Core, Backbone & Internet Edge
Design and operation of the routing core, MPLS backbone, and internet edge — from IGP and BGP architecture through transit blend, IXP peering, content caches, and clean IP resource origination.
The core is where an ISP earns — or quietly loses — its margin and its reputation.
- BGP
- OSPF
- MPLS
- VPRN
- VPLS
- MPLS-TE
- Segment Routing
- RPKI
- IPv6
- IXP Peering
- DPI
02 — The Challenge
The Core Fails Differently
Access networks get the attention because customers can see them. The core fails differently: quietly, expensively, and usually in ways that were designed in years earlier — a flat IGP that no longer converges cleanly, an iBGP mesh nobody dares touch, upstream contracts renewed out of habit rather than measurement, and prefixes announced with no ROAs behind them.
For most African ISPs, upstream capacity is one of the largest recurring costs on the books, and the routing core is the machine that decides how efficiently that money is spent. A core that hauls local traffic through Europe, or that cannot fail over without a human on the console at 3 a.m., is not a technical inconvenience — it is a standing tax on the business.
Our work makes the core boring, in the best sense: predictable convergence, contained failure domains, and an edge that sends every bit over the cheapest sane path.
03 — Core Design
Core & Backbone Engineering
Routing architecture that stays stable under growth, maintenance, and failure
Routing Protocol Architecture
- OSPF area design and IGP stability under growth
- iBGP design: full mesh vs route reflectors
- eBGP policy: communities, local-preference, MED discipline
- Prefix filtering and maximum-prefix protection
- Convergence tuning and graceful restart behavior
MPLS Service Core
- LDP vs RSVP-TE design considerations
- VPRN (L3VPN) design for multi-tenant separation
- VPLS and L2VPN for enterprise and wholesale services
- MPLS-TE for deterministic paths over constrained backhaul
- LSP monitoring and service assurance
Segment Routing Awareness
- SR-MPLS migration paths from LDP cores
- TI-LFA fast reroute without RSVP-TE state
- SRv6 evaluation for greenfield and IPv6-forward cores
- Honest assessment of when SR pays off — and when steady-state LDP is fine
IP Addressing & VLAN Segmentation
- Addressing plans that survive growth and acquisitions
- VLAN segmentation across core, backhaul, and distribution
- Management-plane isolation from customer traffic
- Loopback and infrastructure numbering discipline
- CGNAT placement and public-address conservation
Failure Domains & Failover
- Blast-radius containment by design, not by luck
- Dual-homing, ECMP, and deterministic failover paths
- BFD tuning for sub-second detection
- Control-plane protection and policing
- Maintenance windows that do not become outages
QoS & Traffic Engineering
- Class-of-service models across contended backhaul
- Queueing and drop policy aligned to real traffic mix
- Traffic steering across unequal upstream links
- DPI-informed capacity and policy decisions
A core designed around failure domains degrades gracefully; a core designed around diagrams degrades in production.
The cheapest bit an ISP delivers is the one that never leaves the country.
05 — Internet Edge
Internet Edge & Upstream Strategy
Transit is a bill. Peering and caching are engineering decisions that shrink it.
Transit Blend Design
Upstream strategy is a portfolio problem: blending transit providers, cable systems, and routes so that no single failure — commercial or physical — strands your customers. We planned the IP and systems infrastructure that put SEACOM and TEAMS submarine capacity to work at KDN, with Level 3 (London) and PCCW (Singapore) transit behind it, as the network grew from roughly 60 Mbps to over 3 Gbps of IP transit in 18 months. The 2Africa/Equiano era multiplies the options; the discipline of blending them is unchanged.
Peering & IXP Presence
Every session at an exchange is traffic you stop paying transit for — and latency you stop imposing on customers. We coordinated peering at KIXP, JINX (South Africa), and LINX (UK), cutting transit costs and latency, and we help ISPs build the route policy, capacity, and commercial case for exchange presence today, when Africa’s IXP fabric is finally dense enough to make peering the first lever rather than the last.
Content Caches
Caches turn your heaviest traffic sources into local traffic. We were the technical lead for the first Google Global Cache node in East & Central Africa — a KDN, TESPOK/KIXP, and Google collaboration serving the Kenyan exchange with transit onward to Uganda and Rwanda. The same playbook now applies across Google, Netflix, Meta, and CDN caches: qualify, host, route, and measure them properly, or watch them underperform.
DPI & Traffic Intelligence
You cannot engineer an edge you have not measured. We deployed DPI-based bandwidth monitoring (Allot SG Sigma) to see the real traffic mix behind the interface counters — which applications drive peak load, what caching would actually offload, and where policy beats capacity. Buying upstream without this visibility is guessing with the largest line item in your budget.
06 — IP Resources
IP Resource Strategy & Route Hygiene
Addresses and ASNs are business assets — acquired deliberately, originated cleanly, and defended cryptographically
AfriNIC Resource Acquisition
- AfriNIC membership and resource justification
- IPv4 strategy post-exhaustion: allocations, transfers, leasing trade-offs
- ASN acquisition and multihoming readiness
- IPv6 block sizing and application
Clean Origination
- IRR route objects before the first announcement
- ROAs published before prefixes go live
- Geolocation correction and reputation checks on acquired space
- Blocklist remediation for transferred blocks
RPKI & IRR Hygiene
- ROA coverage for every originated prefix
- Route-origin validation enforced at the edge
- Customer prefix filtering built from IRR data
- Max-prefix and AS-path safeguards on every session
IPv6 Deployment
- Dual-stack core as the default starting point
- IPv6 addressing architecture and customer assignment plans
- Reducing CGNAT cost and state through native v6
- Staff readiness — grounded in AfriNIC IPv6 training
In 2026, a prefix without a ROA is a prefix waiting to be filtered — or hijacked.
07 — Track Record
Where This Experience Comes From
This page describes work we have actually done — at Kenya Data Networks (now Liquid) during the years fibre first landed in East Africa, and for DSI in the DRC through HCS since 2019.
- Technical lead for the first Google Global Cache node in East & Central Africa (KDN + TESPOK/KIXP + Google)
- Planned IP and systems infrastructure for SEACOM and TEAMS submarine capacity, with Level 3 and PCCW transit
- Coordinated peering at KIXP, JINX, and LINX — cutting transit costs and latency
- Grew IP transit from roughly 60 Mbps to over 3 Gbps in 18 months
- Migrated the UN agency headquarters at Gigiri, over 80% of embassies, and all major Kenyan banks from satellite to fibre
- Deployed DPI-based bandwidth monitoring (Allot SG Sigma)
- Acquired and originated public IPv4 and an ASN from AfriNIC for DSI, with VLAN segmentation and security hardening across core, backhaul, and distribution
- R&D grounding in VPRN, VPLS, and MPLS-TE; AfriNIC IPv6 trained (Ghana, 2011); Alcatel-Lucent Advanced IP Networks Convergence; Cisco CCNA
The tools have changed since; the engineering judgment is what transfers.
Route hygiene stopped being optional this decade: with AfriNIC members now publishing ROAs by the thousands and major transit networks dropping RPKI-invalid announcements, unsigned prefixes are the ones that get filtered or hijacked first. The economics keep moving toward the exchange — NAPAfrica past 6 Tbps, Nigeria's IXPN doubling to 2 Tbps in a year, hyperscaler caches answering from Lagos and Nairobi instead of Europe — while IPv4 at roughly $20 per address makes transfers, leasing, and serious IPv6 deployment one financial conversation rather than three. Segment routing is real in carrier cores (SR-MPLS first, SRv6 mostly greenfield), but for most African ISPs the honest sequencing is still: clean BGP, ROAs everywhere, peer locally, cache locally — then modernise the underlay.
Review Your Core, Edge, and Upstream Strategy
Start with a focused assessment of your routing architecture, transit blend, and route hygiene — or study the reference architecture this page is built on.