Re: Question re prevention of enumeration with DNSSEC (NSEC3, etc.)

2022-05-11 Thread Masataka Ohta
As I wrote: But some spam actors deliberately compared zone file editions to single out additions, and then harass the owners of newly registered domains, both by e-mail and phone. If that is a serious concern, stop whois. There are various ways, such as crawling the web, to enumerate domain

Re: Geo-IP Sling.com and/or Dish Network Contact.

2022-05-11 Thread Josh Luthman
Dish/Sling isn't on here but check this list: https://thebrotherswisp.com/index.php/geo-and-vpn/ On Tue, May 10, 2022 at 5:18 PM Nicholas Warren wrote: > Does anyone know how to get ahold of Sling.com or Dish to update location > information on IPv4 addresses? > > I don’t know if meta discussio

Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Pirawat WATANAPONGSE via NANOG
Dear Guru(s), We used to run our ‘Gateway Router’ with ROV turned on. Then, we “upgraded” it to a Cisco NCS-55A1 (5500 Series) running IOS-XR just a few weeks ago. Consequently, during my rummage through Google for a (the?) best (ROV) configuration template for the new router, I found a tutorial

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Job Snijders via NANOG
Hi! In current versions I think enabling “soft-reconfiguration-inbound always” (also described at https://bgpfilterguide.nlnog.net/guides/reject_invalids/#cisco-ios-xr ) should be enough. Make sure to enable it on every EBGP peer you apply ROV to, or just all EBGP peers. This knob slightly incre

Re: Question re prevention of enumeration with DNSSEC (NSEC3, etc.)

2022-05-11 Thread John McCormac
On 11/05/2022 13:31, Masataka Ohta wrote: As I wrote: But some spam actors deliberately compared zone file editions to single out additions, and then harass the owners of newly registered domains, both by e-mail and phone. If that is a serious concern, stop whois. There are various ways, su

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Mark Tinka
On 5/11/22 18:53, Job Snijders via NANOG wrote: Hi! In current versions I think enabling “soft-reconfiguration-inbound always” (also described at https://bgpfilterguide.nlnog.net/guides/reject_invalids/#cisco-ios-xr ) should be enough. Make sure to enable it on every EBGP peer you apply

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Tomoya Takezaki via NANOG
Hi, If you are running "soft-reconfiguration inbound rpki-droppped-only" on IOS-XR7, please note CSCwb17937. We had a terrible time with this. Best regards, takez > 2022/05/12 1:43、Pirawat WATANAPONGSE via NANOG のメール: > > Dear Guru(s), > > > We used to run our ‘Gateway Router’ with ROV turn

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread heasley
Wed, May 11, 2022 at 07:29:04PM +0200, Mark Tinka: > On 5/11/22 18:53, Job Snijders via NANOG wrote: > > In current versions I think enabling “soft-reconfiguration-inbound > > always” (also described at > > https://bgpfilterguide.nlnog.net/guides/reject_invalids/#cisco-ios-xr > > ) should be enou

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Grant Taylor via NANOG
On 5/11/22 10:53 AM, Job Snijders via NANOG wrote: This knob slightly increase your own memory consumption, but makes your router more “neighbourly”! :-) I question how accurate "slightly" is. My understanding is that soft reconfiguration inbound (whatever the syntax for a given IOS is) cause

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Job Snijders via NANOG
On Wed, May 11, 2022 at 01:22:32PM -0600, Grant Taylor via NANOG wrote: > On 5/11/22 10:53 AM, Job Snijders via NANOG wrote: > > This knob slightly increase your own memory consumption, but makes your > > router more “neighbourly”! :-) > > I question how accurate "slightly" is. > > My understandi

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Lukas Tribus
On Wed, 11 May 2022 at 21:22, Grant Taylor via NANOG wrote: > > On 5/11/22 10:53 AM, Job Snijders via NANOG wrote: > > This knob slightly increase your own memory consumption, but makes your > > router more “neighbourly”! :-) > > I question how accurate "slightly" is. > > My understanding is that

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread heasley
Wed, May 11, 2022 at 09:36:36PM +0200, Lukas Tribus: > True and the amount of memory used per prefix also depends on things > like BGP communities. > > When I tested this, on 32 bit XR I had a memory increase of about 400 > MB for a full feed 2 years ago. it depends on the architechture, the vari

Re: Newbie x Cisco IOS-XR x ROV: BCP to not harassing peer(s) and upstream(s)

2022-05-11 Thread Randy Bush
> Is setting 'Soft Reconfiguration' enough for me to keep ROV running? yes, should be. > If not, is there any other solution? yes. jakob says he has implemented https://datatracker.ietf.org/doc/draft-ietf-sidrops-rov-no-rr/, though i do not known in what xr image(s) randy

Re: Question re prevention of enumeration with DNSSEC (NSEC3, etc.)

2022-05-11 Thread Matt Corallo
On 5/6/22 5:58 PM, Amir Herzberg wrote: Hi NANOGers, Questions: - Do you find zone enumeration a real concern? I have found that some people who are concerned about such things will have LetsEncrypt certs for many of the same hosts they were worried about - which of course makes the DNS zo