Re: BGP Engines with support to "RTFilter address-family"

2023-03-01 Thread Chriztoffer Hansen via NANOG
On 26/02/2023 21.46, Douglas Fischer wrote: > However, I'm searching for BGP Engines that implement this address-family > (AFI=1, SAFI=132), to avoid Lock-In. > > But I'm looking for an open-source engine that supports it. rustybgp and gobgp might support it. $ grep -r -P "AFI,SAFI = 1,132"

Peering Contact for AS41552 eBay Classifieds Group

2022-07-11 Thread Chriztoffer Hansen via NANOG
Hi NANOG, AS41552 eBay Classifieds Group https://www.peeringdb.com/asn/41552 Anyone know of a working peering contact for this network? The one email address listed on the peeringdb page returns an error message: "550 #5.1.0 Address rejected." -- Med Venlig Hilsen, Chriztoffer Ha

Re: Setting sensible max-prefix limits

2021-08-18 Thread Chriztoffer Hansen
On Wed, 18 Aug 2021 at 11:33, Lars Prehn wrote: > I guess for long standing peers one could just eyeball it, e.g., current > prefix count + some safety margin. How does that work for new peers? If you have automation in place. Another approach is to count the received prefix. Store the counted

Re: A crazy idea

2021-07-20 Thread Chriztoffer Hansen
On Tue, 20 Jul 2021 at 17:41, Bryan Fields wrote: > On 7/20/21 10:01 AM, Michael Loftis wrote: > > My apologies to everyone using an HTML mail client. > > No reason to apologize for that. If someone is careless enough to use an HTML > client on a mailing list, they deserve what they get :-D

Re: Do you care about "gray" failures? Can we (network academics) help? A 10-min survey

2021-07-09 Thread Chriztoffer Hansen
On Thu, 8 Jul 2021 at 22:10, Baldur Norddahl wrote: > We had a line card that would drop any IPv6 packet with bit #65 in the > destination address set to 1. Turns out that only a few hosts have this bit > set to 1 in the address, so nobody noticed until some Debian mirrors started > to become

Re: BGP38 egress filter on Ubuntu Server

2021-06-01 Thread Chriztoffer Hansen
On Tue, 1 Jun 2021 at 22:58, Chriztoffer Hansen wrote: > https://team-cymru.com/community-services/bogon-reference/bogon-reference-http/ I have found that pfSense uses this feed to filter traffic if 'Block bogon networks' is enabled on the WAN interface(s). I.e. the pfSense bogons + bogon

Re: BGP38 egress filter on Ubuntu Server

2021-06-01 Thread Chriztoffer Hansen
On Tue, 1 Jun 2021 at 22:43, Stephen Satchell wrote: > Before I re-invent the wheel, has anyone come up with blackhole route > specifications for netplan in Ubuntu servers? Such a capability would > perform the egress blocking for an edge server.

Re: BGP Traffic Engineering - Active\Passive

2021-05-21 Thread Chriztoffer Hansen
On Fri, 21 May 2021 at 17:13, nanoguser100 via NANOG wrote: > If I'm unable to do that will most provider prepend on your behalf so that > ISP-A would add the prepends for only? For this part, you will have to investigate which BGP standard/extended/large communities your ISP-A/B supports.

Re: Historic IRR/RADB snapshots?

2021-02-24 Thread Chriztoffer Hansen
On Wed, 24 Feb 2021 at 09:00, Lars Prehn wrote: > Does anybody have (somewhat frequent, e.g., monthly) snapshots of the > various IRR databases lying around? Any snapshot since 2010 would be > helpful! For any specific use-case whowas cannot solve? ¯(°_o)/¯ -- Chriztoffer

Re: DMVPN via Internet or Private APN

2021-01-12 Thread Chriztoffer Hansen
On Mon, 11 Jan 2021 at 19:27, Sean wrote: > I offer a question to help me settle an internal debate. As a network > engineer for a large enterprise, do you choose ISP flexibility or ISP > security when you build an OOB network? I was tasked to create an OOB > network for my company. Realistically

AWS using 169.254.0.0/30 for ptp VPNs.

2020-10-26 Thread Chriztoffer Hansen
On 26 Oct 2020 17:57, B F wrote: > Looking for any fresh experience with this: > > https://docs.aws.amazon.com/vpn/latest/s2svpn/VPNTunnels.html >

Juniper configuration recommendations/BCP

2020-10-08 Thread Chriztoffer Hansen
On 08/10/2020 11:37, Forrest Christian (List Account) wrote: > Is there anything I should worry about > which is Juniper-specific? JUNOS default ARP timeout: 20 min. If you connect to IXP's. Recommended ARP timeout: 4 hours.

cloud automation BGP

2020-09-29 Thread Chriztoffer Hansen
On 29/09/2020 15:36, Graham Johnston wrote: > Does anyone have a quick answer as to what public data sources are used? I > tried looking at the main github page for the project but I either missed it > or it isn't there. https://blog.apnic.net/2020/07/27/easy-bgp-monitoring-with-bgpalerter/ >

BFD for routes learned trough Route-servers in IXPs

2020-09-16 Thread Chriztoffer Hansen
On 16/09/2020 04:01, Ryan Hamel wrote: > CoPP is always important, and it's not just Mikrotik's with default low > ARP timeouts. > > Linux - 1 minute > Brocade - 10 minutes > Cumulus  - 18 minutes > BSD distros - 20 minutes > Extreme - 20 minutes Juniper - 20 minutes > HP - 25 minutes --

Re: BGP Community - AS0 is de-facto "no-export-to" marker - Any ASN reserved to "export-only-to"?'

2020-09-09 Thread Chriztoffer Hansen via NANOG
On Wed, 9 Sep 2020 at 06:25, Mark Tinka via NANOG wrote: > It's not unlike trusting your customers to send you FlowSpec > instructions. No issues technically, but do you want to do it? Why not? As a service offering, it makes total sense. Thou, generally I agree with you. Trust, but verify any

Re: BGP Community - AS0 is de-facto "no-export-to" marker - Any ASN reserved to "export-only-to"?'

2020-09-08 Thread Chriztoffer Hansen via NANOG
Douglas, On Tue, 8 Sep 2020 at 17:55, Douglas Fischer via NANOG wrote: > > Most of us have already used some BGP community policy to no-export some > routes to somewhere. > > On the majority of IXPs, and most of the Transit Providers, the very common > community tell to route-servers and

Re: RFC 5549 - IPv4 Routes with IPv6 next-hop - Does it really exists?

2020-07-29 Thread Chriztoffer Hansen
On Wed, 29 Jul 2020 at 18:06, Mark Tinka wrote: > On 29/Jul/20 16:54, Nick Hilliard wrote: > > it's a capability negotiation, so is handled on session setup. > > Meaning the initial setup would still require the use of literal IP addresses? Unless your (e.g. DC equipment) is set up for automatic

Re: Mikrotik RPKI Testing

2020-06-04 Thread Chriztoffer Hansen
On Thu, 4 Jun 2020 at 16:13, Mike Hammett wrote: > I noticed that Mikrotik has added RPKI into their very much beta v7 branch. I > would like to ask those of you that know RPKI well to check it out and offer > Mikrotik feedback on what they've done right\wrong\broken. Promising development,

[nanog] Re: Quagga for production?

2020-02-23 Thread Chriztoffer Hansen
Raymond Burkholder wrote: > On 2020-02-23 5:26 a.m., Dmitry Sherman wrote: >> Anybody working with Quagga for production peering with multiple peers >> and dynamic eBGP/iBGP announcement? >> > Free Range Routing (FRR) forked Quagga a few years back.  I would say it > is the new Quagga. > > But

Re: NANOG 78 Webcasts

2020-02-15 Thread Chriztoffer Hansen
On Sat, 15 Feb 2020 at 20:40, Ana Tomasović wrote: > Is anyone able to access NANOG 78 playlist on YouTube or the webcast > URL? > > YouTube videos/playlist appear as private. Nope. -_- Wish they would keep the Day 1, Day 2, Day 3 videos online until the edited talks have been published.

Re: Customer sending blackhole route with another provider's AS

2020-02-11 Thread Chriztoffer Hansen
Chris Adams wrote on 11/02/2020 17:30: > Just curious what others do... I always assumed AS path filtering to > customer (and their downstream customers) AS was a standard best > practice. It is. Then again, there exists every exception to the rule you can think of. If the exception has not

Re: Dual Homed BGP

2020-01-24 Thread Chriztoffer Hansen
fre. 24. jan. 2020 18.23 skrev Job Snijders : > > On Fri, 24 Jan 2020 at 17:40, Brian wrote: > > Am I crazy? >> > > I dropped out of university, never completed my psychology studies, I fear > I am unqualified to answer this question. ;-) > Education shopping, it is called by some. Chriztoffer

Re: AS45102 Alibaba - lot networks with ROA wrong and invalid

2020-01-16 Thread Chriztoffer Hansen
Marco, tor. 16. jan. 2020 12.50 skrev Marco Paesani : > I need contact with AS45102 because there is a lot networks with ROA wrong > and invalid. > Nobody knows some technical people inside this AS ? > No succes using the contacts listed in their PeeringDB entry?

Re: GEO IP Updates

2019-08-07 Thread Chriztoffer Hansen
on something today...? ] [ Chriztoffer Hansen+1 914 3133553 ] [ 0x18dd23c550293098de07052a9dcf2ca008ebd2e8 ] signature.asc Description: OpenPGP digital signature

Re: [nanog] Cisco GLBP/HSRP question -- Has it ever been dis

2019-08-06 Thread Chriztoffer Hansen
-RELEASE=default=html -- [ have you enabled IPv6 on something today...? ] [ Chriztoffer Hansen+1 914 3133553 ] [ 0x18dd23c550293098de07052a9dcf2ca008ebd2e8 ]

Re: Xfinity with IPv6 clue?

2019-08-05 Thread Chriztoffer Hansen
Janet, Did an actual person follow up with you privately after ipv6 got working on your connection? ... Or was it more like magic silence from their end. And suddenly it "just" worked? /Chriztoffer On 05/08/2019 04:00, Ross Tajvar wrote: > Did you get in touch with someone? What was the

Re: [nanog] Cisco GLBP/HSRP question -- Has it ever been dis

2019-08-04 Thread Chriztoffer Hansen
about the RFC concerning HSRP.) Haven't gotten a response on the GLBP part. Which I am more than doubtful, myself, will ever come to fruition as a standard in an IETF WG. -- [ have you enabled IPv6 on something today...? ] [ Chriztoffer Hansen+1 914 3133553

Re: [nanog] Cisco GLBP/HSRP question -- Has it ever been discussed to publish fully/in-part the specifications

2019-08-03 Thread Chriztoffer Hansen
Saku Ytti wrote on 03/08/2019 15:49: I don't think any work for GLBP exists in IETF. A shot in the dark. Correct. https://www.google.com/#q=%28"GLBP"%7C"Gateway+Load+Balancing"+Protocol%7C"Global+Load+Balancing"+Protocol%29+AND+inurl%3Adatatracker+AND+inurl%3Aietf (My IETF history is short.

[nanog] Cisco GLBP/HSRP question -- Has it ever been discussed to publish fully/in-part the specifications

2019-08-03 Thread Chriztoffer Hansen
Cisco has their FHR protocol specifications protected as proprietary IP. * Gateway Load Balancing Protocol (GLBP) * Hot Standby Router Protocol (HSRP) * https://packetlife.net/media/library/3/First_Hop_Redundancy.pdf Apart from the EIGRP specifications. Which has become publicly available