Re: Facebook down!! Alert!

2010-10-06 Thread christian koch
+1 On Wed, Oct 6, 2010 at 12:57 AM, Zaid Ali wrote: > I think the Outages mailing list is more appropriate for this. > > > On 10/5/10 9:46 PM, "Mike Lyon" wrote: > > > Same here in SF Bay Area > > > > On Tue, Oct 5, 2010 at 9:44 PM, James Smith >wrote: > > > >> At 1:20am here in Canada,

Re: Weird Nexus AD

2010-10-29 Thread christian koch
in x/y, x= preference, y= metric am= adjacency module, *= best unicast route a better place to have asked this would be c-nsp hth -ck On Fri, Oct 29, 2010 at 7:21 PM, Colby Glass wrote: > We're seeing an AD of 2 on some routes on our Nexus 7k. I can't find > anything (Google) to indicate wher

Re: Trying to Make Sense of the Comcast/Level 3 Dispute

2010-12-03 Thread christian koch
my guess is the info for that was pulled off comcast's route server, where only tata is seen BGP routing table entry for 98.137.128.0/19, version 681406320 Paths: (8 available, best #8, table Default-IP-Routing-Table) Not advertised to any peer 6453 10310 36752 36752, (received & used) 68

Re: ALT-DB Question

2010-12-08 Thread christian koch
http://markmail.org/message/7vm3wk6kcnkqvonj On Wed, Dec 8, 2010 at 7:38 PM, Charles Gucker wrote: > On Wed, Dec 8, 2010 at 1:25 PM, Chadwick Sorrell > wrote: > > Hello, > > > > I'm sending a new MAINT-AS object to the db-ad...@altdb.net, but it > > doesn't appear to be in the database after a

Re: Facebook issue

2010-12-16 Thread christian koch
stop On Thu, Dec 16, 2010 at 1:34 PM, andrew.wallace < andrew.wall...@rocketmail.com> wrote: > Anyone having issue with Facebook? > > Andrew > > > > > >

Re: ALTDB Problems

2009-10-28 Thread christian koch
On Tue, Oct 27, 2009 at 11:21 AM, Steve Rubin wrote: > > ALTDB is free and you get what you pay for. > > However. Donations to http://www.nanog.org/scholarships/abha.php would > probably get requests done a lot faster. > > > -- > Steve Rubin/ AE6CH / http://www.altdb.net/ > E

Re: Anyone notice strange announcements for 174.128.31.0/24

2009-01-12 Thread Christian Koch
> > ] part of the experiment is to measure the difference between the amount > ] of nanog mail lorenzo drew in 2005 by pre-announcing with the amount we > ] get in 2009 while not pre-announcing. :) > > This statement is an admission that he set out to annoy people, > annoy them enough they would

Re: SNMP and syslog forwarders

2009-03-04 Thread Christian Koch
you can easily configure syslog-ng for forwarding/relaying syslog msgs to another box On Wed, Mar 4, 2009 at 1:51 AM, Sam Stickland wrote: > Hi, > > It's looking like running all of our traps and syslog through a couple of > relay devices (and then onwards to the various NMS's) would be quite a w

Re: AS path weirdness

2009-03-22 Thread Christian Koch
a private asn in (parentheses) indicates a bgp confederation, i would tend to think that there is some sort of mis-config or software bug in one of the routers in that path thats leaking it On Sun, Mar 22, 2009 at 7:51 AM, Jason Lewis wrote: > I was under the impression that MRT only used bracket

Re: attacks on MPLS?

2009-04-09 Thread Christian Koch
They presented on the same topic at shmoocon, not sure if the info is any more updated for BH EUROPE, but here is the pres they did in Feb09 http://www.shmoocon.org/slides/rey_mende_all_your_packets_v05.pdf On Thu, Apr 9, 2009 at 10:15 AM, Hector Herrera wrote: > On Thu, Apr 9, 2009 at 9:56 AM

Re: Fiber cut in SF area

2009-04-09 Thread Christian Koch
Monterey Highway I think On Thu, Apr 9, 2009 at 11:11 AM, Mike Lyon wrote: > Anyone know where the actual cut is? > > On 4/9/09, David W. Hankins wrote: > > On Thu, Apr 09, 2009 at 08:14:15AM -0700, Craig Holland wrote: > >> Just dropping a note that there is a fiber cut in the SF area (I have

Re: attacks on MPLS?

2009-04-09 Thread Christian Koch
oh and heres the vid so you can see the demos http://www.shmoocon.org/2009/videos/AllYourPackets-Rey.m4v On Thu, Apr 9, 2009 at 11:28 AM, Christian Koch wrote: > They presented on the same topic at shmoocon, not sure if the info is any > more updated for BH EUROPE, but here is the pre

Re: Fiber cut in SF area

2009-04-09 Thread Christian Koch
nice article on bitgravity blog regarding the cuts.. http://sandbox.bitgravity.com/blog/2009/04/09/destroy-the-internet-with-a-hacksaw/ On Thu, Apr 9, 2009 at 11:22 AM, Charles Wyble wrote: > > > Ravi Pina wrote: > >> News coverage: >> >> http://cow.org/r/?5459 >> http://cow.org/r/?545a >> >>

Re: Cable Colors

2008-06-16 Thread Christian Koch
i guess thats what having a good data center manager is all about - being prepared and keeping things uniform and to a standard they define... On Mon, Jun 16, 2008 at 10:15 PM, Michael Smith <[EMAIL PROTECTED]> wrote: > Hi Joe: > > > > Hello Newbie here (hopefully I have the correct list), > > >

Elanti Inteligent Routing..

2008-06-16 Thread Christian Koch
anyone with firsthand operational experience with this? pro's, con's? feedback? ck

Re: Replacement for Avaya CNA/RouteScience

2008-07-03 Thread Christian Koch
agreed. i see the most benefit from these boxes geared towards networks with critical apps that are latency intensive and more than a handful of transit providers than i do for a smaller provider.. depending on how many upstreams you're juggling, its not that hard to create some traffic engineerin

Re: Replacement for Avaya CNA/RouteScience

2008-07-03 Thread Christian Koch
rovider so they don't have to waste money on highly skilled engineers? maybe i am just thinking "inside" the box at the moment, from an engineers view..if so my apologies for steering off course -christian On Thu, Jul 3, 2008 at 4:51 PM, Eric Van Tol <[EMAIL PROTECTED]> wrote: &

Re: Multiple DNS implementations vulnerable to cache poisoning

2008-07-08 Thread Christian Koch
surely the tool is not focused at a dns operator/admin audience.. On Tue, Jul 8, 2008 at 8:20 PM, Owen DeLong <[EMAIL PROTECTED]> wrote: > The tool, unfortunately, only goes after the server it thinks you are using > to > recurse from the client where you're running your browser. > > This make

Re: Cogent problems in Chicago area?

2008-07-10 Thread Christian Koch
...what did big 'ol 174 say? On Thu, Jul 10, 2008 at 12:31 PM, Brandon Galbraith < [EMAIL PROTECTED]> wrote: > Is anyone seeing Cogent issues in the Chicago area? We have several racks > with them, and our connectivity just dropped off. > > -brandon > -- ^christian$

Re: AS 54271

2008-07-13 Thread Christian Koch
interestingly, before july 7th these prefixes were originating from another private as - 65501, until sometime that day routes were withdrawn from 65501 and began being announced from 54271... On Sun, Jul 13, 2008 at 4:10 PM, Joel Jaeggli <[EMAIL PROTECTED]> wrote: > Scott Morris wrote: > >> W

Re: SANS: DNS Bug Now Public?

2008-07-22 Thread Christian Koch
matasano blogged about it cache of the original post here.. http://beezari.livejournal.com/ matasano apologizes here http://www.matasano.com/log/1105/regarding-the-post-on-chargen-earlier-today/ dan posts (13 - 0) 13 days left to blackhat opposed to the 0 days since the details were discussed

Re: Arbitrary de-peering

2008-07-28 Thread Christian Koch
http://www.renesys.com/blog/2008/03/you_cant_get_there_from_here_1.shtml http://www.renesys.com/blog/2008/03/he_said_she_said_cogent_vs_tel.shtml http://www.renesys.com/blog/2008/03/telia_and_cogent_kiss_and_make_1.shtml On Mon, Jul 28, 2008 at 11:24 AM, William Waites <[EMAIL PROTECTED]> wrote

Re: Hardware capture platforms

2008-07-29 Thread Christian Koch
solera makes some nice boxes also On Tue, Jul 29, 2008 at 7:35 PM, Jared Mauch <[EMAIL PROTECTED]> wrote: > Check out packet forensics depending on what your ultimate requirements > are. > > Jared Mauch > > > On Jul 29, 2008, at 7:10 PM, "John A. Kilpatrick" <[EMAIL PROTECTED]> > wrote: > > >>

Re: Public shaming list for ISPs announcing other ISPs IP space by mistake

2008-08-14 Thread Christian Koch
-BEGIN PGP MESSAGE- Version: GnuPG v1.4.8 (Darwin) Comment: http://getfiregpg.org owFdVAtsFFUUbRdaZRIoQfkUxLzwaRHWbgtIC0RA8YNfsEBAIJTZmbe7r52ZN857 s8tWgSIoUiqoAUUQlE8aAxYrgUpbqKCQEotSykeCKRLoR2qBQspXqN43uy3iJvub ue/cc849dz7q2inGFbtZH3r58It/SbFFnZd5E9OGp2WkD89IHT1iZPoon9/0Z3Hd fIFoeNLWKR+bs

Re: Public shaming list for ISPs announcing other ISPs IP space by mistake

2008-08-14 Thread Christian Koch
n On Thu, Aug 14, 2008 at 11:34 AM, Christian Koch <[EMAIL PROTECTED]> wrote: > -BEGIN PGP MESSAGE- > Version: GnuPG v1.4.8 (Darwin) > Comment: http://getfiregpg.org > > owFdVAtsFFUUbRdaZRIoQfkUxLzwaRHWbgtIC0RA8YNfsEBAIJTZmbe7r52ZN857 > s8tWgSIoUiqoAUUQlE8aAxYrg

Re: Smallest netblock that providers will accept?

2008-08-18 Thread Christian Koch
a lot of providers have their bgp/routing policy published somewhere online/in their community guide for instance, you can find L3's policy in their irr objects ( whois -h whois.radb.net as3356) there are also plenty of community guides available here - http://www.onesc.net/communities/ Christia

Re: Revealed: The Internet's well known BGP behavior

2008-08-27 Thread Christian Koch
what do mpls, ipsec tunnels, ssl have anything to do with someone announcing your address space and hijacking youre prefixes?? i think we all know this is not new.. and these guys didnt claim it to be.. they're not presenting this to a 'xNOG' crowd, defcon has a different type of audience..im not

Re: HurricaneElectric

2008-08-29 Thread Christian Koch
you might want to check the obvious first :) http://www.tunnelbroker.net/forums/ [EMAIL PROTECTED] On Fri, Aug 29, 2008 at 5:34 AM, Colin Alston <[EMAIL PROTECTED]> wrote: > Is anyone from Hurricane Electric/TunnelBroker.net here? > >

Re: only WV FIBER now peering with Atrivo / Intercage

2008-09-06 Thread Christian Koch
On Sat, Sep 6, 2008 at 8:30 PM, Anton Kapela <[EMAIL PROTECTED]> wrote: > On Sat, Sep 6, 2008 at 6:33 PM, Patrick W. Gilmore <[EMAIL PROTECTED]> wrote: > >> Anton's post that GX is still providing them transit is a bit curious, since >> I was under the impression GX had severed all ties with Atrivo

Re: community real-time BGP hijack notification service

2008-09-12 Thread Christian Koch
I've been using IAR and PHAS, but I've noticed IAR seems to work a bit better and much faster. Recently we changed our ASN, and seconds after we started announcing prefixes under thew new ASN I received the email alerts from IAR. I did not receive anything from PHAS. Although I have in the past,

Re: community real-time BGP hijack notification service

2008-09-12 Thread Christian Koch
athan Ward <[EMAIL PROTECTED]> wrote: > On 13/09/2008, at 1:14 AM, Christian Koch wrote: > >> Maybe a better idea would be if you were able to input your origin asn >> and define your upstreams and/or peers, to be alerted on as well. (ie: >> Do not alert me on any pat

Re: New Intercage upstream

2008-09-12 Thread Christian Koch
looks to me as if they are just using output of 'top' and displaying it there as it were for network stats. output of top from one of my boxes.. top - 11:39:48 up 3 days, 20:56, 3 users, load average: 0.07, 0.21, 0.16 On Fri, Sep 12, 2008 at 11:13 AM, Bill Woodcock <[EMAIL PROTECTED]> wrote:

Re: LoA (Letter of Authorization) for Prefix Filter Modification?

2008-09-16 Thread Christian Koch
I dont mind, i think it is another good step towards 'good filtering' but...i think the PITA part is downstream 'clueless' customers, who may need an explanation on prefix hijacking and the state of the internet today, and that these are all just combined efforts to minimize the risk of accepting a

Re: LoA (Letter of Authorization) for Prefix Filter Modification?

2008-09-16 Thread Christian Koch
good point... :) On Tue, Sep 16, 2008 at 10:24 AM, Jon Lewis <[EMAIL PROTECTED]> wrote: > On Tue, 16 Sep 2008, Christian Koch wrote: > >> I dont mind, i think it is another good step towards 'good filtering' >> but...i think the PITA part is >> downstre

Re: Atrivo/Intercage: Now Only 1 Upstream

2008-09-17 Thread Christian Koch
On Wed, Sep 17, 2008 at 1:07 PM, Christopher Morrow <[EMAIL PROTECTED]> wrote: > On Wed, Sep 17, 2008 at 1:01 PM, Gadi Evron <[EMAIL PROTECTED]> wrote: >> On Wed, 17 Sep 2008, Skywing wrote: >>> >>> Putting things in the automated bogon feeds (e.g. Team Cymru) that are not >>> strictly bogons (unal

Re: prefix hijack by ASN 8997

2008-09-22 Thread Christian Koch
I received a phas notification about this today as well... I couldn't find any relevant data confirming the announcement of one of my /19 blocks, until a few minutes ago when i checked the route views bgplay (ripe bgplay turns up nothing) and can now see 8997 announcing and quickly withdrawing my

Re: prefix hijack by ASN 8997

2008-09-22 Thread Christian Koch
- > > --- [EMAIL PROTECTED] wrote: --- > From: "Christian Koch" <[EMAIL PROTECTED]> > > I couldn't find any relevant data confirming the announcement of one > of my /19 blocks, until a few minutes ago when i checked the route > views bgplay (ripe bgplay

Re: prefix hijack by ASN 8997

2008-09-22 Thread Christian Koch
TED]> wrote: > Looking up some of my prefixes in PHAS and BGPPlay, I too see my > prefixes being advertised by 8997 for a short time. It looks like it > happened around 1222091563 according to PHAS. > > Was this a mistake or something else? > > Justin > > > Christian

Re: prefix hijack by ASN 8997

2008-09-22 Thread Christian Koch
Bgplay on routeviews, not the ripe one :) Christian On 9/23/08, Hank Nussbacher <[EMAIL PROTECTED]> wrote: > On Mon, 22 Sep 2008, Christian Koch wrote: > > Strange that RIPE RIS search doesn't show it: > http://www.ris.ripe.net/perl-risapp/risearch.html > but yet y

Re: prefix hijack by ASN 8997

2008-09-22 Thread Christian Koch
Ahah, so my first theory was on the right track :) Thanks for sharing the info... Christian On Tue, Sep 23, 2008 at 2:33 AM, Andree Toonk <[EMAIL PROTECTED]> wrote: > Hi, > > .-- My secret spy satellite informs me that at Tue, 23 Sep 2008, Hank > Nussbacher wrote: > >> I too spotted this via

Re: ARIN Routing Registry vs RADB vs X

2008-09-25 Thread Christian Koch
Sounds ridiculous...radb mirrors arins db, I don't see why they are trying to force you to use radb. You can query whois.radb.net and you will be able to see your arin objects... Did they give you a reason on WHY you should have to use RADB? Christian On Thu, Sep 25, 2008 at 6:38 PM, Craig H

Re: Cox DNS resolver engineers?

2008-09-25 Thread Christian Koch
a good place to get noc contact info is: as22773.peeringdb.com On Thu, Sep 25, 2008 at 11:47 PM, William Pitcock <[EMAIL PROTECTED]> wrote: > Hi, > > Anyone involved in Cox's DNS resolver engineering and maintainance: can > you contact me off list to resolve some problems? > > Thanks! > > Willi

Re: More ASN collissions

2009-12-10 Thread christian koch
i believe john curran just posted the follow up to the list yesterday on this matter On Thu, Dec 10, 2009 at 10:51 AM, Dobbins, Roland wrote: > > On Dec 11, 2009, at 1:35 AM, Jared Mauch wrote: > > > As always, good research by renesys. > > What happens when an ASN is requested, and it's discover

Re: box.net network engineer

2011-02-10 Thread christian koch
On Thu, Feb 10, 2011 at 12:01 PM, Andrew Matthews wrote: > Can someone with the box.net engineering group email me off list. > > I have a peering issue with you guys at any2 in socal. > One would think, if you are interconnecting with another network you should have some contact info for them. Or

Re: ipv6 day DDoS threat?

2011-06-07 Thread christian koch
I can confirm, it was indeed Verisign who emailed me with the same message. I am slightly disappointed by this course of action, needless to say I am not surprised, because this kind of behavior is expected from sales people. I had a bit more respect for them, however... -ck On Tue, Jun 7, 201