Re: OOB core router connectivity wish list

2013-01-10 Thread Christopher Morrow
On Thu, Jan 10, 2013 at 9:44 AM, wrote: >> I don't think you can get ethernet and transport out-of-the-area in >> some places at a reasonable cost, so having serial-console I think is >> still a requirement. > > TDM is disappearing quickly in at least some parts of the world. We > may not be quit

Re: OOB core router connectivity wish list

2013-01-10 Thread Christopher Morrow
On Thu, Jan 10, 2013 at 9:51 AM, Mikael Abrahamsson wrote: > On Thu, 10 Jan 2013, Christopher Morrow wrote: > >>> - rs232: please no. it's 2013. I don't want or need a protocol >>> which >>> was designed for access speeds appropriate to th

Re: OOB core router connectivity wish list

2013-01-10 Thread Christopher Morrow
On Thu, Jan 10, 2013 at 12:16 PM, Warren Bailey wrote: > Why is Satellite not a good OOB option? > inside iron boxes satellite signal is 'hard'. getting a roof mounted antenna is extra cost/complexity. or so some thinking goes.

Re: OOB core router connectivity wish list

2013-01-12 Thread Christopher Morrow
On Sat, Jan 12, 2013 at 3:26 PM, Nick Hilliard wrote: > I want OOB with ethernet, MDIX, 100base-TX or 1000base-TX, with DHCP client > support. With a cherry. and auto configuration that works? :) reliably? with your switch/router upstream? :)

Re: Issues with level3?

2013-01-15 Thread Christopher Morrow
On Tue, Jan 15, 2013 at 12:52 PM, joel jaeggli wrote: > On 1/15/13 9:31 AM, Bruce H McIntosh wrote: >> >> On Tue, 2013-01-15 at 17:23 +, Warren Bailey wrote: >>> >>> I still call a /24 a class c too.. :/ lol >> >> More efficient that way - "class c" uses fewer syllables than "slash >> twenty f

Re: Intermittent incorrect DNS resolution?

2013-01-16 Thread Christopher Morrow
On Wed, Jan 16, 2013 at 5:00 PM, Erik Levinson wrote: > Any ideas? Can folks try resolving eriktest.uberflip.com and post > here with details only if it resolves to an IP starting with 76.9 (old IPs)? > for d in $(seq 1 1000); do dig @pdns01.domaincontrol.com. eriktest.uberflip.com >> /tmp/tst

Re: Intermittent incorrect DNS resolution?

2013-01-16 Thread Christopher Morrow
On Wed, Jan 16, 2013 at 5:24 PM, Erik Levinson wrote: > Yes, though I tried way less than 1000 in the loop. > :) given a large list of recursives you could even test resolution through a bunch of recursive servers...

Re: DNS resolver addresses for Sprint PCS/3G/4G

2013-01-16 Thread Christopher Morrow
On Wed, Jan 16, 2013 at 7:13 PM, Jay Ashworth wrote: > I've noticed, for quite some time, that there seems to be a specific category > of slow that I see in using apps on my HTC Supersonic/Sprint EVO, on both > their 3G and 4G networks, and I wonder if it isn't because the defined > resolvers are

Re: Netflow Nfsen Server Hardware

2013-01-17 Thread Christopher Morrow
On Thu, Jan 17, 2013 at 9:05 AM, Joe Loiacono wrote: > Tim Calvin wrote on 01/16/2013 05:51:11 PM: > >> PowerEdge R610 - >> >> 2x Intel E5540, 2.53GHz Quad Core Processor >> >> 32GB RAM >> >> 2x 300gb 10k 2.5" SAS HDD > > Since netflow processing is generally I/O bound, you may want t

Re: Netflow Nfsen Server Hardware

2013-01-17 Thread Christopher Morrow
On Thu, Jan 17, 2013 at 11:16 AM, Joe Loiacono wrote: > christopher.mor...@gmail.com wrote on 01/17/2013 11:01:06 AM: > >> From: Christopher Morrow >> To: Joe Loiacono/USA/CSC@CSC >> Cc: Tim Calvin , "nanog@nanog.org" >> Date: 01/17/2013 11:01 AM >&

Re: Device specifically made for high capacity GRE tunnels for dozens of sites

2013-01-18 Thread Christopher Morrow
On Fri, Jan 18, 2013 at 12:51 PM, A. Pishdadi wrote: > Hello, > > Can anyone recommend a device that will allow for multiple gigabit gre > tunnels with ability to handle up to a million pps? > I know it can be done on a bsd or nix box , or something running junos but > Im looking for something spe

Re: CALEA options for small/midsize ISPs

2013-01-20 Thread Christopher Morrow
On Fri, Jan 18, 2013 at 4:52 PM, Byron Hooper wrote: > Hello All, > > My company is looking at updating our CALEA set up. Our network has > changed appreciably since our initial rollout and I am looking at utilizing > Cisco's Lawful Intercept. I'm wondering what people are using as "Mediator > D

Re: The 100 Gbit/s problem in your network

2013-02-08 Thread Christopher Morrow
On Fri, Feb 8, 2013 at 3:58 PM, Laurent GUERBY wrote: > The "problem" with increasing capacity is that it opens up captive > eyeballs to innovative services from "outside": monopoly operators will > prefer to deal with CDN providers & the like and keep control. there are ways to offer vod/etc wi

Re: The 100 Gbit/s problem in your network

2013-02-11 Thread Christopher Morrow
On Mon, Feb 11, 2013 at 3:01 PM, Scott Helms wrote: > If you're a large MSO (say top 15) > then I can see it with today's technology, but even those guys seem to be > moving in other directions to get out of the provider controlled set top > box model. really? verizon still wants to sell the hell

Re: puck.nether.net outage?

2013-02-13 Thread Christopher Morrow
wait, email outages! wait! :) apparently jared's working on it. On Wed, Feb 13, 2013 at 2:54 PM, Jay Ashworth wrote: > Checking; thanks. > - jra > > Brian Dickson wrote: > >>Anyone know about puck.nether.net? >> >>I read the "outages" list via web archive there, but can't connect >>currently. >

Re: puck.nether.net outage?

2013-02-13 Thread Christopher Morrow
On Wed, Feb 13, 2013 at 3:08 PM, Christopher Morrow wrote: > wait, email outages! wait! :) > > apparently jared's working on it. oh sorry,. 'whats going on' == zombie attack... <http://www.krtv.com/news/bogus-emergency-alert-message-transmitted/> > On

Re: puck.nether.net outage?

2013-02-13 Thread Christopher Morrow
On Wed, Feb 13, 2013 at 3:09 PM, Christopher Morrow wrote: >> >> apparently jared's working on it. sorry, also: "should be better later today" is the update...

Re: Suggestions for managed DNS provider?

2013-02-15 Thread Christopher Morrow
If you have a dns server already, you can get some diversity for free with: http://puck.nether.net/dns/ of course, this week's outage not withstanding, puck has been pretty stable for me for this... On Fri, Feb 15, 2013 at 10:56 AM, Raj Jalan wrote: > http://www.dnsmadeeasy.com > Cost effective

Re: Network security on multiple levels (was Re: NYT covers China cyberthreat)

2013-02-21 Thread Christopher Morrow
On Thu, Feb 21, 2013 at 11:23 AM, Jack Bates wrote: > On 2/21/2013 12:03 AM, Scott Weeks wrote: >> >> I would sure be interested in hearing about hands-on operational >> experiences with encryptors. Recent experiences have left me >> with a sour taste in my mouth. blech! >> >> scott >> >> > > Ag

Re: NYT covers China cyberthreat

2013-02-21 Thread Christopher Morrow
On Thu, Feb 21, 2013 at 3:58 PM, Jack Bates wrote: > The A-team doesn't get caught and detailed no, the A-team has BA Baraccus... he pities the fool who gets caught and detailed... the last thing BA detailed was his black van.

Re: Cloudflare is down

2013-03-04 Thread Christopher Morrow
On Mon, Mar 4, 2013 at 2:31 AM, Saku Ytti wrote: > I know lot of vendors are fuzzing with 'codenomicon' and they appear not to > have flowspec fuzzer. i suspect they fuzz where the money is ... number of users of bgp? number of users of flowspec?

Re: whois.radb.net returning blank results

2013-03-04 Thread Christopher Morrow
On Mon, Mar 4, 2013 at 11:24 AM, Nick Hilliard wrote: > whois -h whois.radb.net 198.41.0.0 fgets: Connection reset by peer :( larry blunk has helped in the past to fix this...

Re: whois.radb.net returning blank results

2013-03-04 Thread Christopher Morrow
s to have come back from the dead: $ whois -h 198.108.0.18 216.239.32.0 | wc -l 7 huzzah! > Kind regards, > > Job > > > On Mar 4, 2013, at 5:36 PM, Christopher Morrow > wrote: > >> On Mon, Mar 4, 2013 at 11:24 AM, Nick Hilliard wrote: >>> whois -h who

Re: Time Warner Cable YouTube throttling

2013-03-06 Thread Christopher Morrow
On Wed, Mar 6, 2013 at 3:11 PM, Randy Carpenter wrote: > > We have recently been having some serious speed issues with YouTube on our > home connections, which are all Time Warner Cable. > Some searching on forums and such revealed a work around: > > Block 206.111.0.0/16 at the router. > this wa

Re: Time Warner Cable YouTube throttling

2013-03-06 Thread Christopher Morrow
On Wed, Mar 6, 2013 at 3:34 PM, Randy Carpenter wrote: > > - Original Message - >> On Wed, Mar 6, 2013 at 3:11 PM, Randy Carpenter >> wrote: >> > >> > We have recently been having some serious speed issues with YouTube >> > on our home connections, which are all Time Warner Cable. >> > So

Re: What do you have in your datacenters' toolbox?

2013-03-10 Thread Christopher Morrow
should all of this end up on a wiki/etc perhaps? like cluepon or equivalent? it seems this question set comes up periodically and having a google-able/bing-able/webcrawler-able reference available would be helpful to everyone. On Sun, Mar 10, 2013 at 2:00 PM, Andrew Latham wrote: > On Sun, Mar 10

Re: traffic accounting

2013-03-12 Thread Christopher Morrow
On Tue, Mar 12, 2013 at 9:53 AM, Joe Abley wrote: > > On 2013-03-12, at 09:30, "Dobbins, Roland" wrote: > >> On Mar 12, 2013, at 8:25 PM, Joe Abley wrote: >> >>> What are better approaches? >> >> Flow telemetry. > > Can you use cflow/jflow/ipfix exports with 1:1 sampling on an MX480 without > an

Re: Odd announcement from AS27048

2013-03-12 Thread Christopher Morrow
On Tue, Mar 12, 2013 at 9:55 AM, Alain Hebert wrote: > Hi, > > On the 5th we notice that 27048 was announcing 2 of ours /24 > > 812 3549 209 721 27064 27047 27047 27047 27048 > maybe 721 doesn't have prefix AND as-path filters? (or 209 maybe?) or intentional filtering gone wrong

Re: What are y'all doing for CALEA compliance?

2013-03-15 Thread Christopher Morrow
On Fri, Mar 15, 2013 at 9:38 AM, Ben Bartsch wrote: > What are you RENs out there doing for CALEA compliance? Is there actually being happy we solved it 6 yrs ago? > any teeth to the law? Our systems guys have tried a product called 'Open teeth as in the 100k/day fine? > CALEA' but the route

Re: What are y'all doing for CALEA compliance?

2013-03-15 Thread Christopher Morrow
zz from Palo > Alto. Worked okay, never did have to execute a warrant or anything. > > > From my Android phone on T-Mobile. The first nationwide 4G network. > > > > Original message > From: Joshua Goldbard > Date: 03/15/2013 8:25 AM (GMT-08:00) &g

Re: [c-nsp] DNS amplification

2013-03-17 Thread Christopher Morrow
On Sun, Mar 17, 2013 at 11:33 AM, Arturo Servin wrote: > > Yes, BCP38 is the solution. > > Now, how widely is deployed? > > Someone said in the IEPG session during the IETF86 that 80% of the > service providers had done it? right... sure. > This raises two questio

Re: [c-nsp] DNS amplification

2013-03-17 Thread Christopher Morrow
On Sun, Mar 17, 2013 at 6:36 PM, Arturo Servin wrote: > > They should publish the spoofable AS. Not for public shame but at > least > to show the netadmins that they are doing something wrong, or if they > are trying to do the good think is not working. > > Or at least a tool to c

Re: [c-nsp] DNS amplification

2013-03-19 Thread Christopher Morrow
On Tue, Mar 19, 2013 at 7:15 AM, Aled Morris wrote: > On 19 March 2013 01:06, Masataka Ohta wrote: > >> LISP merely attempts to replace BGP routing table bloat with >> something a lot worse than that, that is, a lot more serious >> routing table bloat of its mapping system. >> > > I'm guessing you

Re: [c-nsp] DNS amplification

2013-03-19 Thread Christopher Morrow
On Tue, Mar 19, 2013 at 1:45 PM, David Conrad wrote: > On Mar 19, 2013, at 10:12 AM, Christopher Morrow > wrote: >> There's nothing inherent in BGP that would not work with an >> unconstrained growth of the routing table, right? You just need enough >> bandwidt

Re: [c-nsp] DNS amplification

2013-03-19 Thread Christopher Morrow
On Tue, Mar 19, 2013 at 1:57 PM, Jared Mauch wrote: > > On Mar 19, 2013, at 1:50 PM, Christopher Morrow > wrote: > >> On Tue, Mar 19, 2013 at 1:45 PM, David Conrad wrote: >>> On Mar 19, 2013, at 10:12 AM, Christopher Morrow >>> wrote: >>>> The

Re: [c-nsp] DNS amplification

2013-03-19 Thread Christopher Morrow
On Tue, Mar 19, 2013 at 2:12 PM, Joe Abley wrote: > Which is not to say that the prediction is wrong, but at some point you've > got to look at the guy wearing the sign with the crazed expression and wonder > whether he's a couple of sandwiches short of a picnic. i also brought wine to the picn

Re: [c-nsp] DNS amplification

2013-03-19 Thread Christopher Morrow
On Tue, Mar 19, 2013 at 2:12 PM, David Conrad wrote: > Chris, > > On Mar 19, 2013, at 10:50 AM, Christopher Morrow > wrote: >>> With enough thrust, pigs fly quite well. Landing can get messy though... >> I was being serious... > > As was I. :) >>

Re: [c-nsp] DNS amplification

2013-03-19 Thread Christopher Morrow
On Tue, Mar 19, 2013 at 2:44 PM, David Conrad wrote: >> anyway, we seem to mostly agree, which again makes me realize I'm not >> crazy... > > The more likely alternative is that we both are. doh! the unexpected third option! >> but I stil have wine and sandwiches, come along with jabley and I?

Re: [c-nsp] DNS amplification

2013-03-19 Thread Christopher Morrow
On Tue, Mar 19, 2013 at 2:50 PM, Leo Bicknell wrote: > Juniper is actually closer > given their internal ethernet connection model. Basically the question > is why is an RE/RP specific to a particular chassis, or even vendor? openflow/sdn/pce ... congrats! you predicted correctly!

Re: Open Resolver Problems

2013-03-25 Thread Christopher Morrow
On Mon, Mar 25, 2013 at 11:44 AM, wrote: > On Mon, 25 Mar 2013 15:38:01 -, Nick Hilliard said: >> On 25/03/2013 14:33, Mikael Abrahamsson wrote: >> > I would like to be able to request an IP list of open resolvers in my ASN, >> > perhaps sent to the contact details in RIPE whois database to m

Re: alexandria cable cutters?

2013-03-28 Thread Christopher Morrow
On Thu, Mar 28, 2013 at 2:46 AM, Randy Bush wrote: > nyt reports capture of scuba divers attempting to cut telecom egypt > undersea fiber. > > > http://www.nytimes.com/aponline/2013/03/27/world/middleeast/ap-ml-egypt-internet.html how likely is it that a diver can cut an armored cable close

Re: alexandria cable cutters?

2013-03-29 Thread Christopher Morrow
On Thu, Mar 28, 2013 at 4:50 PM, Andrew Latham wrote: > On Thu, Mar 28, 2013 at 4:44 PM, Christopher Morrow > wrote: >> On Thu, Mar 28, 2013 at 2:46 AM, Randy Bush wrote: >>> nyt reports capture of scuba divers attempting to cut telecom egypt >>> underse

Re: alexandria cable cutters?

2013-04-01 Thread Christopher Morrow
On Mon, Apr 1, 2013 at 1:08 PM, Andrew Latham wrote: > Thermal Lances can be started with various heat sources. Some are self > contained for emergency use. > > either way, there's no mention of such a device in the reporting... or picts. right? > On Mon, Apr 1, 2013 at 1:04 PM, Warren Bailey

Re: Wells Fargo getting DDoSed ?

2013-04-05 Thread Christopher Morrow
On Fri, Apr 5, 2013 at 2:33 AM, Ryan Finnesey wrote: > I have been having issues with their iPad App all day > > the boneheads doing the attacking keep calling their shots on pastebin... http://www.reuters.com/article/2013/03/26/net-us-wellsfargo-website-attacks-idUSBRE92P14320130326 which is f

Re: Verizon DSL moving to CGN

2013-04-06 Thread Christopher Morrow
On Sun, Apr 7, 2013 at 1:22 AM, Julien Goodwin wrote: > >> ...CGN will not impact the access, > >> reliability, speed, or security of Verizon’s broadband services. ... > ... > > > > Good luck with that, pretty much by definition it has to do all four > (albeit at levels that shouldn't be detectab

Re: Verizon DSL moving to CGN

2013-04-08 Thread Christopher Morrow
On Mon, Apr 8, 2013 at 2:19 PM, Rajiv Asati (rajiva) wrote: > Yes, MAP (T-Translation or E-Encap mode) is implemented on two regular > routers that I know of - ASR9K and ASR1K. Without that, you are right that > MAP wouldn't have been as beneficial as claimed. > glad it's cross platform... is it

Re: Verizon DSL moving to CGN

2013-04-08 Thread Christopher Morrow
; -Original Message- > From: Chuck Anderson > Date: Monday, April 8, 2013 3:18 PM > To: Rajiv Asati > Cc: Christopher Morrow , nanog list > > Subject: Re: Verizon DSL moving to CGN > > >I think he means patent encumbered. > > > >On Mon, Apr 08, 2013

Re: Verizon DSL moving to CGN

2013-04-08 Thread Christopher Morrow
hat's not been my experience.. see flow-spec for a great example. 'mostly nullified' is .. disingenuous at best. > > > > -Original Message- > From: Christopher Morrow > Date: Monday, April 8, 2013 3:41 PM > To: Rajiv Asati > Cc: Chuck Anderson , nanog

Re: Verizon DSL moving to CGN

2013-04-08 Thread Christopher Morrow
On Mon, Apr 8, 2013 at 11:23 PM, Rajiv Asati (rajiva) wrote: > For ex, there are numerous android apps that are not supported > on many android devices. :=( > I think this is actually up to the developer of the APP not the hardware nor OS manufacturer.

Re: Google incorrect IPv6 GeoIP

2013-04-12 Thread Christopher Morrow
On Fri, Apr 12, 2013 at 11:06 AM, cb.list6 wrote: > Heather, > > I see the same thing from my arpnetworks vps > > no you don't... the dreamhost example used the google ARIN allocation 2607:: this example uses the 2404 APNIC allocation. note that this may still be 'wrong', but .. it's a diff

Re: Google incorrect IPv6 GeoIP

2013-04-12 Thread Christopher Morrow
On Fri, Apr 12, 2013 at 9:48 PM, Scott Howard wrote: > On Fri, Apr 12, 2013 at 5:58 PM, Christopher Morrow < > morrowc.li...@gmail.com> wrote: > >> no you don't... the dreamhost example used the google ARIN allocation >> 2607:: this example uses the 2404 A

Re: Google incorrect IPv6 GeoIP

2013-04-15 Thread Christopher Morrow
On Fri, Apr 12, 2013 at 11:37 PM, Yang Yu wrote: > DNS is actually working correctly I think. > 1) The outputs are from Dreamhost Ashburn, but I saw the same result > over IPv6 at Dreamhost LAX. Different DNS servers. > over ipv6 there might not be enough distinction between locations ... > 2)

Re: Fiber cut in SF Bay Area?

2013-04-16 Thread Christopher Morrow
On Tue, Apr 16, 2013 at 1:48 PM, Ryan Bonnell wrote: > MegaPath reports no service disruptions for DSL services. My latency graph > says otherwise... > that's not a service 'disruption'... that's just longer latency. > > http://i.imgur.com/pwC2oX2.png looks like your packets took the east-co

Re: someone from Sprint

2013-04-18 Thread Christopher Morrow
On Thu, Apr 18, 2013 at 12:05 PM, wrote: > > > paging Softbank/Sony. > don't you mean ericsson? :) > > /bill > > On Thu, Apr 18, 2013 at 11:50:57AM -0400, Jay Ashworth wrote: > > - Original Message - > > > From: bmann...@vacation.karoshi.com > > > > > your not alone... (Sprint is

Re: "It's the end of the world as we know it" -- REM

2013-04-24 Thread Christopher Morrow
On Wed, Apr 24, 2013 at 1:42 PM, Andrew Latham wrote: > FYI, What can ARIN, RIPE et al do to reclaim > http://www.spamhaus.org/drop/drop.txt networks? > nothing since they don't control routability of the prefixes in question?

Re: lag testbed needed

2013-04-26 Thread Christopher Morrow
what platform and what requirements for the network bits? is multiple lag hops good? bad? other? On Fri, Apr 26, 2013 at 5:16 AM, Randy Bush wrote: > a small gaggle of researchers are looking at some measurements over > a setup like this > > .--. .-

Re: Comcast Launches IPv6 for Business Customers

2013-04-29 Thread Christopher Morrow
On Mon, Apr 29, 2013 at 6:38 PM, Brzozowski, John < john_brzozow...@cable.comcast.com> wrote: > FYI for folks that are interested: > > > http://corporate.comcast.com/comcast-voices/comcast-launches-ipv6-for-business-customers > > > hurray! how long until VZ puts out a PR note for Fios Business cus

Re: Comcast Launches IPv6 for Business Customers

2013-04-29 Thread Christopher Morrow
On Tue, Apr 30, 2013 at 12:05 AM, Darren Pilgrim wrote: > On 2013-04-29 15:38, Brzozowski, John wrote: > >> FYI for folks that are interested: >> >> http://corporate.comcast.com/**comcast-voices/comcast-** >> launches-ipv6-for-business-**customers

Re: Google Public DNS Problems?

2013-05-01 Thread Christopher Morrow
On Wed, May 1, 2013 at 4:14 PM, Yang Yu wrote: > It is very courteous to reply a SERVFAIL for requests being rate limited. > > I believe the 'rate-limit' response is actually 'no response' ... though I haven't tested this myself :) > On Wed, May 1, 2013 at 1:17 PM, Andrew Fried > wrote: > > Yo

Re: Google Public DNS Problems?

2013-05-02 Thread Christopher Morrow
On Thu, May 2, 2013 at 10:32 AM, Jay Ashworth wrote: > - Original Message - > > From: "Perry Lorier" > > > On 5/1/13 12:38 PM, Blair Trosper wrote: > > > > > That's all well and good, but I certainly wouldn't expect "nslookup > > > gmail.com " or for "nslookup google.co

Re: Google Public DNS Problems?

2013-05-02 Thread Christopher Morrow
On Thu, May 2, 2013 at 11:51 AM, Jay Ashworth wrote: > - Original Message - > > From: "Christopher Morrow" > > > On Thu, May 2, 2013 at 10:32 AM, Jay Ashworth wrote: > > > > > - Original Message - > > > > From: "Pe

Re: whoami.akamai.net [was: Google Public DNS Problems?]

2013-05-02 Thread Christopher Morrow
On Thu, May 2, 2013 at 2:12 PM, Patrick W. Gilmore wrote: > On May 02, 2013, at 12:12 , Joe Abley wrote: > > On 2013-05-02, at 12:10, Joe Abley wrote: > >> On 2013-05-02, at 11:59, Charles Gucker wrote: > > >>> That's not entirely true.You can easily do lookup for > >>> whoami.akamai.net

Re: Illegal usage of AS51888 (and PI 91.220.85.0/24) from AS42989 and AS57954 (in ukraine)

2013-05-03 Thread Christopher Morrow
On Fri, May 3, 2013 at 1:49 PM, Xavier Beaudouin wrote: > Hello there, > > I'm not sure I'd have lead with 'illegal', certainly 'not friendly' fits though :( also, I'm so glad we're doing well with: 1) provider filters 2) verification of address/number-holder validity 3) route origin aut

Re: Illegal usage of AS51888 (and PI 91.220.85.0/24) from AS42989 and AS57954 (in ukraine)

2013-05-03 Thread Christopher Morrow
On Fri, May 3, 2013 at 2:01 PM, Nick Hilliard wrote: > It will be a brave person who drops both unknown and invalid prefixes. > hopefully it won't involve people being brave :) hopefully good measurement and metrics lead us to a position where things 'just work' and we can do it with confidence!

Re: Illegal usage of AS51888 (and PI 91.220.85.0/24) from AS42989 and AS57954 (in ukraine)

2013-05-03 Thread Christopher Morrow
On Fri, May 3, 2013 at 2:21 PM, Nick Hilliard wrote: > On 03/05/2013 19:08, Christopher Morrow wrote: > > hopefully it won't involve people being brave :) hopefully good > measurement > > and metrics lead us to a position where things 'just work' and w

Re: [apops] BGP Update Report

2013-05-03 Thread Christopher Morrow
On Fri, May 3, 2013 at 6:00 PM, wrote: > BGP Update Report > Interval: 25-Apr-13 -to- 02-May-13 (7 days) > Observation Point: BGP Peering with AS131072 > > TOP 20 Unstable Origin AS > Rank ASNUpds % Upds/PfxAS-Name > 1 - AS58113 64482 2.7% 96.8 -- LIR-AS

Re: Illegal usage of AS51888 (and PI 91.220.85.0/24) from AS42989 and AS57954 (in ukraine)

2013-05-06 Thread Christopher Morrow
On Mon, May 6, 2013 at 12:23 PM, wrote: > On Mon, 06 May 2013 15:27:35 -, Warren Bailey said: > > Illegal or undesired? > > This sort of stuff comes in two flavors: "typo" and "intentionally done > in furtherance of criminal activities". > > The fact that an AS number and matching IP range ar

Re: Illegal usage of AS51888 (and PI 91.220.85.0/24) from AS42989 and AS57954 (in ukraine)

2013-05-06 Thread Christopher Morrow
Device > > > > Original message > From: goe...@anime.net > Date: 05/06/2013 11:31 AM (GMT-08:00) > To: Warren Bailey > Cc: Christopher Morrow ,Valdis Kletnieks > ,NANOG > Subject: Re: Illegal usage of AS51888 (and PI 91.220.85.0/24) from AS

Re: Variety, On The Media, don't understand the Internet

2013-05-14 Thread Christopher Morrow
On Tue, May 14, 2013 at 3:53 PM, Jean-Francois Mezei wrote: > On 13-05-14 13:06, Jay Ashworth wrote: > >> >> http://variety.com/2013/digital/news/netflix-puts-even-more-strain-on-the-internet-1200480561/ >> >> they suggest that Akamai and other ISP-side caching is either not >> affecting these

Re: Variety, On The Media, don't understand the Internet

2013-05-15 Thread Christopher Morrow
On Wed, May 15, 2013 at 11:46 AM, Jean-Francois Mezei wrote: > On 13-05-15 06:24, ja...@towardex.com wrote: > >> We're a small ISP and we reach lot of content via peering just fine. Lot of >> these contents that you speak of (Netflix, Akamai, et al) have open peering >> policies and are present i

Re: Variety, On The Media, don't understand the Internet

2013-05-15 Thread Christopher Morrow
On Wed, May 15, 2013 at 12:59 PM, Jean-Francois Mezei wrote: > On 13-05-15 09:02, Brett Frankenberger wrote: > >> So it's only on the Internet if it uses a provider's transit capacity? > > I made the statement in a context of "the internet is crumbling under > the Netflix load". There have been ma

Re: Inventory and workflow management systems

2013-05-19 Thread Christopher Morrow
On Sun, May 19, 2013 at 1:21 PM, vijay gill wrote: > Resurrecting this thread. Anyone? > What software solution do people use for inventory management for things > like riser/conduit drawdown, fiber inventory, physical topology store, > CLR/DLR, x-connect, contracts, port inventory, etc. > Any exp

Re: Inventory and workflow management systems

2013-05-20 Thread Christopher Morrow
On Mon, May 20, 2013 at 9:53 AM, Justin M. Streiner wrote: > > I haven't looked lately to see what's out there, but I'd imagine there *has* > to be something. I bet this is a market/cost thing... there are ~100 people who want this? it's going to take a few million in SWE resources to build, and

Re: Remote Hands Nation-Wide?

2013-05-20 Thread Christopher Morrow
there's also a mailing-list Warren Kumari setup ... there are folk in the DC area (myself and warren) who have on occasion helped out with these sorts of things. http://www.ne-where.com/cgi-bin/mailman/listinfo/ne-where I think is the thing in question... On Mon, May 20, 2013 at 2:37 PM, Brandon

Re: Bermuda connectivity

2013-05-21 Thread Christopher Morrow
On Tue, May 21, 2013 at 3:37 PM, Christer Swartz wrote: > > Contact either Logic Communications or TeleBermuda. I used to work for the > former. > > --- Christer > > > > On May 21, 2013, at 12:02 PM, Hank Disuko wrote: > >> Hello, >> >> Link Bermuda and Logic Communications are 2 broadband car

Re: A bit of historical news

2013-05-31 Thread Christopher Morrow
On Fri, May 31, 2013 at 9:54 AM, ML wrote: > On 5/31/2013 9:01 AM, David Hubbard wrote: >> Not holding my breath on that; been complaining to my VZ >> rep for v6 on fios for two years now since we have it in >> several remote locations and the most he could find for >> me as of last month was: >>

Re: Remote Hands Nation-Wide?

2013-06-03 Thread Christopher Morrow
On Mon, Jun 3, 2013 at 10:27 PM, Ryan Finnesey wrote: > Great list to know about I just joined thank you > thanks to warren, really.

Re: BGP and Firewalls...

2011-12-07 Thread Christopher Morrow
On Wed, Dec 7, 2011 at 12:31 PM, Gregory Croft wrote: > Hi All, > > > > Does anyone have any experience with using firewalls as edge devices > when BGP is concerned? > > Specifically the Palo Alto series of devices. nokia/checkpoint has done this for ages. what's the problem you have?

Re: Writable SNMP

2011-12-07 Thread Christopher Morrow
On Wed, Dec 7, 2011 at 11:29 AM, Keegan Holley wrote: >> >> > I can see the other comments about interactive commands and bulk >> > read/writes, but what's the harm of doing it on internet connected boxes >> > vs. >> > non-internet boxes.  Just about everyone uses snmp reads in the >> > interwebs

Re: Writable SNMP

2011-12-07 Thread Christopher Morrow
On Wed, Dec 7, 2011 at 11:19 AM, Keegan Holley wrote: > It was more curiosity.  I'm looking in to scripting and starting to get > tired of having to account for ssh/telnet, credentials, differences in 'write a library'... someone once said. > platforms and code from the same vendor and my variou

Re: BGP and Firewalls...

2011-12-07 Thread Christopher Morrow
On Wed, Dec 7, 2011 at 1:04 PM, Gregory Croft wrote: > I'm not having problems... Well, not yet anyways.  :) > > Just investigating to see if there is a reason I shouldn't use a > firewall at the edge versus a dedicated router as well as to see if > anyone can share their specific experience with

Re: Inaccessible network from Verizon, accessible elsewhere.

2011-12-11 Thread Christopher Morrow
On Sun, Dec 11, 2011 at 3:11 PM, Joseph Snyder wrote: > I believe 130.81 is blocked. Traceroute to your gateway address. portions (at least) of that are 19262's loopback/ptp space, they block/rate-limit toward that at their edge.

Re: Inaccessible network from Verizon, accessible elsewhere.

2011-12-11 Thread Christopher Morrow
On Sun, Dec 11, 2011 at 10:28 PM, Matthew Huff wrote: > I'm seeing the same thing from my home lan via fios. I've run a recursive dns > server for years and can't reach the roots. Had to switch to using verizon's > dns servers as forwarders. > business or consumer fios? 3 G0-9-4-7.WASHDC-LCR-

Re: Overall Netflix bandwidth usage numbers on a network?

2011-12-11 Thread Christopher Morrow
On Sun, Dec 11, 2011 at 10:46 PM, Faisal Imtiaz wrote: > Simple, keep traffic off paid ip transit circuits > (I think joel's point was: "peer with amazon, done-and-done") > Faisal > > On Dec 11, 2011, at 10:21 PM, Joel Jaeggli wrote: > >> Netflix uses CDNs for content delivery and the platf

Re: Inaccessible network from Verizon, accessible elsewhere.

2011-12-11 Thread Christopher Morrow
eems rather dastardly of them... considering they deployed that hateful paxfire/nominum garbage on their recursive servers :( -chris > On Dec 11, 2011, at 10:48 PM, "Christopher Morrow" > wrote: > >> On Sun, Dec 11, 2011 at 10:28 PM, Matthew Huff wrote: >>> I

Re: Inaccessible network from Verizon, accessible elsewhere.

2011-12-11 Thread Christopher Morrow
On Mon, Dec 12, 2011 at 1:26 AM, Adam Greene wrote: > 130.81.107.228 hrm... LCR == lata-core-router... something fairly close to you, like 2 router-hops from your first L3 hop... sounds like someone ought to call the vz customer service line and ask for a fix :)

Re: Multiple ISP Load Balancing

2011-12-14 Thread Christopher Morrow
On Wed, Dec 14, 2011 at 2:28 PM, Drew Weaver wrote: > I've asked several times about this in the past; although I learned quickly > to stop asking. > > It seems that the consensus has generally been that the best way to handle > traffic engineering in networks where you have multiple full-feed u

Re: software wanted

2011-12-20 Thread Christopher Morrow
mrtg? www.mrtg.org On Tue, Dec 20, 2011 at 9:21 AM, Gregory Edigarov wrote: > Hi everybody, > > can anybody recomend a piece of software, that could "graph" a live > network scanning it via snmp. > requirements are: > 1. must produce a text output suitable for postproduction. graphviz is > an ide

Re: Any tools to help network security

2011-12-21 Thread Christopher Morrow
On Wed, Dec 21, 2011 at 2:12 PM, David Miller wrote: > On 12/21/2011 2:03 PM, sth...@nethelp.no wrote: >>> >>> We discover there are so many (source) ip not belonging to our network >>> to go to outside. >>> >>> We can block it but don't know how to locate the source. >>> >>> Any tools can be easi

Re: Misconceptions, was: IPv6 RA vs DHCPv6 - The chosen one?

2011-12-28 Thread Christopher Morrow
On Wed, Dec 28, 2011 at 6:16 PM, Doug Barton wrote: > On 12/28/2011 03:13, Iljitsch van Beijnum wrote: >> Second, publishing specifications, implementing them and waiting for >> users to adopt them takes a very, very long time. For DHCPv6 support, >> the time from first publication (2003) until w

next-best-transport! down with ethernet!

2011-12-29 Thread Christopher Morrow
(you forgot to change subj:) On Thu, Dec 29, 2011 at 7:59 AM, Cameron Byrne wrote: > Next topic, ethernet is too chaotic and inefficient to deploy and support > mission critical applications in LAN or WAN or data center. yes, let's get something with say fixed sized packets, ability to have pred

Re: L3 consequences of WLAN offload in cellular networks (was - endless DHCPv6 thread)

2012-01-02 Thread Christopher Morrow
On Fri, Dec 30, 2011 at 9:34 AM, Cameron Byrne wrote: > The state of the industry is the support of nomadic mobility from cellular > to / from Wi-Fi , there is nearly no support of mobile IP that I have seen. > > It is going more and more in this direction. At T-Mobile USA we have > evolved our wi

Re: IPv6 resolvers

2012-01-04 Thread Christopher Morrow
On Wed, Jan 4, 2012 at 3:00 PM, Seth Mos wrote: > Hi Nanog, Owen, > > I was wondering if many people are seeing horrendous latency on the free > Hurricane Electric resolvers? > > Both accessing the v4 or v6 resolvers have horrendous latency. This could > well be coupled to their free nature and

Re: IPv6 resolvers

2012-01-04 Thread Christopher Morrow
does pfsense need real dns hosting maybe? I hear: http://puck.nether.net/dns ... works. On Wed, Jan 4, 2012 at 6:48 PM, Chris Adams wrote: > registrar-servers.com.

Re: Trouble accessing www.nanog.org

2012-01-04 Thread Christopher Morrow
On Wed, Jan 4, 2012 at 6:10 PM, Michael K. Smith - Adhost wrote: > There was a single source IP with 200+ open, active http connections to a > single large media file.  The single IP address was blocked.  The file itself > is still available on the site. oh! so the 200 or so users on tulip.net

Re: incoming smtp from v6 addresses

2012-01-04 Thread Christopher Morrow
On Wed, Jan 4, 2012 at 5:26 AM, Randy Bush wrote: > hold your nose > > zgrep '<=.*\[:' /var/spool/exim/log/main* | wc > zgrep '<=' /var/spool/exim/log/main* | wc > > and the ever failthful bc :) err... one of 4 MX's for home email... (I'll catch the others later on) v6 inbound: $ egrep '\[2.

Re: Trouble accessing www.nanog.org

2012-01-04 Thread Christopher Morrow
On Wed, Jan 4, 2012 at 10:41 PM, Michael K. Smith - Adhost wrote: >> Err, while we're talking about video files and nanog, why is the video >> content still served off (stored content I mean) nanog.org servers? >> Why not use one of the many video serving services? some of which are >> free even

Re: Router Assessment Tool

2012-01-05 Thread Christopher Morrow
On Thu, Jan 5, 2012 at 12:11 PM, Green, Timothy wrote: > Happy New Year All!!! > > I'm trying to perform STIG compliancy on various Cisco equipment.  Has > anybody used the Router Assessment Tool (RAT) for routers and switches?   Any > cheap (free) recommendations?  As a last ditch effort I coul

Re: Trouble accessing www.nanog.org

2012-01-05 Thread Christopher Morrow
On Thu, Jan 5, 2012 at 3:21 PM, Keith Medcalf wrote: > >> Is H.264 Turing-complete ? Is Ogg-Vorbis ? (It seems like those are >> the two reasonable open standard choices.)) > > Okay by me.  Just no "Flash Video Streams" if you please. what about html5?

Re: SSL Certificates

2012-01-06 Thread Christopher Morrow
>> From: Michael Carey [mailto:mca...@kinber.org] >> Sent: Friday, January 06, 2012 9:15 AM >> To: nanog@nanog.org >> Subject: SSL Certificates >> >> Looking for a recommendation on who to buy affordable and reputable >> SSL certificates from?  Symantec, Thawte, and Comodo are the names >> that com

<    5   6   7   8   9   10   11   12   13   14   >