Re: Am I the only one who thinks this is disconcerting?

2023-11-08 Thread Mark Andrews
The other thing it could be is broken PMTUD / failure fragment at network MTU. We defined socket options to do this 2 decades ago. -- Mark Andrews > On 9 Nov 2023, at 06:00, Matthew Pounsett wrote: > > On Wed, Nov 8, 2023 at 2:12 AM Bryan Fields wrote: >> >> >> Could these be related

Re: Am I the only one who thinks this is disconcerting?

2023-11-08 Thread Matthew Pounsett
On Wed, Nov 8, 2023 at 2:12 AM Bryan Fields wrote: > > > Could these be related to the fact that dnsvis.net is trying to reach these > servers via IPv6 and I think they use Hurricane for transit. Since HE and > Cogent is a major gap, this causes them to time out trying to reach the C root > serve

Re: AS8003 mysteries

2023-11-08 Thread Christopher Morrow
On Wed, Nov 8, 2023 at 4:51 PM Dave Taht wrote: > > Anyone have an update as to where this effort, announcing qute a bit > of usa government space, stands? > they stopped their internet telescope project? > https://www.kentik.com/blog/the-mystery-of-as8003/ > -- > Oct 30: https://netdevconf.info

Re: Am I the only one who thinks this is disconcerting?

2023-11-08 Thread Bryan Fields
On 11/8/23 2:25 PM, o...@delong.com wrote: Seems irresponsible to me that a root-server (or other critical DNS provider) would engage in a peering war to the exclusion of workable DNS. I've brought this up before and the root servers are not really an IANA function IIRC. There's not much gov

AS8003 mysteries

2023-11-08 Thread Dave Taht
Anyone have an update as to where this effort, announcing qute a bit of usa government space, stands? https://www.kentik.com/blog/the-mystery-of-as8003/ -- Oct 30: https://netdevconf.info/0x17/news/the-maestro-and-the-music-bof.html Dave Täht CSO, LibreQos

Re: Am I the only one who thinks this is disconcerting?

2023-11-08 Thread owen--- via NANOG
> On Nov 7, 2023, at 23:09, Bryan Fields wrote: > > On 11/8/23 1:29 AM, Owen DeLong via NANOG wrote: >> https://dnsviz.net/d/10.159.192.in-addr.arpa/dnssec/ >> Seems to report a bunch of errors in the DS records for 192.in-addr.arpa >> held in the in-addr.arpa zone. >> I figured I’d wait a fe

Spoofer Report for NANOG for Oct 2023

2023-11-08 Thread CAIDA Spoofer Project
In response to feedback from operational security communities, CAIDA's source address validation measurement project (https://spoofer.caida.org) is automatically generating monthly reports of ASes originating prefixes in BGP for systems from which we received packets with a spoofed source address.