Re: Checking bogon status of new address space

2009-05-26 Thread Oliver Hookins
Thanks for all your suggestions on this topic. For what it's worth, I attempted a few of the suggestions as well as my own idea and documented the outcomes here: http://www.anchor.com.au/blog/2009/05/testing-your-connectivity/ In summary, there's no definitive method for testing your connectivity

Re: Checking bogon status of new address space

2009-05-12 Thread Robert E. Seastrom
James Hess writes: >> 29/256 = 11% of the available address space.  My argument is, if >> someone is scanning you from random source addresses blocking 10% >> of the scan traffic is reaching a point of very little return for >> the effort of updating the address lists, and as we all know it is >

Re: Checking bogon status of new address space

2009-05-11 Thread Jon Lewis
On Fri, 8 May 2009, Steve Bertrand wrote: IMHO, if a network doesn't either update filters based on IANA notifications or follow Cymru BOGON, then they don't deserve to receive traffic from your network ;) See how far you get telling customers that after you've given them recently debogonized

Re: Checking bogon status of new address space

2009-05-11 Thread Steve Bertrand
Oliver Hookins wrote: > Hi, > > my company has just been allocated some new IPv4 address space, and I want > to do some sort of automated testing to find out any ASs out there that > haven't removed the /8 it's on from their bogon list (the allocation to our > local registry only occurred in Novem

Re: Checking bogon status of new address space

2009-05-09 Thread James Hess
> 29/256 = 11% of the available address space.  My argument is, if > someone is scanning you from random source addresses blocking 10% > of the scan traffic is reaching a point of very little return for > the effort of updating the address lists, and as we all know it is > getting smaller and small

RE: Checking bogon status of new address space

2009-05-08 Thread Frank Bulk
nk -Original Message- From: Steve Dalberg [mailto:steve+na...@sendithere.com] Sent: Friday, May 08, 2009 9:45 AM To: Oliver Hookins Cc: nanog@nanog.org Subject: Re: Checking bogon status of new address space Having recently received some de-bogon'ed addressing in or about this Marc

Re: Checking bogon status of new address space

2009-05-08 Thread Owen DeLong
29/256 = 11% of the available address space. My argument is, if someone is scanning you from random source addresses blocking 10% of the scan traffic is reaching a point of very little return for the effort of updating the address lists, and as we all know it is getting smaller and smaller. Tr

Re: Checking bogon status of new address space

2009-05-08 Thread Leo Bicknell
In a message written on Fri, May 08, 2009 at 12:27:29PM -0500, Rob Thomas wrote: > This is the primary reason we removed the static bogon lists from our > Secure [BIND|IOS|BGP] Templates. My thanks to Randy Bush (and a few > other folks) for the suggestion. I want to thank Team Cymru for their ef

Re: Checking bogon status of new address space

2009-05-08 Thread Rob Thomas
Hi, Steve. > Having recently received some de-bogon'ed addressing in or about this March, > I can tell you that the one problem I had was people that had not updated > their Bind Bogon filters ( > http://www.cymru.com/Documents/secure-bind-template.html) ... This is the primary reason we removed

Re: Checking bogon status of new address space

2009-05-08 Thread Steve Dalberg
Having recently received some de-bogon'ed addressing in or about this March, I can tell you that the one problem I had was people that had not updated their Bind Bogon filters ( http://www.cymru.com/Documents/secure-bind-template.html) and so were not responding to requests from our address space,

Re: Checking bogon status of new address space

2009-05-08 Thread Wolfgang Nagele
Hi, Yes, we do this for all new /8 issued to RIR's. You can find the details here: http://www.ris.ripe.net/debogon/ Regards, Wolfgang Marco Hogewoning wrote: On May 8, 2009, at 2:44 PM, Frank Bulk wrote: Please set up a pingable IP address for each new netblock and post it to NANOG with a r

Re: Checking bogon status of new address space

2009-05-08 Thread Jon Lewis
On Fri, 8 May 2009, Oliver Hookins wrote: my company has just been allocated some new IPv4 address space, and I want to do some sort of automated testing to find out any ASs out there that haven't removed the /8 it's on from their bogon list (the allocation to our local registry only occurred in

Re: Checking bogon status of new address space

2009-05-08 Thread Marco Hogewoning
On May 8, 2009, at 2:44 PM, Frank Bulk wrote: Please set up a pingable IP address for each new netblock and post it to NANOG with a request to have us ping it. It's not automated, but it's a good start. Frank You might also want to have a look at the RIPE NCC's beacon stuff: http://www

RE: Checking bogon status of new address space

2009-05-08 Thread Frank Bulk
Please set up a pingable IP address for each new netblock and post it to NANOG with a request to have us ping it. It's not automated, but it's a good start. Frank -Original Message- From: Oliver Hookins [mailto:oliver.hook...@anchor.com.au] Sent: Friday, May 08, 2009 12:34 AM To: nanog@