Changes

Jump to: navigation, search

Network Infrastructure and Services

3,328 bytes added, 04:36, 6 September 2017
Fuck you; we turned it off
'''NI&S''', previously known as '''Communications Network Services ''' ('''CNS'''), and briefly as ''' Advanced Network Infrastructure and Services''' ('''ANIS''') is a division the ISP of [[Virginia Tech]], and part of the Office [[Division of the Vice President for Information TechnologyIT]], which provides ISP providing services including telephone and Internet to the university. Around 2015, they went through a significant rebranding effort, because of the poor reputation earned by CNS as being "unhelpful, tyrannical network overlords", in the words of a former student. Today, they attempt to exist by their ''Brand Promise'', "Let's explore what's possible together", and ''Brand Character'', "Approachable, Plain Spoken, Collaborative", in order to prevent the need for further rebranding. Several NI&S employees have suggested a more accurate motto would read "F*ck you; we turned it off", in reference to several services essential to the jobs of departmental IT, like rdweb, the "temporary" port 22 block, the L2TP VPN, and several other useful services. Unlike most departments, CNS operates as an auxillary service, and therefore recieves funding through cost-recovery rather than university budgets. Individual departments and students must pay a ''per-port'' charge for each IP or phone device attached to the network.
=== Network Topology ===In Blacksburg, CNS has about 4 Gbps aggregate bandwidth of commodity Internet from its Cogent uplink in the [[Andrews Information Systems Building]], which is fed to campus via redundant fiber connections uplinks to both Burruss Hall and Cassell Colliseum. Owens HallAshburn, Virginia, McLean, Hillcrest HallVirginia, and Shanks Hall also serve as routers for some buildingsAtlanta, Georgia. Additional connections for The [[Network VirginiaMid-Atlantic Broadband Communities Corporation]], provides the OC-192 (10 Gigabit) connections to Ashburn and McLean from the [[National LambaRailAndrews Information Systems Building]], [[Midand the OC-Atlantic Terascale Partnership]], and 192 (10 Gigabit) connection to Atlanta from [[Internet2Hillcrest Hall]] exist at AISB. Nearly all ethernet portals on campus are capable of 100 Mbps or Gigabit speedsIn summer 2015, due the OC-192 connection to fiber interconnects between buildings; however, intrabuilding wiring varies in age and may not support high speeds. The vast majority of campus IPv4s come from two directlyAshburn will be upgraded to OC-allocated blocks 768 (128100 Gigabit).173.0.0<ref>[https://16 and 198www.82vtnews.0vt.0edu/articles/16)2015/04/042115-it-gigabits.html]</ref>
For cost-savings reasons, the university's connectivity is primarily provided through an aggregation network shared by several other universities in Virginia, the [[Mid-Atlantic Research and Education Exchange]] (MREX). MREX, also known as the [[Mid-Atlantic Terascale Partnership]] (MATP)<ref>[https://beta.peeringdb.com/net/4326 PeeringDB: Mid-Atlantic Terascale Partnership - MATP]</ref>, is operated by Virginia Tech and provides connectivity for the [[Mid-Atlantic Research Infrastructure Alliance]] (MARIA), an alliance of the universities that receive connectivity through MREX.<ref>[http://www.marialliance.net/about-us About Maria - Mid-Atlantic Research Infrastructure Alliance]</ref> MREX operates two regional hubs: MREX-ATL, at Telx Atlanta, and MREX-DC, at Equinix Ashburn. At each hub, MREX operates a Cisco ASR9006 aggregation router. There is another MREX facility at Level3 McLean, connected as part of a fiber ring that also includes the [[Arlington Research Center]] and the [[Northern Virginia Center]]. At Equinix in [[Ashburn]], MREX-DC has a 100 Gigabit connection to [[Internet2]], 10 Gigabit connections to [[ESnet]] and the Equinix Internet Exchange, and 30 Gigabits of commodity Internet connectivity through Cogent. Virginia Tech also has a 10 Gigabit connection to [[Mid-Atlantic Crossroads]] and a 1 Gigabit connection to [[NetworkVirginia]] here. At Telx in Atlanta, MREX-ATL has 10 Gigabit connections to [[Southern Crossroads]], [[ESnet]], the Telia Internet Exchange, and 30 Gigabits of commodity Internet connectivity through Telia.<ref>[http://www.cafm.vt.edu/busprac/_docs/bpseminar_2014/2014-BusinessPracticeSeminar-Internet.pdf]</ref> MREX-ATL was opened in 2014 and is the first network facility operated by Virginia Tech located outside of Virginia.<ref>[https://www.vtnews.vt.edu/articles/2014/03/032114-it-datanetworkexchange.html]</ref> At Level3 in McLean, MREX's McLean facility, referred to as the National Capital Region (NatCap) Aggregation Facility, has a 10 Gigabit connection to [[Mid-Atlantic Crossroads]] and a connection to [[NetworkVirginia]].<ref>[http://www.cns.vt.edu/docs/NIS_SubcommitteeMinutes07Dec2009.pdf]</ref> From the Andrews Information Systems Building, there are redundant fiber connections to the main campus at both [[Burruss Hall]] and [[Cassell Colliseum]]. [[Owens Hall]], [[Hillcrest Hall]], and [[Shanks Hall]] have intermediate routers for some buildings. Nearly all ethernet portals on campus are capable of 100 Mbps or Gigabit speeds, due to fiber interconnects between buildings; however, intrabuilding wiring varies in age and may not support high speeds. The vast majority of campus IPv4s come from two directly-allocated blocks (128.173.0.0/16 and 198.82.0.0/16). === IPv6 === CNS is a leader in the transition to IPv6, as their [[w:Autonomous System|ASN]] consistently ranks in the top 5 in terms of percentage of IPv6 traffic, according to [http://www.worldipv6launch.org/measurements/ World IPv6 Launch Measurements]. A dual-stack topology exists for the entirety of campus, with but not all systems connected to the notable exception of network are IPv6-enabled. One system that notably lacks connectivity is the main university vt.edu website, which is due to a lack of support from the load balancers currently in use. HoweverFor legacy reasons, Virginia Tech does not currently have continues to use its own IPv6 block; the addresses used are from a /48 sub-allocated allocation from the [[w:University of Maryland|UMDUniversity of Maryland]]on many subnets, although newer equipment is being configured with the assigned IPv6 block (2607:b400::/32)=== Unified Communications ===
In December 2011, CNS announced that a contract had been awarded to IBM and Avaya for ''Unified Communications'', a project to both replace the aging ROLM phone system with SIP phones and upgrade the network infrastructure in each building. This has also somewhat reduced monthly rates of common telephone and ethernet services for departments. While most buildings will be undergoing upgrades through 2014, it is unknown whether or not each will have full gigabit speeds at actual user ports. It is also unknown whether users will be able to use SIP softphones in conjunction with this.
=== Network Policies ===
Contrary to popular belief, CNS does not actively monitor users for torrenting activity; however, they are obligated to forward DMCA notifications to the relevant parties. Residential users that engage in peer-to-peer filesharing are often throttled (according to policy) if their daily upload average exceeds 4.9 GB. Campus-wide intrusion detection systems are deployed through cooperation with the [[IT Security Lab]].
Port security is enabledon most ports, meaning that users are not permitted to attach a switch to the network and must pay for new connections for all devices. While the $20/month fee for gigabit connectivity is generally thought to be reasonable, many department networks require them to evade this restriction through the use of NAT routing, ARP proxies, and/or NDP proxies. For most public portals, MAC address registration is often required, although some department ports are known to not carry this restriction.
NAT routers are officially banned, largely due to dorm residents bringing their own NAT router, plugging it in backwards, and sending DHCP leases to their entire building. While the ban is generally unenforced unless a problem arises, users are encouraged to purchase additional connections through CNS instead. === Controversies ===
In addition to the network policies stated above, the following controversial activities have arisen:
* CNS has begun deploying [[w:Network Address Translation | NAT]] to dorm buildings, starting with the [[Ambler Johnston HallGraduate Life Center]]<ref>[http://ipv6.cns.vt.edu/ IPv6 at Virginia Tech]</ref>, as it has done in the past with wireless access points. This causes issues for students that need to forward ports for services such as SSH. IPv6 addresses, however, are global. It is unknown whether CNS has applied for additional addresses from ARIN.
* In January 2013, emergency maintenance was done at Virginia Tech's uplink in Ashburn, but users were not informed in advance of the potential downtime. This initially took out VT's edge IPv4 access for several hours, and later resulted in intermittent routing issues at the BGP level until the next morning.
* Like most administrative university offices, CNS is often regarded as having much bureaucracy. For example, the processes for obtaining SSL certificates or a DNS entry directly under "vt.edu" are especially tedious.
* CNS services such as VPN and VT-Wireless (the secure wireless network) require use of MS-CHAPv2, which is proven to be very insecure.<ref>{{cite news| title = Wifi Security| url = https://www.hokieprivacy.org/wifi/| work = Hokie Privacy| accessdate = 7 October 2015}}</ref>  == References ==<references/>
[[Category:Blacksburg ISPs]]
Anonymous user

Navigation menu