Re: Strict route filtering at IX?

2012-12-12 Thread Peter Ehiwe
I use a mixture of BGP communities and prefix lists and it scales very well for me . Rgds Peter, Sent from my Asus Transformer Pad On Dec 12, 2012 3:24 AM, "Dan Luedtke" wrote: > Hi NANOGers, > > tl;dr What is the best practice for filtering a large number of > prefixes at an internet exchange

Re: looking glass for Level 3

2012-12-28 Thread Peter Ehiwe
I normally use the 3rd one you mentioned but they seem to be down at the moment. Rgds Peter, Sent from my Asus Transformer Pad On Dec 28, 2012 1:51 AM, "Tassos Chatzithomaoglou" wrote: > Anyone have any looking glass for Level 3? > > The following seem not to be working > > http://www.level3.co

Re: Level3 worldwide emergency upgrade?

2013-02-06 Thread Peter Ehiwe
Also received same ... On Wed, Feb 6, 2013 at 10:58 AM, Ray Wong wrote: > Does anyone have details on tonight's apparent worldwide emergency > router upgrade? All I managed to get out of the portal was 30 minutes, > "Service Affecting" (no kidding?) and the NOC line gave me the > recording about

Should the Facebook's, Google , Amazon's of this world operate a BGP looking glass ?

2013-03-28 Thread Peter Ehiwe
Hi All Should major social networking sites like Facebook,Google and Amazon operate an IP looking glass ? i think they should , here is a short justification write-up i did , using a real life troubleshooting scenario. http://www.slideshare.net/peterehiwe/why-major-content-providers-need-an-ip

Re: ISIS and OSPF together

2013-05-12 Thread Peter Ehiwe
Ospf offered as Pe-ce protocol to L3 mpls vpn customers and Isis as IGP for MPLS Core. Sent from my iPhone On May 12, 2013, at 9:41 AM, Glen Kent wrote: > Hi, > > I would like to understand the scenarios wherein the service > provider/network admin might run both ISIS and OSPF together insid

DOS ATTACK ON BGP , LPTS ??

2012-02-06 Thread Peter Ehiwe
Hi , What is the best way to mitigate DOS attack against the bgp process of a router , is LPTS on IOS-XR enough ? Rgds Peter

Re: DOS ATTACK ON BGP , LPTS ??

2012-02-06 Thread Peter Ehiwe
Thanks Roland, Does anyone have a recommended value for tuning LPTS based on experience ? Rgds Peter On Tue, Feb 7, 2012 at 7:45 AM, Dobbins, Roland wrote: > > On Feb 7, 2012, at 1:43 PM, Peter Ehiwe wrote: > > > What is the attacker spoofs the correct peering address , > &g

Re: IP Transit with netflow report?

2012-02-12 Thread Peter Ehiwe
Why cant you do the netflow from your end? On Mon, Feb 13, 2012 at 7:48 AM, ali baba wrote: > Hi Everyone, > > Hope someone can help me out.. I have some IP Transit links with one of the > Tier1s and I need to know the source<>destination of traffic passing > though.. My provider gives me a stra

Re: do not filter your customers

2012-02-22 Thread Peter Ehiwe
IOS-XR On 2/23/12, Randy Bush wrote: >>> and things when further downhill from there, when telstra also did not >>> filter what they announced to their peers, and the peers went over >>> prefix limits and dropped bgp. >> Oh! so protections worked! > > imiho, prefix count is too big a hammer. > >

Re: VLAN Troubles

2012-03-06 Thread Peter Ehiwe
Verify what protocol the dell switch uses to tag the traffic(from the datasheet) , i have seen some switches that wont trunk .1q with cisco On Tue, Mar 6, 2012 at 5:07 PM, Alan Bryant wrote: > I hope everyone is having a better workday so far than I am. > > I am trying to clean up the network f

Re: VLAN Troubles

2012-03-06 Thread Peter Ehiwe
yep , verify how dell tags the vlans , it may use a proprietory tagging method for the trunk. On Tue, Mar 6, 2012 at 5:36 PM, Alan Bryant wrote: > Thank you for the suggestions, unfortunately none of them are working. > > I have tried with the uplink in general & trunk mode. I have allowed > all

Re: VLAN Troubles

2012-03-06 Thread Peter Ehiwe
cool! On Tue, Mar 6, 2012 at 7:10 PM, Alan Bryant wrote: > Just wanted to say a quick thank you to everyone who chimed in. Like I > thought, it turned out to be something very simple and routine. I had > not added the vlan to the Cisco switch. I had added it during testing, > but I removed all t

AUT-NUM ROUTE OBJECT

2012-06-08 Thread Peter Ehiwe
Please can any one familiar with route object creation help with understanding this error I am having a weird error with AUT-NUM object , even though i am using the correct maintainer password i keep getting this error message. Authorisation for parent [as-block] using mnt-lower:

Re: AUT-NUM ROUTE OBJECT

2012-06-09 Thread Peter Ehiwe
This has been sorted out now. On Fri, Jun 8, 2012 at 5:59 PM, Nick Hilliard wrote: > On 08/06/2012 17:55, Peter Ehiwe wrote: > > Authorisation for parent [as-block] > > using mnt-lower: > > not authenticated by: RIPE-NCC-RPSL-MNT > > http://apps.db

Net::Perl::SSH for MRLG

2012-06-26 Thread Peter Ehiwe
Hello All , Has anyone successfully implemented Net::perl::ssh with mrlg . If yes please unicast me. The Perl module works fine but mrlg dosent seem to be able to connect to the routers using that module . .

MPLS L2VPN monitoring

2012-07-17 Thread Peter Ehiwe
Hello , For those who provide l2vpn services to customers over MPLS , what kind of tools do you use for monitoring the circuits and what kind of values do you proactively monitor I have tools in place to monitor these circuits but i want to know based on group members experiences in order to imp

Re: Egress filters dropping traffic

2013-06-30 Thread Peter Ehiwe
I usually do ingress acl on CE facing PE interfaces , that way I can provide one level of anti spoofing on IPs "I control" . I've not had the need for an egress ACL yet but then again I think it depends on network design and habits from Day 1. One use case though may be to mitigate DDOS attack