ „ํŒŒ๋˜์–ด ํŠธ๋ž˜ํ”ฝ์ด ์˜๋„์น˜ ์•Š์€ ๊ฒฝ๋กœ๋กœ ์šฐํšŒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

3️⃣ 2024๋…„ 6์›”: Cloudflare 1.1.1.1 ์„œ๋น„์Šค ์žฅ์•  ์‚ฌ๊ฑด

  • ์˜ํ–ฅ์„ ๋ฐ›์€ ๊ธฐ์—…: Cloudflare
  • ๋ฐœ์ƒ ์‹œ๊ฐ„: 2024๋…„ 6์›” 27์ผ
  • ์ง€์† ์‹œ๊ฐ„: ์•ฝ 1์‹œ๊ฐ„
  • ๊ธฐ์ˆ ์  ์›์ธ: BGP ํ•˜์ด์žฌํ‚น ๋ฐ ๋ผ์šฐํŒ… ์œ ์ถœ

์ด ์‚ฌ๊ฑด์—์„œ๋Š” ๋ธŒ๋ผ์งˆ์˜ ๋„คํŠธ์›Œํฌ ์ œ๊ณต์—…์ฒด์ธ ELETRONET SA(AS267613)๊ฐ€ 1.1.1.1/32 ๊ฒฝ๋กœ๋ฅผ ์ž˜๋ชป ๊ด‘๊ณ ํ•˜์—ฌ, ์ผ๋ถ€ ๋„คํŠธ์›Œํฌ์—์„œ Cloudflare์˜ DNS ๋ฆฌ์กธ๋ฒ„ ์„œ๋น„์Šค์ธ 1.1.1.1์— ๋Œ€ํ•œ ์ ‘์†์ด ๋ถˆ๊ฐ€๋Šฅํ•ด์กŒ์Šต๋‹ˆ๋‹ค. ์ด๋กœ ์ธํ•ด ์•ฝ 70๊ฐœ๊ตญ์˜ 300์—ฌ ๊ฐœ ๋„คํŠธ์›Œํฌ์—์„œ ์‚ฌ์šฉ์ž๋“ค์ด ์˜ํ–ฅ์„ ๋ฐ›์•˜์œผ๋ฉฐ, ์ด๋Š” BGP ํ•˜์ด์žฌํ‚น๊ณผ ๋ผ์šฐํŒ… ์œ ์ถœ์ด ํ˜ผํ•ฉ๋˜์–ด ๋ฐœ์ƒํ•œ ๋ฌธ์ œ์˜€์Šต๋‹ˆ๋‹ค.


9. ์š”์•ฝ ๋ฐ ์˜๊ฒฌ

๋„คํŠธ์›Œํฌ ์—”์ง€๋‹ˆ์–ด๋กœ์„œ BGP๋ฅผ ๋‹ค๋ฃจ๋ฉฐ ๋А๋‚€ ์ ์€, ์ธํ„ฐ๋„ท์˜ ๊ทผ๊ฐ„์„ ์ด๋ฃจ๋Š” ๊ธฐ์ˆ ์ด์ง€๋งŒ ๋ณด์•ˆ ์ธก๋ฉด์—์„œ๋Š” ์—ฌ์ „ํžˆ ์ทจ์•ฝ์ ์ด ๋งŽ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ํŠนํžˆ, BGP ํ•˜์ด์žฌํ‚น ๊ฐ™์€ ๊ณต๊ฒฉ์ด ๊ณ„์†ํ•ด์„œ ๋ฐœ์ƒํ•˜๋Š” ๊ฒƒ์€ ์šฐ๋ฆฌ๊ฐ€ ๋„คํŠธ์›Œํฌ๋ฅผ ๋”์šฑ ๊ฐ•๋ ฅํ•˜๊ฒŒ ๋ณดํ˜ธํ•ด์•ผ ํ•จ์„ ์‹œ์‚ฌํ•ฉ๋‹ˆ๋‹ค. RPKI ๊ฐ™์€ ์ธ์ฆ ๊ธฐ์ˆ ์ด ํ™•์‚ฐ๋˜๊ณ  ์žˆ์ง€๋งŒ, ์—ฌ์ „ํžˆ ๋งŽ์€ ๊ธฐ์—…๊ณผ ISP๊ฐ€ ์ด๋ฅผ ์ ์šฉํ•˜์ง€ ์•Š๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ, BGP๋Š” ์ˆ˜๋™์ ์ธ ์šด์˜์ด ๋งŽ์•„ ๊ด€๋ฆฌ์ž์˜ ์ˆ™๋ จ๋„๊ฐ€ ๋งค์šฐ ์ค‘์š”ํ•˜๋ฉฐ, ์‹ค์ˆ˜ ํ•˜๋‚˜๊ฐ€ ๋Œ€๊ทœ๋ชจ ๋„คํŠธ์›Œํฌ ์žฅ์• ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•ž์œผ๋กœ๋Š” ์ž๋™ํ™”๋œ ๋ณด์•ˆ ์†”๋ฃจ์…˜๊ณผ ์ •์ฑ… ๊ธฐ๋ฐ˜ ๋ผ์šฐํŒ…์ด ๋” ์ค‘์š”ํ•ด์งˆ ๊ฒƒ์ด๋ฉฐ, ์ด์— ๋Œ€๋น„ํ•œ ์ง€์†์ ์ธ ์—ฐ๊ตฌ์™€ ๊ต์œก์ด ํ•„์š”ํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.


Popular posts from this blog

SSL ์ธ์ฆ์„œ๋ž€? ๐Ÿšจ "๋‹น์‹ ์˜ ์›น์‚ฌ์ดํŠธ, ํ•ด์ปค์—๊ฒŒ ๋ฌด๋ฐฉ๋น„ ๋…ธ์ถœ?" SSL ์ธ์ฆ์„œ(certificate) ์—†์œผ๋ฉด ์œ„ํ—˜ํ•ฉ๋‹ˆ๋‹ค! ๐Ÿ”’