Current Location: Blog >
Singapore CN2
1. project preparation and requirement confirmation
- clarify the requirements: public network or dedicated line access (ipsec/direct connect/mpls);- determine traffic direction, bandwidth, sla, redundancy (two links or two cloud vendors);
- prepare information: customer as number, reserved ip segment, public and private network mapping, cloud vpc/vnet id and subnet.
2. network topology design
- draw a logic diagram: cn2 export -> operator switch/peering -> cloud side router/gateway;- decide on bgp or static routing: it is recommended to use bgp ebgp with as number across clouds for route propagation and fault recovery;
- design subnet/vrf partitions, routing policies, acls and nat boundaries.
3. physical and link preparation
- confirm the delivery point with singtel: pop computer room, port type, mtu, link label;- if ipsec is used, prepare the public network egress ip and ike parameters (ikev2/psk or certificate);
- if using direct connect/mpls, confirm vlan/vci, l2/l3 delivery information.
4. cloud-side gateway and router configuration (taking common clouds as an example)
- in aws: create vgw/transit gateway and associate vpc, configure vpn connection or direct connect;- in azure: create expressroute or vpn gateway and configure the connection; in gcp: create cloud router and configure bgp;
- configure local-cloud mtu consistency (recommend 1500 or confirm according to cn2 link)
5. specific steps for establishing bgp peering (example)
- confirm the as numbers and peer ip of both parties; create a bgp session on the cloud side and fill in the local as, peer as, and peer ip;- configure keepalive/holdtime (commonly used for 60/180) and enable multipath (ecmp) if necessary;
- check bgp neighbor status: show ip bgp summary / cloud console status.
6. routing strategies and filters
- apply prefix filtering on inbound: allow customer prefixes, block bogon and excessively long prefixes;- outbound application route-map/community modifies med/localpref to control route preferences;
- set blacklists and whitelists for cross-cloud traffic down to the subnet level.
7. security and encryption (key points of ipsec implementation)
- ike parameters: ikev2, encryption aes-gcm/chacha20, dh group selection (14 or higher);- subnet-level security group/nsg releases bgp port (tcp 179) and necessary service ports;
- rotate psk regularly or use certificates, enable log auditing.
8. multi-cloud routing synchronization and traffic engineering
- synchronize routing policies using centralized routing control (such as sd-wan or cloud transit);- use bgp community and localpref to distribute traffic between different clouds;
- for critical services, use the cn2 priority link, and for non-critical services, use the public internet or backup link.
9. testing and verification steps
- verify that the bgp neighbor is established and the routing table is visible (show ip route/bgp/cloud console);- perform ping/traceroute to the target cloud resource and record delay and packet loss;
- do bandwidth testing (iperf3) and observe queues and packet loss under high concurrency.
10. monitoring, alarming and operation and maintenance
- deploy traffic monitoring (netflow/sflow/cloud monitoring) and set threshold alarms;- monitor bgp status, packet loss, delay, queue length, and regularly execute link health check scripts;
- establish a change management process to record each routing/policy change.
11. common faults and troubleshooting steps
- bgp is not established: check whether the access-list/firewall blocks tcp179 and confirm that the as number/ip is correct;- route failure: check route propagation, nat rules, mtu, and vrf isolation issues;
- performance issues: check link congestion, qos settings, and packet loss occurrence points.
12. question: what necessary information is needed to access cn2?
- answer: you must provide the customer's public/private network ip, customer as number, expected bandwidth, business priority, cloud-side vpc/vnet id and available subnets, etc.; and confirm the delivery point, mtu, vlan number or vpn parameters with singtel.13. question: how to ensure that traffic between multiple clouds goes through cn2 instead of the public network?
- answer: in the routing policy, add localpref to the cn2 prefix or use the bgp community tag, combine the sd-wan/transit gateway to centrally deliver the policy, and prioritize the bgp path established through cn2 on the cloud side.14. question: what are some quick suggestions for common performance optimizations after deployment?
- answer: adjust mtu to avoid fragmentation, enable multi-path ecmp, use med/localpref in bgp to optimize paths, do qos based on business classification, and monitor link delay and packet loss for regular adjustments.
- Latest articles
- Optimization Strategy For Combining Vps Server Access To The United States And Local Cdn In Overseas Site Deployment
- Performance Cases For Media And Streaming Platforms Using Vietnamese Cn2 Servers
- How To Change The Name Of The Taiwan Server In The Control Panel With Detailed Step-by-step Instructions
- Actual Test Shows How Much Faster Hong Kong’s Cn2 Line Can Be Delay Evaluation
- Description Of Legal Compliance And Responsibility Boundaries Involved In Us High-defense Server Q&a Questions
- How To Deploy A High-availability Architecture On Tk Malaysia Vps To Reduce The Risk Of Downtime
- From A Technical Perspective, We Will Explain Which Vps In Hong Kong Is Reliable And Compare Bandwidth And Protection.
- Safe Backup Vietnam Vps Rental Data Backup Strategy And Practical Experience In Disaster Recovery Drills
- Amazon Japan Site Clearance Group Logistics And Warehousing Options To Save Costs
- Protection Test Report Of Hong Kong High-defense Server Ruiyi In Gaming And E-commerce Scenarios
- Popular tags
Cheapest
Line Selection
Scalability
Network
Vps Trial Service
Malaysia CN2
Second-hand Servers
Server Solution Comparison
Current Development Status
Malaysia Server Registration
Malaysian Tianlong Server
Performance
Server Price
High-speed Network
Malaysia Wechat Server
Local Cloud
Cloud Server
Multi-machine Room Layout
Trends In Network Development
Virtual Host
Ddos Protection
Online Demand
Use Value
Delivery
Vps Comparison
Home Broadband
Line Optimization
Malaysia Cn2gia
Cn2 Connection
Malaysia Cloud Server Purchase Encrypted Backup Compliance Pdpakmsluksaes-256 Backup Policy
Related Articles
-
Comparative Study On Network Latency Of Hong Kong And Singapore Cn2
this article conducts an in-depth comparison of the cn2 network delays in hong kong and singapore, and analyzes the technical differences between the two places in terms of servers, vps, and hosts. -
How To Choose A Reliable CN2 Acceleration Service Provider In Singapore Within A Limited Budget
How to evaluate and choose a suitable Singapore-based CN2 acceleration service provider when budget is limited? This article focuses on five common issues and provides practical evaluation criteria, cost control methods, technical alternatives, as well as testing and operational recommendations, to help you achieve the best value for your money within a limited budget. -
Comparison Of Cn2 Lines Between Alibaba Cloud Singapore And Hong Kong
this article compares alibaba cloud singapore and hong kong cn2 lines in detail to help users choose the best and cheapest server.