Re: A survey on BGP MRAI timer values in practice

2021-06-08 Thread Saku Ytti
On Wed, 9 Jun 2021 at 01:18, Adam Thompson wrote: If your work results in actionable recommendations such as "don't use BGP > out-delay timers to mitigate XYZ in circumstance LMNO, do ABC instead", > that's fantastic. Please keep us advised, and do post aggregated survey > results here once you

Re: BCP38 on public-facing Ubuntu servers

2021-06-08 Thread Stephen Satchell
On 6/8/21 2:38 PM, Fran via NANOG wrote: Hey, to my knowledge there is no IPv6 equivalent for net.ipv4.conf.all.rp_filter. Therefore I use netfilter to do the RP filtering for both address families. ip(6)tables -t raw -I PREROUTING -m rpfilter --invert -j DROP Using the raw tables less reso

Re: BCP38 on public-facing Ubuntu servers

2021-06-08 Thread Fran via NANOG
Hey, to my knowledge there is no IPv6 equivalent for net.ipv4.conf.all.rp_filter. Therefore I use netfilter to do the RP filtering for both address families. ip(6)tables -t raw -I PREROUTING -m rpfilter --invert -j DROP Using the raw tables less resources are used, but you could also cho

Re: A survey on BGP MRAI timer values in practice

2021-06-08 Thread Adam Thompson
+1 to Saku's concerns - I simply ignored the survey because I wasn't sure what MRAI was, and I wasn't sure what my values would be. But I have time to be interested right now, so a-spelunking I go... The term "MRAI" does not appear anywhere in Arista's or Extreme's documentation. Nor does thi

Spoofer Report for NANOG for May 2021

2021-06-08 Thread CAIDA Spoofer Project
In response to feedback from operational security communities, CAIDA's source address validation measurement project (https://spoofer.caida.org) is automatically generating monthly reports of ASes originating prefixes in BGP for systems from which we received packets with a spoofed source address.

Re: Fastly CDN down globally?

2021-06-08 Thread Robert Webb
Fix has already been applied. Might take some time for things to get back to normal since this was a global outage. On Tue, Jun 8, 2021, 8:24 AM Tony McCrory wrote: > Affected for example:- > > theguardian.co.uk > nytimes.com > fastly.com > > All return 503 Service Unavailable from Varnish Cache

Re: Fastly CDN Down?

2021-06-08 Thread Karl Auer
On Tue, 2021-06-08 at 18:11 +0800, Jason Cooper via NANOG wrote: > I just got an email from my CI alert that says registry.terraform.io > is experiencing HTTP 503. > And not just terraform, repo.maven.apache.org/maven2 also seems down. > Even with their own website: fastly.com > Is there anyone at

Fastly CDN down globally?

2021-06-08 Thread Tony McCrory
Affected for example:- theguardian.co.uk nytimes.com fastly.com All return 503 Service Unavailable from Varnish Cache Tony

Fastly CDN Down?

2021-06-08 Thread Jason Cooper via NANOG
I just got an email from my CI alert that says registry.terraform.io is experiencing HTTP 503. And not just terraform, repo.maven.apache.org/maven2 also seems down. Even with their own website: fastly.com Is there anyone at Fastly? -- Jason

Re: DANE of SMTP Survey

2021-06-08 Thread Mark Tinka
On 6/3/21 23:41, babydr DBA James W. Laferriere wrote: The Signing of the 'Zone' ,  Can the 'Zone' be signed by a self-signed key ?  Or MUST I (and others) rely on a external certificate authority ? Mind you I notice in rfc6487 (note(s)) about self-signed certificates . So M