Re: AWS Using Class E IPv4 Address on internal Routing

2021-03-09 Thread Enno Rey
r > > wrote: > > Has anybody seen that also? > > > > P.S.: I'm completely in favor of a complementary RFC assing FUTURE USE > > exclusively to "Between Routers" Link Networks... > > > > -- > > Douglas Fernando Fischer > > Eng?? de Controle e Automao > > > > > > -- > > - Forrest > > > > > > > -- Enno Rey Cell: +49 173 6745902 Twitter: @Enno_Insinuator

Re: Class D addresses? was: Redploying most of 127/8 as unicast public

2021-11-20 Thread Enno Rey
8 is not going to work: https://theinternetprotocolblog.wordpress.com/2019/10/06/some-notes-on-ipv4-address-space/ For the sake of the thread it should be noted that both the reception of and the response to the initial e-mail primarily happened over IPv6. I wish everybody a great weekend Enno -- Enno Rey

Re: IPv6 "bloat"

2022-03-20 Thread Enno Rey
can encapsulate in that. But PPPoE is very 1990 and has its own > >> set of problems.?? For those running encapsulated traffic, > >> authentication to the modem MAC via DHCP that becomes broken.?? And > >> thus far, I have not seen a solution offered to it. > > > > I was honestly more interested in the bloat angle, but this sounds like > > a backend problem of your own making most likely. But I'm not motivated > > to see if it's actually the case or just a misunderstanding. -- Enno Rey Cell: +49 173 6745902 Twitter: @Enno_Insinuator

Re: Request comment: list of IPs to block outbound

2019-10-13 Thread Enno Rey
ple allow that range as blocking it will drop NA/NS packets with the upstream router which in turn can delay the establishment of the BGP session (provided there is one over IPv6). best Enno -- Enno Rey https://theinternetprotocol.blog Twitter: @Enno_Insinuator

Re: ARIN legacy block transfer process

2016-09-30 Thread Enno Rey
it won't be "legacy" any more in the course of the 2nd step and RIPE's 2-yr holding period comes into play (=> it can't be transferred during that time). Note also there's voices recommending not to sign an RSA for legacy space (in certain situations, at least),

Re: BCP for securing IPv6 Linux end node in AWS

2017-05-14 Thread Enno Rey
router discovery gets broken by too tight of filters. > > Thanks for any guidance. > > EKG > -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregist

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
ct IP access to these IP addresses. or, maybe even more efficient, assign all loopbacks from a dedicated netblock which you null-route on the edge/your border devices. best Enno -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 41900

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
t customer's SADDR. > > However I don't think market would generally appreciate the > implications linklocal brings to traceroute, where least bad option > would be just to originate hop-limit exceeded from loop0, with no > visibility on actual interface. some might b

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
Hi, On Sun, Sep 10, 2017 at 12:08:59PM +0200, Job Snijders wrote: > Hi, > > On Sun, Sep 10, 2017 at 11:53:20AM +0200, Enno Rey wrote: > > On Sun, Sep 10, 2017 at 10:47:05AM +0100, Nick Hilliard wrote: > > > Baldur Norddahl wrote: > > > > Loopback interfaces s

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
Hi, On Sun, Sep 10, 2017 at 12:08:59PM +0200, Job Snijders wrote: > Hi, > > On Sun, Sep 10, 2017 at 11:53:20AM +0200, Enno Rey wrote: > > On Sun, Sep 10, 2017 at 10:47:05AM +0100, Nick Hilliard wrote: > > > Baldur Norddahl wrote: > > > > Loopback interfaces s

Re: IPv6 Unique Local Addresses (was Re: New Active Exploit: memcached on port 11211 UDP & TCP being exploited for reflection attacks)

2018-03-02 Thread Enno Rey
al reach(ability), which applies to pretty much all environments nowadays. best Enno > > (As it turns out my ISP prefix has been static for years, but I'm too lazy > to undo all of the work...) > > -- > Harald -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115

Re: IPv6 isn't SMTP

2014-03-27 Thread Enno Rey
http://dotat.at/ > Malin: East 5 or 6. Moderate or rough, occasionally very rough in northwest. > Showers. Good, occasionally moderate. > -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 41

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Enno Rey
overloading) NAT for their firewall environments. A few think about very specific deployments of NPTv6 like stuff for connections to supplier/partner networks (to map those to their own address space) but these are corner cases not even relevant for their "firewalls". best Enno &

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Enno Rey
tion/solution: "when there's a [continued] decision problem, just don't offer a choice". Read, in IPv6 context: "go with GUAs only and only one per interface". best Enno -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Enno Rey
Hi, On Fri, Apr 18, 2014 at 11:59:04AM -0700, Doug Barton wrote: > On 04/18/2014 12:57 AM, Enno Rey wrote: > > I fully second Sander's input. I've been involved in IPv6 planning in a > > number of very large enterprises now and_none_ of them required/asked for >

Re: Automatic IPv6 due to broadcast

2012-04-23 Thread Enno Rey
ess > anyhow). > > > how can enforcing the use of DHCPv6 be counter-productive? > > Remember, Owen was talking about "in a lot of cases". I suspect Owen was > saying > that if you enforce that all source addresses are ones that the DHCPv6 server > hand

Re: IPv6 Default Allocation - What size allocation for Loopback Address

2014-10-13 Thread Enno Rey
esses can be helpful. Something like 2001:db8::1 is easier to remember and type correctly than e.g. 2001:db8:18ba:ff42::1 :) > > Cheers, > Sander > -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +4

Re: Seeking IPv6 Security Resources

2014-11-26 Thread Enno Rey
not requesting that anyone do any new work, just that you point me to > > solid public documents that already exist. Feel free to share on-list or > > privately, both documents you may have authored and those you have found > > helpful. > > > > Thanks! > > ~Chris &g

Re: Estonian IPv6 deployment report

2014-12-27 Thread Enno Rey
om what I understand, in their scenario RAs are not sent to link-local scope all nodes (ff02::1), so that would eliminate another attack vector (depending on the actual processing of RAs on the CPEs). best Enno > > /Anders > -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidel

Re: Android and DHCPv6 again

2015-10-06 Thread Enno Rey
> >> > >> To me it seems that the Macbook has one SLAAC address, one privacy > >> extension address and one DHCPv6 managed address. > >> > >> In fact the CPE manufacturer is a little clever here. They gave m

Re: IPV6 planning

2016-03-08 Thread Enno Rey
entioned 1st (non-temporary) one. best Enno > > > Bj??rn -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregister Mannheim: HR

Re: SNMP DDoS: the vulnerability you might not know you have

2013-07-31 Thread Enno Rey
>> even surpassing DNS, Chargen, or NTP by a wide margin. I have tested a > >> 68 byte query and received responses of up to 30,000 to 60,000 bytes. > >> The trick is to use GetBulkRequest to start enumerating from the first > >> OID and setting max repetitions to a la

Re: NSA able to compromise Cisco, Juniper, Huawei switches

2013-12-30 Thread Enno Rey
ot; m ight be enough to perform the task remotely. have a good one Enno > > --- > Roland Dobbins // <http://www.arbornetworks.com> > > Luck is the residue of opportunity and design. > >

Re: NSA able to compromise Cisco, Juniper, Huawei switches

2013-12-31 Thread Enno Rey
; infected. The hardware industry needs to do better. > > I'm still taking all these revelations with grain of salt, until real > speciment is dissected. > > -- > ++ytti > -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49

Re: turning on comcast v6

2014-01-02 Thread Enno Rey
(or rarely, two) are things that > should have been a post-deployment surprise (to name just a couple pet > peeves of mine... there's more design flaws that could have been easily > avoided had enough people cared to do so). > > Matthew Kaufman > > > -- Enno

Re: 202401100645.AYC Re: IPv4 address block

2024-01-10 Thread Enno Rey via NANOG
) > > > > On 2024-01-07 22:46, KARIM MEKKAOUI wrote: > > > > Hi Nanog Community > > > > Any idea please on the best way to buy IPv4 blocs and what is the price? > > > > Thank you > > > > KARIM > > > > &

Re: v4 and v6 BOGON list

2024-03-21 Thread Enno Rey via NANOG
love to discuss more on the topic. > > URLs: > https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml > https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml > > Thanks, > > Gabriel L. Terry > -