Re: Egress filters dropping traffic

2013-06-30 Thread Peter Ehiwe
I usually do ingress acl on CE facing PE interfaces , that way I can provide one level of anti spoofing on IPs I control . I've not had the need for an egress ACL yet but then again I think it depends on network design and habits from Day 1. One use case though may be to mitigate DDOS attack

Re: ISIS and OSPF together

2013-05-12 Thread Peter Ehiwe
Ospf offered as Pe-ce protocol to L3 mpls vpn customers and Isis as IGP for MPLS Core. Sent from my iPhone On May 12, 2013, at 9:41 AM, Glen Kent glen.k...@gmail.com wrote: Hi, I would like to understand the scenarios wherein the service provider/network admin might run both ISIS and

Should the Facebook's, Google , Amazon's of this world operate a BGP looking glass ?

2013-03-28 Thread Peter Ehiwe
Hi All Should major social networking sites like Facebook,Google and Amazon operate an IP looking glass ? i think they should , here is a short justification write-up i did , using a real life troubleshooting scenario.

Re: Level3 worldwide emergency upgrade?

2013-02-06 Thread Peter Ehiwe
Also received same ... On Wed, Feb 6, 2013 at 10:58 AM, Ray Wong r...@rayw.net wrote: Does anyone have details on tonight's apparent worldwide emergency router upgrade? All I managed to get out of the portal was 30 minutes, Service Affecting (no kidding?) and the NOC line gave me the

Re: looking glass for Level 3

2012-12-28 Thread Peter Ehiwe
I normally use the 3rd one you mentioned but they seem to be down at the moment. Rgds Peter, Sent from my Asus Transformer Pad On Dec 28, 2012 1:51 AM, Tassos Chatzithomaoglou ach...@forthnetgroup.gr wrote: Anyone have any looking glass for Level 3? The following seem not to be working

Re: Strict route filtering at IX?

2012-12-12 Thread Peter Ehiwe
I use a mixture of BGP communities and prefix lists and it scales very well for me . Rgds Peter, Sent from my Asus Transformer Pad On Dec 12, 2012 3:24 AM, Dan Luedtke m...@danrl.de wrote: Hi NANOGers, tl;dr What is the best practice for filtering a large number of prefixes at an internet

MPLS L2VPN monitoring

2012-07-17 Thread Peter Ehiwe
Hello , For those who provide l2vpn services to customers over MPLS , what kind of tools do you use for monitoring the circuits and what kind of values do you proactively monitor I have tools in place to monitor these circuits but i want to know based on group members experiences in order to

Net::Perl::SSH for MRLG

2012-06-26 Thread Peter Ehiwe
Hello All , Has anyone successfully implemented Net::perl::ssh with mrlg . If yes please unicast me. The Perl module works fine but mrlg dosent seem to be able to connect to the routers using that module . .

Re: AUT-NUM ROUTE OBJECT

2012-06-09 Thread Peter Ehiwe
This has been sorted out now. On Fri, Jun 8, 2012 at 5:59 PM, Nick Hilliard n...@foobar.org wrote: On 08/06/2012 17:55, Peter Ehiwe wrote: Authorisation for parent [as-block] using mnt-lower: not authenticated by: RIPE-NCC-RPSL-MNT http://apps.db.ripe.net/whois/lookup

AUT-NUM ROUTE OBJECT

2012-06-08 Thread Peter Ehiwe
Please can any one familiar with route object creation help with understanding this error I am having a weird error with AUT-NUM object , even though i am using the correct maintainer password i keep getting this error message. Authorisation for parent [as-block] using mnt-lower:

Re: VLAN Troubles

2012-03-06 Thread Peter Ehiwe
Verify what protocol the dell switch uses to tag the traffic(from the datasheet) , i have seen some switches that wont trunk .1q with cisco On Tue, Mar 6, 2012 at 5:07 PM, Alan Bryant a...@alanbryant.com wrote: I hope everyone is having a better workday so far than I am. I am trying to clean

Re: VLAN Troubles

2012-03-06 Thread Peter Ehiwe
yep , verify how dell tags the vlans , it may use a proprietory tagging method for the trunk. On Tue, Mar 6, 2012 at 5:36 PM, Alan Bryant a...@alanbryant.com wrote: Thank you for the suggestions, unfortunately none of them are working. I have tried with the uplink in general trunk mode. I

Re: VLAN Troubles

2012-03-06 Thread Peter Ehiwe
cool! On Tue, Mar 6, 2012 at 7:10 PM, Alan Bryant a...@alanbryant.com wrote: Just wanted to say a quick thank you to everyone who chimed in. Like I thought, it turned out to be something very simple and routine. I had not added the vlan to the Cisco switch. I had added it during testing, but

Re: do not filter your customers

2012-02-22 Thread Peter Ehiwe
IOS-XR On 2/23/12, Randy Bush ra...@psg.com wrote: and things when further downhill from there, when telstra also did not filter what they announced to their peers, and the peers went over prefix limits and dropped bgp. Oh! so protections worked! imiho, prefix count is too big a hammer.

Re: IP Transit with netflow report?

2012-02-12 Thread Peter Ehiwe
Why cant you do the netflow from your end? On Mon, Feb 13, 2012 at 7:48 AM, ali baba alibaba123...@gmail.com wrote: Hi Everyone, Hope someone can help me out.. I have some IP Transit links with one of the Tier1s and I need to know the sourcedestination of traffic passing though.. My

DOS ATTACK ON BGP , LPTS ??

2012-02-06 Thread Peter Ehiwe
Hi , What is the best way to mitigate DOS attack against the bgp process of a router , is LPTS on IOS-XR enough ? Rgds Peter