Re: v4 and v6 BOGON list

2024-03-21 Thread Enno Rey via NANOG
love to discuss more on the topic. > > URLs: > https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml > https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml > > Thanks, > > Gabriel L. Terry > -

Re: 202401100645.AYC Re: IPv4 address block

2024-01-10 Thread Enno Rey via NANOG
> On 2024-01-07 22:46, KARIM MEKKAOUI wrote: > > > > Hi Nanog Community > > > > Any idea please on the best way to buy IPv4 blocs and what is the price? > > > > Thank you > > > > KARIM > > > > > -- > This em

Re: IPv6 "bloat"

2022-03-20 Thread Enno Rey
t PPPoE is very 1990 and has its own > >> set of problems.?? For those running encapsulated traffic, > >> authentication to the modem MAC via DHCP that becomes broken.?? And > >> thus far, I have not seen a solution offered to it. > > > > I was honestly more interested in the bloat angle, but this sounds like > > a backend problem of your own making most likely. But I'm not motivated > > to see if it's actually the case or just a misunderstanding. -- Enno Rey Cell: +49 173 6745902 Twitter: @Enno_Insinuator

Re: Class D addresses? was: Redploying most of 127/8 as unicast public

2021-11-20 Thread Enno Rey
not going to work: https://theinternetprotocolblog.wordpress.com/2019/10/06/some-notes-on-ipv4-address-space/ For the sake of the thread it should be noted that both the reception of and the response to the initial e-mail primarily happened over IPv6. I wish everybody a great weekend Enno -- Enno Rey Cell:

Re: AWS Using Class E IPv4 Address on internal Routing

2021-03-09 Thread Enno Rey
so? > > > > P.S.: I'm completely in favor of a complementary RFC assing FUTURE USE > > exclusively to "Between Routers" Link Networks... > > > > -- > > Douglas Fernando Fischer > > Eng?? de Controle e Automao > > > > > > -- > > - Forrest > > > > > > > -- Enno Rey Cell: +49 173 6745902 Twitter: @Enno_Insinuator

Re: Request comment: list of IPs to block outbound

2019-10-13 Thread Enno Rey
ple allow that range as blocking it will drop NA/NS packets with the upstream router which in turn can delay the establishment of the BGP session (provided there is one over IPv6). best Enno -- Enno Rey https://theinternetprotocol.blog Twitter: @Enno_Insinuator

Re: IPv6 Unique Local Addresses (was Re: New Active Exploit: memcached on port 11211 UDP & TCP being exploited for reflection attacks)

2018-03-02 Thread Enno Rey
ystems need global reach(ability), which applies to pretty much all environments nowadays. best Enno > > (As it turns out my ISP prefix has been static for years, but I'm too lazy > to undo all of the work...) > > -- > Harald -- Enno Rey ERNW GmbH - Carl-Bosch-Str.

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
Hi, On Sun, Sep 10, 2017 at 12:08:59PM +0200, Job Snijders wrote: > Hi, > > On Sun, Sep 10, 2017 at 11:53:20AM +0200, Enno Rey wrote: > > On Sun, Sep 10, 2017 at 10:47:05AM +0100, Nick Hilliard wrote: > > > Baldur Norddahl wrote: > > > > Loopback interfaces s

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
Hi, On Sun, Sep 10, 2017 at 12:08:59PM +0200, Job Snijders wrote: > Hi, > > On Sun, Sep 10, 2017 at 11:53:20AM +0200, Enno Rey wrote: > > On Sun, Sep 10, 2017 at 10:47:05AM +0100, Nick Hilliard wrote: > > > Baldur Norddahl wrote: > > > > Loopback interfaces s

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
> However I don't think market would generally appreciate the > implications linklocal brings to traceroute, where least bad option > would be just to originate hop-limit exceeded from loop0, with no > visibility on actual interface. some might be willing to accept that, as a trade-off fo

Re: IPv6 Loopback/Point-to-Point address allocation

2017-09-10 Thread Enno Rey
ct IP access to these IP addresses. or, maybe even more efficient, assign all loopbacks from a dedicated netblock which you null-route on the edge/your border devices. best Enno -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 41900

Re: BCP for securing IPv6 Linux end node in AWS

2017-05-14 Thread Enno Rey
router discovery gets broken by too tight of filters. > > Thanks for any guidance. > > EKG > -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregist

Re: ARIN legacy block transfer process

2016-09-30 Thread Enno Rey
ny more in the course of the 2nd step and RIPE's 2-yr holding period comes into play (=> it can't be transferred during that time). Note also there's voices recommending not to sign an RSA for legacy space (in certain situations, at least), see http://ipv4marketgroup.com/dont-sign-an-rsa-durin

Re: IPV6 planning

2016-03-08 Thread Enno Rey
ned 1st (non-temporary) one. best Enno > > > Bj??rn -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregister Mannheim: HRB 337

Re: Android and DHCPv6 again

2015-10-06 Thread Enno Rey
gt; nd6 options=1 > >> media: autoselect > >> status: active > >> > >> To me it seems that the Macbook has one SLAAC address, one privacy > >> extension address and one DHCPv6 managed address. > >> > >> In fact the CPE manufacturer is a l

Re: Estonian IPv6 deployment report

2014-12-27 Thread Enno Rey
are not sent to link-local scope all nodes (ff02::1), so that would eliminate another attack vector (depending on the actual processing of RAs on the CPEs). best Enno /Anders -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221

Re: Seeking IPv6 Security Resources

2014-11-26 Thread Enno Rey
helpful. Thanks! ~Chris Note: Not every document shared will get posted to the Deploy360 site. -- @ChrisGrundemann http://chrisgrundemann.com -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173

Re: IPv6 Default Allocation - What size allocation for Loopback Address

2014-10-13 Thread Enno Rey
:db8:18ba:ff42::1 :) Cheers, Sander -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregister Mannheim: HRB 337135 Geschaeftsfuehrer: Enno Rey

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Enno Rey
for connections to supplier/partner networks (to map those to their own address space) but these are corner cases not even relevant for their firewalls. best Enno Cheers, Sander -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Enno Rey
-- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregister Mannheim: HRB 337135 Geschaeftsfuehrer: Enno Rey === Blog: www.insinuator.net || Conference

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Enno Rey
Hi, On Fri, Apr 18, 2014 at 11:59:04AM -0700, Doug Barton wrote: On 04/18/2014 12:57 AM, Enno Rey wrote: I fully second Sander's input. I've been involved in IPv6 planning in a number of very large enterprises now and_none_ of them required/asked for (66/overloading) NAT

Re: IPv6 isn't SMTP

2014-03-27 Thread Enno Rey
in northwest. Showers. Good, occasionally moderate. -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregister Mannheim: HRB 337135 Geschaeftsfuehrer: Enno Rey

Re: turning on comcast v6

2014-01-02 Thread Enno Rey
avoided had enough people cared to do so). Matthew Kaufman -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 173 6745902 Handelsregister Mannheim: HRB 337135 Geschaeftsfuehrer: Enno Rey

Re: NSA able to compromise Cisco, Juniper, Huawei switches

2013-12-31 Thread Enno Rey
. Why do we accept our devices, be it a PC or a router, can be persistently infected. The hardware industry needs to do better. I'm still taking all these revelations with grain of salt, until real speciment is dissected. -- ++ytti -- Enno Rey ERNW GmbH - Carl-Bosch-Str. 4

Re: NSA able to compromise Cisco, Juniper, Huawei switches

2013-12-30 Thread Enno Rey
one Enno --- Roland Dobbins rdobb...@arbor.net // http://www.arbornetworks.com Luck is the residue of opportunity and design. -- John Milton -- Enno Rey ERNW GmbH - Carl-Bosch-Str

Re: Automatic IPv6 due to broadcast

2012-04-23 Thread Enno Rey
was saying that if you enforce that all source addresses are ones that the DHCPv6 server handed out, you just broke a host that tries to do RFC4941 addresses or other similar things. -- Enno Rey ERNW GmbH - Breslauer Str. 28 - 69124 Heidelberg - www.ernw.de Tel. +49 6221 480390 - Fax 6221