RE: YouTube Video Streaming

2012-05-18 Thread Leigh Porter
time and could not be bothered to look into it at the time and kind of put it down to one of those things that will be fixed later. So I'd be really interested in what the outcome is! -- Leigh Porter __ This email has been

RE: CDNs should pay eyeball networks, too.

2012-05-02 Thread Leigh Porter
> I (in the UK) had the same letter from LLNW yesterday, word for word. Me too. > However I must say that the wording of their letter is appalling Agreed. > I am glad they are spending ton of money to upgrade their > infrastructure.. but so am I. Slightly odd though that they are upgrading t

Re: Operation Ghost Click

2012-04-26 Thread Leigh Porter
On 26 Apr 2012, at 22:47, "Andrew Latham" mailto:lath...@gmail.com>> wrote: On Thu, Apr 26, 2012 at 5:38 PM, Jeroen van Aart mailto:jer...@mompl.net>> wrote: Yes its a major problem for the users unknowingly infected. To them it will look like their Internet connection is down. Expect ISPs t

Re: Securing OOB

2012-04-23 Thread Leigh Porter
I have juniper SRX110s that use the magic new multi site IPSec thing. -- Leigh Porter On 23 Apr 2012, at 13:43, "Eric" wrote: > Hello, > > It seems that the current practice is to use a DSL line, as opposed to a > modem, for accessing an OOB a console server at

RE: Communal Dining

2012-04-16 Thread Leigh Porter
Is this going to be like when teenagers advertise their parties on facebook? > -Original Message- > From: Ronald Bonica [mailto:rbon...@juniper.net] > Sent: 16 April 2012 15:09 > To: frbi...@aol.com; Nicholas Hinko; Susan Hinko; jay cuasay; William > Richey; Will Ress; maria torres; landr

Re: Cheap Juniper Gear for Lab

2012-04-11 Thread Leigh Porter
w mode stuff had its issues, but as a *small* MPLS box it is very functional. Of course in MPLS mode, you turn the flow stuff off.. -- Leigh Porter __ This email has been scanned by the Symantec Email Security.cloud service. For more information please visit http://www.symanteccloud.com __

Re: Cheap Juniper Gear for Lab

2012-04-10 Thread Leigh Porter
On 11 Apr 2012, at 02:34, "Owen DeLong" wrote:. > >> Don't let the "mpls" keyword throw you off. This actually causes the >> box to run the inet /and/ mpls address families in packet mode. >> > > I'm not unfamiliar or uninitiated in this regard. I had tickets with Juniper > for > over a year

April fools joke?

2012-04-01 Thread Leigh Porter
http://www.bbc.co.uk/news/uk-politics-17576745 It's sad when you just can't tell with things like this.. -- Leigh __ This email has been scanned by the Symantec Email Security.cloud service. For more information please visit

Re: Outdoor Wireless Access Point

2012-04-01 Thread Leigh Porter
On 31 Mar 2012, at 23:51, "Network IP Dog" mailto:network.ip...@gmail.com>> wrote: Hi...How do I do it! I'm utterly amazed how many people give away free consultant work. We need to keep people working... not giving it away. Ethics... Security... etc... Does the university give away free dip

RE: OWA blocked by China

2012-03-27 Thread Leigh Porter
Are there any issues with general https there also? -- Leigh > -Original Message- > From: Lyle Giese [mailto:l...@lcrcomputer.net] > Sent: 27 March 2012 15:39 > To: nanog@nanog.org > Subject: Re: OWA blocked by China > > On 03/27/12 09:16, Jim Gonzalez wrote: > > Hello, > > > >

RE: $1.5 billion: The cost of cutting London-Tokyo latency by 60ms

2012-03-23 Thread Leigh Porter
> -Original Message- > From: Vitkovsky, Adam [mailto:avitkov...@emea.att.com] > Sent: 23 March 2012 12:57 > To: Aled Morris; Eugen Leitl > Cc: NANOG list > Subject: RE: $1.5 billion: The cost of cutting London-Tokyo latency by > 60ms > > That is why there's this neutrinos project It's no

RE: Shim6, was: Re: filtering /48 is going to be necessary

2012-03-14 Thread Leigh Porter
> -Original Message- > From: valdis.kletni...@vt.edu [mailto:valdis.kletni...@vt.edu] > > The only reason you got HDMI at all was because the content owners > managed to get HDCP included. You won't get a replacement that doesn't > do HDCP until we fix the sorry state of copyright in th

Re: shared address space... a reality!

2012-03-13 Thread Leigh Porter
On 14 Mar 2012, at 06:31, "Joel jaeggli" wrote: > On 3/13/12 23:22 , Christopher Morrow wrote: >> NetRange: 100.64.0.0 - 100.127.255.255 >> CIDR: 100.64.0.0/10 >> OriginAS: >> NetName:SHARED-ADDRESS-SPACE-RFCTBD-IANA-RESERVED > > Already updated my martians acl and deplo

RE: Shim6, was: Re: filtering /48 is going to be necessary

2012-03-12 Thread Leigh Porter
> > Grass-roots, bottom-up policy process > + > Need for multihoming > + > Got tired of waiting > = > IPv6 PI > > -r A perfect summation. Also given that people understand what PI space is and how it works and indeed it does pretty much just work for the end

RE: Huawei edge routers..

2012-03-07 Thread Leigh Porter
> -Original Message- > From: Jay Ashworth [mailto:j...@baylink.com] > Sent: 07 March 2012 15:28 > To: NANOG > Subject: Re: Huawei edge routers.. > > - Original Message - > > From: "Saku Ytti" > > > On (2012-03-07 09:46 -), Tim Franklin wrote: > > > This does occasionally br

Re: Huawei edge routers..

2012-03-07 Thread Leigh Porter
On 7 Mar 2012, at 09:48, "Tim Franklin" wrote: >> On the other hand, if you hop into other people's Huawei >> routers via CLI you will curse and scream. As close as I >> could tell, it handles most functionality of IOS, but >> they tried to find a synonym for every word cisco used >> in the cli.

L3 VPN Management

2012-03-06 Thread Leigh Porter
Folks, I have a number of L3 MPLS VPNs. For example, there is the WiFi management VPN (WiFi management interface). There is th systems VPN where things like RADIUS servers, Databases talk. There is a VPN for LTE OAM. There are alsomseparate VPNs for other LTE functions. All OK. Then are var

Huawei edge routers..

2012-03-06 Thread Leigh Porter
HI All, Has anybody had any experience of Huawei Mobile/Metro edge routers? I'm looking for something that will handle various MPLS services (Layer 2/3), QinQ with about 10x1Gb Ethernet interfaces (no need for 10G). How are they compared to JNPR/CSCO/etc equivalent ? Thanks, Leigh Port

RE: Falling for address collection (Was: Evil Bit and Spread Spectrum IP Addressing - NANOG Source Address Shaping)

2012-03-05 Thread Leigh Porter
ause they died last year, but still, who knows.. -- Leigh Porter > -Original Message- > From: Jason Hellenthal [mailto:jhellent...@dataix.net] > Sent: 05 March 2012 03:27 > To: nanog@nanog.org > Subject: Falling for address collection (Was: Evil Bit and Spread > Sp

Re: NANOG Operational TTL Alert for 160-bit Headers (aka IPv4)

2012-03-03 Thread Leigh Porter
so they can use it to control people ready for the new world order. It was all predicted by Nostradamus. Innit. -- Leigh Porter On 3 Mar 2012, at 23:27, "Robert Glover" wrote: > Someone get this man a Xanax! > > -Original message- > From: Guru NANOG > To

RE: Reliable Cloud host ?

2012-02-27 Thread Leigh Porter
> -Original Message- > From: Tony Patti [mailto:t...@swalter.com] > Sent: 27 February 2012 02:42 > To: 'david raistrick'; 'Randy Carpenter' > Cc: 'Nanog' > Subject: RE: Reliable Cloud host ? > > > -Original Message- > > From: david raistrick [mailto:dr...@icantclick.org] > > Sent:

RE: HP A6600 experiences

2012-02-24 Thread Leigh Porter
I thought the A6604 was EOL? http://h17007.www1.hp.com/docs/products/eos/Select_HP_A6600_Routers_and_Modules_ES_Announcement.pdf -- Leigh > -Original Message- > From: Christopher Pilkington [mailto:c...@0x1.net] > Sent: 24 February 2012 19:05 > To: NANOG mailing list > Subject: HP A66

Re: Most energy efficient (home) setup

2012-02-22 Thread Leigh Porter
On 22 Feb 2012, at 22:40, "Jeroen van Aart" wrote: > Leigh Porter wrote: >> You dudes need to get with the times and put all this stuff in the cloud. >> Ok so I joke a little.. > > The "cloud" seems to be a more modern implementation of the mainf

Re: Most energy efficient (home) setup

2012-02-22 Thread Leigh Porter
some VMs and it works fine. Less to mess around with and prob cheaper too. The only thing I keep at home now is storage. -- Leigh Porter __ This email has been scanned by the Symantec Email Security.cloud service. For more information please visit http://www.symanteccloud.com __

RE: Customer Notification System.

2012-02-22 Thread Leigh Porter
> -Original Message- > From: Rich Kulawiec [mailto:r...@gsp.org] > Sent: 22 February 2012 11:04 > To: nanog@nanog.org > Subject: Re: Customer Notification System. > > On Tue, Feb 21, 2012 at 05:58:19PM -0500, James Wininger wrote: > > We would need to send notifications out to say about

Re: WW: Colo Vending Machine

2012-02-18 Thread Leigh Porter
On 18 Feb 2012, at 01:46, "Owen DeLong" wrote: > I have, on occasion been away from my laptop and gotten the call to go to the > colo and deal with XYZ hardware problem and the colo was either: A in the > opposite or orthogonal direction from my house and significantly closer or B > the colo

Re: Colo Vending Machine

2012-02-17 Thread Leigh Porter
On 17 Feb 2012, at 20:18, "Randy Bush" wrote: > i just want to pay a compliment to the fibercloud colo in the seattle > westin. there are crash carts, a tool-chest, rack screws, other screws, > garbage cans, ... and, if you are polite, they'll loan you usbs, blank > cds, ... and, as remote ha

Re: WW: Colo Vending Machine

2012-02-17 Thread Leigh Porter
On 17 Feb 2012, at 20:10, "Peter Kristolaitis" wrote: > On 12-02-17 03:05 PM, Leigh Porter wrote: >> Did anybody say beer yet? >> > > Don't forget the 30lb sledgehammer for those times when, ah, "percussive > maintenance" is the only possib

Re: WW: Colo Vending Machine

2012-02-17 Thread Leigh Porter
Did anybody say beer yet? -- Leigh On 17 Feb 2012, at 18:37, "Jay Ashworth" wrote: > Please post your top 3 favorite components/parts you'd like to see in a > vending machine at your colo; please be as specific as possible; don't > let vendor specificity scare you off. > > Cheers, > -- jra

Re: WW: Colo Vending Machine

2012-02-17 Thread Leigh Porter
On 17 Feb 2012, at 18:37, "Jay Ashworth" wrote: > Please post your top 3 favorite components/parts you'd like to see in a > vending machine at your colo; please be as specific as possible; don't > let vendor specificity scare you off. Pizza, condoms and headache tablets. -- Leigh

Re: Spam from Telx

2012-02-17 Thread Leigh Porter
No he didnt. The one he sent to me actually included part of the thread he picked me up from. I told him the most exciting thing he could do is to not spam me again. Poor guy, did nobody tell him? -- Leigh Porter On 17 Feb 2012, at 15:11, "Justin M. Streiner" wrote: > On Fri

Re: Common operational misconceptions

2012-02-16 Thread Leigh Porter
On 15 Feb 2012, at 20:50, "John Kristoff" wrote: > Hi friends, > > As some of you may know, I occasionally teach networking to college > students and I frequently encounter misconceptions about some aspect > of networking that can take a fair amount of effort to correct. > > For instance, a to

RE: Sonicwall 3500/netflow

2012-02-14 Thread Leigh Porter
ith no problems thus far. As for the CLI, yes it > is CLUNKY. > > But they are completely revamping it, it will be very similar to Cisco > in the near future... Why do people like to base their CLIs on the really rather awful Cisco style interface rather than something with some mo

RE: 10G switchrecommendaton

2012-02-09 Thread Leigh Porter
> -Original Message- > From: Brent Jones [mailto:br...@brentrjones.com] > Sent: 27 January 2012 06:33 > To: Rodrick Brown > Cc: nanog list > Subject: Re: 10G switchrecommendaton > > On Thu, Jan 26, 2012 at 8:40 PM, Rodrick Brown > wrote: > > > Not to mention Arista's cli runs a busybox

RE: Firewalls in service provider environments

2012-02-07 Thread Leigh Porter
y be quite important for another. Whilst filtering port 25 outbound may help prevent some bots from emanating spam, it certainly does a lot to annoy other people. -- Leigh Porter __ This email has been scanned by the Symante

RE: Optimal IPv6 router

2012-02-06 Thread Leigh Porter
he description. And where half the useful features just don't support IPv6. Make it support draft-ietf-mpls-ldp-ipv6 and we're away :) -- Leigh Porter __ This email has been scanned by the Symantec Email Security.cloud service. For more information please visit http://www.symanteccloud.com __

Re: Thanks & Let's Prevent this in the Future.

2012-02-01 Thread Leigh Porter
On 1 Feb 2012, at 09:01, "Kelvin Williams" wrote: > > A few months ago, when establishing a new peering relationship I was > encouraged (actually required) to utilize one of the IRRs. I took the time > to register all of my routes, ASNs, etc. However, as I learned today, this > was probably d

Re: Console Server Recommendation

2012-01-30 Thread Leigh Porter
On 30 Jan 2012, at 18:41, "Brent Jones" wrote: > Another +1 to Opengear > Just buy the units that have the pinout for your devices, or you may need > adapters. And making them gets boring very quickly! -- Leigh __ This email

Re: Console Server Recommendation

2012-01-30 Thread Leigh Porter
On 30 Jan 2012, at 16:10, "Ray Soucy" wrote: > What are people using for console servers these days? We've > historically used retired routers with ASYNC ports, but it's time for > an upgrade. > > OpenGear seems to have some nice stuff, anyone else? > +1 for OpenGear. I asked this same quest

Re: 10G switchrecommendaton

2012-01-27 Thread Leigh Porter
On 27 Jan 2012, at 10:21, "Fabien Delmotte" wrote: > I worked for Extreme, and I deployed a lot of X650 (24 10G ports) for > DataCenter environment. The box is really good. > In fact if you use the box at a layer 2 it is perfect, BUT DON'T use their > BGP code, they never understood what is BG

Re: 10G switchrecommendaton

2012-01-26 Thread Leigh Porter
Let's see how many vendors you get listed! I would go for Brocade. -- Leigh Porter On 26 Jan 2012, at 20:24, "Deric Kwok" wrote: > Hi all > > I would like to have 10G switchrecommendaton > Ipref software can test around 9.2G but we can have congestion over 6G &

RE: juniper mx80 vs cisco asr 1000

2012-01-19 Thread Leigh Porter
it looks like a capable box. You would do well to look at the MX80 fixed chassis, it comes with 48 1G interfaces and 4 10G interfaces. They are pretty good value, I think. -- Leigh Porter __ This email has been scanned by t

RE: RIS raw data

2012-01-19 Thread Leigh Porter
> -Original Message- > From: Peter Kristolaitis [mailto:alte...@alter3d.ca] > Sent: 19 January 2012 16:04 > To: nanog@nanog.org > Subject: Re: RIS raw data > > On 12-01-19 10:46 AM, valdis.kletni...@vt.edu wrote: > > On Thu, 19 Jan 2012 21:52:52 +0900, Randy Bush said: > > > >> uselessne

RE: DNS Attacks

2012-01-18 Thread Leigh Porter
Yeah like I say, it wasn't my idea to put DNS behind firewalls. As long as it is not *my* firewalls I really don't care what they do ;-) -- Leigh Porter > -Original Message- > From: Dennis [mailto:den...@justipit.com] > Sent: 18 January 2012 12:55 > To: Leigh Po

Re: DNS Attacks

2012-01-17 Thread Leigh Porter
the firewall as it is rather under specified (not my idea..). It did originate from Chinese address space and consisted of DNS queries for lots of hosts. There was also a port-scan in the traffic and a SYN attack on a few hosts on the same small subnet as the DNS, a web server and an

Re: enterprise 802.11

2012-01-15 Thread Leigh Porter
I use ruckus in town and city installs and despite rather a lot of other APs it performs very well. I don't have experience of them in high connected station density though. -- Leigh Porter On 15 Jan 2012, at 19:33, "Ken King" wrote: > I need to choose a wireless solutio

Re: Whois 172/12

2012-01-15 Thread Leigh Porter
On 15 Jan 2012, at 07:39, "Ted Fischer" wrote: > Hi all, > > Tearing what's left of my hair out. > > A customer is getting scanned by a host claiming to be "172.0.1.216". > > I know this is bogus, but I want to go back to the customer with as > much authoritative umph as I can (heaven f

Re: VPC=S/MLT?

2012-01-13 Thread Leigh Porter
as shown >> up 8 years late and is trying to hype it up to compensate? > > vpc/vlt/mlag/s/mlt > I am using the Brocade version, Multi Chassis Trunking (MCT), and it really does make things a lot nicer. -- Leigh Porter ___

Re: anycast load balancing issue

2012-01-06 Thread Leigh Porter
On 6 Jan 2012, at 07:33, "Måns Nilsson" wrote: > > Thanks all who made me think a second round and solve this. Hence why people prefer to ask people and not GOOG et-al. -- Leigh Porter __ This email has

Re: OSS Systems

2012-01-05 Thread Leigh Porter
was to build our own mail system. Not that it was an issue, it never went wrong, but these days I'd just send people to gmail or something. -- Leigh Porter __ This email has been scanned by the Symantec Email Security.

DC wiring standards

2012-01-03 Thread Leigh Porter
Hi all, Does anybody know where I can find standards for DC cabling for -48v systems? I'm looking for general best common practices, cable colouring etc. Thanks, -- Leigh Porter __ This email has been scanned b

Re: Ethernet From China to Singapor or Hong Kong ?

2012-01-02 Thread Leigh Porter
I'd second PCCW. I have contacts there if you drop me a mail off list. -- Leigh Porter UKBroadband PCCW... On 2 Jan 2012, at 14:08, "Paul Rolland" wrote: > Hello, > > On Mon, 2 Jan 2012 14:30:47 +0100 > Olivier CALVANO wrote: > >> anyone have contac

Re: Speed Test Results

2011-12-23 Thread Leigh Porter
They are completely unreliable and not to be trusted except for an occasional general indication of speed. -- Leigh Porter On 23 Dec 2011, at 09:20, "jacob miller" wrote: > Hi, > > Am having a debate on the results of speed tests sites. > > Am interested i

Re: Recognized Address Transfer Facilitators (was: Your Christmas Bonus Has Arrived)

2011-12-14 Thread Leigh Porter
I love the anti v6 stuff on some of their sites! http://www.iptrading.com/news/news.htm -- Leigh On 14 Dec 2011, at 12:21, "John Curran" wrote: > On Dec 14, 2011, at 12:40 AM, Patrick W. Gilmore wrote: > >> I believe this company is the one that sold the MS & Borders blocks, so they >> ma

RE: Your Christmas Bonus Has Arrived

2011-12-13 Thread Leigh Porter
> -Original Message- > From: Chaim Rieger [mailto:chaim.rie...@gmail.com] > Sent: 14 December 2011 06:10 > To: IPv4 Brokers; nanog@nanog.org > Subject: Re: Your Christmas Bonus Has Arrived > > What do you have for those that don't do the whole Jesus thing ? > That would be Hell.. --

RE: Sad IPv4 story?

2011-12-12 Thread Leigh Porter
> -Original Message- > From: Vitkovsky, Adam [mailto:avitkov...@emea.att.com] > Sent: 12 December 2011 09:19 > To: Eric Parsonage; valdis.kletni...@vt.edu > Cc: nanog@nanog.org > Subject: RE: Sad IPv4 story? > > > and models that doesn't take "we may not get IPv4 space" into account > and

RE: On Working Remotely

2011-12-04 Thread Leigh Porter
This pretty much says it all, I think: http://www.youtube.com/watch?v=co_DNpTMKXk -- Leigh > -Original Message- > From: Keegan Holley [mailto:keegan.hol...@sungard.com] > Sent: 04 December 2011 18:50 > To: Jay Ashworth > Cc: NANOG > Subject: Re: On Working Remotely > > Maybe I have a d

RE: IP addresses are now assets

2011-12-02 Thread Leigh Porter
> -Original Message- > From: Justin M. Streiner [mailto:strei...@cluebyfour.org] > Sent: 02 December 2011 19:26 > To: Leo Bicknell > Cc: NANOG > Subject: Re: IP addresses are now assets > > On Fri, 2 Dec 2011, Leo Bicknell wrote: > > > In a message written on Thu, Dec 01, 2011 at 11:04:

RE: IP addresses are now assets

2011-12-02 Thread Leigh Porter
or requiring the space within the next 12 months BEFORE they part with their cash. It would be most amusing for somebody to buy space, hand over the money and then have ARIN deny the transfer. So I do wonder, how is this policy is being enforced and will ARIN be investigating

RE: Looking for a Tier 1 ISP Mentor for career advice.

2011-12-02 Thread Leigh Porter
> -Original Message- > From: Thorsten Dahm [mailto:t.d...@resolution.de] > Sent: 02 December 2011 12:28 > To: nanog@nanog.org > Subject: Re: Looking for a Tier 1 ISP Mentor for career advice. > > Am 12/1/11 9:35 PM, schrieb David Radcliffe: > > Since I like to work and code (I spend 10 hou

RE: Looking for a Tier 1 ISP Mentor for career advice.

2011-12-01 Thread Leigh Porter
> -Original Message- > From: Leo Bicknell [mailto:bickn...@ufp.org] > Sent: 01 December 2011 16:15 > To: nanog@nanog.org > Subject: Re: Looking for a Tier 1 ISP Mentor for career advice. > It's a wonderful double edged sword. Someone who can think their way > out of a myriad of technic

RE: Looking for a Tier 1 ISP Mentor for career advice.

2011-12-01 Thread Leigh Porter
I am looking for just such a person now. Good Juniper, some Cisco and Sysadmin experience with an ISP background.. I expect it will be immensely difficult to find somebody. What makes it even more frustrating is that just such a person was not all that long ago made redundant! So if anybody is

RE: Odd router brokenness

2011-11-23 Thread Leigh Porter
> -Original Message- > From: Mark Radabaugh [mailto:m...@amplex.net] > Sent: 23 November 2011 16:53 > To: NANOG list > Subject: Re: Odd router brokenness > > On 11/23/11 11:33 AM, Saku Ytti wrote: > > On (2011-11-23 09:41 -0500), Mark Radabaugh wrote: > > > >> The question is: How does

Re: Any recommended router. They are reliable and have good support.

2011-11-22 Thread Leigh Porter
wireless and much more. > thank you > > ----- Original Message - From: "Leigh Porter" > > To: > Cc: "nanog list" > Sent: Tuesday, November 22, 2011 6:02 PM > Subject: Re: Any recommended router. They are reliable and have good support. > > > Has a

Re: Any recommended router. They are reliable and have good support.

2011-11-22 Thread Leigh Porter
Has anybody had experience of mikrotik support? Is it any good? Any thoughts about the time to fix bugs? -- Leigh On 22 Nov 2011, at 15:57, "Faisal Imtiaz" wrote: > mikrotik family .. you can have all sizes and shapes of routers .. > lots of support available online or from independent consu

Re: Any recommended router. They are reliable and have good support.

2011-11-22 Thread Leigh Porter
Brocade have some reasonable boxes. -- Leigh Porter On 22 Nov 2011, at 15:40, "Deric Kwok" wrote: > Hi > > Can I know any selection of Linux routers except cisco / juniper? > > They are reliable and have good support provided > > We would like to get

Re: First real-world SCADA attack in US

2011-11-21 Thread Leigh Porter
On 21 Nov 2011, at 20:23, "Ryan Pavely" wrote: > Might I suggest using 127.0.0.2 if you want less spam :P > > Pretty scary that folks have > 1. Their scada gear on public networks, not behind vpns and firewalls. Do people really do that? Just dump a /24 of routable space on a network and use

Re: First real-world SCADA attack in US

2011-11-21 Thread Leigh Porter
I checked the SCADA boxes used in our "smart" building. They are all using 127.0.0.1 Is that a security risk? -- Leigh Porter On 21 Nov 2011, at 19:20, "Arturo Servin" wrote: > >I wonder if they are using private IP addresses. > > -as > > On 21

RE: Have they stopped teaching Defense in Depth?

2011-11-16 Thread Leigh Porter
> -Original Message- > From: Jay Ashworth [mailto:j...@baylink.com] > Sent: 16 November 2011 13:38 > To: NANOG > Subject: Re: Have they stopped teaching Defense in Depth? > > - Original Message - > > From: "Jimmy Hess" > > > Or, the attack is against a legitimate user's outboun

Re: Arguing against using public IP space

2011-11-15 Thread Leigh Porter
edu] > Sent: Tuesday, November 15, 2011 9:17 AM > To: Leigh Porter > Cc: nanog@nanog.org; McCall, Gabriel > Subject: Re: Arguing against using public IP space > >> And this is totally overlooking the fact that the vast majority of > *actual* attacks these days are web-based drive-b

Re: Arguing against using public IP space

2011-11-15 Thread Leigh Porter
On 15 Nov 2011, at 15:36, "Owen DeLong" wrote: > > On Nov 15, 2011, at 2:57 AM, Leigh Porter wrote: > >> >> >> On 14 Nov 2011, at 18:52, "McCall, Gabriel" >> wrote: >> >>> Chuck, you're right that this should n

Re: Arguing against using public IP space

2011-11-15 Thread Leigh Porter
On 14 Nov 2011, at 18:52, "McCall, Gabriel" wrote: > Chuck, you're right that this should not happen- but the reason it should not > happen is because you have a properly functioning stateful firewall, not > because you're using NAT. If your firewall is working properly, then having > publi

Re: Arguing against using public IP space

2011-11-13 Thread Leigh Porter
I was involved in a security review of a SCADA system a couple of years ago. Their guy was very impressed with himself and his "Internet air-gap" but managed to leave all their ops consoles on both the SCADA network and their internal corp LAN. Their corp LAN was a mess with holes through their

Re: where was my white knight....

2011-11-08 Thread Leigh Porter
would expect a high incidence of change to trigger something sensible to mitigate this kind of craziness from happening. I am sure enough people have had incorrectly scaled RADIUS farms blow up when a load of DSLAMS vanish and come back again not to repeat such storms. -- Leigh Porter

Re: where was my white knight....

2011-11-08 Thread Leigh Porter
On 8 Nov 2011, at 18:24, "Dobbins, Roland" wrote: > > On Nov 9, 2011, at 1:14 AM, wrote: > >> that was/is kindof orthoginal to the question... would the sidr plan for >> routing security have been a help in this event? > > SIDR is intended to provide route-origination validation - it isn't

Re: XO blocking individual IP's

2011-11-08 Thread Leigh Porter
So if you want to launch a DoS attack against a specific IP address you spoof TCP3389 SYNs to networks single homed to XO and they will null it for you. -- Leigh On 8 Nov 2011, at 04:36, "Blake T. Pfankuch" wrote: > Oh yes! Good lord I about went insane with this. I was working with a > c

Re: TATA problems?

2011-11-07 Thread Leigh Porter
Any thoughts on just how wide read this was? Did every Juniper that receives Internet BGP updates with the affected software break? Or did it die out quite quickly? -- Leigh On 7 Nov 2011, at 19:55, "John van Oppen" wrote: > We saw several customers go away this morning as well. Our netwo

Re: General Internet Instability

2011-11-07 Thread Leigh Porter
On 7 Nov 2011, at 16:41, "Todd Snyder" wrote: > On Mon, Nov 7, 2011 at 11:27 AM, Richard Golodner < > rgolod...@infratection.com> wrote: > >> On Mon, 2011-11-07 at 11:09 -0500, Todd Snyder wrote: >>> Can anyone point to any authoritative updates about this? >> >>I think Jared's sugges

Re: TATA problems?

2011-11-07 Thread Leigh Porter
My 10.4r1.9 boxes died also but I saw interfaces go down whilst bgpd seemed stable. -- Leigh On 7 Nov 2011, at 15:34, "Pierre-Yves Maunier" wrote: > 2011/11/7 Tom Hill > >> On Mon, 2011-11-07 at 10:00 -0500, Todd Snyder wrote: >>> We seem to be having some problems with our tata links -

Re: Performance Issues - PTR Records

2011-11-07 Thread Leigh Porter
On 7 Nov 2011, at 14:03, "Bjørn Mork" wrote: > Leigh Porter writes: > >> Indeed, there is no way I would allow that either. But really, >> providing a reverse zone and forward zone to match is a case of five >> minutes and a shell script or a DNS that a

Re: Performance Issues - PTR Records

2011-11-07 Thread Leigh Porter
e is no way I would allow that either. But really, providing a reverse zone and forward zone to match is a case of five minutes and a shell script or a DNS that as Steinar said, will synthesise results. It's really not all that difficult.. -- Leigh Porter __

RE: IPv6 beta support for Android phones

2011-11-07 Thread Leigh Porter
s > once for 5 to 10+ year life ...) > Most networks seem to dish out address space behind a LSN box these days. I have three dongle things from three networks in the UK, none of them give me a public address. -- Leigh Porter ___

RE: Hands and Eyes for London and Amsterdam

2011-10-31 Thread Leigh Porter
For London: http://www.netsumo.com/ -- Leigh Porter > -Original Message- > From: Mike Rae [mailto:mike@sjrb.ca] > Sent: 31 October 2011 16:26 > To: nanog@nanog.org > Subject: Hands and Eyes for London and Amsterdam > > Hi : > > Looking for some recomm

Re: Recommendation for customer monitoring network tool/portal for a large ISP

2011-10-27 Thread Leigh Porter
I looked at Statseeker a while back and it was very good. -- Leigh On 27 Oct 2011, at 09:47, "Alex Nderitu" wrote: > Hello, > What solutions do you guys in the fixed network business/ISPs use to provide > customer portals for network KPI reporting to customers in a fixed network on > real

Re: Outgoing SMTP Servers

2011-10-26 Thread Leigh Porter
servers and we can set them a bespoke profile for rate limiting and message size etc etc. That worked rather well because people's email got out and SPAM was largely stopped. The Ironports were darn good boxes if a little pricey, -- Leigh Porter __ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email __

Re: Outgoing SMTP Servers

2011-10-26 Thread Leigh Porter
On 25 Oct 2011, at 09:34, "Tim" wrote: > This sadly is very common. It is getting more common by the day it seems but > this practice has started almost a decade ago. > > An easy work around is to use a custom port as they seem to just block port > 25 as a bad port but leave just about everythin

RE: [outages] News item: Blackberry services down worldwide

2011-10-14 Thread Leigh Porter
> -Original Message- > From: Nikolay Shopik [mailto:sho...@inblock.ru] > Sent: 14 October 2011 10:17 > To: nanog@nanog.org > Subject: Re: [outages] News item: Blackberry services down worldwide > > On 13/10/11 19:56, Jared Mauch wrote: > > Rebuilding this trust can take some time. I do

RE: [outages] News item: Blackberry services down worldwide

2011-10-12 Thread Leigh Porter
> -Original Message- > From: D. Marshall Lemcoe Jr. [mailto:fo...@lemcoe.com] > Sent: 12 October 2011 18:01 > Cc: nanog@nanog.org > Subject: Re: [outages] News item: Blackberry services down worldwide > > Haven't received an e-mail on my Blackberry since around 4AM, located > in Atlanta.

RE: [outages] News item: Blackberry services down worldwide, Egypt affected (not N.A.)

2011-10-12 Thread Leigh Porter
s just that I haven't personally seen a full > blown failure like that without human help. You have not seen VIP2-40s and CEF in action ;-) -- Leigh Porter __ This email has been scanned by the MessageLabs Email Sec

Re: passive bandwidth estimation

2011-10-05 Thread Leigh Porter
I used a passive TCP RTT calculator and TCP re-trans monitor to guess the conditions to a host or group of hosts with some success. I the. Derived the network "weather" from this and it worked pretty well to dynamically tune DPI box policing for wireless networks. It also makes cool graphs. Esp

Re: events

2011-10-04 Thread Leigh Porter
8pussy.org ? -- Leigh Porter On 4 Oct 2011, at 10:59, "Ben Roeder" wrote: > Hi Mike, > We have used octopussy ( http://www.8pussy.org/dokuwiki/doku.php?id=home yes > it is work safe :-) ) with ok results. > Have used sec ( simple event correlator http://simple-

RE: Mails to Google being blocked for illegal attachments

2011-09-30 Thread Leigh Porter
Yeah.. +1 reasons not to use Google Aps.. -- Leigh Porter > -Original Message- > From: Meftah Tayeb [mailto:tayeb.mef...@gmail.com] > Sent: 30 September 2011 13:19 > To: foks; nanog@nanog.org > Subject: Re: Mails to Google being blocked for illegal attachments > &

Re: SDH Fiber Problem

2011-09-19 Thread Leigh Porter
Did you try turning it off and on again? ;-) -- Leigh Porter On 19 Sep 2011, at 10:21, "jacob miller" wrote: > I have triend to do a ping with the DF bit set. > Maximum am able to get to is 1600. > This am guessing is because of the fact I have set the mtu size on My

Re: SDH Fiber Problem

2011-09-19 Thread Leigh Porter
It does sound like an MTU issue. Symptoms are typical. Did you try pings end to end with DF bit set and full size datagrams? -- Leigh Porter On 19 Sep 2011, at 09:15, "jacob miller" wrote: > By meanigful traffic I mean traffic like Http traffic > > Am able to ssh no pr

Re: SDH Fiber Problem

2011-09-19 Thread Leigh Porter
What exactly do you mean by meaningful traffic? ICMP from port to port works, can you pass TCP? SSH between routers? Establish a TCP session over it? Are you using Juniper SRXs ? :-) -- Leigh Porter On 19 Sep 2011, at 08:24, "jacob miller" wrote: > I have tried the pings a

RE: wet-behind-the-ears whippersnapper seeking advice on building a nationwide network

2011-09-18 Thread Leigh Porter
> -Original Message- > From: Frank Bulk [mailto:frnk...@iname.com] > Sent: 18 September 2011 23:14 > To: 'Charles N Wyble'; nanog@nanog.org > Subject: RE: wet-behind-the-ears whippersnapper seeking advice on > building a nationwide network > > Where I live in rural America, I would not b

RE: wet-behind-the-ears whippersnapper seeking advice on building a nationwide network

2011-09-16 Thread Leigh Porter
> -Original Message- > From: Randy Bush [mailto:ra...@psg.com] > Sent: 16 September 2011 21:38 > To: Randy Carpenter > Cc: North American Network Operators' Group > Subject: Re: wet-behind-the-ears whippersnapper seeking advice on > building a nationwide network > > > As an ISP, ARIN wil

RE: wet-behind-the-ears whippersnapper seeking advice on building a nationwide network

2011-09-16 Thread Leigh Porter
> -Original Message- > From: Charles N Wyble [mailto:char...@knownelement.com] > Sent: 16 September 2011 20:47 > To: nanog@nanog.org > Subject: wet-behind-the-ears whippersnapper seeking advice on building > a nationwide network > > > > Wow this turned into a very long post > > On

RE: Disappointing ARIN - A great advertisement for the USA ?

2011-09-16 Thread Leigh Porter
> -Original Message- > From: Randy Bush [mailto:ra...@psg.com] > Sent: 16 September 2011 16:05 > To: John Curran > Cc: NANOG list > Subject: Re: Disappointing ARIN - A great advertisement for the USA ? > > > If you have a particular suggestion for changing whois, please > > feel free to

Re: ouch..

2011-09-15 Thread Leigh Porter
That will either be because you exceeded your port count or the RTSP ALG is broken. -- Leigh Porter On 15 Sep 2011, at 07:48, "valdis.kletni...@vt.edu" wrote: > On Thu, 15 Sep 2011 06:36:42 -, Leigh Porter said: >> I'm looking forward to the awful experience

  1   2   3   >