Re: Slashdot: UK ISP PlusNet Testing Carrier-Grade NAT Instead of IPv6

2013-01-18 Thread Andre Tomt
(resending with nanog-approved address..) On 18. jan. 2013 01:30, Jeff Kell wrote: On 1/17/2013 6:50 PM, Owen DeLong wrote: Vonage will, in most cases fail through CGN as will Skype, Xbox-360, and many of the other IM clients. Not sure about Vonage, but Skype, Xbox, and just about everything

Re: High throughput bgp links using gentoo + stipped kernel

2013-05-19 Thread Andre Tomt
On 18. mai 2013 17:39, Nick Khamis wrote: Hello Everyone, We are running: Gentoo Server on Dual Core Intel Xeon 3060, 2 Gb Ram Ethernet controller: Intel Corporation 82571EB Gigabit Ethernet Controller (rev 06) Ethernet controller: Intel Corporation 82573E Gigabit Ethernet Controller (rev 03)

Re: High throughput bgp links using gentoo + stipped kernel

2013-05-19 Thread Andre Tomt
(oops, I keep forgetting to send with my nanog identity..) On 19. mai 2013 17:48, Nick Khamis wrote: We do use a statefull iptables on our router, some forward rules... This is known to be on of our issues, not sure if having a separate iptables box would be the best and only solution for this?

Re: High throughput bgp links using gentoo + stipped kernel

2013-05-19 Thread Andre Tomt
Minor nitpicking I know.. On 20. mai 2013 01:23, Ben wrote: With Linux you have to disable reverse path filtering, screw around with iptables to do bypass on stateful filtering. You dont have to "screw around" with iptables. The kernel wont load the conntrack modules/code unless you actually

Re: Typical additional latency for CGN?

2012-10-10 Thread Andre Tomt
On 08. okt. 2012 11:27, Daniel Roesen wrote: On Sun, Oct 07, 2012 at 03:18:56PM -0700, Cameron Byrne wrote: On Oct 7, 2012 1:48 PM, "Tom Limoncelli" wrote: Have there been studies on how much latency CGN adds to a typical internet user? I'd also be interested in anecdotes. Anecdote. Sub-

Re: Linux: concerns over systemd adoption and Debian's decision to switch

2014-10-22 Thread Andre Tomt
On 22. okt. 2014 03:40, Matt Palmer wrote: > On Tue, Oct 21, 2014 at 07:20:12PM -0500, Jimmy Hess wrote: >> Yikes. What's next? Built-in DNS server + LDAP/Hesiod + Kerberos + >> SMB/Active Directory client and server + Solitaire + Network >> Neighborhood functionality built into the program ?

.biz DNSSEC borked

2013-06-22 Thread Andre Tomt
Seems the entire .biz tld is failing DNSSEC validation now. All of my DNSSEC validating resolvers are tossing all domains in .biz. The non-signed domains too of course because trust of the tld itself cannot be established. http://dnssec-debugger.verisignlabs.com/nic.biz

Re: .biz DNSSEC borked

2013-06-22 Thread Andre Tomt
On 22. juni 2013 20:45, Andre Tomt wrote: Seems the entire .biz tld is failing DNSSEC validation now. All of my DNSSEC validating resolvers are tossing all domains in .biz. The non-signed domains too of course because trust of the tld itself cannot be established. http://dnssec

Re: If you're on LinkedIn, and you use a smart phone...

2013-10-26 Thread Andre Tomt
On 26. okt. 2013 08:06, Jimmy Hess wrote: Perhaps a prudent countermeasure would be to redirect all POP, IMAP, and Webmail access to your corporate mail server from all of LinkedIn's IP space to a "Honeypot" that will simply log usernames/credentials attempted. The list of valid crede

Re: Mikrotik Cloud Core Router and BGP real life experiences?

2013-12-27 Thread Andre Tomt
On 27. des. 2013 17:26, Jim Shankland wrote: Routing table size was completely not an issue in our environment; we were looking at a number of concurrent flows in the high-5 to low-6-digit range, and since Linux uses a route cache, it was that number, rather than the number of full tables we car