Connect at least two Anapaya COREs to your backbone and establish IP connectivity between them.
Elevate your ISP services with Anapaya CORE
Designed for ISPs, Anapaya CORE delivers a high-performance, carrier-grade routing solution that enhances security, resilience, and performance. Empower your network to leverage SCION's advanced architecture and offer customers a superior, uninterrupted internet experience.
Accelerated deployment
Anapaya CORE seamlessly integrates with existing intra-domain networks, ensuring a swift transition to SCION capabilities without the overhaul. It's compatible with standard x86 COTS servers, bypassing the financial burden of specialized hardware. With just a few border routers, your network is SCION-ready, streamlining the deployment process.
Flexible operations
Upgrade your capacity according to your needs whenever you like and ensure your network remains efficient and responsive. End-users gain the ability to effortlessly modify their network configurations, promoting optimal data flow and connectivity without the complexity traditionally associated with network adjustments.
Monetization opportunities
Anapaya CORE enables the implementation of sophisticated traffic policies and performance metrics, allowing you to provide bespoke optimizations as premium services. Coupled with expert remote management and support, Anapaya CORE enhances your service portfolio and opens new avenues for revenue generation.
Trusted by industry leaders
Getting started with CORE
Service providers need to install Anapaya COREs to connect to the SCION network. Anapaya CORE services are strategically placed within your physical or virtual data centers, which connect at designated interconnection points with other SCIONabled providers.
Configuration guide
1
Network integration
2
Connect to the SCION-Internet
Peer your COREs with other SCION-enabled providers, via a SCION-abled IXP or a SCION transit provider.
3
End-customer access
Ensure your access network can connect end-customers' locations to your COREs.
CORE-AS-A-SERVICE
Fast-track your network with CORE-as-a-Service
CORE-as-a-Service allows service providers to outsource day-to-day network operations to our specialists while you train your team up to take over. That enables you to implement and offer SCION Internet within your packages without the need for any downtime. Once you are ready to start taking over, you can define which management aspects you would like to take over and which you want to leave with the Anapaya team.
Included in CORE managed services:
- CORE software: Get the complete CORE software package, including critical border routers and core services.
- Initial setup: We handle the full rollout of your infrastructure, from software to optional hardware.
- Expert management: Benefit from our team's remote management, including monitoring, configuration, updates, and troubleshooting, ensuring your network runs smoothly.
We’re revolutionizing the Internet with SCION
Seamless, secure, and uninterrupted, blending public Internet accessibility with private network security for end users.
Controlled data exchange
Customize your network paths with precision, avoiding specific regions and ensuring compliance with regulatory standards.
Secure networking
Defend against routing attacks and secure your network from DDoS threats using concealed paths and source authentication.
Optimal connections
Enhance performance by instantly redirecting data through multiple paths, eliminating downtime and boosting efficiency.
Cloud connectivity
Ensure seamless connections to cloud service providers without the constraints of dedicated leased lines
How does SCION Internet transform connectivity?
Today's Internet relies on a decades-old border gateway protocol, not built for the speed, reliability, and security modern organizations demand. Businesses require a solution that's application-aware, simple to manage, robust, and secure to ensure seamless business continuity.
Frequently Asked Questions
ESSENTIAL
How can I join SCION?
There are three main ways to join SCION:
- SSFN, follow this process
- HVR, follow this process
- Swiss ISD, follow this process
What is Anapaya EDGE?
Anapaya EDGE is the gateway that connects users to the SCION Internet. The Anapaya EDGE is installed physically or in a virtual environment at the edge of a customer’s network. The Anapaya EDGE is connected to the SCION network through a SCIONabled ISP. Through Anapaya’s IP-in-SCION tunneling mechanism, the EDGE can tunnel IP traffic from the customer’s LAN and communicate with remote destinations through the SCION network.
For information on Anapaya EDGEs and common setups, please refer to Overview and Deployment Examples.
What is Anapaya CORE?
Anapaya CORE is a router that is part of the SCION backbone. It is placed at the border of the network of Internet Service Providers and connects to other SCIONabled ISPs and customers.
For information on Anapaya COREs and common setups, please refer to Overview and Deployment Example.
What is Anapaya GATE?
Anapaya GATE is the gateway that connects end-users to the SCION Internet. It allows users of SCIONabled ISPs to connect to remote locations, such as a company’s headquarter network using the SCION Internet even if the user does not have an EDGE at home. It is located at the edge of SCIONabled ISPs and advertises the ISP user prefixes to SCIONabled organizations and vice versa. This solution protects remote access, e.g., VPN connections, and access to other workloads by an organization’s remote workforce.
For information on Anapaya GATEs and common setups, please refer to Overview and Deployment Example.
PROTECTION AGAINST DDoS ATTACKS
Scenario 1
There are a few different scenarios in which Anapaya appliances and SCION can protect against DDoS attacks.
Scenario 1: The attacker is not part of the SCION network and tries to attack the target through the public Internet. The target uses prefixes that are not routed in the public Internet, but only in the SCION network.
Protection: Since the target’s prefix range is not accessible through the public Internet, the target is basically “invisible” to the attacker. In other words, the attacker cannot carry out the attack as it has no way of reaching the target’s network.
Scenario 2
There are a few different scenarios in which Anapaya appliances and SCION can protect against DDoS attacks.
Scenario 2: The attacker is not part of the SCION network and tries to attack the target through the public Internet. The target uses prefixes that are routed through the public and the SCION Internet.
Protection: The attacker can reach the target’s network only through the public Internet. This means that users connecting through the public Internet to the target can suffer from availability problems of the service in case of an attack. However, users connecting through the SCION network use a different entry point to the service which will remain unaffected.
Scenario 3
There are a few different scenarios in which Anapaya appliances and SCION can protect against DDoS attacks.
Scenario 3: The attacker is part of the SCION network.
Protection: In this case, the user needs to resort to other defense mechanisms such as SCION Hidden Paths. With Hidden Paths, an organization can control which other SCION ASes can retrieve SCION paths leading to the organization’s network. That way, the organization is in control of which entities can send it traffic.
To learn more about the possibilities of using SCION Hidden Paths for additional DDoS protection within a SCION network, please contact customer-support@anapaya.net.
Scenario 4
There are a few different scenarios in which Anapaya appliances and SCION can protect against DDoS attacks.
Scenario 4: The attacker has a target and due to the network topology, there are other organizations affected as collateral damage (e.g. an ISP is under attack).
Protection: If the organizations affected by the attack as collateral damage are part of the SCION network, traffic will automatically be rerouted to avoid congested areas under attack. This is one of the benefits of the SCION protocol, as path selection depends on static data, such as the user-defined policies, and real-time performance data, such as latency and jitter. In other words, in case of an attack on an ISP, paths through that ISP will be de-prioritized due to their bad performance.
SET-UP
On what kind of platform can I run the Anapaya software?
The Anapaya software can run both on physical hardware and virtual environments. For details on computing requirements, please refer to our Computing resources guide.
How can an Anapaya EDGE connect to a SCIONabled provider?
The recommended way to connect to a SCIONabled provider is through the ISP’s access network. Please contact your SCIONabled access provider for further details.
How can an Anapaya appliance be connected to the internal network of an organization?
An Anapaya appliance can connect to the internal network of the organization it belongs to through a variety of connection types. Specifically, supported setups include static routing, eBGP, VRRP (in case of redundant setups). For more information, refer to Deployment Examples and Deployment Example.
What is the difference between MTU and SCION MTU?
Due to the fact that every SCION packet uses an IP/UDP underlay, a SCION packet has an overhead of 24 bytes for IPv4 and 48 bytes for IPv6. For this reason, the SCION protocol defines the SCION MTU which is equal to the difference of the underlay MTU minus the overhead bytes. This means that effectively slightly fewer bytes can be communicated through a single SCION packet compared to a non-SCION packet. Note also that the size of the payload additionally depends on the length of the chosen SCION path since the latter is included in the packet’s SCION header.
COMPARISON
Why is the GATE solution secure and preferable to using a normal VPN connection?
Security has three aspects: Confidentiality, Integrity and Availability (CIA). Current VPN solutions can provide confidentiality and integrity as they encrypt traffic and perform integrity checks. However, they cannot guarantee availability because traffic is still routed through the public Internet. The Anapaya GATE solution guarantees availability by hiding the VPN connection from the Internet. In other words, the combination of VPN and the Anapaya GATE can provide full CIA security.
Another aspect in which the Anapaya GATE fortifies the system is routing security. As VPN traffic goes through the public Internet, it is susceptible to BGP hijacking attacks. With the Anapaya GATE solution, traffic goes from an ISP’s internal network to the SCION network and vice versa, which offers BGP hijack resilience by design.
For further information, you can also refer to the How to protect company data while working from home and VPN connections need protection blog posts.
How can I communicate with entities in ISDs my organization is not part of and I do not have trust?
For a host within an AS to be able and get paths to a remote ISD, it needs to have the valid Trust Root Configuration (TRC) for that ISD (and the ISDs it needs to traverse until it reaches the destination). The TRC of an ISD defines the trusted entities within an ISD, such as the core ASes and the Certificate Authorities. Based on this, the ASes can then fetch the necessary information to validate the received paths.
What happens if a link fails along the path that a packet is being forwarded through?
If there is a link failure along a path in use, the router that detects the link failure sends a SCION Control Message Protocol (SCMP) message to the sender, stating the location of the link failure.
Once the sender receives the SCMP packet, it will immediately switch to a path that is functioning.
For further information on how SCMP works, please refer to the official SCION SCMP documentation.
Partner with Anapaya
Our team of experts is ready to help you become
SCIONabled. Fill in the form and
elevate your network to the next level.