Re: GEO location issue with google

2014-02-07 Thread Jonathan Lassoff
Here's the FAQ on this topic: https://support.google.com/websearch/answer/873?hl=en It links to a contact form where you can ask for some redress. Cheers, jof On Fri, Feb 7, 2014 at 7:20 AM, Praveen Unnikrishnan wrote: > Hi, > > We are an ISP based in UK. We have got an ip block from RIPE whic

Re: Blocking of domain strings in iptables

2014-02-08 Thread Jonathan Lassoff
This is going to be tricky to do, as DNS packets don't necessarily contain entire query values or FQDNs as complete strings due to packet label compression (remember, original DNS only has 512 bytes to work with). You can use those u32 module matches to find some known-bad packets if they're suffi

Re: Fwd: Serious bug in ubiquitous OpenSSL library: "Heartbleed"

2014-04-08 Thread Jonathan Lassoff
For testing, I've had good luck with https://github.com/titanous/heartbleeder and https://gist.github.com/takeshixx/10107280 Both are mostly platform-independent, so they should be able to work even if you don't have a modern OpenSSL to test with. Cheers and good luck (you're going to need it), j

Re: Odd syslog-ng problem

2014-05-11 Thread Jonathan Lassoff
Peter, it's a bit difficult to tell what's going on without seeing the rest of the syslog-ng configuration and your script's source code. However, a couple possibilities come to mind: - Your script is only reading one line at a time. syslog-ng starts a program() output persistently and expects tha

Re: MACsec SFP

2014-06-24 Thread Jonathan Lassoff
On Tue, Jun 24, 2014 at 12:59 AM, Pieter Hulshoff wrote: > On 24-6-2014 8:37, Saku Ytti wrote: >> >> On (2014-06-23 11:13 +0200), Pieter Hulshoff wrote: >> >>> feature and market information for such a device, and I would welcome >>> some >>> feedback from interested people. Discussion about other

Re: BGP Session

2014-07-16 Thread Jonathan Lassoff
Wow -- be careful playing with public eBGP sessions unless you know what you're doing. It can affect the entire Internet. Since you're just connecting to a single upstream ISP, you wont qualify for a public AS number. So, you'll have to work with your upstream ISP to agree on a private AS number y

Re: BGP Session

2014-07-19 Thread Jonathan Lassoff
An Anycasting node. For example, as part of a reliable DNS service. A /24 is usually the smallest prefix length that is portably accepted. Also, applications where connections need to appear to be coming from many source IPs. On Saturday, July 19, 2014, Suresh Ramasubramanian wrote: > A single

Re: BGP Session

2014-07-19 Thread Jonathan Lassoff
m/ It's only ~250 small pages. To practice and experiment, emulate some example configurations with GNS3 and Dynamips, or some Linux VMs with Quagga or BIRD. > > > On Sat, Jul 19, 2014 at 10:06 AM, Jonathan Lassoff wrote: >> >> An Anycasting node. For example, as pa

Re: Firewalls - Ease of Use and Maintenance?

2011-11-08 Thread Jonathan Lassoff
It really depends on what constraints you have. Do you care about: cost? performance? support? Personally, for cost-constrained applications of 1 Gbit/s or less (assuming modestly-sized packets, not all-DNS for example), I like OpenBSD/pf or Linux/netfilter and generic x86 64-bit servers. It's che

Re: Firewalls - Ease of Use and Maintenance?

2011-11-09 Thread Jonathan Lassoff
On Wed, Nov 9, 2011 at 5:24 AM, Nick Hilliard wrote: > On 09/11/2011 12:22, Richard Kulawiec wrote: >> You will find it very difficult to beat pf on OpenBSD for efficiency, >> features, flexibility, robustness, and security.  Maintenance is very >> easy: edit a configuration file, reload, done. >

Re: Firewalls - Ease of Use and Maintenance?

2011-11-10 Thread Jonathan Lassoff
On Wed, Nov 9, 2011 at 12:44 PM, Nick Hilliard wrote: > On 09/11/2011 19:07, C. Jon Larsen wrote: >> >> put the main portion of the conf in subversion as an include file and >> factor out local differences in the configs with macros that are defined >> in >> pf.conf >> >> Easy. > > As I said, it's

Re: Cable standards question

2011-11-14 Thread Jonathan Lassoff
On Mon, Nov 14, 2011 at 7:12 AM, Jon Lewis wrote: > On Mon, 14 Nov 2011, Sam (Walter) Gailey wrote: > > My question is this; Is there an appropriate standard to specify for >> fiber-optic cabling that if it is followed the fiber will be installed >> correctly? Would specifying TIA/EIA 568-C.3, f

Re: ASA log viewer

2011-11-19 Thread Jonathan Lassoff
On Sat, Nov 19, 2011 at 4:51 PM, Duane Toler wrote: > Hey NANOG! > > My employer is deploying CIsco ASA firewalls to our clients > (specifically the 5505, 5510 for our smaller clients). We are having > problems finding a decent log viewer. Several products seem to mean > well, but they all fall

Re: ASA log viewer

2011-11-19 Thread Jonathan Lassoff
On Sat, Nov 19, 2011 at 5:32 PM, Duane Toler wrote: > On Sat, Nov 19, 2011 at 20:04, Jay Ashworth wrote: > > - Original Message - > >> From: "Duane Toler" > > > >> My employer is deploying CIsco ASA firewalls to our clients > >> (specifically the 5505, 5510 for our smaller clients). We

Re: ASA log viewer

2011-11-19 Thread Jonathan Lassoff
On Sat, Nov 19, 2011 at 5:46 PM, Duane Toler wrote: > On Sat, Nov 19, 2011 at 20:30, Jonathan Lassoff wrote: > > On Sat, Nov 19, 2011 at 4:51 PM, Duane Toler wrote: > >> > >> Hey NANOG! > >> > >> My employer is deploying CIsco ASA firewalls to our

Re: IPv6 prefixes longer then /64: are they possible in DOCSIS networks?

2011-11-28 Thread Jonathan Lassoff
On Mon, Nov 28, 2011 at 10:43 PM, wrote: > On Tue, 29 Nov 2011 00:15:02 EST, Jeff Wheeler said: > > > Owen and I have discussed this in great detail off-list. Nearly every > > time this topic comes up, he posts in public that neighbor table > > exhaustion is a non-issue. I thought I'd mention t

Re: Internet Edge and Defense in Depth

2011-12-06 Thread Jonathan Lassoff
I would argue that collapsing all of your policy evaluation and routing for a size/zone/area/whatever into one box is actually somewhat detrimental to stability (and consequently, security to a certain extent). Cramming every little feature under the sun into one appliance makes for great glossy b

Re: L3 East cost maint / fiber 05FEB2012 maintenance

2013-02-05 Thread Jonathan Lassoff
My hunch is that this is fallout and repairs from Juniper PR839412. Only fix is an upgrade. Not sure why they're not able to do a hitless upgrade though; that's unfortunate. Specially-crafted TCP packets that can get past RE/loopback filters can crash the box. --j On Tue, Feb 5, 2013 at 7:39 AM,

Re: L3 East cost maint / fiber 05FEB2012 maintenance

2013-02-05 Thread Jonathan Lassoff
my part; I don't know their network from an internal perspective. --j > > Should an upgrade be performed? Yes, but certainly doesn't have to have > right away or without notice to customers. > > On Tue, Feb 5, 2013 at 11:23 AM, Jonathan Lassoff wrote: > >> My h

Re: AT&T Uverse/DSL Network Engineer DNS question

2013-02-05 Thread Jonathan Lassoff
These appear to be an anycasted service, as I reach different destinations based on my source address. Hopefully each deployment has unique origin IPs for their recursive queries. I would recommend against looking at RIR registration data to determine IP location. There's often little to no corre

Re: AT&T Uverse/DSL Network Engineer DNS question

2013-02-05 Thread Jonathan Lassoff
On Tue, Feb 5, 2013 at 1:10 PM, Jonathan Lassoff wrote: > These appear to be an anycasted service, as I reach different destinations > based on my source address. > > Hopefully each deployment has unique origin IPs for their recursive > queries. > Just confirmed this.

Re: Micro Trenching for Fiber Optic Deployment

2013-02-11 Thread Jonathan Lassoff
I would think that in such a deployment scenario, microtrenching might not be the best bet. Part of the appeal (IMO) of microtrenching in existing pavement is that once filled, the pavement slab provides for some protection and rigidity. If making a small trench into packed dirt, you're much more s

Re: BGP RIB Collection

2013-02-26 Thread Jonathan Lassoff
Personally, I would just use BGP on a PC to collect this information. Place some import/input policy on your eBGP sessions on your edge routers to add communities to the routes such that you can recognize which peers gave you the route. Then, use an iBGP session to a BIRD or Quagga instance from w

Re: need help about free bandwidth graph program

2013-04-08 Thread Jonathan Lassoff
I'm not sure of your specific application, but it sounds to me like netflow/sflow exports would be the most scalable way to do this. For small applications, ntop or bandwidthd can do this. http://www.ntop.org/products/ntop/ http://bandwidthd.sourceforge.net/ Cheers, jof On Mon, Apr 8, 2013 at 12

Re: Cat-5 cables near 200 Paul, SF

2013-05-31 Thread Jonathan Lassoff
I could suggest a few places. Might want to call ahead to make sure they'll have what you need: - Central Computer. Has locations in San Francisco and San Mateo. SF maybe closer, but will take longer with traffic and parking. -- http://www.centralcomputers.com/commerce/misc/sanfrancisco.jsp -- http

Re: Headscratcher of the week

2013-05-31 Thread Jonathan Lassoff
Those are some truly perplexing graphs. Quite strange that it appears linear, as if something is slightly changing over time or growing/shrinking at a constant-ish rate. Do you have throughput or PPS graphs for the intermediate links as well? Any similar correlations in the derivative slope? My o

Re: PRISM: NSA/FBI Internet data mining project

2013-06-06 Thread Jonathan Lassoff
Agreed. I can already pretty much just assume this widespread surveillance is going on. The Bluffdale, Utah facility isn't being built to store nothing. It's happening whether we like it or not. When I care about my privacy, I know that I have to take matters into my own hands. GnuPG and TLS are m

Re: Inaccessible network from Verizon, accessible elsewhere.

2011-12-11 Thread Jonathan Lassoff
On Sat, Dec 10, 2011 at 11:49 AM, NetSecGuy wrote: > I have a Linode VPS in Japan that I can't access from Verizon FIOS, > but can access from other locations. I'm not sure who to blame. > > The host, 106.187.34.33, is behind the gateway 106.187.34.1: > > From FIOS to 106.187.34.1 (this works).

Re: Multiple ISP Load Balancing

2011-12-14 Thread Jonathan Lassoff
The best applications for analyzing paths, that I've seen, have been in-house development projects. So, admittedly, I don't have much experience with commercial products for route optimization. Projects I've seen that analyze "best" paths to Internet destinations via multiple ISPs add instrumentat

Re: subnet prefix length > 64 breaks IPv6?

2011-12-24 Thread Jonathan Lassoff
On Sat, Dec 24, 2011 at 6:48 AM, Glen Kent wrote: > > > > SLAAC only works with /64 - yes - but only if it runs on Ethernet-like > > Interface ID's of 64bit length (RFC2464). > > Ok, the last 64 bits of the 128 bit address identifies an Interface ID > which is uniquely derived from the 48bit MAC

Re: bgp question

2012-01-10 Thread Jonathan Lassoff
On Tue, Jan 10, 2012 at 2:43 PM, Deric Kwok wrote: > Hi all > > When we get newip, we should let the upstream know to expor it as > there should have rule in their side. > > how about upstream provider, does they need to let their all bgp > interconnect to know those our newip? > > If no, Can I k

Re: Linux Centralized Administration

2012-01-12 Thread Jonathan Lassoff
On Thu, Jan 12, 2012 at 1:02 PM, Paul Stewart wrote: > Hey folks. just curious what people are using for automating updates to > Linux boxes? > > > > Today, we manually do YUM updates to all the CentOS servers . just an > example but a good one.  I have heard there are some open source solutions >

Re: enterprise 802.11

2012-01-15 Thread Jonathan Lassoff
On Sun, Jan 15, 2012 at 3:36 PM, Greg Ihnen wrote: > Since we're already top-posting… > > I've heard a lot of talk on the WISPA (wireless ISP) forum that 802.11g/n > starts to fall apart with more than 30 clients associated if they're all > reasonably active. I believe this is a limitation of 80

Re: bgp question

2012-01-18 Thread Jonathan Lassoff
On Wed, Jan 18, 2012 at 5:58 AM, Deric Kwok wrote: > ls it supporting equally multipath in different bgp connections? Most software routing protocols have support for this in their RIBs, but the actual forwarding ability of the underlying kernel will determine the support for this. What platform

Re: Populating BGP from Connected or IGP routes

2012-01-23 Thread Jonathan Lassoff
On Mon, Jan 23, 2012 at 12:46 PM, Eric C. Miller wrote: > Hi all, > > I'm looking for a best practice sort of answer, plus maybe comments on why > your network may or may not follow this. > > First, when running a small ISP with about the equivilent of a /18 or /19 in > different blocks, how sho

Re: Wireless Recommendations

2012-01-30 Thread Jonathan Lassoff
On Mon, Jan 30, 2012 at 12:46 PM, Jim Gonzalez wrote: > Hi, > >                I am looking for a Wireless bridge or Router that will > support 600 wireless clients concurrently (mostly cell phones).  I need it > for a proof of concept. I've had some great luck with a variety of vendors, though n

Re: Hijacked Network Ranges

2012-01-31 Thread Jonathan Lassoff
On Tue, Jan 31, 2012 at 10:19 AM, Grant Ridder wrote: > Hi, > > What is keeping you from advertising a more specific route (i.e /25's)? Most large transits and NSPs filter out prefixes more specific than a /24. Conventionally, at least in my experience, /24's are the most-specific prefix you can

Re: Hijacked Network Ranges

2012-01-31 Thread Jonathan Lassoff
On Tue, Jan 31, 2012 at 10:00 AM, Kelvin Williams wrote: > We've been in a 12+ hour ordeal requesting that AS19181 (Cavecreek Internet > Exchange) immediately filter out network blocks that are being advertised > by ASAS33611 (SBJ Media, LLC) who provided to them a forged LOA. > > [ ...snip...] U

Re: Wireless Recommendations

2012-02-07 Thread Jonathan Lassoff
On Tue, Feb 7, 2012 at 11:19 AM, Arzhel Younsi wrote: > Xirrus say that they can support 640 clients with this device: > http://www.xirrus.com/Products/Wireless-Arrays/XR-Series/XR-4000-Series > I heard about it a couple weeks ago, didn't try it yet. That's a pretty neat product -- it seems like

Re: Wireless Recommendations

2012-02-15 Thread Jonathan Lassoff
On Wed, Feb 15, 2012 at 7:50 PM, Faisal Imtiaz wrote: > Is that because of Channel Spacing ? or some other reason ? I would presume channel spacing. In FCC-land, there are only 3 non-overlapping 20 Mhz bandwidths available. --j

Re: Wireless Recommendations

2012-02-15 Thread Jonathan Lassoff
On Wed, Feb 15, 2012 at 8:41 PM, Joel jaeggli wrote: > On 2/15/12 20:14 , Mario Eirea wrote: >> This is my guess too, i guess there is some bleed over from their antenna >> arrays. > > Even the most directional sector antenna in the world has a back lobe... > and there there's the clients... Agr

Re: 802.11 MAC Point Coordination Function

2012-02-16 Thread Jonathan Lassoff
On Wed, Feb 15, 2012 at 8:13 PM, Jeremy wrote: > I'm doing some research on 802.11 quality of service, congestion control, > etc. I'm trying to find some information on the Point Coordination > Function, a polling based access control method, but I'm having a hard time > finding much in the way of

Re: WW: Colo Vending Machine

2012-02-17 Thread Jonathan Lassoff
On Fri, Feb 17, 2012 at 10:35 AM, Jay Ashworth wrote: > Please post your top 3 favorite components/parts you'd like to see in a > vending machine at your colo; please be as specific as possible; don't > let vendor specificity scare you off. This is a riot! I'd love to have something like this at

Re: WW: Colo Vending Machine

2012-02-17 Thread Jonathan Lassoff
On Fri, Feb 17, 2012 at 10:55 AM, Leo Bicknell wrote: > In a message written on Fri, Feb 17, 2012 at 01:35:15PM -0500, Jay Ashworth > wrote: >> Please post your top 3 favorite components/parts you'd like to see in a >> vending machine at your colo; please be as specific as possible; don't >> let

Re: Concern about gTLD servers in India

2012-03-10 Thread Jonathan Lassoff
On Sat, Mar 10, 2012 at 10:45 AM, Bill Woodcock wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > > On Mar 10, 2012, at 8:05 AM, Suresh Ramasubramanian wrote: >> Sure, if you can find a datacenter that's capable of handling all the >> traffic, and has staff who are able to provide eff

Re: airFiber (text of the 8 minute video)

2012-03-29 Thread Jonathan Lassoff
On Thu, Mar 29, 2012 at 12:33 PM, Oliver Garraux wrote: > I was at Ubiquiti's conference.  I don't disagree with what you're > saying.  Ubiquiti's take on it seemed to be that 24 Ghz would likely > never be used to the extent that 2.4 / 5.8 is.  They are seeing 24 Ghz > as only for backhaul - no c

Re: airFiber (text of the 8 minute video)

2012-03-29 Thread Jonathan Lassoff
On Thu, Mar 29, 2012 at 2:37 PM, Joel jaeggli wrote: > Cost will continue to drop, fact of the matter is the beam width is > rather narrow and they attenuate rather well so you can have a fair > number of them deployed without co-channel interference. if you pack a > tower full of them you're goin

Re: About Juniper MX10 router performance

2012-04-22 Thread Jonathan Lassoff
On Sun, Apr 22, 2012 at 9:05 PM, Md.Jahangir Hossain wrote: > Dear valued member: > > > Wishes all are fine. > > > i need   suggestion from you about Juniper MX10 router performance. i want > to buy  this router for IP Transit provider where i received  all global > routes . Do you have some spec

Re: About Juniper MX10 router performance

2012-04-22 Thread Jonathan Lassoff
On Sun, Apr 22, 2012 at 9:48 PM, Md.Jahangir Hossain wrote: > Thanks jonathan for your reply . > > Actually i have not specific question , i need suggestion about this product > if i purchase this  as IP Transit provider. Only someone with the knowledge of your business and requirements can answe

Re: Squeezing IPs out of ARIN

2012-04-24 Thread Jonathan Lassoff
On Tue, Apr 24, 2012 at 10:32 AM, wrote: > Anyone have any tips for getting IPs from ARIN? For an end-user allocation > they are requesting that we provide customer names for existing allocations, > which is information that will take a while to obtain. They are insisting > that this is standard

Re: Squeezing IPs out of ARIN

2012-04-24 Thread Jonathan Lassoff
On Tue, Apr 24, 2012 at 11:14 AM, Owen DeLong wrote: > That's not entirely true. What you say applies to one possible way for an > ISP to get an allocation. It does not apply at all to end-users. Even for end-user allocations, they would still need to fulfill the requirements of 4.3.3 in the ARIN

Re: Squeezing IPs out of ARIN

2012-04-25 Thread Jonathan Lassoff
On Wed, Apr 25, 2012 at 8:46 AM, Kenneth McRae wrote: > I have never provided the names of end users.. How the address space > would be utilized? Definitely.. But not the names of end users... > Probably because you are an "end user". If you're talking about AS26347, I don't think there is any

Re: VoIP vs POTS (was Re: Operation Ghost Click)

2012-05-03 Thread Jonathan Lassoff
On Thu, May 3, 2012 at 12:25 PM, Luke S. Crawford wrote: > On Thu, May 03, 2012 at 10:59:47AM -0400, Brandt, Ralph wrote: >> One of the first things cellular companies can do is stop overselling >> cellular.  The second is end or raise the price significantly on >> unlimited plans, both voice and

Re: Peer1/Server Beach support for BGP on dedicated servers

2012-05-19 Thread Jonathan Lassoff
On Sat, May 19, 2012 at 3:23 AM, Anurag Bhatia wrote: > Was wondering if there's anyone from Server Beach/Peer1 here. We have a > dedicated server with them which we primarily use for DNS. I am adding > support for anycasting on that one but seems like Peer1 is not supporting > BGP at all. NOC sup

Re: technical contact at ATT Wireless

2012-06-28 Thread Jonathan Lassoff
On Thu, Jun 28, 2012 at 1:50 PM, Christopher Morrow wrote: > of course, but you aren't supposed to be doing that on their network > anyway... so says the nice man from sprint 4 nanogs ago. That, and if you are tunneling in, it's good practice to forward over any DNS traffic as well (or all, depen

Re: Why use PeeringDB?

2012-07-18 Thread Jonathan Lassoff
On Wed, Jul 18, 2012 at 8:43 AM, Chris Grundemann wrote: > I am currently working on a BCOP for IPv6 Peering and Transit and > would very much appreciate some expert information on why using > PeeringDB is a best practice (or why its not). All opinions are > welcome, but be aware that I plan on us

Re: Why use PeeringDB?

2012-07-18 Thread Jonathan Lassoff
On Wed, Jul 18, 2012 at 9:59 AM, Zaid Ali wrote: > The goal is "Source of truth" for any peer to know information at the > Exchange points as well as peering coordinator information. I think it is > a great tool for the peering community and definitely useful. Cons: Will > it be the next RADB? The

Re: dot1q encapsulation overhead?

2012-09-06 Thread Jonathan Lassoff
On Thu, Sep 6, 2012 at 7:55 AM, wrote: > A while back we had a customer colocated vpn router (2911) come in and we put > it > on our main vlan for initial set up and testing. Once that was done, I > created a > separate VLAN for them and a dot1q subinterface on an older, somewhat > overloaded

Re: best way to create entropy?

2012-10-11 Thread Jonathan Lassoff
On Thu, Oct 11, 2012 at 5:01 PM, shawn wilson wrote: > in the past, i've done many different things to create entropy - > encode videos, watch youtube, tcpdump -vvv > /dev/null, compiled a > kernel. but, what is best? just whatever gets your cpu to peak or are > some tasks better than others? Per

Re: best way to create entropy?

2012-10-11 Thread Jonathan Lassoff
On Thu, Oct 11, 2012 at 5:20 PM, Jimmy Hess wrote: > On 10/11/12, shawn wilson wrote: >> in the past, i've done many different things to create entropy - >> encode videos, watch youtube, tcpdump -vvv > /dev/null, compiled a >> kernel. but, what is best? just whatever gets your cpu to peak or are

Re: Detection of Rogue Access Points

2012-10-14 Thread Jonathan Lassoff
On Sun, Oct 14, 2012 at 1:59 PM, Jonathan Rogers wrote: > Gentlemen, > > An issue has come up in my organization recently with rogue access points. > So far it has manifested itself two ways: > > 1. A WAP that was set up specifically to be transparent and provided > unprotected wireless access to

Re: Whats so difficult about ISSU

2012-11-08 Thread Jonathan Lassoff
On Thu, Nov 8, 2012 at 8:13 PM, Mikael Abrahamsson wrote: > On Thu, 8 Nov 2012, Phil wrote: > >> The major vendors have figured it out for the most part by moving to >> stateful synchronization between control plane modules and implementing >> non-stop routing. > > > NSR isn't ISSU. > > ISSU conta

Re: Keeping Track of Data Usage in GB Per Port

2014-10-15 Thread Jonathan Lassoff
On Wed, Oct 15, 2014 at 12:38 PM, Colton Conor wrote: > So based on the response I have received so far it seems cable was a > complicated example with service flows involved. What if we are talking > about something simpler like keeping track of how much data flows in and > out of a port on a swi

Re: Zayo opinions

2014-11-12 Thread Jonathan Lassoff
Zayo owns what used to be Abovenet. In my experience, your experience will vary from market to market, depending on the network you're based on. As of late, we've had repeated capacity issues and packet loss in the San Francisco Bay Area, however other metros have been perfectly stable. On Wed,

Re: Prism continued

2013-06-12 Thread Jonathan Lassoff
Logstash and Splunk are both wonderful, in my experience. What sets them apart from just a plain grep(1) is that they build an index that points keywords to to logging events (lines). What if you're looking for events related to a specific interface or LSP? Not a problem with a modest log volume,

Re: Blocking TCP flows?

2013-06-13 Thread Jonathan Lassoff
Are you trying to block flows from becoming established, knowing what you're looking for ahead of time, or are you looking to examine a stream of flow establishments, and will snipe off some flows once you've determined that they should be blocked? If you know a 5-tuple (src/dst IP, IP protocol, s

Re: Blocking TCP flows?

2013-06-13 Thread Jonathan Lassoff
hat this can only match against strings contained within a single packet; this doesn't do L4 stream reconstruction. You can do some incredibly-parallel stuff with ntop's PF_RING code, if you blow more traffic through a single core than it can chew through. It all depends on what you'

Re: WaPo writes about vulnerabilities in Supermicro IPMIs

2013-08-15 Thread Jonathan Lassoff
The primary point of IPMI for most users is to be able to administer and control the box when it's not running. Using the host itself as a firewall is the quickest way to get that BMC online, but it kinda defeats the purpose. On Thu, Aug 15, 2013 at 7:46 PM, Jay Ashworth wrote: > - Original

Re: The state of TACACS+

2013-12-30 Thread Jonathan Lassoff
I don't understand why vendors and operators keep turning to TACACS. It seems like they're often looking to Cisco as some paragon of best security practices. It's a vulnerable protocol, but some times the only thing to choose from. One approach to secure devices that can support only TACACS or RAD

Re: San Francisco Power Outage

2007-07-24 Thread Jonathan Lassoff
nsferred to the generator, while apparently large DCs that are charging premium rates, do not. Cordially Patrick Giagnocavo [EMAIL PROTECTED] -- Jonathan Lassoff echo thejof | sed 's/^/jof@/;s/$/.com/' http://thejof.com GPG: 0xC8579EE5

Re: senate.gov down

2008-06-07 Thread Jonathan Lassoff
Querying from here (inside 69.59.128.0/18), I see sen-dmzp.senate.gov (156.33.195.40) and sen-dmzs.senate.gov (156.33.195.41) returning authoritatively for senate.gov: -- [EMAIL PROTECTED]:~$ dig @156.33.195.40 senate.gov. in a ; <<>> DiG 9.3.4 <<>> @156.33.195.40 senate.gov. in a ; (1

Re: Layer 2 vs. Layer 3 to TOR

2009-11-12 Thread Jonathan Lassoff
Excerpts from David Coulson's message of Thu Nov 12 13:07:35 -0800 2009: > You could route /32s within your L3 environment, or maybe even leverage > something like VPLS - Not sure of any TOR-level switches that MPLS > pseudowire a port into a VPLS cloud though. I was recently looking into this (

Re: news from Google

2009-12-03 Thread Jonathan Lassoff
Excerpts from Charles Wyble's message of Thu Dec 03 10:44:49 -0800 2009: > 8.8.8.8 6.6.6.6 would have been really really funny. :) Nice IPs from Level 3, huh? 6.6.6.6 belongs to the US Army. --j

Re: I don't need no stinking firewall!

2010-01-05 Thread Jonathan Lassoff
Excerpts from Dobbins, Roland's message of Tue Jan 05 20:23:28 -0800 2010: Roland, On many of the points you've made, I totally agree. Well-managed hardware routers that have support for ACLs in hardware are a great firewall for things that have a relatively small set of rules (e.g. "any:any -> s

Re: DDoS mitigation recommendations

2010-01-28 Thread Jonathan Lassoff
Excerpts from Christopher Morrow's message of Thu Jan 28 08:55:34 -0800 2010: > On Thu, Jan 28, 2010 at 10:00 AM, Jeffrey Lyon > wrote: > > IntruGuard is highly customizable both from the GUI and CLI with the > > engineer's assistance. Its the highest performance, reasonably priced box > > that we

Re: Using private APNIC range in US

2010-03-18 Thread Jonathan Lassoff
Excerpts from Jaren Angerbauer's message of Thu Mar 18 09:22:40 -0700 2010: > Thanks all for the on / off list responses on this. I acknowledge I'm > playing in territory I'm not familiar with, and was a bad idea to jump > to the conclusion that this range was private. I made that assumption > or

Re: what about 48 bits?

2010-04-04 Thread Jonathan Lassoff
Excerpts from John Peach's message of Sun Apr 04 08:17:28 -0700 2010: > On Sun, 4 Apr 2010 11:10:56 -0400 > David Andersen wrote: > > > There are some classical cases of assigning the same MAC address to every > > machine in a batch, resetting the counter used to number them, etc.; > > unless

Re: IPv6 Availability on XO

2011-05-28 Thread Jonathan Lassoff
On Mon, May 23, 2011 at 4:39 PM, Ryan Rawdon wrote: > I've heard some mixed reports of XO's IPv6 availability - some that they have > full deployment/availability, but others like the answer back from our XO > reseller that XO does not offer IPv6 on circuits under 45mbit/s. > > What is the exper