Strange Traffic on IXPs: An Admin's Observations
The author, operating one of the largest IXP networks on the internet, uses bgp.tools to monitor and reveal a surprising amount of unexpected traffic on IXPs. This includes various routing protocols (OSPF, IS-IS, RIP), auto-addressing protocols (DHCP, IPv6 RA), and vendor-specific protocols (LLDP, CDP, MNDP), all posing security risks like information disclosure and traffic hijacking, even causing outages. The author also highlights bizarre traffic like home networking protocols (UPnP), printer discovery protocols (MDNS), and erroneous broadcast DNS queries stemming from misconfigurations. The author calls for increased traffic monitoring and access controls on IXPs to enhance network security.
Read more