configuration sanity check

2015-10-29 Thread marcel.durega...@yahoo.fr
Hi Nanogers, Any recommendation about a software which check the live config of cisco/juniper devices against some templates ? The goal is to have a template about different function device, like: - CORE device must have this bloc and this clock - PE device must have at least that and that - C

Re: configuration sanity check

2015-10-29 Thread Daniel Corbe
"marcel.durega...@yahoo.fr" writes: > Hi Nanogers, > > Any recommendation about a software which check the live config of > cisco/juniper devices against some templates ? > > The goal is to have a template about different function device, like: > - CORE device must have this bloc and this clock >

Re: configuration sanity check

2015-10-29 Thread Joe Abley
Salut Marcel, On Oct 29, 2015, at 04:16, "marcel.durega...@yahoo.fr" wrote: > Any recommendation about a software which check the live config of > cisco/juniper devices against some templates ? > > The goal is to have a template about different function device, like: > - CORE device must have t

RE: configuration sanity check

2015-10-29 Thread Naslund, Steve
I use a system called Device Expert that does exactly what you say below. I am not affiliated with them just a satisfied customer. https://www.manageengine.com/network-configuration-manager/ Steven Naslund Chicago IL -Original Message- From: NANOG [mailto:nanog-boun...@nanog.org] On Be

Re: configuration sanity check

2015-10-29 Thread Chuck Anderson
On Thu, Oct 29, 2015 at 09:16:48AM +0100, marcel.durega...@yahoo.fr wrote: > Hi Nanogers, > > Any recommendation about a software which check the live config of > cisco/juniper devices against some templates ? > > The goal is to have a template about different function device, like: > - CORE devi

DDoS mitigation for ISPs

2015-10-29 Thread Mike
Hello, Is there any DDoS mitigation service provider that can scrub traffic for an ISP network? I have an ASN and BGP and my own netblocks, and I have a 1gbps pipe. I was thinking the scenario would be during attack, we could bring up a tunnel and run bgp over it and advertise some portio

Re: configuration sanity check

2015-10-29 Thread Jason Lixfeld
Either of these might come in handy.. https://www.nanog.org/meetings/abstract?id=2673 https://www.nanog.org/meetings/abstract?id=2678 > On Oct 29, 2015, at 4:16 AM, marcel.durega...@yahoo.fr wrote: > > Hi Nanogers, > > Any recommendation about a software which check the live config of > cisco/

Re: configuration sanity check

2015-10-29 Thread Michal Loncek
On 10/29/2015 09:16 AM, marcel.durega...@yahoo.fr wrote: Hi Nanogers, Any recommendation about a software which check the live config of cisco/juniper devices against some templates ? The goal is to have a template about different function device, like: - CORE device must have this bloc and th

Re: configuration sanity check

2015-10-29 Thread chip
I've used ansible for this and generated config based on roles. It's a little weird to get started but allows modularization of config. You can then go so far as have the same "functions" for different platforms and software versions. To be clear, this was just for config generation, not verifyi

Re: configuration sanity check

2015-10-29 Thread Justin Seabrook-Rocha
On Oct 29, 2015, at 01:16, marcel.durega...@yahoo.fr wrote: > > Hi Nanogers, > > Any recommendation about a software which check the live config of > cisco/juniper devices against some templates ? > > The goal is to have a template about different function device, like: > - CORE device must hav

Re: DDoS mitigation for ISPs

2015-10-29 Thread Job Snijders
On Thu, Oct 29, 2015 at 08:42:31AM -0700, Mike wrote: > Is there any DDoS mitigation service provider that can scrub traffic > for an ISP network? Yeah, plenty. A non-exhaustive list: Prolexic, Incapsula, Staminus or Nexusguard. There is no lack of choice. > I have an ASN and BGP and my own net

Re: DDoS mitigation for ISPs

2015-10-29 Thread Hugo Slabbert
On Thu 2015-Oct-29 08:42:31 -0700, Mike wrote: Hello, Is there any DDoS mitigation service provider that can scrub traffic for an ISP network? I have an ASN and BGP and my own netblocks, and I have a 1gbps pipe. I was thinking the scenario would be during attack, we could bring up a tun

Re: DDoS mitigation for ISPs

2015-10-29 Thread Mike
On 10/29/2015 08:54 AM, Hugo Slabbert wrote: On Thu 2015-Oct-29 08:42:31 -0700, Mike wrote: Hello, Is there any DDoS mitigation service provider that can scrub traffic for an ISP network? I have an ASN and BGP and my own netblocks, and I have a 1gbps pipe. I was thinking the scenario

Re: configuration sanity check

2015-10-29 Thread Jesse McGraw
Historically there was RAT (Router Audit Tool). You'll have to do some googling to see where it's hosted now and whether or not it's still being developed as I haven't looked at it in years. On 10/29/2015 04:16 AM, marcel.durega...@yahoo.fr wrote: Hi Nanogers, Any recommendation about a sof

Re: configuration sanity check

2015-10-29 Thread Paul Ferguson
Be careful in your search for RATs -- in the security world it also stands for Remote Access Trojan. :-) - ferg On October 29, 2015 3:06:23 PM EDT, Jesse McGraw wrote: >Historically there was RAT (Router Audit Tool). You'll have to do some > >googling to see where it's hosted now and whether

Re: DDoS mitigation for ISPs

2015-10-29 Thread Hugo Slabbert
Alternatively: http://lmgtfy.com/?q=ddos+protection Actually I did the google thing first and followed up with several of the top results, and not once did I see anyone offering a bgp tunnel + scrub which is why I asked. I did get some good off list responses however, thanks all. Mike- Ap

Re: DDoS mitigation for ISPs

2015-10-29 Thread Pavel Odintsov
Hello! Could recommend folks from EU - http://qrator.net/en/ Two years without any issues. Perfect SSL and http filtration. On Thu, Oct 29, 2015 at 10:53 PM, Hugo Slabbert wrote: >>> Alternatively: http://lmgtfy.com/?q=ddos+protection >>> >> Actually I did the google thing first and followed up

[CenturyLink][Proto UDP] Blockage of UDP Outbound from Source Port 53

2015-10-29 Thread Jason Hellenthal
Could a CenturyLink network admin/engineer contact me off list. We have multiple locations receiving DNS queries over UDP where we see the connections making into our server and back out to our CenturyLink edge routers but never completes back to the connecting client at multiple locations. Con

RE: configuration sanity check

2015-10-29 Thread Andrew Bosch
What is the opinion about CatTools? > -Original Message- > From: NANOG [mailto:nanog-boun...@nanog.org] On Behalf Of > marcel.durega...@yahoo.fr > Sent: Thursday, October 29, 2015 3:17 AM > To: nanog > Subject: configuration sanity check > > Hi Nanogers, > > Any recommendation about a s

Re: NANOG list attack

2015-10-29 Thread Lamar Owen
On 10/26/2015 03:17 PM, Larry Blunk wrote: As Job Snijders (a fellow Communications Committee member) noted in an earlier post, we will be implementing some additional protection mechanisms to prevent this style of incident from happening again. We will be more aggressively moderating posts fr