IPv6 first hop security on a budget?

2017-05-05 Thread Joel Whitehouse
What's a good budget option for switching a small lab or office ipv6 with RA Guard, DHCP6 snooping, and ICMP6 snooping?

RE: Ingress filtering from an external cloud service to the internal network

2017-05-05 Thread Torres, Matt
NANOG, Thank you all. I have more than enough research to do now to further learn about everyone’s suggestions. ~Matt >But if you at least had the freedom to put something like this: > >http://www.sproute.com/span > >in place or 20 other similar solutions. As in you do VPN, but right from the >c

RE: Question about experiences with BGP remote-AS

2017-05-05 Thread Tony Wicks
JunOS has three different modes for Virtual routers depending on your situation requirements. I would suggest that something in the QFX or ACX range will be able to replicate what you are after. Otherwise the entry level MX will certainly do the job for a little more outlay. -Original Message

Re: Question about experiences with BGP remote-AS

2017-05-05 Thread Radu-Adrian Feurdean
On Fri, May 5, 2017, at 18:55, LF OD wrote: > of our existing ASNs and peerings. As it turns out, there are many > routers that can do VRFs but you cannot put a unique ASN on each VRF so > replicating the old environment isn't quite that straightforward. The BGP > remote-as looks to be a possible

Re: Question about experiences with BGP remote-AS

2017-05-05 Thread Tyler Conrad
Neighbor x.x.x.x local-as {whateverasn} no-prepend replace-as On Friday, May 5, 2017, LF OD wrote: > We have a number of small routers in co-lo sites that peer with B2B > partners. As more of our partners move to cloud, we are considering a > consolidation effort and putting all of our peering

Weekly Routing Table Report

2017-05-05 Thread Routing Analysis Role Account
This is an automated weekly mailing describing the state of the Internet Routing Table as seen from APNIC's router in Japan. The posting is sent to APOPS, NANOG, AfNOG, AusNOG, SANOG, PacNOG, MENOG, SAFNOG, SdNOG, BJNOG, CaribNOG and the RIPE Routing WG. Daily listings are sent to bgp-st...@lists

Re: Need recommendation on an affordable internet edge router

2017-05-05 Thread Bryan Holloway
+1 on the 7280R We just started deploying them on our edges for peering and port-density. Great little box. ... and their A-Care support has been good and responsive. On 5/4/17 7:55 PM, Tyler Conrad wrote: I use the 7280R in production. Love it. Pros: Cheap, fantastic API, can take (curren

Question about experiences with BGP remote-AS

2017-05-05 Thread LF OD
We have a number of small routers in co-lo sites that peer with B2B partners. As more of our partners move to cloud, we are considering a consolidation effort and putting all of our peering routers in a cloud exchange site on a single HA pair of routers. Now, each existing B2B peering router us

Re: Ingress filtering from an external cloud service to the internal network

2017-05-05 Thread Yan Filyurin
I just read an article about these people. They are even more interesting than Illumio or these other VPN solutions. The important part is that you get to stitch tunnels together on some other host, so the changing IP of endpoints is irrelevant. http://zentera.net/ On Fri, May 5, 2017 at 11:13

Re: Ingress filtering from an external cloud service to the internal network

2017-05-05 Thread Yan Filyurin
Since you can't change the design you may not be able to put some kind of overlay solution in place, which is just a fancy way of saying a VPN solution. What if you look at it in a different way and put some kind of endpoint security cloud solution like Illumio. But if you at least had the freedo

RE: Ingress filtering from an external cloud service to the internal network

2017-05-05 Thread Torres, Matt
According to my application guy, this is true of the Microsoft O365 hybrid solution. It requires direct inbound connections on various ports from largely undefined IP space. I imagine the private VPN limitation (i.e., not having a VPN) is on our side and MS provides something like this... >Bett

Re: Ingress filtering from an external cloud service to the internal network

2017-05-05 Thread George William Herbert
You can usually run OpenVPN from a cloud host. The source IP changing possibly should require only one open exception to the local VPN termination point. Better, find a cloud that doesn't do that shit with changing endpoints and gives you real VPNs. What sort of cloud doesn't these days?...?...

Static IP allocation schemes for end users (commercial)

2017-05-05 Thread Graham Johnston
I work for a cable MSO, meaning that our access network is DOCSIS based. 15 years ago when we had way more IP addresses than customers we had a static IP allocation scheme wherein we aligned a /24 with each node and reserved the first 20 or so IPs for static assignment, the rest being left for d

Re: Retarus (AS 48328)

2017-05-05 Thread Martin Hannigan
I heard from the team at Retarus. They were responsive. Much appreciated. Thanks all. On Fri, May 5, 2017 at 08:41 Patrick Schultz wrote: > Hi Martin, > the only address I can point you at is "support at retarus dot com". > We once had to contact them about a SMTP problem and this was the only

TCP over fragmented IPv6 dropped in Comcast's network

2017-05-05 Thread Clint Armstrong
In troubleshooting why a DNS zone transfer fails over IPv6 from a DNS master hosted on a Comcast connection, I've discovered that a router in Comcast's network is IPv6 Fragments with TCP headers. More specifically it appears that this router silently drops any packet with a non-zero fragment offse

Re: Retarus (AS 48328)

2017-05-05 Thread Patrick Schultz
Hi Martin, the only address I can point you at is "support at retarus dot com". We once had to contact them about a SMTP problem and this was the only working contact. Best, Patrick Am 04.05.17 um 06:31 schrieb Martin Hannigan: > I hate to do this, but I have exhausted _all of my sources of data

RE: Ingress filtering from an external cloud service to the internal network

2017-05-05 Thread Torres, Matt
Unfortunately, a private connection or VPN to the cloud service provider is not available right now, but I can see how that could help solve my problem. :-) ~Matt > Is it possible for you to get a private/direct connect service from your > network perimeter to the cloud provider and eliminate us