Re: Requirements for IPv6 Firewalls

2014-04-21 Thread Fernando Gont
Hi, Brandon, On 04/17/2014 08:20 PM, Brandon Ross wrote: > On Thu, 17 Apr 2014, Sander Steffann wrote: > >>> Also, I note your draft is entitled "Requirements for IPv6 Enterprise >>> Firewalls." Frankly, no "enterprise" firewall will be taken seriously >>> without address-overloaded NAT. I realiz

Re: Requirements for IPv6 Firewalls

2014-04-21 Thread Lee Howard
On 4/18/14 10:16 PM, "Matt Palmer" wrote: >On Fri, Apr 18, 2014 at 10:04:35PM -0400, Jeff Kell wrote: >> As to address the other argument in this threat on NAT / private >> addressing, PCI requirement 1.3.8 pretty much requires RFC1918 >>addressing >> of the computers in scope... has anyone hi

Re: Requirements for IPv6 Firewalls

2014-04-21 Thread Lee Howard
From: George Herbert Date: Friday, April 18, 2014 7:11 PM To: Lee Howard Cc: Eugeniu Patrascu , "draft-gont-opsec-ipv6-firewall-r...@tools.ietf.org" , "nanog@nanog.org" Subject: Re: Requirements for IPv6 Firewalls > Lee Howard: >> So, yeah, you have to give your firewall administrator ti

Re: Requirements for IPv6 Firewalls

2014-04-21 Thread Brandon Ross
On Mon, 21 Apr 2014, Fernando Gont wrote: Are you argung against of e.g. "default-deny inbound traffic"? Absolutely not, default deny of traffic should most certainly be one of the tools in the toolbox. -- Brandon Ross Yahoo & AIM: BrandonNRoss +1-404-6

Re: Requirements for IPv6 Firewalls

2014-04-21 Thread Valdis . Kletnieks
On Mon, 21 Apr 2014 12:10:31 -0400, Lee Howard said: > "Methods used to meet the intent of this > requirement may vary depending on the specific > networking technology being used. For example, > the controls used to meet this requirement may be > different for IPv4 networks than for IPv6 networks

Pluggable Coherent DWDM 10Gig

2014-04-21 Thread Tim Durack
Anyone know if pluggable coherent DWDM 10Gig optics exist? (I'm finding no such thing.) How about narrow-band/filtered receive 10Gig optics? (Inline FBG filter receive side might be doable?) -- Tim:> p.s. Before you ask, DTAG Terastream has got me thinking...

Re: Pluggable Coherent DWDM 10Gig

2014-04-21 Thread Tim Durack
As a follow up, I did not miss a zero. TenGig. If you want to know why: https://ripe67.ripe.net/presentations/131-ripe2-2.pdf (I'll take 100Gig once I can get the optics for less than the cost of a v.nice sports car...) On Mon, Apr 21, 2014 at 2:42 PM, Tim Durack wrote: > Anyone know if plugga

Re: Requirements for IPv6 Firewalls

2014-04-21 Thread George Herbert
On Mon, Apr 21, 2014 at 9:32 AM, Lee Howard wrote: > > You're describing best practice. Yes, of course, you should have well > documented technical and business needs for what's open and what's closed > in firewalls, and should have traceability from the rules in place to the > requirements, and

Re: Pluggable Coherent DWDM 10Gig

2014-04-21 Thread Jared Mauch
You can get 100G-LR4 CFP for ~10k from good vendors. You can get them sub-10k from china what i'm hearing, but those failure rates are higher.. - Jared On Apr 21, 2014, at 2:57 PM, Tim Durack wrote: > As a follow up, I did not miss a zero. TenGig. If you want to know why: > https://ripe67.rip

Re: DMARC -> CERT?

2014-04-21 Thread Florian Weimer
* Christopher Morrow: > I sort of wonder if this is really just yahoo trying to use a stick to > motivate people to do the right thing? But what is the right thing here? Do we really want that *all* mailing lists must not provider "reply to sender" option to all their users? Will this list make

Re: Pluggable Coherent DWDM 10Gig

2014-04-21 Thread Tim Durack
On Mon, Apr 21, 2014 at 2:57 PM, Tim Durack wrote: > On Mon, Apr 21, 2014 at 2:42 PM, Tim Durack wrote: > >> Anyone know if pluggable coherent DWDM 10Gig optics exist? (I'm finding >> no such thing.) >> >> How about narrow-band/filtered receive 10Gig optics? (Inline FBG filter >> receive side mi

Call for Presenations: NANOG 61 Data Center Track

2014-04-21 Thread Martin Hannigan
Hi Everyone, We are soliciting presentation proposals for a 30m time slot during the Data Center Track being held at NANOG 61 in Bellevue, WA. See http://bit.ly/1rg4eyn for dates/location. The topics that we'd like to hear from you on are: - Data Center Infrastructure Management "DCIM" (use case

Re: OT: Re: [[Infowarrior] - NSA Said to Have Used Heartbleed Bug for Years]

2014-04-21 Thread Mike A
On Fri, Apr 18, 2014 at 03:47:25PM -0700, Scott Weeks wrote: > > :: There being no cable between the Hawaiian Islands > :: and the mainland at the time > > Wait...what? > > https://en.wikipedia.org/wiki/Submarine_communications_cable#Submarine_cables_across_the_Pacific > > "The first trans-pac

Re: OT:[Infowarrior] - NSA Said to Have Used Heartbleed Bug for Years

2014-04-21 Thread Scott Weeks
--- mi...@mikea.ath.cx wrote: From: Mike A On Fri, Apr 18, 2014 at 03:47:25PM -0700, Scott Weeks wrote: > > :: There being no cable between the Hawaiian Islands > :: and the mainland at the time > > Wait...what? > > https://en.wikipedia.org/wiki/Submarine_communications_cable#Submarine_cable

[Infowarrior] - FYI ~ attrition.org uses an invalid security certificate for mailing list sign-up

2014-04-21 Thread Network IPdog
FYI... Say it isn't so In today's Heartbleed state of affairs... attrition.org uses an invalid security certificate. The certificate is not trusted because it is self-signed. The certificate is only valid for Lyger The certificate expired on 12/21/2012 1:44 PM. The current time i

Re: AT&T / Verizon DNS Flush?

2014-04-21 Thread Dennis B
The default TTL should be 300 secs, esp with everyone switching A records to cloud providers, imho. That way, who ever is the SOA and the zone master, can update it based on design scale or sla of that provider. DNS needs a protocol refresh anyways. Dennis B. On Apr 16, 2014 7:30 PM, "John Peach