Re: Hurricane Electric now supports ASPA for route filtering

2024-09-22 Thread Jeroen Massar via NANOG
> On 22 Sep 2024, at 23:14, Christopher Morrow wrote: > > On Sat, Sep 14, 2024 at 4:18 PM Lancheng via NANOG wrote: >> >> Hi Mike, >> >>> Hurricane Electric now uses ASPA to do hop by hop checking of AS paths >>> when deciding which routes to accept when building prefix filters. >> >>> Her

Out-of-Bailiwick DNS? (Was: HE.net problem)

2024-07-05 Thread Jeroen Massar via NANOG
> On 4 Jul 2024, at 23:22, Paul Ebersman wrote: > > cjc> On the other side of this, we all may be learning the value of not > cjc> having all of you NS records in a single zone with a domain under a > cjc> single registrar. > > From some trainings I did on how to be sure your DNS was robust:

Re: Correcting Netflix ipv6 geolocation

2023-10-19 Thread Jeroen Massar via NANOG
> On 19 Oct 2023, at 02:09, Justin Kilpatrick wrote: > > Our ipv6 subnet 2602::FBAD::/40 is You likely mean 2602:FBAD::/40, as the one above is not a valid IPv6 address ;) BGP wise it seems only 2602:fbad:8::/45 and 2602:fbad:10::/45 are announced as per https://bgp.tools/as/400429#prefixe

Re: Do ISP's collect and analyze traffic of users?

2023-05-16 Thread Jeroen Massar via NANOG
> On 16 May 2023, at 06:46, Matthew Petach wrote: > [..] > I admit, I'm perhaps a little behind on the latest netflow whiz-bangs, > but I've never seen a netflow record type that included HTTP cookies > or PCAP data before. Take your pick from the "latest" ~2009 IPFIX Information Elements:

Re: Gmail (thus Nanog) rejecting ipv6 email

2022-04-02 Thread Jeroen Massar via NANOG
> On 3 Apr 2022, at 00:29, Michael Thomas wrote: > > > On 4/2/22 3:23 PM, Jeroen Massar via NANOG wrote: >> Hi Dan, >> >> Hope the rest of the world is treating you decently! >> >> There are a lot of bits and bobs that one has to get right for mai

Re: Gmail (thus Nanog) rejecting ipv6 email

2022-04-02 Thread Jeroen Massar via NANOG
Hi Dan, Hope the rest of the world is treating you decently! There are a lot of bits and bobs that one has to get right for mail to flow, amongst which: - IP -> PTR lookup -> that hostname lookup, and match to IP again (https://en.wikipedia.org/wiki/Forward-confirmed_reverse_DNS) - SPF -

Re: ASN in use, but no whois data?

2022-02-25 Thread Jeroen Massar via NANOG
> On 20220225, at 23:45, Matt Harris wrote: > > Hey folks, > I'm looking at an ASN 394183 and I can't find any whois or other contact data. First stop for info: bgp.tools! https://bgp.tools/as/394183#whois But yes, as others commented, looks like a ARIN-expired ASN... as long as one pay th

Re: FORT monitoring/visibility

2021-10-27 Thread Jeroen Massar via NANOG
> On 20211027, at 09:26, Lukas Tribus wrote: > > On Wed, 27 Oct 2021 at 08:47, Mark Tinka wrote: >> >> On 10/27/21 01:58, Randy Bush wrote: >>> my old DRL RP instances produce MRTG graphs etc of the CA >>> fetching side, though nothing on the rpki-rtr side. >> >> Randy, I actually have an on

Re: Geolocation accuracy

2021-10-19 Thread Jeroen Massar via NANOG
On 2021-10-19 13:39, Hank Nussbacher wrote: Can anyone recommend a geo-location service with high city accuracy? Maxmind, for most countries (broadband, which does move) is below 50% accuracy (they claim 68% accuracy for USA cities): https://www.maxmind.com/en/geoip2-city-accuracy-comparison?cou

Re: Admin for .tk (not a spam/abuse complaint!)

2021-09-29 Thread Jeroen Massar via NANOG
On 2021-09-29 01:03, Tim Harman via NANOG wrote: [..] {11:58}~ ➭ dig @194.0.41.1 test.tk ; <<>> DiG 9.11.5-P4-5.1+deb10u5-Debian <<>> @194.0.41.1 test.tk ; (1 server found) ;; global options: +cmd ;; connection timed out; no servers could be reached A traceroute with a source IP would be sooo

Re: IPv6 woes - RFC

2021-09-16 Thread Jeroen Massar via NANOG
> On 20210916, at 11:15, John Curran wrote: > > On 14 Sep 2021, at 3:46 AM, Eliot Lear wrote: >> …. >> There is no evidence that any other design choices on the table at the time >> would have gotten us transitioned any faster, and a lot of evidence and >> analysis that the exact opposite i

Re: IPv6 woes - RFC

2021-09-10 Thread Jeroen Massar via NANOG
On 2021-09-10 18:27, Owen DeLong wrote: On Sep 10, 2021, at 01:39 , Jeroen Massar wrote: On 20210909, at 21:55, Owen DeLong via NANOG wrote: [..] Awful lot of red spots even in the top 100. Hell, even amazon.com isn't IPv6 yet. And the long tail is going to be the death of a thousand

Re: IPv6 woes - RFC

2021-09-10 Thread Jeroen Massar via NANOG
> On 20210909, at 21:55, Owen DeLong via NANOG wrote: >> [..] >> Awful lot of red spots even in the top 100. Hell, even amazon.com >> isn't IPv6 yet. And the long tail is going to be the death of a thousand >> cuts for the call center unless you have a way to deal with those sites. > > This

Re: IPv6 woes - RFC

2021-09-04 Thread Jeroen Massar via NANOG
On 2021-09-04 23:02, Ryan Hamel wrote: Jeroen, > You people keep on giving money to ISPs that are not providing the service you want. Not everyone has the luxury of picking their ISP, But this list is NANOG Network Operators. We are the ISPs and the common consumer doesn't know o

Re: IPv6 woes - RFC

2021-09-04 Thread Jeroen Massar via NANOG
> On 20210904, at 22:26, Grant Taylor via NANOG wrote: > > Hi, > > Does anyone have any recommendation for a viable IPv6 tunnel broker / > provider in the U.S.A. /other/ /than/ Hurricane Electric? SixXS shut down 4 years ago, to get ISPs to move their butts... as long as there are tunnels,

Re: The great Netflix vpn debacle! (geofeeds)

2021-08-31 Thread Jeroen Massar via NANOG
On 2021-09-01 01:13, Owen DeLong via NANOG wrote: You just broke 99% of the smart television sets in people’s homes, unfortunately. If only everybody would not get a separate box, be that a AppleTV, a Playstation, a XBox, Chromecast, ... or many other options. Fun part being that it is hard

Re: What is your preferred outage tracking service? (Hurricane Ida)

2021-08-29 Thread Jeroen Massar via NANOG
On 2021-08-29 23:29, Sean Donelan wrote: Netblocks is reporting connectivity in New Orleans LA is at 72% of normal as Hurricane Ida makes landfall. https://twitter.com/netblocks/status/1432038858460442625 There are per-incident things, like the outages mailing list and downdetector.com.  And

Re: DANE of SMTP Survey

2021-06-02 Thread Jeroen Massar via NANOG
[ The kicker about DNSSEC is in the dnsviz links, enjoy ;) TLDR: As long as the very big providers don't demand DNSSEC / DANE, why bother as a small network (just, be prepared to deploy when it starts affecting spam scoring or your search rankings), but small networks do benefit unlike the la

Re: DANE of SMTP Survey

2021-06-02 Thread Jeroen Massar via NANOG
On 2021-06-02 15:47, Bjørn Mork wrote: Jeroen Massar via NANOG writes: For many organisations DNSSEC is 'scary' and a burden as it feels 'fragile' for them. For "many"? Can you name one that doesn't feel like that? Large organisations with 24/7 NOC te

Re: DANE of SMTP Survey

2021-06-02 Thread Jeroen Massar via NANOG
> On 20210601, at 15:15, Moritz Müller via NANOG wrote: > > Hi, > > DANE for SMTP is not deployed on large scale. Together with researchers from > Seoul National University, Virginia Tech and the University of Twente, we > would like to understand which challenges operators face when deploy