Skip to main content
Software Engineering Daily

The Architecture of the Internet with Erik Seidel

51 min episode · 2 min read
·

Episode

51 min

Read time

2 min

Topics

Software Development

AI-Generated Summary

Key Takeaways

  • BGP Route Propagation: Border Gateway Protocol sessions between edge routers exchange IP prefix road maps constantly. Tier one networks see high dynamics as customer changes propagate upward, while small regional networks maintain stable sessions with minimal prefix updates throughout the day.
  • Anycast DDoS Defense: Cloudflare spreads single IP addresses across 10,000+ servers in hundreds of data centers globally. When botnets attack with 100+ terabits per second, traffic naturally disaggregates across locations, reducing each site to absorbable gigabit-level chunks that enable effective filtering without congestion.
  • China Network Architecture: Mainland China requires separate infrastructure partnerships with China Telecom, Unicom, or Mobile due to Great Firewall packet inspection overhead and mandatory local network transit. Cloudflare cannot operate its standard global backbone there, making China an enterprise-only service requiring special contracts.
  • Peering Economics: Tier one networks like AT&T, Telia, and NTT reach the entire Internet without paying anyone through settlement-free peering agreements. Smaller networks buy transit services for full Internet routing tables containing one million IPv4 prefixes, while strategic peering reduces latency and costs.

What It Covers

Erik Seidel from Cloudflare explains Internet architecture fundamentals including BGP routing protocol, peering versus transit relationships, anycast DDoS mitigation, China's unique networking challenges, and how Cloudflare's 300+ global data centers handle millions of requests per second.

Key Questions Answered

  • BGP Route Propagation: Border Gateway Protocol sessions between edge routers exchange IP prefix road maps constantly. Tier one networks see high dynamics as customer changes propagate upward, while small regional networks maintain stable sessions with minimal prefix updates throughout the day.
  • Anycast DDoS Defense: Cloudflare spreads single IP addresses across 10,000+ servers in hundreds of data centers globally. When botnets attack with 100+ terabits per second, traffic naturally disaggregates across locations, reducing each site to absorbable gigabit-level chunks that enable effective filtering without congestion.
  • China Network Architecture: Mainland China requires separate infrastructure partnerships with China Telecom, Unicom, or Mobile due to Great Firewall packet inspection overhead and mandatory local network transit. Cloudflare cannot operate its standard global backbone there, making China an enterprise-only service requiring special contracts.
  • Peering Economics: Tier one networks like AT&T, Telia, and NTT reach the entire Internet without paying anyone through settlement-free peering agreements. Smaller networks buy transit services for full Internet routing tables containing one million IPv4 prefixes, while strategic peering reduces latency and costs.

Notable Moment

Seidel handled 100 terabit per second DDoS attacks without receiving alerts because Cloudflare's anycast architecture automatically distributed the massive traffic across global infrastructure. He only discovered attacks when investigating single congested links, demonstrating how effective geographic distribution neutralizes concentrated botnet assaults.

Know someone who'd find this useful?

You just read a 3-minute summary of a 48-minute episode.

Get Software Engineering Daily summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

More from Software Engineering Daily

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's Software Engineering Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Software Engineering Daily.

Every Monday, we deliver AI summaries of the latest episodes from Software Engineering Daily and 192+ other podcasts. Free for up to 3 shows.

Start My Monday Digest

No credit card · Unsubscribe anytime