Re: what's that smell?

2002-10-08 Thread Barb Dijker
At 11:51 AM 10/8/02 -0700, John M. Brown wrote: We in the technical community need to develop or modify our tools to make those tasks easier. So right. I don't know what the fuss is all about. Not that our little ISP matters in the grand scheme of things... but we've always blocked RFC1918

Re: Who does source address validation? (was Re: what's that smell?)

2002-10-08 Thread Barb Dijker
At 10:34 PM 10/8/02 +0100, Stephen J. Wilcox wrote: Not all IP packets require a return, indeed only TCP requires it. It is quite possible to send data over the internet on UDP or ICMP with RFC1918 source addresses and for their to be no issue. Examples of this might be icmp fragments or UDP

Re: Security Practices question

2002-10-03 Thread Barb Dijker
I was assuming a more complex configuration than the wide-open one advocated by Barb, which seems to add little to no security benefit. I'm sorry I wasn't clear on this point; of course pushing out a single file to n machines shouldn't be a problem. Of course. And a complex sudoers setup can

Re: Security Practices question

2002-10-02 Thread Barb Dijker
At 05:48 PM 10/2/02 -0700, just me wrote: In an environment where every sysadmin is interchangable, and any one of them can be woken up at 3am to fix the random problem of the day, you tell me how to manage 'sudoers' on 4000 machines. Sudo provides for one master sudoers file that you can copy

Re: 95th percentile

2002-08-19 Thread Barb Dijker
I have a home grown program that gives 95th percentile from mrtg data files... and can display it on the mrtg page as an odometer (using fly) or text for a monthly report. Because of mrtg data reduction, it isn't exact (weighted on the most recent three days), but it does its best to