Contact for AS4134 - China Backbone

2010-04-25 Thread Anderson
Grettings, does someone know contact person at noc for AS4134 - China Backbone ? thank you very much. -- regards, anderson l. CBN Network Operation Center

Re: Cisco ASR

2010-05-26 Thread Anderson
for a few days ago, i just tested the ASR1006, i tested it for 2 weeks and it never reboot itself. i was using IOS: asr1000rp2-adventerprisek9.BLD_V122_33_XNE_ASR_RLS5_THROTTLE_LATEST_20090926_060026.bin i tested it for bgp propagation and pppoe. i think it enough good. #Anderson

Linux router network cards

2020-10-20 Thread micah anderson
I'm looking around for networking cards to build a linux based router. It needs to be able to do XDP, multiqueues, have good in-kernel driver support and be able to handle 10Gbe with good offloading for dealing with high packets per second. What features should I be looking for to really optimiz

RE: Linux router network cards

2020-10-22 Thread micah anderson
Thanks for the reply. Philip Loenneker writes: > Take a look at the Mellanox ConnectX 5 series of cards. They handle > DPDK, PVRDMA (basically SR-IOV that allows live migration between > hosts), and can even process packets within the NIC for some >From what I can tell, SR-IOV/PVRDMA aren't re

Scanning activity from 2620:96:a000::/48

2021-07-06 Thread Tore Anderson
A couple of hours after midnight UTC, the control plane policers for unresolved traffic on a couple of our CE routers started being clogged with ping-scanning activity from 2620:96:a000::/48, which belongs to «Internet Measurement Research (SIXMA)» according to ARIN. Excerpt of this traffic (anony

Re: Scanning activity from 2620:96:a000::/48

2021-07-06 Thread Tore Anderson
* Dobbins, Roland > Scanning is part of the ‘background radiation’ of the Internet, and it’s > performed by various parties with varying motivations. Of necessity, IPv6 > scanning is likely to be more targeted (were your able to discern any rhyme > or reason behind the observed scanning patter

Re: happy birthday, jon

2021-08-06 Thread Celeste Anderson
He'd be 78 today. Still miss him, he was a great mentor and human being. --celeste Get Outlook for Android From: NANOG on behalf of Randy Bush Sent: Friday, August 6, 2021 11:48:18 AM To: North American Network Operators' Group Subjec

Re: Dual Homed BGP

2020-01-25 Thread Tore Anderson
* Baldur Norddahl > If you join any peering exchanges, full tables will be mandatory. Some > parties will export prefixes and then expect a more specific prefix received > from your transit to override a part of the space received via the peering. That would be a fundamentally flawed expectati

RE: RIP: Bill Manning

2020-01-29 Thread Celeste Anderson
Definitely sad news. I worked with Bill at ISI when we were forming the MAE-LA-LAAP Internet Exchange and owe a lot of my current contributions to his efforts back then. He had some of the most interesting (and funny after-the-fact) stories surrounding his many international trips, including th

Re: [EXT] Re: Hi-Rise Building Fiber Suggestions

2020-02-26 Thread Chuck Anderson
After 30 add/drops you may lose too much power. There is a minimum 1.4dB per passthru and 1.3dB per add/drop, 3.5dB per MUX at the ends. With these SFP+ modules: https://www.fs.com/products/31238.html it looks like you would have a 19-20 dB budget to work with. You may be able to get 10 add/

Re: [EXT] ISC BIND 9 breakage?

2020-03-25 Thread Chuck Anderson
On the BIND Users list: https://lists.isc.org/pipermail/bind-users/2020-March/102820.html On Wed, Mar 25, 2020 at 05:18:49PM +, Drew Weaver wrote: > Did anyone else on CentOS 6 just have some DNS resolvers totally fall over? > > I noticed that this command: dnssec-lookaside auto; was causing

Re: [EXT] Shining a light on ambulance chasers - Noction

2020-03-25 Thread Chuck Anderson
Someone should tell them what happened to Cogent for scraping ARIN WHOIS. On Wed, Mar 25, 2020 at 04:13:51PM -0400, Rodney Joffe wrote: > Under the heading of sales spam from our community that is in even poorer > taste, and sucks: > > > Begin forwarded message: > > > From: Josh Ankin > > Sub

Re: [EXT] Shining a light on ambulance chasers - Noction

2020-03-25 Thread Chuck Anderson
repulsive. > > Public pressure is the only way to police _this_. > > YMMV, > > -M< > > On Wed, Mar 25, 2020 at 4:30 PM Chuck Anderson wrote: > > > Someone should tell them what happened to Cogent for scraping ARIN WHOIS. > > > > On Wed, Mar 25, 2

Re: [EXT] Shining a light on ambulance chasers - Noction

2020-03-26 Thread Chuck Anderson
On Thu, Mar 26, 2020 at 01:39:20PM -0700, Sabri Berisha wrote: > - On Mar 25, 2020, at 5:13 PM, Chuck Anderson c...@wpi.edu wrote: > > > Let's start a public blacklist, sort of like a RBL reputation block list or > > 800notes.com, but for companies to "never to do

Re: rack rails

2020-03-30 Thread Tore Anderson
* David Funderburk > 2 - Do you know of any universal rail kits for 1U, 2U and 3U servers, > routers, switches that work well?  The brand names are nice but expensive. > Thought I'd explore some cheaper options first. We use a lot of MikroTik, HP, > Dell and some CISCO with a few other things h

Re: [EXT] Re: rack rails

2020-03-30 Thread Chuck Anderson
On Mon, Mar 30, 2020 at 04:18:18PM +0200, Tore Anderson wrote: > When a rack has been filled up, removal/insertion through the rear will often > be essentially impossible due to cables, vertical PDUs and stuff like that > that gets in the way. > > Explained in pictures

Re: rack rails

2020-03-30 Thread Tore Anderson
* Luke Guillory > I've had gear that came with a small rear support shelf that didn't had to > the height, RGB Networks BNPs for example. I'm pretty sure we've used these > with the BNPs one on top of the other. > > Page 16 in this PDF shows the shelf. > > http://www.konturm.ru/catalogy/df/bn

Re: [EXT] Re: rack rails

2020-03-30 Thread Chuck Anderson
On Mon, Mar 30, 2020 at 10:09:25AM -0500, Chris Adams wrote: > Once upon a time, Chuck Anderson said: > > I've been asking manufacturers for proper server-like slide-rails for their > > switches for years. Now they've started making the switches as deep or > >

Re: [EXT] Re: rack rails

2020-03-30 Thread Tore Anderson
* Chuck Anderson > The point is that the switches need to be removable without empty > space above/below, and ideally from the rear side of the rack. By > having extending/sliding rails, you can lift out or drop in the switch > after you slide it out. Then you can remove the rail

Re: [EXT] Re: rack rails

2020-03-30 Thread Chuck Anderson
On Mon, Mar 30, 2020 at 03:15:54PM +, Cummings, Chris wrote: > Juniper's ToR switches have slide in rails. They are a bit frustrating > compared to Dell easy rails, but they do the trick. You can slide the switch in/out while attached securely to the rails? That is news to me and my QFX5k

Re: [EXT] Re: rack rails

2020-03-30 Thread Chuck Anderson
On Mon, Mar 30, 2020 at 05:27:44PM +0200, Tore Anderson wrote: > * Chuck Anderson > > > The point is that the switches need to be removable without empty > > space above/below, and ideally from the rear side of the rack. By > > having extending/sliding rails, you can

Re: [EXT] Re: rack rails

2020-03-30 Thread Tore Anderson
* Cummings, Chris > Now that you say that, I think you're right. I am referring specifically to > the EX4650 and they are the cheesy type where the rear half of the rail stays > screwed in to the rack and the front half of the rail is attached to the > switch. I assume it is the same on the QFX

Re: [EXT] Re: rack rails

2020-03-30 Thread Chuck Anderson
On Mon, Mar 30, 2020 at 07:09:48PM +0300, Nitzan Tzelniker wrote: > We tried to flip the sides of rails in QFX5120 and it cause two problems > that prevent us from keeping it this way > 1. The switch was 2 cm from the rear post line > 2. The switch vibrate as you can see in the video > https://pho

Re: [EXT] AS hijacking (Philosophy, rants, GeoMind)

2020-05-29 Thread Chuck Anderson
Go back to them and tell them that a hijacked prefix is different from a hijacked AS. On Fri, May 29, 2020 at 11:39:46AM -0400, Justin Wilson (Lists) wrote: > One of the companies I work for recently had an issue with AS 2 (University > of Delaware) hijacking a prefix. Due to Origin AS, good up

Re: Partial vs Full tables

2020-06-05 Thread Tore Anderson
* James Breeden > I come to NANOG to get feedback from others who may be doing this. We > have 3 upstream transit providers and PNI and public peers in 2 > locations. It'd obviously be easy to transition to doing partial > routes for just the peers, etc, but I'm not sure where to draw the > line o

Re: Partial vs Full tables

2020-06-05 Thread Tore Anderson
* Saku Ytti > On Fri, 5 Jun 2020 at 10:48, Tore Anderson wrote: > > > We started taking defaults from our transits and filtering most of the > > DFZ over three years ago. No regrets, it's one of the best decisions we > > ever made. Vastly reduced both convergence

Re: Partial vs Full tables

2020-06-05 Thread Tore Anderson
* Saku Ytti > On Fri, 5 Jun 2020 at 11:23, Tore Anderson wrote: > > > Sure you can, you just ask them. (We did.) > > And is it the same now? Some Ytti didn't 'fix' the config last night? > Or NOS change which doesn't do conditional routes? Or they &g

Re: Partial vs Full tables

2020-06-05 Thread Tore Anderson
* Michael Hare > I'm considering an approach similar to Tore's blog where at some > point I keep the full RIB but selectively populate the FIB. Tore, > care to comment on why you decided to filter the RIB as well? Not «as well», «instead». In the end I felt that running in production with the R

Re: Partial vs Full tables

2020-06-05 Thread Chuck Anderson
On Fri, Jun 05, 2020 at 10:20:00AM -0700, William Herrin wrote: > On Fri, Jun 5, 2020 at 9:49 AM Saku Ytti wrote: > > The comparison isn't between full or default, the comparison is > > between static default or dynamic default. Of course with any default > > scenario there are more failure modes

Re: [EXT] Xfinity (both ends) - can't ping from users home to office

2020-06-19 Thread Chuck Anderson
On Thu, Jun 18, 2020 at 11:57:12PM +, Spencer Coplin wrote: > I have a client that is unable to ping his office Comcast Business connection > from his home Xfinity connection. It was working a month ago and we can > confirm that his connection works over his iphone's hotspot. I am able to >

AT&T Wireless contact

2020-08-14 Thread Nathan Anderson
This is probably a long shot, but are there any AT&T Wireless engineers here, & one who wouldn't mind contacting me off-list? I may be misinterpreting what I'm seeing, but I think you might have a small number of MMSC servers that are down... -- Nathan

Re: Rack rails on network equipment

2021-09-27 Thread Tore Anderson
* Andrey Khomyakov > Interesting tidbit is that we actually used to manufacture custom rails for > our Juniper EX4500 switches so the switch can be actually inserted from the > back of the rack (you know, where most of your server ports are...) and not > be blocked by the zero-U PDUs and all th

IPv6 on Lumen/CL

2022-08-29 Thread Nathan Anderson
We have a circuit on AS209 that was originally provisioned v4-only. I'm now trying to get Lumen to turn v6 up on it. How long does this typically take? I've had a configuration ticket open for nearly 3 biz days now with no movement (or even acknowledgement). For anybody who has gone through

RE: iCloud/Apple Mail contact.

2022-09-15 Thread Nathan Anderson
Did you ever manage to find out who at Apple to speak to about getting things added to or changed in this database? Quite irritating how there is zero public-facing information about this. Also, an Apple employee authored RFC 6186, yet they don't implement it?? -- Nathan From: NANOG [m

Offline contact for MS Windows network stack dev? (Win10 IPv6 bug Q.)

2022-11-07 Thread Nathan Anderson
rely because of lack of AOAC support in the driver for IPv6?!], which is clearly not the case). Thanks! -- Nathan Anderson First Step Internet, LLC nath...@fsr.com

Re: Reverse Traceroute

2023-02-25 Thread Tore Anderson
* Rolf Winter > If you would like to play with reverse traceroute, the easiest option > is to work with the client and use one of the public server instances > (https://github.com/HSAnet/reverse-traceroute/blob/main/ENDPOINTS). > If you would be willing to host a public server instance yourself,

Facebook (account)

2019-04-09 Thread Nathan Anderson
I'm not sure I would bother and I'd just tell her to get a new one. But she runs a business (popular local coffee shop) with a FB page that this account of hers was apparently the only admin for. Thanks in advance for any leads, -- Nathan Anderson First Step Internet, LLC nath...@fsr.com

RE: Facebook (account)

2019-04-10 Thread Nathan Anderson
Matt Harris wrote: > On Apr 9, 2019, at 21:05, Nathan Anderson wrote: > > > a FB page that this account of hers was apparently the only admin for. > > Redundancy: it's not just a concept to be applied to devices and wiring.    Preaching. To. The. Choir. :-) -- Nat

Re: Gi Firewall for mobile subscribers

2019-04-11 Thread Tore Anderson
* Owen DeLong > What would be the process for a subscriber who wishes to allow inbound > connections? > > If you are simply saying that as a customer of your ISP you simply can’t > allow inbound IPv6 connections at all, then you are becoming a very poor > substitute for an ISP IMHO. I have to

Re: Gi Firewall for mobile subscribers

2019-04-13 Thread Tore Anderson
* Mark Milhollan > On Thu, 11 Apr 2019, Tore Anderson wrote: > >> We've been wanting to replace our all of our ad-hoc OOB links with a >> standardised setup based on LTE connectivity to an embedded >> login/console server at each PoP. IPv6 would be perfect due to

Re: BGP router question

2019-08-09 Thread Tore Anderson
* Art Stephens > Hope this is not too off topic but can any one advise if a Dell S4048-ON can > support full ebgp routes? As others have mentioned, you won't be able to program them all in the forwarding plane, but the control plane can receive them all just fine (it has more than enough RAM).

Re: Couple of questions about "baremetal/ONIE" networking equipment sellers

2019-10-27 Thread Tore Anderson
* Nick ten Cate > We also have lots of experience with FS.com switches; however.. One thing we > noticed really quick is that its better to order 1 and to find the actual > supplier and order with them directly. FS.com is a reseller; and they will > switch (no pun intended) supplier almost year

Re: ECN

2019-11-13 Thread Tore Anderson
* Saku Ytti > Not true. Hash result should indicate discreet flow, more importantly > discreet flow should not result into two unique hash numbers. Using > whole TOS byte breaks this promise and thus breaks ECMP. > > Platforms allow you to configure which bytes are part of hash > calculation, wh

Re: FYI - Suspension of Cogent access to ARIN Whois

2020-01-07 Thread Tore Anderson
* David Guo via NANOG > Good News! But we still received several spams from Cogent for our RIPE and > APNIC ASNs. If you are an EU/EEA citizen, you may object to their use of your personal information for marketing purposes (or for any purpose at all), as well as request erasure. (Note: these

Re: NIST NTP servers

2016-05-13 Thread Chuck Anderson
On Fri, May 13, 2016 at 10:12:49AM -0400, Lamar Owen wrote: > On 05/11/2016 09:46 PM, Josh Reynolds wrote: > >maybe try [setting up an NTP server] with an odroid? > > > ... > > I have several ODroid C2's, and the first thing to note about them > is that there is no RTC at all. Also, the oscillato

SNMP "bridging"/proxy?

2016-05-20 Thread Nathan Anderson
'lo all, Is anybody out there aware of a piece of software that can take data from an arbitrary source and then present it, using a MIB or set of OIDs of your choosing, as an SNMP-interrogatable device? We have some CPE that supports SNMP, but considers it to be a mutually-exclusive "remote ma

RE: SNMP "bridging"/proxy?

2016-05-20 Thread Nathan Anderson
Hey, thanks guys! I had never really looked that deeply into Net-SNMP and had only ever installed it either to use as a client (snmpget/snmpwalk) or a basic agent w/ standard MIBs for the host it's running on, so I was unaware of its extensibility. And it even looks like it ships with a Perl m

RE: SNMP "bridging"/proxy?

2016-05-20 Thread Nathan Anderson
On Friday May 20, 2016 @ 21:45, Robert Drake wrote: > I would move away from this CPE vendor. I'm not thrilled with it either, but at this moment in time, this is easier said than done for many unfortunately good and unavoidable reasons. We will see how the future plays out, though. > [...]

Re: Public DNS64

2016-06-01 Thread Tore Anderson
* Baldur Norddahl > It goes to the USA and back again. They would need NAT64 servers in > every region and then let the DNS64 service decide which one is close > to you by encoding the region information in the returned IPv6 > address. Such as 2001:470:64:[region number]::/96. > > An anycast solu

Re: Public DNS64

2016-06-01 Thread Tore Anderson
* Mark Andrews > In message <20160601103707.7de9d...@envy.e5.y.home>, Tore Anderson writes: > > Or you could simply accept that active sessions are torn down > > whenever the routing topology changes enough to flip traffic to the > > anycast prefix to another NAT64 ins

Re: Netflix VPN detection - actual engineer needed

2016-06-06 Thread Tore Anderson
* Spencer Ryan > As an addendum to this and what someone said earlier about the > tunnels not being anonymous: From Netflix's perspective they are. Yes > HE knows who controls which tunnel, but if Netflix went to HE and > said "Tell me what user has x/48" HE would say "No". Thus, making > them

Re: Netflix VPN detection - actual engineer needed

2016-06-07 Thread Tore Anderson
* Davide Davini > On 04/06/2016 20:46, Owen DeLong wrote: > > Get your own /48 and advertise to HE Tunnel via BGP. Problem > > solved. > > Even though that sounds like an awesome idea it does not seem trivial > to me to obtain your own /48. Which is a good thing, as every new PI /48 advertise

Re: Measuring the quality of Internet access

2016-06-13 Thread Collin Anderson
and NDT, as do a few regulators in Europe and elsewhere. Please always feel free to reach out, we are always eager to collaborate with network operators to use our tools and extend our platform – everything is open source and open access. Cordially, Collin -- *Collin David Anderson* averysmal

Re: IPv6 deployment excuses

2016-07-03 Thread Tore Anderson
* Mark Tinka > I understand your points - to your comment, my question is around > whether it is cheaper (for you) to just run IPv6 in lieu of IPv6 and > IPv4. We've found that it is. IPv6-only greatly reduces complexity compared to dual stack. This means higher reliability, lower OpEx, shorter r

Re: IPv6 deployment excuses

2016-07-04 Thread Tore Anderson
* Mark Tinka > What I was trying to get to is that, yes, running a single-stack is > cheaper (depending on what "cheaper" means to you) than running > dual-stack. Wholeheartedly agreed. > That said, running IPv4-only means you put yourself at a disadvantage > as IPv6 is now where the world is g

Re: University of Alaska AS7774 NOC?

2016-07-18 Thread Britton Anderson
find any issues, but if folks wouldn't mind running traces to 137.229.0.0/16 & 199.165.64.0/18 and pinging me with any anomalies, that would be great. Thanks, Britton Britton Anderson | Senior Network Communications Specialist | University of Alaska <http://www.alaska.edu/oit> |

Re: Speedtest.net not accessible in Chrome due to deceptive ads

2016-07-20 Thread Collin Anderson
t; > > > > (with the pre-condition of " if you understand the risks to your > > security" > > > > > > > > > I personally dont want or need Google to start being my nanny on the > > > internet :/ > > > > > > > > > alan > > > > > > PS you may have other interests involved here given your affiliation to > > > speedchecker.xyz > > > > > > -- *Collin David Anderson* averysmallbird.com | @cda | Washington, D.C.

Re: Speedtest.net not accessible in Chrome due to deceptive ads

2016-07-20 Thread Collin Anderson
e with error handling on the IPv6 side that lead to it being disabled temporarily. We will follow through on this. -- *Collin David Anderson* averysmallbird.com | @cda | Washington, D.C.

Re: IPv6 Deployment for Mobile Subscribers

2016-07-22 Thread Tore Anderson
* Baldur Norddahl > Den 22. jul. 2016 20.25 skrev "Ca By" : > > > Phones, as in 3gpp? If so, each phone alway gets a /64, there is > > no choice. > > > > https://tools.ietf.org/html/rfc6459 > > Here the cell companies are marketing their 4G LTE as an alternative > to DSL, Coax and fiber for in

Re: MTU

2016-07-23 Thread Tore Anderson
* Baldur Norddahl > What is best practice regarding choosing MTU on transit links? > > Until now we have used the default of 1500 bytes. I now have a > project were we peer directly with another small ISP. However we need > a backup so we figured a GRE tunnel on a common IP transit carrier > woul

Re: MTU

2016-07-23 Thread Tore Anderson
* Baldur Norddahl > I did not say we were doing internet peering... Uhm. When you say that you peer with another ISP (and keep in mind what the "I" in ISP stands for), while giving no further details, then folks are going to assume that you're talking about a standard eBGP peering with inet/inet6

Re: Advertising rented IPv4 prefix from a different ASN.

2016-08-05 Thread Tore Anderson
* Mark Tinka > On 5/Aug/16 15:40, Soon Keat Neo wrote: > > > If you are just announcing more specific address space that you've > > obtained legitimately off their assigned address space, it should > > be no problem, just obtain an LoA and register it on the different > > databases and you should

Re: 10G switch drops traffic for a split second

2016-11-29 Thread Chuck Anderson
Without more detail, I'm grasping at straws here, but see this recent thread about QoS and microbursts on the juniper-nsp list: https://puck.nether.net/pipermail/juniper-nsp/2016-November/033692.html Do you have ports with different speeds connected? Another idea: Are you using Spanning Tree Pro

Re: External BGP Controller for L3 Switch BGP routing

2017-01-15 Thread Tore Anderson
Hi Saku, > > https://www.redpill-linpro.com/sysadvent/2016/12/09/slimming-routing-table.html > > --- > As described in a prevous post, we’re testing a HPE Altoline 6920 in > our lab. The Altoline 6920 is, like other switches based on the > Broadcom Trident II chipset, able to handle up to 720 Gbp

Re: External BGP Controller for L3 Switch BGP routing

2017-01-16 Thread Tore Anderson
* Saku Ytti > Why I said it won't be a problem inside DC, is because low RTT, which > means small bursts. I'm talking about backend network infra in DC, not > Internet facing. Anywhere where you'll see large RTT and > speed/availability step-down you'll need buffers (unless we change TCP > to pac

Re: External BGP Controller for L3 Switch BGP routing

2017-01-16 Thread Tore Anderson
* Saku Ytti > On 16 January 2017 at 14:36, Tore Anderson wrote: > > > Put it another way, my «Internet facing» interfaces are typically > > 10GEs with a few (kilo)metres of dark fibre that x-connects into my > > IP-transit providers' routers sitting in nearby r

Re: radb mirroring

2017-01-25 Thread Chuck Anderson
On a similar note, Level3's database has many stale entries from WCGDB which no longer exists as far as I can tell. Does anyone have a good contact at Level3 for removing all the entries with a source: WCGDB? There are some of mine that I'd like to have removed. Here is an example of Charter's AS

Re: DWDM Optics cheaper than CWDM Optics?

2017-01-31 Thread Chuck Anderson
I've bought their DWDM 80km 10gig and they are working beautifully on a couple amplified circuits with both Cisco and Juniper routers. I've also bought gray optics and DACs. The only issue I've noted with some QSFP+ DACs is some kind of programming issue where the serial number is mis-read by som

Re: Bogon prefix c0f:f618::/32 announced via Cogent

2018-07-17 Thread Chuck Anderson
Looks like a typo of 2c0f:f618: A V DestinationP Prf Metric 1 Metric 2 Next hopAS path* ? 2c0f:f618::/32 B 170150 69040 174 327814 ? unverified >fe80::f5c0:800:2 On Sat, Jul 14, 2018 at 08:18:25AM +08

Re: Bogon prefix c0f:f618::/32 announced via Cogent

2018-07-17 Thread Chuck Anderson
On Mon, Jul 16, 2018 at 05:20:12PM +0200, Stephane Bortzmeyer wrote: > On Sat, Jul 14, 2018 at 08:18:25AM +0800, > Siyuan Miao wrote > a message of 27 lines which said: > > > c0f:f618::/32 originated from AS327814 is announcing via Cogent for several > > weeks. > > Apparently withdrawn 2018-0

Re: What NMS do you use and why?

2018-08-15 Thread Chuck Anderson
On Wed, Aug 15, 2018 at 08:49:12AM -0500, Colton Conor wrote: > We are looking for a new network monitoring system. Since there are so many > operators on this list, I would like to know which NMS do you use and why? > Is there one that you really like, and others that you hate? > > For free optio

Re: What NMS do you use and why?

2018-08-15 Thread Chuck Anderson
On Wed, Aug 15, 2018 at 08:49:12AM -0500, Colton Conor wrote: > We are looking for a new network monitoring system. Since there are so many > operators on this list, I would like to know which NMS do you use and why? > Is there one that you really like, and others that you hate? > > For free optio

Re: China ’s Maxim – Leave No Access Point Unexploited: The Hidden Story of China Telecom’ s BGP Hijacking

2018-11-05 Thread Tore Anderson
* Harley H > Curious to hear others' thoughts on this.  > https://scholarcommons.usf.edu/cgi/viewcontent.cgi?article=1050&context=mca > > This paper presents the view that several BGP hijacks performed by China > Telecom had malicious intent. The incidents are: > * Canada to Korea - 2016 > * US

Re: Most peered AS per country

2018-11-28 Thread Tore Anderson
* Mehmet Akcin > I am noticing provider A enters market X saying they are tier 1 network but > they do not have a si ngle peering session in country and they backhaul > everything back to market Z where they deliver traffic to the peer via high > latency and low performance method. This is caus

Bulk IP abuse reporting

2018-11-28 Thread micah anderson
Hi all, It seems that outdated CLDAP servers on the internet are being used again for DDoS amplification attacks. I've got about 16k IPs that have participated in several of these over the last several weeks and I'd like to report these to the relevant abuse departments so they can be properly h

Re: Should ISP block child pornography?

2018-12-11 Thread William Anderson
On Fri, 7 Dec 2018 at 06:08, Lotia, Pratik M wrote: > Hello all, was curious to know the community’s opinion on whether an ISP > should block domains hosting CPE (child pornography exploitation) content? > Interpol has a ‘worst-of’ list which contains such domains and it wants > ISPs to block it.

Re: BGP Experiment

2019-01-08 Thread Tore Anderson
* Job Snijders > Given the severity of the bug, there is a strong incentive for people to > upgrade ASAP. The buggy code path can also be disabled without upgrading, by building FRR with the --disable-bgp-vnc configure option, as I understand it. I've been told that this is the default in Cumul

Re: SMTP Over TLS on Port 26 - Implicit TLS Proposal [Feedback Request]

2019-01-14 Thread William Anderson
On Sun, 13 Jan 2019 at 21:19, Viruthagiri Thirumavalavan wrote: > Let me copy paste some part I posted in ietf-smtp forum. > Please, stop. -n

Re: ICMPv6 "too-big" packets ignored (filtered ?) by Cloudflare farms

2019-03-05 Thread Tore Anderson
* Jean-Daniel Pauget > I confess using IPv6 behind a 6in4 tunnel because the "Business-Class" > service > of the concerned operator doesn't handle IPv6 yet. > > as such, I realised that, as far as I can figure, ICMPv6 packet "too-big" > (rfc 4443) > seem to be ignored or filtere

Re: Open source Netflow analysis for monitoring AS-to-AS traffic

2024-03-28 Thread Tore Anderson
On 27/03/24 01:04, Brian Knight via NANOG wrote: What's presently the most commonly used open source toolset for monitoring AS-to-AS traffic? I want to see with which ASes I am exchanging the most traffic across my transits and IX links. I want to look for opportunities to peer so I can bette

Re: Looking for anycast DNS services..

2024-06-14 Thread Tore Anderson
* Carlos Kamtha Looking for upstream provider where I can locate DNS servers with global anycast service. We have our own CIDR to announce and would prefer physical presence starting with South Asia and Europe. Commemts and suggestions welcome. Something like Netnod DNSNODE? We're using the

Re: Consumer networking head scratcher

2017-03-01 Thread Chuck Anderson
On Thu, Mar 02, 2017 at 12:24:38PM +0700, Roland Dobbins wrote: > On 2 Mar 2017, at 9:55, Oliver O'Boyle wrote: > > >Currently, I have 3 devices connected. :) > > What about DNS issues? Are you sure that you really have a > networking issue, or are you having intermittent DNS resolution > proble

Re: google ipv6 routes via cogent

2017-03-02 Thread Chuck Anderson
Define "good" vs. "bad" transport of bits. As long as there is adequate bandwidth and low latency, who cares? On Thu, Mar 02, 2017 at 08:30:37PM +0100, Baldur Norddahl wrote: > That will have the effect of prioritizing Cogent routes as that would be > more specific than the default routes from th

Re: difference with caching when connected to telia internet

2017-03-18 Thread Tore Anderson
Hi Aaron, > What happened was, when I turned up my new 10 gig Telia Internet > connection a few days ago, I needed to balance out my (4) 10 gig > internet connections so I chopped up a /17 into (4) /19's. When I > did this, I was still advertising the /17 to my local caches, but I > was advertisi

Re: [SPF:Probably_Forged] Merit RADB support

2017-06-07 Thread Chuck Anderson
On Wed, Jun 07, 2017 at 10:41:16AM -0500, Kaiser, Erich wrote: > Anyone gonna email me back from RADB support? In my experience, no.

Re: Merit RADB support

2017-06-07 Thread Chuck Anderson
On Wed, Jun 07, 2017 at 12:08:50PM -0400, Chuck Anderson wrote: > On Wed, Jun 07, 2017 at 10:41:16AM -0500, Kaiser, Erich wrote: > > Anyone gonna email me back from RADB support? > > In my experience, no. Apologies to Merit RADB, it was BGPmon that never responds. Merit RAD

Re: Vendors spamming NANOG attendees

2017-06-13 Thread Chuck Anderson
I've started keeping a list of companies who make unsolicited calls/emails. I tell them that I put them on my list of companies never to do business with. On Tue, Jun 13, 2017 at 01:12:07PM -0400, Rich Kulawiec wrote: > On Tue, Jun 13, 2017 at 03:31:46PM +, Mel Beckman wrote: > > Sometimes th

Re: BGP peering question

2017-07-12 Thread Tore Anderson
* craig washington > Newbie question, what criteria do you look for when you decide that > you want to peer with someone or if you will accept peering with > someone from an ISP point of view. Routing hygiene. I expect the would-be peer to keep the number of advertised routes that are either 1) no

RE: USA local SIM card

2017-09-18 Thread Nathan Anderson
ll likely have to work out a separate solution for any time spent up there.) Hope this helps, -- Nathan Anderson First Step Internet, LLC nath...@fsr.com -Original Message- From: NANOG [mailto:nanog-boun...@nanog.org] On Behalf Of Max Tulyev Sent: Sunday, September 17, 2017 10:08 AM To: nanog@

Re: Temp at Level 3 data centers

2017-10-11 Thread Chuck Anderson
Install an air conditioner in your rack. On Wed, Oct 11, 2017 at 02:39:19PM -0500, Andrew Latham wrote: > David > > The issue has several components and is vendor agnostic. > > Set Point: The systems are specifically set at a temperature > Capacity Ability: The systems can maintain a temperature

Re: Are there inexpensive DWDM products?

2017-11-02 Thread Chuck Anderson
CWDM is cheaper and will probably work fine within a city. Check fs.com. On Thu, Nov 02, 2017 at 06:01:10PM +, LF OD wrote: > We have several buildings and a couple data centers spread around the city > and interconnected via dark fiber. It's a very simple setup - no ROADM, no > real ring,

Re: Looking for help @ 60 Hudson

2017-11-13 Thread Chuck Anderson
On Mon, Nov 13, 2017 at 01:30:25PM -0800, Seth Mattinen wrote: > On 11/13/17 12:49, Mike Hammett wrote: > >Keep the humans out of the rack and you should be fine. > > > >Where should I send the invoice?:-P > > > It's easy to keep a rack nice if you take the time. I've spent hours > removing and r

Re: Incoming SMTP in the year 2017 and absence of DKIM

2017-11-29 Thread Chuck Anderson
On Wed, Nov 29, 2017 at 12:17:57PM -0800, Michael Thomas wrote: > The real problem with large enterprise that we found, however, is > that it was really hard to track down every 25 year > old 386 sitting in dusty corners that was sending mail directly > instead of through corpro servers to make cer

Re: Novice sysadmins

2017-12-06 Thread Chuck Anderson
On Wed, Dec 06, 2017 at 02:18:07PM -0500, Harald Koch wrote: > On 6 December 2017 at 13:51, Stephen Satchell wrote: > > > What professional engineers you mentioned do can kill people. I have yet > > to hear of anyone dying from a sysadmin or netadmin screwing up. > > > > Oh c'mon. Now you're be

Re: Switch/Router

2017-12-12 Thread Chuck Anderson
Juniper MX150, except only single PS. But they are cheap enough you could buy two. Upside: most of the MX feature set is available because it is vMX (software) inside. QFX5110 is more expensive but has more ports and dual PS. Downside: Broadcom chipset limitations. On Tue, Dec 12, 2017 at 0

Re: Xbox Live and Teredo

2018-01-03 Thread Tore Anderson
* Martin List-Petersen > Your best bet: set up a Terredo gateway and facilitate these Xboxes as > long as you don't give them native IPv6. This is unlikely to help, as the XB1 doesn't use Teredo relays at all. The XB1 uses Teredo to facilitate direct p2p communication between IPv4 consoles onl

Re: Site-Local/Unique-Local Addressing (IPv6)

2018-01-08 Thread Chuck Anderson
On Mon, Jan 08, 2018 at 05:03:14PM +, Nicholas Warren wrote: > Layman here, I was reviewing RFCs for a local address for IPv6. I came across > two RFCs that seem interesting. > > 3879 Which deprecates Site Local Addresses. > 4193 Which seems to add Unique Local Addresses. > > What is the mai

Re: Juniper MX - Routed pseudowire using LDP - VPWS or VPLS

2018-03-19 Thread Chuck Anderson
Would you mind sharing the solution(s)? I've stiched a L2 PW using lt-interfaces. Thanks. On Mon, Mar 19, 2018 at 11:51:36AM -0500, Ben Bartsch wrote: > I want to thank everyone who contacted me on and off list on this request. > I now have two methods to land a layer 3 endpoint on a layer 2 ci

Re: How are you configuring BFD timers?

2018-03-21 Thread Chuck Anderson
In practice, the vendor's recommendations regarding Routing Engine HA provide a lower bound. I'm just starting out with 1000ms x 3 multiplier, but my network is not national or global. I believe I could go as low as 500ms to keep HA happy. On Wed, Mar 21, 2018 at 09:10:28AM -0400, Jason Lixfe

Re: Cloudflare 1.1.1.1 public DNS different as path info for 1.0.0.1 and 1.1.1.1 london

2018-04-02 Thread Tore Anderson
* Marty Strong via NANOG > Routing from ~150 locations, plenty of redundancy. Any plans to support NSID and/or "hostname.bind" to allow clients to identify which node is serving their requests? For example: $ dig @nsb.dnsnode.net. hostname.bind. CH TXT +nsid [...] ;; OPT PSEUDOSECTION: ; EDNS:

  1   2   3   4   5   >