Any tool or theorical method on detecting number of computer behind a NAT box?

2008-04-07 Thread Joe Shen
hi, Sharing internet access bandwidth between multiple computers is common today. Usually, bandwidth sharer bought a little router with NAT/PAT function. After connecting that box to a ADSL/LAN access link, multiple computer could share a single access link. I heard some company provi

load balancing and fault tolerance without load balancer

2008-03-14 Thread Joe Shen
hi, we plan to set up a web site with two web servers. The two servers should be under the same domain name. Normally, web surfing load should be distributed between the servers. when one server fails, the other server should take all of load automatically. When fault sever recovers, loa

RE: Tools to measure TCP connection speed

2008-03-10 Thread Joe Shen
fast as it > can, and when it reaches the total the OS can handle > it lets you know the time passed. Take that and > divide by total number of connections and you get > the average It won't be very accurate, but it > will give you some kind of idea. > > Please forgive

Tools to measure TCP connection speed

2008-03-10 Thread Joe Shen
hi, is there any tool could measue e2e TCP connection speed? e.g. we want to measue the delay between the TCP SYN and receiving SYN ACK packet. Joe __ Search, browse and book your hotels and flights through Yaho

question on algorithm for radius based accouting

2007-08-16 Thread Joe Shen
hi, I 'google' algorithm for radius based accounting. but can't find anything. My question is: what's the best algorithm for constrcting broadband access record from radius accouting packets? To my knowledge, some system takes: Record Accouting-on packet arriving time -> re

Network Parameters on Subscriber side feelings

2007-06-18 Thread Joe Shen
hi, is there any work or research on measuring method for subscriber (customer)side feelings of network service? It seems that e2e ping delay, packet loss may miss some important factor when we consider subscriber's feelings. Joe __ Yahoo! Movies

Policy of Dial-up session processing

2007-05-11 Thread Joe Shen
hi, Maybe this is out-of-topic ,but I can't find any place where could find answer for this question. If this is intrusive, just ingore it please. my question is : how does ISP do with DSL dial-up sessions which pass the accouting period time. E.g. If a customer subscribe DSL ser

Re: barak-online.net icmp performance vs. traceroute/tcptraceroute, ssh, ipsec

2007-05-07 Thread Joe Shen
I agree with Dale. The problem should be with e2e TCP performance. Maybe there is misconfigured firewall which block SYN or ACK packet. Or, packet larger than 128B is dropped. As you can find in your data, ping and traceroute show different response speed. Maybe you could try layer4 tracerout

Re: Ratio between Number of Radius Accouting Server and Number of Radiuis Authentication Server

2007-05-03 Thread Joe Shen
AIL PROTECTED]> wrote: > > On 5/3/07, Joe Shen <[EMAIL PROTECTED]> wrote: > > Is there any recommendation on Ratio between > number of > > radius accouting server and number of radius > > authentication server, if accouting and > authentication > > are

Ratio between Number of Radius Accouting Server and Number of Radiuis Authentication Server

2007-05-03 Thread Joe Shen
Is there any recommendation on Ratio between number of radius accouting server and number of radius authentication server, if accouting and authentication are executed by different hardware platform ? Is there any way to estimate the burst rate of radius protocol packet in ISP network? thanks i

Re: Could it be possible to extend PPPoE Error code?

2007-03-27 Thread Joe Shen
> > client device. In my experience there are almost > no client devices that > > actually display the "Reply-Message", but as > always YMMV. > > It seems to me this would be something best reserved > for the radius > server, not the end-user to track. > To my opion, if customer's PC could s

Could it be possible to extend PPPoE Error code?

2007-03-26 Thread Joe Shen
hi, We provide broadband access by ADSL. The cucurrent session number and access port is controled by radius server. E.g. an PPPoE account can ONLY be used with a designated access port, and current session of that account is limited to 3 or 5. If a subscriber dials with a username. mis

Application management in ISP network

2006-10-18 Thread Joe Shen
It is heard many ISPs are implementing or plan to implement application management facilities. With such tools/facilities, it is said they could control applications in their network, such as blocking BT, degrade QoS of e2e VoIP , or control attacking traffic. Is there anyone could tell me ho

Re: Anycast applicable to Radius Server Farm - further questions?

2006-05-08 Thread Joe Shen
> > > JS> Could it be any problem with AAA procedure? > > UDP is anycast-friendly. Your biggest problems are > likely to be > authentication database replication/synchronization > and merging > accounting records... i.e., nothing really different > from standard > RADIUS deployments. What I m

Re: Anycast applicable to Radius Server Farm ?

2006-05-08 Thread Joe Shen
e > RADIUS, things like EAP that require multiple > exchanges of RADIUS > requests typically require state to be maintained in > the single > RADIUS server that is processing the entire EAP > sequence. > > regards > > Hugh > > > On 8 May 2006, at 14:07, Jo

Anycast applicable to Radius Server Farm ?

2006-05-07 Thread Joe Shen
Hi, we have a radius server farm. there is a L4 switch installed behind all servers. Incoming AAA packets are switched by L4 switch to different servers. In previous days we met a couple of problems with L4 switch which degraded our service a lot. Could it be possible to implement IPv4 Anycas

Security control in DSL access network

2006-03-25 Thread Joe Shen
Hi, Is there any books or papers on carrier level DSL access network and LAN access network? Specifically, it should analysis the futures of DSL network and security problems in DSL networks. Joe __ Meet your soulmate! Yahoo! Asia presents M

Re: Security problem in PPPoE connection

2006-03-12 Thread Joe Shen
> >What's your method to deal with such problem? Will > CHAP in PPPoE help? > > That may help against password sniffing but won't > help against sniffing > traffic by an active attacker once the session has > been established. > Also, you'll have to revisit all CPE to explicitly > disable PAP,

Security problem in PPPoE connection

2006-03-11 Thread Joe Shen
Hi, We are facing problem with PPPoE in ethernet access network. To provide high speed access, 10Mbps/100Mbps ethernet is used as access method. But, we found some guy 'steal' some other's account by listening to broadcasting packets, and they also set up 'phishing' PPPoE server to catch those

Re: Identify amount of traffic to special IP address in Radius

2006-02-28 Thread Joe Shen
> why in the world > would you want to do something like that rather than > have another > device generate flow records which you then can > correlate with RADIUS > accounting data? > The reason is the cost of system building. As there are a lot of broadband subscribers, if we want to core

Re: FYI - China To Launch Alternate Country Code Domains

2006-02-28 Thread Joe Shen
I've read the public announcement of Chinese Ministry of Information Industry. It just state that: there will be another sub-domain mil.cn created besides another six english lettter sub domain in .cn And, it also states: three Chinese Character TLD is establish which is "China"/"Cooperation"/"Ne

Identify amount of traffic to special IP address in Radius

2006-02-28 Thread Joe Shen
Hi, In order to summrize broadband subsciber's traffic data, we need to identify those traffic to our video servers by BRAS which use Radius. Currently, our BRAS could only report total amount of traffic a subscriber transferred. Could we make BRAS genenrate radius accounting data including tag

dnsauth3.sys.gtei.net DNS record is poisoned???

2006-02-15 Thread Joe Shen
Hi, Today, some of our customers could not resolve state.gov by our cache server. I found state.gov is served by dnsauth1.sys.gtei.net, dnsauth2.sys.gtei.net, dnsauth3.sys.gtei.net. Using some others' DNS servers I found their IP addresses should be 4.2.49.2, 4.2.49.3, 4.2.49.4. But, our cache

Re: DOS attack against DNS?

2006-01-17 Thread Joe Shen
Last saturday one of our Web server experienced a TCP SYN attck which make the system down for four hours. It seems there is not a good solution which could detect & defend DoS traffic at any time. So, to the class ANY queries, should we only filtering out class any queries on public cache serv

Gmail Contact and Gmail bugs

2006-01-01 Thread Joe Shen
Hi, Is there way to contact Gmail? Message in my gmail account could not be access for three days. When I tried to click on any message ( or search, move to othe folder .. ) it always pop up with " Ooops, the system was unable to perform your operation.Please try again in a few seconds". Joe

Re: Two Tiered Internet

2005-12-14 Thread Joe Shen
What I'm interested in is how the two service providers will build a two tiered Internet. To our experience, current QoS mechanism ( WRR + multiple_Queue) could not differentiate service quality when bandwidth is overprivisioned. If there is congestion, why should I stay with it while there is a

RE: QoS for ADSL customers

2005-12-06 Thread Joe Shen
Could IPtables control traffic with inspecting layer7 information? As someone suggested, bandwidth allocation could be done with TCP protocol control ( ACK dropping or so); How can we do that? NBAR only limit the bandwidth, and to our experience with cisco7609 it cost a lot of cpu time! Whe

Re: QoS for ADSL customers

2005-11-29 Thread Joe Shen
> > While some people will cry network neutrality and > think the Yellow Pages > must sell only one size listing, some people are > willing to pay for > differentiated service. Trying to classify "bad" > traffic can be > done using products like Sandvine. But it may be > easier to classify "pr

Re: the iab simplifies internet architecture!

2005-11-10 Thread Joe Shen
Maybe Bob Braden's presentaion in e2e task group could do some help. In fact, they just start to discusss what will be the next generation architecture, but does not reach agreement at all. http://www.isi.edu/~braden/e2e-tf/braden.newarch.ppt Joe --- Randy Bush <[EMAIL PROTECTED]> wrote: > >

P2P & Skype traffic control in ISP networks

2005-11-10 Thread Joe Shen
it seems some ISPs have started to introduce management facilities into their networks. Is those products of carrier level? reference: http://webreprints.djreprints.com/1341970908457.html Joe __ Do you Yahoo!? New and Impr

To get internet full routing table

2005-11-02 Thread Joe Shen
Hi, Is that possible to get full internet routing table without help from upstream ISP? or is there anyway to get some backbone network's internet routing table directly? thanks Joe Send instant messages to your online friends http://asia.messenger.yahoo.com

estimating VoIP data traffic size from VoIP signaling traffic size ?

2005-10-22 Thread Joe Shen
Hi, is there any statistics on aggregated VoIP signaling bandwidth and aggregated VoIP data bandwidth? eg. if we monitored there is 2Mbps(average) traffic on VoIP signaling protocol ports ( including SIP, H.323, MGCP), how could we estimate average VoIP data bandwidth? Joe

Re: First step of network optimization

2005-10-02 Thread Joe Shen
Thanks for the response. > > You want to optimize for the lowest monetary cost > network that still allows you > to meet all the SLA's you've negotiated. And this > depends on what you > negotiated - for instance, if the SLA specifies 3 > 9's of reliability, spending > money to build a 4 9's ne

First step of network optimization

2005-10-02 Thread Joe Shen
Hi, this may be a OOO..LD topic which is talked, discussed or agrued for year. ISP networks may need to be optimized continuously. But, it seems people have different view of optimization when they use this word at different place; sometimes optimization means adding more access router, add more

Re: Tools classifying network traffic to applications

2005-09-22 Thread Joe Shen
hi, > > Christopher L. Morrow wrote: > > >>which can't really tell bittorrent (or ssh or aim > or...) over tcp/80 from > >>http over tcp/80... I think Joe's looking for > something that knows what > >>protocols look like below the port number and can > spit out numbers for > >>that... these, it

Tools classifying network traffic to applications

2005-09-22 Thread Joe Shen
Hi, As I know there is tools designed to analyze VoIP traffic, but for viewpoint of traffic management this is not enough. Is there tool which could classify network traffic to its applications? e.g. the tools catch network traffic and recognize its application type automatically. If 80% of (80/

Load Balancing between multiple BGP peer connections

2005-09-14 Thread Joe Shen
Hi, How could load on multiple BGP peer links be balanced automatically? The situation we are facing: ---| | Service provider| | | --R1R2--- |\

Arbor's technical support contact?

2005-08-28 Thread Joe Shen
Hi, How can I contact Arbor's technical support enigneer? Joe Send instant messages to your online friends http://asia.messenger.yahoo.com

SNMP tool summrizing multiple interfaces traffic data

2005-08-26 Thread Joe Shen
Hi, Beside monitoring in/out traffic on each egress links, is there a tool which could provide a summary bandwidth utilization on two or more router interfaces? thanks Joe __ Meet your soulmate! Yahoo! Asia presents Meetic - where millions

Re: What application runs on port 8094?

2005-08-18 Thread Joe Shen
AIL PROTECTED]> wrote: > Hi Joe, > > Joe Shen wrote: > > Hi, > > > > Using netflow based monitor tool, I noticed there > is a > > lot of traffic on 8094/UDP and 4662/TCP( both > exceed > > 1Gbps, and exist all the time) > > > > > >

What application runs on port 8094?

2005-08-17 Thread Joe Shen
Hi, Using netflow based monitor tool, I noticed there is a lot of traffic on 8094/UDP and 4662/TCP( both exceed 1Gbps, and exist all the time) What application use that port? Is there any P2P application use UDP as transportation protocol? thanks in advance. Joe

Re:Provider-based DDoS Protection Services

2005-07-28 Thread Joe Shen
Hi, I'm very interested in technical solutions of ISP based (D)DOS solutions. Where can I find document/information on it? thanks. Joe Send instant messages to your online friends http://asia.messenger.yahoo.com

Re: Enable BIND cache server to resolve chinese domain name?

2005-07-03 Thread Joe Shen
Hi, > > Only if you wish to do all your other customers a > disfavour > by configuring your caching servers to support a > private > namespace then yes. > The problem is chinese domain name is hosted and could be registered by people around. So, we just have to enable

Enable BIND cache server to resolve chinese domain name?

2005-07-03 Thread Joe Shen
Hi, Some of our customer complaint they could not visit back to their web site, which use chinese domain name. I google the net and found some one recommend to use public-root.com servers in hint file. I found domain name like xn--8pru44h.xn--55qx5d could not be resolved either. Our cache ser

Re: Is my BIND Server's Cache Poisioned ?

2005-06-30 Thread Joe Shen
Hi, thanks for the help. > > Because IPv6 aware nameservers make queries > for the > IPv6 addresses of the nameservers and as a result > see the > NXDOMAIN / CNAME. The IPv4 only nameservers don't > make > these queries, as a matter of practice, and only > see the

Is my BIND Server's Cache Poisioned ?

2005-06-29 Thread Joe Shen
Hi, I met a strange problem with my cache server, which runs BIND9.3.1. In past days, our customers complaint that three domain names (www.hangzhou.gov.cn, www.zpepc.com.cn) could not be resolved frequently. I checked on the cache server and found, when the cache server could not resolve www.han

Re: Malicious DNS request?

2005-05-17 Thread Joe Shen
ay be type of attack. If we only rely on cacheing to remove paient of CPU time, cache server load will be increased. So, what I'm tryting to ask is , is there some mechanism proposed to deal with such problem? BIND is just a sample. joe --- Paul Vixie <[EMAIL PROTECTED]> wrote: &

Re: Malicious DNS request?

2005-05-17 Thread Joe Shen
Sorry to attach the "rndc stats" result. I run "rndc stats" continuously( interval is less than 2 seconds), it's shown: success 17950622 referral 225680 nxrrset 1691861 nxdomain 11203490 recursion 3648017 failure 1363923 ... --- Statistics Dump --- (1116319437) +++ Statistic

Re: Malicious DNS request?

2005-05-17 Thread Joe Shen
Sorry to attach the "rndc stats" result. I run "rndc stats" continuously( interval is less than 2 seconds), it's shown: success 17950622 referral 225680 nxrrset 1691861 nxdomain 11203490 recursion 3648017 failure 1363923 ... --- Statistics Dump --- (1116319437) +++ Statistic

Re: Malicious DNS request?

2005-05-17 Thread Joe Shen
Hi, thanks for your help. I noticed that the requests of those non-exist domain name disappeared yesterday. But the NXDOMAIN record in named.stats keep increasing. ( see attachment) I'm using BIND9.2.5 & BIND9.3.1 on two Solaris box, each box has two CPUs installed. it's found BIND8.4.6 running

Malicious DNS request?

2005-05-12 Thread Joe Shen
Hi, In past days I noticed the nxdomain statistics in named.stats keeps increasing.( I run it every 5 min) By tcpdump, it's found a remote computer keep asking address for record like 999d38e693b9e6293b450.0existence.com, 60d38e693b9e6293b450.0be6c1xfa.net. is that a virus affacted computer?

watchdog of BIND server

2005-04-30 Thread Joe Shen
Hi , currently, I run named with -f option. As named is started at system boot time, a starting up script hang around console is a possible problem for system administration & security. Is there any configurable watchdog of BIND server deamon? E.g. once it found named is down, it will shutdown

Re: Detecting VoIP traffic in ISP network

2005-04-27 Thread Joe Shen
e traffic should be carried at the best performance/cost rate. joe --- Suresh Ramasubramanian <[EMAIL PROTECTED]> wrote: > Local telco concerned about voip eating into their > revenues, and wants > to push through legislation or something? :) > > On 4/27/05, Joe Shen <[E

Detecting VoIP traffic in ISP network

2005-04-27 Thread Joe Shen
Hi, we want to collect statistics in our backbone networks. Is there any good method to this? is there any product for this ? Joe _ Do You Yahoo!? 嫌邮箱太小?雅虎电邮自助扩容! http://cn.rd.yahoo.com/mail_cn/tag/10m/*http://cn.mail.yahoo.com/event/10

Re: Schneier: ISPs should bear security burden

2005-04-26 Thread Joe Shen
Hi, maybe this is an OLD topic, but the problem is "what is security? " or "how to define a secure internet access service ". E.g. should ISP respond for managing application transmitted across its backbone? if so, how to define "standard" appliation model while keeping internet a flexible platfo

Re: Intradomain DNS Anycast revisited

2005-03-24 Thread Joe Shen
thanks. > No, because both routers are reached through the > same L1/L2 medium, so > Quagga can't use link-state to determine > reachability of the next-hop. > You could fix that by getting rid of the switches, > and just having a bunch > of router interfaces facing two Ethernet interfaces > on

Intradomain DNS Anycast revisited

2005-03-24 Thread Joe Shen
Hi, I'm trying to set up a anycast DNS server farm for customer service. In order to improve availability, we plan to install those servers in one LAN which has the similar structure like : server-(1,3)---switch1---router-1---(outside) | | server-(2,4)---switch

Re: Traceroute with ASN

2005-03-15 Thread Joe Shen
Yes. Can I do this on a Linux box without having to install Zebra BGP on it? Joe > > Something like this? > > [EMAIL PROTECTED] root]# lft www.level3.net -A > > Tracing . > > TTL LFT trace to Level3.com (209.245.19.41):80/tcp > 1 [AS24730] amsterdam-c1-f1.prolo

Traceroute with ASN

2005-03-15 Thread Joe Shen
Hi, maybe this is a OLD question. But, where can I get a traceroute program which can show ASN beside each hop IP address? I know router with full BGP routes could traceroute with ASN, but can a linux box do the same? thanks Joe __ Do You Yah

How to identify interconnection relationship between AS?

2005-03-08 Thread Joe Shen
Hi, I'm trying to identify how an AS is interconnected with other ASes. For example, I can access our border router which has BGP run, and I want to know how another AS ( e.g. 1234 ) is connected to internetwork ( e.g. as1234 interconnects with as1235, as1236, as1345 ). How can I do it?

Re: Is current DDoS detecting method effective?

2005-03-07 Thread Joe Shen
Hi, > > you aren't distinguishing between 'dos attack' and > 'scan' or 'probe' or > 'welcome to the Internet!' traffic. The Arbor > systems may see 'scan' > traffic (depending upon sample rates and traffic > loads) and they may > not... They aren't designed to see that, they are > designed to:

Re: Is current DDoS detecting method effective?

2005-03-06 Thread Joe Shen
Hi, > It frightens me that you're sitting on 11Gb/s+ and > unable to utilize > existing toold to determine what is within profile > for your network and > what is not. That what makes me think it's not possible to determine "legal" traffic model by available tools. The total BW keeps increasi

Is current DDoS detecting method effective?

2005-03-06 Thread Joe Shen
Hi, I use flow-tools to monitor the link bandwidth utilization on three backbone interfaces. The total bandwidth utilized is about 11Gbps, and netflow data is analyzed to show statistics on some special port (e.g. port 0, port 445 etc.). I think this could give us some indication of possible DoS

Measure overall network availability

2005-01-06 Thread Joe Shen
Hi, is there any recommended method to measure overall network availability? Currently we use packet loss rate as indication of network availability, but to my understanding this just means the possiblity of e2e communication degrade but not the network availability. regards Joe

Re: Anycast 101

2004-12-20 Thread Joe Shen
I don't think PPLB is compatible with anycast esp. in situation when we consider end-to-end communication with multiple packets. As PPLB may derive to out-of-sequence between TCP pacekets & different DNS server destination of the same UDP stream, it will broke anycast DNS service in some situa

Re: Anycast 101

2004-12-20 Thread Joe Shen
Hi, That's what I want to discuss about. The paper gives a very detailed explanation on anycast with OSPF_ecmp, and what I want to know is: is there anything not included in it but must be considered carefully when anycast cache server farm is to be established in MAN ? Will there be any prob

Re: Anycast 101

2004-12-17 Thread Joe Shen
My question: I noticed that people always talked about BGP when they talked about anycast dns server farm. But, is there any problem or anything must be taken care about when anycast is employed within a DNS server farm within MAN? What I mean is, if we want to employ anycast in a cache serv

RE: identifying application type of network traffic

2004-12-16 Thread Joe Shen
Thanks for all your reply. My situation is not to apply QoS policy to those application but to get statistics of applications. According to netflow records, the traffic across our egress interface has port number range from 11 to 65534 , there is record for port 0! So, what are those applicatio

identifying application type of network traffic

2004-12-15 Thread Joe Shen
Hi, I'm trying to identify applications which generate those traffic on our border routers. I use sampled netflow as data source and some flow-tools as analizer. Currently, I use (protocol, port_number) as indicator of application. Referring to rfc on wellknown protocol and port allocation, I

Topology of current network

2004-12-15 Thread Joe Shen
Hi, I'm looking for information on backbone/PoP topology . To my memory there is a web has a lot of topology graphs but I can't call it. Could anybody do some help? thanks Joe __ Do You Yahoo!? Log on to Messenger with your mobile phone! ht

How to monitor BGP route stability ?

2004-11-26 Thread Joe Shen
Hi, Is there any tool to monitor BGP route stablity? thanks Joe __ Do You Yahoo!? Log on to Messenger with your mobile phone! http://sg.messenger.yahoo.com

Need help on process netflow sampling data

2004-11-24 Thread Joe Shen
Hi, I'm trying to analize our egree router traffic by using flow-tools and CUFlow. There are three edge routers: two Juniper M160 and one Cisco GSR. All of them are set up to sample outgoing interfaces. With Juniper M160, I set up forwarding-option as: = forwarding-

Netflow analysis best pratice and tools ?

2004-11-18 Thread Joe Shen
Hi, We plan to set up netflow analysis in our backbone. It's hoped to be able to track communication demand inside our AS as well as our AS and other ASes. It also expected to be able to support route optimization and to detect abnormal network behavior . And, report generation is needed too.

Re: Problems receiving emails from china...

2004-11-18 Thread Joe Shen
Hi, Is there similar problem existing with sending email to email server inside china? maybe you could check end-to-end delay and packet loss rate. Another method, ask your customer to cut the attachment to several parts and send them seperately. Joe --- Lou Laczo <[EMAIL PROTECTED]

Re: How to Blocking VoIP ( H.323) ?

2004-11-12 Thread Joe Shen
o Blocking VoIP ( H.323) ? > > > > On Thu, 11 Nov 2004, Robert Mathews wrote: > > > > > > > > > To Joe Shen: > > > > > > Perhaps 'I am failing to see it' but, what can > be gained by blocking VoIP > > > traffic other than freeing bandw

How to Blocking VoIP ( H.323) ?

2004-11-11 Thread Joe Shen
Hi, How could it be done to block VoIP at access router? I've thought about using ACL to block UDP port 1719,but this could be overcome by modifying protocol port number. regards Joe __ Do You Yahoo!? Log on to Messenger with your mobile phon

Re: why upload with adsl is faster than 100M ethernet ?

2004-11-01 Thread Joe Shen
> On Fri, 15 Oct 2004 00:14:11 -0800, Joe Shen wrote: > >|-(ADSL)\ > > customer/ > --Edge_router---...---Japan Server > > \-(100Methernet)-/ > > > it is probably worth doing an experiment, by placing > a target h

Re: Network Monitoring System - Recommendations?

2004-11-01 Thread Joe Shen
Hi, I googled with "CCR" but it seems nothing useful in 5 pages. Would you please do me a favor to give the URL of that tool ? I tried to set up MRTG monitoring Unishpere BRAS 1400 and M160, but I failed with data collection because wrong OID used ( CPU, mem, tempreture, BW etc ) :-( regards

Re: Network Monitoring System - Recommendations?

2004-10-31 Thread Joe Shen
I read document of these tools and find they work with Cisco products. But, how about Juniper M160 or M320, Unishpere's BRAS products? Where can I find Juniper's OID on its tempreture, chassis, CPU, bandwidth ? Does anyone have a running configuration for M160 or Unishpere's BRAS products? On

Re: why upload with adsl is faster than 100M ethernet ?

2004-10-15 Thread Joe Shen
> > It's generally a bad idea to turn of ethernet > autonegotiation unless > the equipment at the other side doesn't support it. > Yes, we've checked the configuration, both access router interface and customer's ethernet interface are forced to be (100Mbsp, full duplex). And, there is no CRC

Re: why upload with adsl is faster than 100M ethernet ?

2004-10-15 Thread Joe Shen
Hi, the network path is: |-(ADSL)\ customer/ --Edge_router---...---Japan Server \-(100Methernet)-/ So, from edge_router to Japan server the path is identical. > > There is something wrong with both scenarios. > > A 5 Mbyte file is 40 megabits. W

why upload with adsl is faster than 100M ethernet ?

2004-10-14 Thread Joe Shen
Hi, I met a question with upload speed and network access speed. One of our customer lease two lines from us. One is 2Mbps ADSL line the other is 100Mbps fiber ethernet link. The customer needs to upload files to server in Japan usually. Now, the customer complaint that the upload speed of A

Question on IP address used by anycast DNS cache server

2004-10-11 Thread Joe Shen
Hi, I'm , but I met some questions when reading those paper from ISC on F-root anycasting. 1. As it's descripted in J.Abley's paper, DNS server in anycast group should be configured with a real IP on its NIC and one or two service IP on loopback interface(s). BIND listen on both real IP and serv

Is those ICP crazy -- 10GB free emailbox?

2004-09-28 Thread Joe Shen
Hi, I just received an email from one of my friends and he told me http://www.hriders.com/ is providing free 10GB email box for subscribers. Is that crazy in competition of BIG size free email account? Joe __ Do You Yahoo!? Log on to Messenger wi

Log Analizing tool for Cisco and Juniper router (switch)

2004-09-21 Thread Joe Shen
Hi, We want to analize log from Cisco and Juniper Router and switch periodically. We have set up a Solaris box to collect all those log generated by Juniper router ,Cisco Router , cisco L2/L3 switch. But, we found log file format diverse greatly even between Cisco products. Is there any good t

Re: Excessive Internet Traffic

2004-09-15 Thread Joe Shen
Is that a variant of Nachi B. ? The source address may be generated. joe --- Robert Scott <[EMAIL PROTECTED]> wrote: > > The University of Central Florida has seen a sudden > jump in tcp 445 > denies. It began a little after 9:00 AM EDST. New > Worm? > > I am denying about 32 thousand packet

Re: Network Configuration Management Practices

2004-09-15 Thread Joe Shen
There has been some public available software for backing up Cisco router configuration. The backup is not in CVS but in plain file. Joe --- Alexei Roudnev <[EMAIL PROTECTED]> wrote: > > Hmm, there are many approaches, starting with _what > is primary_ (in Moscow's > ISP files was prima

RE: Email Complexes

2004-09-15 Thread Joe Shen
Hi, Is there any free tools or methods to measure SMTP performance and email service quality between two email server ? Is there any implementation of message track? thanks Joe --- "Hosman, Ross" <[EMAIL PROTECTED]> wrote: > > I've gotten a few emails asking why we are doing > this. > >

Re: EVENT - Building a network and system management open source tool - talk at BayLISA, Cupertino, California, USA, Thursday 16 Sept. 2004 19:30-21:00

2004-09-13 Thread Joe Shen
In those network administration software it seems configuration management, e.g. periodic backup, integrity checking etc, is not covered. Is that possible to include this ? Joe --- Philippe Ombredanne <[EMAIL PROTECTED]> wrote: > > If you are in the San Francisco Bay Area, you can > join us

Re: Gb ethernet interface keeping dropping packet in ingress

2004-09-13 Thread Joe Shen
Hi, we do not sniffing the Gbps ethernet link, and the box I mentioned in previous message is not oversubscribed at all. In fact, the 10Gbps switch is newly installed and only two link connected ( one to catalyst6509, one to firewall). Anyway, thanks for your analysis and I want to know what's

Gb ethernet interface keeping dropping packet in ingress

2004-09-13 Thread Joe Shen
Hi, I'm using Harbour 10G lay3 switch which interconnects a Catalyst6509 and a Foundry switch. the interconnecting lines are all 1Gbps ethernet (1000Gb LX). Catalyst6509Harbour 10G switchFoundry Switch---Firewall the firewall and harbour interconnect at layer 3. We noticed there is

Re: DNS Weather Report 2004-09-07

2004-09-06 Thread Joe Shen
What does "find" in the report mean? no lookup timeout or no out-of-sync? Joe --- Daniel Roesen <[EMAIL PROTECTED]> wrote: > > DNS WEATHER REPORT for selected infrastructure zones > > Issue 2004-09-07 > > Zones analyzed and their SOA

QoS Service and montoring methods

2004-09-06 Thread Joe Shen
Hi, I'm woring with QoS level analysis in ISP networks. But I don't know where could I find infomation on the following questions: 1. Is there a list of ISPs providing QoS in their networks? 2. Where could I find detailed infomation on QoS level parameters in those ISPs who do QoS? e.g.,( e2e

WRED and QoS provisioning in ISP network

2004-08-31 Thread Joe Shen
environment? esp. in DiffServ network 5. Is there any possible security problem in a QoS enabled network? 6. How could we optimize network architecutre according to QoS policy? Each word will be highly appreciated. Joe Shen __ Do You Yahoo!? Download

Re: OT - 3 Free Gmail invites

2004-08-21 Thread Joe Shen
it been since you have used it? > What browsers were you using? > > I have had a few issues but they have all been > resolved so Im unsure as > to were your problems stem from. > > Just curious. > > Andre > > On Thu, 2004-08-19 at 02:28, Joe Shen wrote: >

Re: OT - 3 Free Gmail invites

2004-08-18 Thread Joe Shen
Gmail seems to be in Beta stage. I got a Gmail account months ago, but I do not use it by now. The reason is it does not solve two bugs I met. The first is, after logining into gmail it will prompt with "Ooops, the system was unable to perform your operation. Please try again in a few seconds" if

Re: Summary with further Question: Domain Name System protection

2004-08-17 Thread Joe Shen
Hi, > > in situation of DoS attack or situation of high > > session rate; > > Routers with hardware based access lists. No > problem. What I'm not sure about ACL on router is, how to survive DNS server under DoS/DDos attack. We suffered from DoS attack last year, and we found the source IPs of

Summary with further Question: Domain Name System protection

2004-08-16 Thread Joe Shen
Hi, thanks for your help on my question. After reading carefully those comments, I reach the following conclusion: 1. ISPs use firewall to protect their DNS server; 2. ACL on router may be a good solution for protecting DNS servers, the policy could be "only pass those packets, whose originat

Domain Name System protection

2004-08-15 Thread Joe Shen
Hi, We are trying to extend our DNS service system in near future. In current stage, it consist of 2 SUN FIRE Server with Solaris8 and BIND9 installed. Each server is configured with a IP address which is known to our customers. The DNS server is set up as Cache Server because it only servers our

Re: That MIT paper

2004-08-10 Thread Joe Shen
Hi, >The paper doesn't pass any judgement on types of lookups, but obviously >not all DNS lookups are equal from the end user perspective. In our observation, looking for IP address consists 70% of our cache server load, MX consists of 14% and PTR only occupies 5%. And, on the other hand, the

  1   2   >