Re: Is NAT can provide some kind of protection?

2011-01-14 Thread Douglas Otis
On 1/14/11 4:10 PM, William Herrin wrote: On Fri, Jan 14, 2011 at 2:43 PM, Owen DeLong wrote: Ah, but, the point here is that NAT actually serves as an enabling technology for part of the attack he is describing. As for strictly passive attacks, like the so-called drive by download, it is not

RE: Is NAT can provide some kind of protection?

2011-01-14 Thread George Bonser
> From: William Herrin > Sent: Friday, January 14, 2011 4:11 PM > To: nanog@nanog.org > Subject: Re: Is NAT can provide some kind of protection? > > On Fri, Jan 14, 2011 at 2:43 PM, Owen DeLong wrote: > > Ah, but, the point here is that NAT actually serves as an enabling > > technology for par

Re: Is NAT can provide some kind of protection?

2011-01-14 Thread William Herrin
On Fri, Jan 14, 2011 at 2:43 PM, Owen DeLong wrote: > Ah, but, the point here is that NAT actually serves as an enabling > technology for part of the attack he is describing. Hi Owen, Doug's comments on that were pretty abstract, so let me try to ground it a little bit. He basically observed tha

Re: Routing Suggestions

2011-01-14 Thread Sam Silvester
On Fri, Jan 14, 2011 at 8:20 PM, Randy Bush wrote: > i'm with jon and the static crew.  brutal but simple. Depending on how the interconnect is built, using the "permanent" keyword along with the static route may be worth investigating also if you want the static route to stay in place, if you wi

Re: Is NAT can provide some kind of protection?

2011-01-14 Thread Douglas Otis
On 1/14/11 11:49 AM, Jack Bates wrote: On 1/14/2011 1:43 PM, Owen DeLong wrote: Ah, but, the point here is that NAT actually serves as an enabling technology for part of the attack he is describing. Another example where NAT can and is a security negative. The fact that you refuse to acknowledge

INDOSAT Internet Network Provider NOC Contact

2011-01-14 Thread Tim Donahue
Hi all, Sorry for the noise, but I was wondering if anyone has a NOC or BGP knowledgeable contact with INDOSAT Internet Network Provider (AS4761). I have emailed the hostmaster@ email address listed in the WHOIS contact, and tried calling the phone number listed as well (disconnect message).

The Cidr Report

2011-01-14 Thread cidr-report
This report has been generated at Fri Jan 14 21:11:53 2011 AEST. The report analyses the BGP Routing Table of AS2.0 router and generates a report on aggregation potential within the table. Check http://www.cidr-report.org for a current version of this report. Recent Table History Date

BGP Update Report

2011-01-14 Thread cidr-report
BGP Update Report Interval: 06-Jan-11 -to- 13-Jan-11 (7 days) Observation Point: BGP Peering with AS131072 TOP 20 Unstable Origin AS Rank ASNUpds % Upds/PfxAS-Name 1 - AS18025 25153 1.9%1676.9 -- ACE-1-WIFI-AS-AP Ace-1 Wifi Network 2 - AS32528 1

Re: Single AS Number for multiple prefixes in different country

2011-01-14 Thread Patrick W. Gilmore
On Jan 14, 2011, at 11:03 AM, Michel de Nostredame wrote: > On Fri, Jan 14, 2011 at 3:33 AM, Bogdan wrote: >> allowas-in will do the trick > > Provided your uplink ISP does not filter out that. Why would your upstream filter that out? I would get a new upstream if they do. -- TTFN, patrick

RE: Single AS Number for multiple prefixes in different country

2011-01-14 Thread Eric Morin
I have 5 discrete networks across Canada using one ASN (will be down to 2 by end of year!). We accept a default (along with full tables) to route between discrete networks. Not very elegant but gets the job done. Eric -Original Message- From: Harris Hui [mailto:harris@gmail.com] Se

Re: Is NAT can provide some kind of protection?

2011-01-14 Thread Jack Bates
On 1/14/2011 1:43 PM, Owen DeLong wrote: Ah, but, the point here is that NAT actually serves as an enabling technology for part of the attack he is describing. Another example where NAT can and is a security negative. The fact that you refuse to acknowledge these is exactly what you were accusing

Re: Is NAT can provide some kind of protection?

2011-01-14 Thread Owen DeLong
On Jan 14, 2011, at 6:24 AM, William Herrin wrote: > On Thu, Jan 13, 2011 at 11:50 PM, Douglas Otis wrote: >> Unfortunately, a large number of web sites have been compromised, where an >> unseen iFrame might be included in what is normally safe content. A device >> accessing the Internet throug

Re: BGP route-map options

2011-01-14 Thread Greg Whynott
haha… yeah that is not a copy and paste but rather me just typing that out. the proper spelling in the config is being used, or the american spelling… english is the worse language… thanks again, greg On Jan 14, 2011, at 12:52 PM, Thomas Magill wrote: > Wait... > > Does the router even acce

Re: BGP route-map options

2011-01-14 Thread Greg Whynott
thanks Thomas, I opened a ticket with Cisco and am pestering other lists so i'm not bothering anyone with my operational issues. it does accept it under address-family, and doing a show bgp indicates something is going on: ASR1004#show bgp | inc \ \ 150\ *> 132.248.13.0/24 205.211.94.145

RE: BGP route-map options

2011-01-14 Thread Thomas Magill
Wait... Does the router even accept 'neighbour' instead of ' neighbor'? -Original Message- From: Greg Whynott [mailto:greg.whyn...@oicr.on.ca] Sent: Friday, January 14, 2011 9:00 AM To: nanog@nanog.org list Subject: BGP route-map options Following a few documents on how to use route-m

RE: BGP route-map options

2011-01-14 Thread Thomas Magill
Try doing it under the 'address-family ipv4'? I've never seen any version of IOS not take it. -Original Message- From: Greg Whynott [mailto:greg.whyn...@oicr.on.ca] Sent: Friday, January 14, 2011 9:00 AM To: nanog@nanog.org list Subject: BGP route-map options Following a few documents o

Re: BGP route-map options

2011-01-14 Thread ryanL
1) this is probably better posed over at cisco-nsp instead of NANOG. 2) i really hope you aren't using the canadian version of 'neighbor' On Fri, Jan 14, 2011 at 9:59 AM, Greg Whynott wrote: > Following a few documents on how to use route-maps to set preference of > routes (related to my last thr

BGP route-map options

2011-01-14 Thread Greg Whynott
Following a few documents on how to use route-maps to set preference of routes (related to my last thread regarding asymmetrical routing) all the ones I have looked at today (about 6or so) use the below method to apply the route map under the router section: router bgp YOURAS# neighbour x.x.x.x

Re: Routing Suggestions

2011-01-14 Thread Christopher Morrow
On Fri, Jan 14, 2011 at 8:54 AM, Dorn Hetzel wrote: >> >> Randy, I know my solution was right.  I don't need your blessing. >> >> Go fuck yourself. >> >> > > It's nice to see we've really elevated the level of discourse around here :) yea... back to the coffee urn for me! (sometimes folks have h

Re: Single AS Number for multiple prefixes in different country

2011-01-14 Thread Michel de Nostredame
On Fri, Jan 14, 2011 at 3:33 AM, Bogdan wrote: > On 14.01.2011 12:06, Patrick W. Gilmore wrote: > allowas-in will do the trick > Provided your uplink ISP does not filter out that. -- Michel~

Re: Cisco Sanitization

2011-01-14 Thread Jason LeBlanc
I was fired from eBay several years ago for posting to NANOG trying to help others deal with the dDoS issues of those days, nothing said was fair for termination IMO. Using a personal account may be prudent. Now I hardly ever even post. On 01/12/2011 03:17 PM, Michael Hallgren wrote: Le mer

Re: Is NAT can provide some kind of protection?

2011-01-14 Thread William Herrin
On Thu, Jan 13, 2011 at 11:50 PM, Douglas Otis wrote: > Unfortunately, a large number of web sites have been compromised, where an > unseen iFrame might be included in what is normally safe content.  A device > accessing the Internet through a NATs often creates opportunities for > unknown sources

Re: Routing Suggestions

2011-01-14 Thread Jack Bates
On 1/14/2011 7:49 AM, Jon Lewis wrote: My boss calls NANOG the Masters of the Universe conference. Beats "Unruly kids with toys" conference. ;) Jack

Re: Is NAT can provide some kind of protection?

2011-01-14 Thread Jack Bates
On 1/13/2011 10:50 PM, Douglas Otis wrote: Unfortunately, a large number of web sites have been compromised, where an unseen iFrame might be included in what is normally safe content. A device accessing the Internet through a NATs often creates opportunities for unknown sources to reach the devi

Re: Routing Suggestions

2011-01-14 Thread Randy Bush
> My name is Joe, not jon, Randy. congrats. but i was speaking of jon lewis. randy

Re: Routing Suggestions

2011-01-14 Thread Dorn Hetzel
> > Randy, I know my solution was right. I don't need your blessing. > > Go fuck yourself. > > It's nice to see we've really elevated the level of discourse around here :) -dorn

Re: Routing Suggestions

2011-01-14 Thread Jon Lewis
On Fri, 14 Jan 2011, Joe Hamelin wrote: On Fri, Jan 14, 2011 at 1:50 AM, Randy Bush wrote: i'm with jon and the static crew. brutal but simple. My name is Joe, not jon, Randy. But what can I expect from a man that used the phrase "tell him to go fuck himself" when I put my hand out in gre

Re: Routing Suggestions

2011-01-14 Thread Matthew S. Crocker
- Original Message - > From: "Joe Hamelin" > To: "Randy Bush" , "NANOG list" > Sent: Friday, January 14, 2011 6:50:05 AM > Subject: Re: Routing Suggestions > On Fri, Jan 14, 2011 at 1:50 AM, Randy Bush wrote: > > i'm with jon and the static crew. brutal but simple. > > My name is Joe,

Re: Routing Suggestions

2011-01-14 Thread Joe Hamelin
On Fri, Jan 14, 2011 at 1:50 AM, Randy Bush wrote: > i'm with jon and the static crew. brutal but simple. My name is Joe, not jon, Randy. But what can I expect from a man that used the phrase "tell him to go fuck himself" when I put my hand out in greeting back at Atlanta NANOG in 2001, when y

Re: Single AS Number for multiple prefixes in different country

2011-01-14 Thread Bogdan
On 14.01.2011 12:06, Patrick W. Gilmore wrote: > On Jan 14, 2011, at 4:58 AM, Harris Hui wrote: > >> We have an AS Number AS2 and have 2 /24 subnets belongs to this AS >> Number. It is using in US and peering with US Service Providers now. >> >> We are going to deploy another site in Asia, can

Re: Single AS Number for multiple prefixes in different country

2011-01-14 Thread Patrick W. Gilmore
On Jan 14, 2011, at 4:58 AM, Harris Hui wrote: > We have an AS Number AS2 and have 2 /24 subnets belongs to this AS > Number. It is using in US and peering with US Service Providers now. > > We are going to deploy another site in Asia, can we use the same AS Number > AS2 and have 2 other

Single AS Number for multiple prefixes in different country

2011-01-14 Thread Harris Hui
Hi, We have an AS Number AS2 and have 2 /24 subnets belongs to this AS Number. It is using in US and peering with US Service Providers now. We are going to deploy another site in Asia, can we use the same AS Number AS2 and have 2 other /24 subnets and peering with other Asia Service Provi

Re: Routing Suggestions

2011-01-14 Thread Randy Bush
i'm with jon and the static crew. brutal but simple. if you want no leakage, A can filter the prefix from it's upstreams, both can low-pref blackhole it, ... randy

Re: co-location and access to your server

2011-01-14 Thread Randy Bush
> Cruzio in Santa Cruz ... > Their 1U offer comes with limited access to your server, only from 10AM > to 6 PM. I find that not acceptable. sheesh d00d, you ever been to cruz? randy