Re: Carrier Grade NAT

2014-07-29 Thread Matt Palmer
On Wed, Jul 30, 2014 at 09:28:53AM +1200, Tony Wicks wrote: 2. IPv6 is nice (dual stack) but the internet without IPv4 is not a viable thing, perhaps one day, but certainly not today (I really hate clueless people who shout to the hills that IPv6 is the solution for today's internet access)

Re: Richard Bennett, NANOG posting, and Integrity

2014-07-28 Thread Matt Palmer
On Sun, Jul 27, 2014 at 10:53:51PM -0700, Richard Bennett wrote: In fact Netflix is asking to connect to eyeball networks for free: http://blog.netflix.com/2014/03/internet-tolls-and-case-for-strong-net.html Strong net neutrality additionally prevents ISPs from charging a toll for

Re: Richard Bennett, NANOG posting, and Integrity

2014-07-28 Thread Matt Palmer
On Mon, Jul 28, 2014 at 01:38:03PM -0700, Michael Thomas wrote: On 7/28/14, 12:39 PM, William Herrin wrote: And continued selling the product as described, long beyond any reasonable doubt their customers expected it to work with Netflix. Right through this very minute and beyond. It would

Re: Richard Bennett, NANOG posting, and Integrity

2014-07-27 Thread Matt Palmer
On Sun, Jul 27, 2014 at 05:28:08PM -0700, Richard Bennett wrote: It's more plausible that NAACP and LULAC have correctly deduced that net neutrality is a de facto subsidy program that transfers money from the pockets of the poor and disadvantaged into the pockets of super-heavy Internet users

Re: Richard Bennett, NANOG posting, and Integrity

2014-07-27 Thread Matt Palmer
On Mon, Jul 28, 2014 at 08:16:36AM +0530, Suresh Ramasubramanian wrote: On 28-Jul-2014 8:06 am, Matt Palmer mpal...@hezmatt.org wrote: On Sun, Jul 27, 2014 at 05:28:08PM -0700, Richard Bennett wrote: It's more plausible that NAACP and LULAC have correctly deduced that net neutrality

Re: Richard Bennett, NANOG posting, and Integrity

2014-07-27 Thread Matt Palmer
On Sun, Jul 27, 2014 at 08:59:14PM -0700, Richard Bennett wrote: Maybe it would help if you tried to address the issues in a serious way instead of just trying to be cute. I will when you will, poopy head. - Matt

Re: Richard Bennett, NANOG posting, and Integrity

2014-07-27 Thread Matt Palmer
On Sun, Jul 27, 2014 at 09:08:17PM -0700, Richard Bennett wrote: I don't think it's conflation, Joly, since the essence of NN is for the eyeballs to pay for the entire cost of the network and for edge providers to use it for free; isn't that what Netflix is asking the FCC to impose under the

Re: Verizon Public Policy on Netflix

2014-07-21 Thread Matt Palmer
On Mon, Jul 21, 2014 at 09:47:34PM +0900, Paul S. wrote: On 7/21/2014 午後 09:31, Michael Conlen wrote: On Jul 18, 2014, at 2:32 PM, Jay Ashworth j...@baylink.com wrote: - Original Message - From: Owen DeLong o...@delong.com But the part that will really bend your mind is when you

Re: Inevitable death, was Re: Verizon Public Policy on Netflix

2014-07-15 Thread Matt Palmer
On Mon, Jul 14, 2014 at 10:05:21PM -0600, Brett Glass wrote: At 09:40 PM 7/14/2014, John Curran wrote: Myself, I'd call such fees to be uniform, Ah, but they are not. Smaller providers pay more per IP address than larger ones. And a much larger share of their revenues as the base fee

Re: Verizon Public Policy on Netflix

2014-07-14 Thread Matt Palmer
On Mon, Jul 14, 2014 at 10:25:22AM -0400, Jay Ashworth wrote: - Original Message - From: Matthew Petach mpet...@netflight.com It's now called Any2 Denver: Annoyingly enough, I can't find a street address for it anywhere among their literature. :( It's in a closet in the

Re: Verizon Public Policy on Netflix

2014-07-10 Thread Matt Palmer
On Thu, Jul 10, 2014 at 09:40:13PM -0400, Miles Fidelman wrote: Jimmy Hess wrote: On Thu, Jul 10, 2014 at 8:12 PM, Miles Fidelman mfidel...@meetinghouse.net wrote: Randy Bush wrote: [snip] At the ISPs expense, including connectivity to a peering point. Most content providers pay Akamai,

Re: Ars Technica on IPv4 exhaustion

2014-06-19 Thread Matt Palmer
On Thu, Jun 19, 2014 at 06:46:11PM -0500, Larry Sheldon wrote: On 6/19/2014 5:14 PM, Randy Bush wrote: and cut the tea party fanaticism. What might this mean in this context (IP) and environment (NANOG)? Death to the lemon wedge

Re: routing issues to AWS via 2914(NTT)

2014-06-13 Thread Matt Palmer
On Fri, Jun 13, 2014 at 11:44:51AM +, Paul WALL wrote: Amazon peers at many key exchanges, with dozens of hosting shops (where customers might share mutual infrastructure) like yours: https://www.peeringdb.com/view.php?asn=16509 Rather than play the blame game with third-party transit

Re: AmazonAWS contact

2014-06-04 Thread Matt Palmer
On Wed, Jun 04, 2014 at 03:19:01PM -0700, Eric Brunner-Williams wrote: Could someone from Amazon Web Services contact me off list? I'm getting root login attempts from one of your assets You and the rest of the Internet. Who would have thought that giving anything[1] than can scrape up a valid

Rick Astley, Network Engineer [was: Observations of an Internet Middleman (Level3)]

2014-05-16 Thread Matt Palmer
On Fri, May 16, 2014 at 01:47:53PM -0500, Blake Hudson wrote: Mr. Rick Astley (I assume a pseudonym) Why would you assume that? Mr. Astley has long been a champion of solid network engineering, and even net neutrality... he's long said that he's Never gonna drop a route, never gonna fill a

Re: Observations of an Internet Middleman (Level3) (was: RIP Network Neutrality

2014-05-15 Thread Matt Palmer
On Thu, May 15, 2014 at 07:29:06AM -0700, Owen DeLong wrote: The result of deregulating the current environment would only be more pain and cost to the consumer than we currently have with no improvement in speeds or capabilities and no additional innovation. Indeed. While I certainly

Re: Observations of an Internet Middleman (Level3) (was: RIP Network Neutrality

2014-05-14 Thread Matt Palmer
On Wed, May 14, 2014 at 07:01:36PM -0500, Larry Sheldon wrote: Maybe it is time to try a free market. Can't do that, it would be UnAmerican! - Matt -- I can only guess that the designer of the things had a major Toilet Duck habit and had managed to score a couple of industrial-sized bottles

Re: US patent 5473599

2014-05-07 Thread Matt Palmer
On Wed, May 07, 2014 at 05:57:01PM -0400, David Conrad wrote: However, assume that the OpenBSD developers did document their protocol and requested an IESG action and was refused. Do you believe that would justify squatting on an already assigned number? I'm going to go with yes, just to be

Re: US patent 5473599

2014-05-07 Thread Matt Palmer
On Wed, May 07, 2014 at 07:33:45PM -0700, Owen DeLong wrote: On May 7, 2014, at 4:19 PM, Matt Palmer mpal...@hezmatt.org wrote: On Wed, May 07, 2014 at 05:57:01PM -0400, David Conrad wrote: However, assume that the OpenBSD developers did document their protocol and requested an IESG action

Re: Phase 4.

2014-04-27 Thread Matt Palmer
On Sun, Apr 27, 2014 at 03:21:50AM -0400, Andrew D Kirch wrote: On Apr 24, 2014, at 1:54 AM, Bryan Socha br...@digitalocean.com wrote: Whats the big deal If your just arin, dont panic. Akamai and digitalocean has been the only people aquire fair priced v4 putside arin.So

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Matt Palmer
On Thu, Apr 17, 2014 at 09:05:17PM -0500, Timothy Morizot wrote: On Apr 17, 2014 7:52 PM, Matthew Kaufman matt...@matthew.at wrote: While you're at it, the document can explain to admins who have been burned, often more than once, by the pain of re-numbering internal services at static

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Matt Palmer
On Fri, Apr 18, 2014 at 06:37:28PM -0400, Lee Howard wrote: On 4/18/14 4:33 PM, George Herbert george.herb...@gmail.com wrote: If William and I fight that fight, lose it, and come back and tell you They won't go because insufficient NAT you need to listen. I've fought this in a dozen places

Re: Requirements for IPv6 Firewalls

2014-04-18 Thread Matt Palmer
On Fri, Apr 18, 2014 at 10:04:35PM -0400, Jeff Kell wrote: As to address the other argument in this threat on NAT / private addressing, PCI requirement 1.3.8 pretty much requires RFC1918 addressing of the computers in scope... has anyone hinted at PCI for IPv6? 1.3.8 lists use of RFC1918

Re: DNSSEC?

2014-04-11 Thread Matt Palmer
On Fri, Apr 11, 2014 at 09:37:38PM +0200, Carsten Bormann wrote: On 11 Apr 2014, at 21:25, Chris Adams c...@cmadams.net wrote: DNSSEC does not use TLS (or any other kind of transport encryption). The administrative interfaces controlling the implementation might still do. That's not

Re: [[Infowarrior] - NSA Said to Have Used Heartbleed Bug for Years]

2014-04-11 Thread Matt Palmer
On Fri, Apr 11, 2014 at 04:03:36PM -0400, William Herrin wrote: The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two

Re: Serious bug in ubiquitous OpenSSL library: Heartbleed

2014-04-08 Thread Matt Palmer
On Wed, Apr 09, 2014 at 12:18:00AM -0500, jamie rishaw wrote: Here's the only way to keep a system safe from Internet hackers: http://goo.gl/ZvGrXw [google images] /me is disappointed that wasn't a pair of scissors - Matt -- Sure, it's possible to write C in an object-oriented way. But,

Re: Cisco Security Advisory: Cisco IOS Software SSL VPN Denial of Service Vulnerability

2014-03-27 Thread Matt Palmer
On Wed, Mar 26, 2014 at 10:52:42AM -0600, kendrick eastes wrote: The Full-disclosure mailing list was recently... retired, I guess cisco thought NANOG was the next best place. Nope, they've been sending these things here for as long as I can remember. I have NFI why -- probably hubris,

Re: IPv6 Security [Was: Re: misunderstanding scale]

2014-03-26 Thread Matt Palmer
On Wed, Mar 26, 2014 at 10:55:03AM -0700, Luke S. Crawford wrote: There are many ways to skin this cat; stateless autoconfig looks like it mostly works, but privacy extensions seem to be the default in many places; outgoing IPv6 from those random addresses will trip my BCP38 filters. Your

Re: misunderstanding scale (was: Ipv4 end, its fake.)

2014-03-23 Thread Matt Palmer
On Sat, Mar 22, 2014 at 07:57:04PM -, John Levine wrote: In such a case, where you are still pushing the case for IPv4, how do you envisage things will look on your side when everybody else you want to talk to is either on IPv6, or frantically getting it turned up? Do you reckon anyone

Re: misunderstanding scale

2014-03-23 Thread Matt Palmer
On Mon, Mar 24, 2014 at 10:15:27AM +1100, Mark Andrews wrote: In message 532f60dd.3030...@foobar.org, Nick Hilliard writes: On 23/03/2014 21:02, Mark Andrews wrote: Actually all you have stated in that printer vendors need to clean up their act and not that one shouldn't expect to be

Re: Fwd: [ PRIVACY Forum ] Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping

2014-03-06 Thread Matt Palmer
On Wed, Mar 05, 2014 at 12:37:29PM +0100, María García wrote: 2014-03-05 7:17 GMT+01:00 Matt Palmer mpal...@hezmatt.org: the 'goto cleanup' tests were introduced in 0fba2d90, way back in October 2003 Where can you see that the 'goto cleanup' tests were introduced in 0fba2d90, way back

Re: Fwd: [ PRIVACY Forum ] Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping

2014-03-04 Thread Matt Palmer
On Tue, Mar 04, 2014 at 10:07:56PM -0500, Jay Ashworth wrote: Oh hell. Is this the *same* bug that just broke in Apple code last week? I'd be surprised if Apple used GnuTLS, on licencing grounds... widely used cryptographic code library. The bug in the GnuTLS library On the other hand,

Re: Updated ARIN allocation information

2014-01-31 Thread Matt Palmer
On Fri, Jan 31, 2014 at 11:09:43AM -0500, John Curran wrote: better utilization. It would be nice if there was a way to fairly settle up for the imputed cost of adding a given route to the routing table, as this would provide some proportionate backpressure on growth, would

Re: Updated ARIN allocation information

2014-01-31 Thread Matt Palmer
On Fri, Jan 31, 2014 at 03:10:56PM -0800, Owen DeLong wrote: On Jan 31, 2014, at 1:29 PM, Matt Palmer mpal...@hezmatt.org wrote: Imagine one of the big players saying, we're going to charge you $X per route you send to us (just like transit agreements that state, we will charge you $X/GB

Re: looking for good AU dedicated server providers..

2014-01-30 Thread Matt Palmer
On Thu, Jan 30, 2014 at 08:49:53AM -0500, Carlos Kamtha wrote: The box will provide services to clients. so it has to be robust and free from bandwidth limitations. That's going to get expensive. .au bandwidth is a touch on the pricey side. - Matt

Re: looking for good AU dedicated server providers..

2014-01-29 Thread Matt Palmer
On Wed, Jan 29, 2014 at 06:37:35PM -0500, Carlos Kamtha wrote: b.) relatively acessible support staff. Accessable for what? Hardware maintenance, or full-service outsourced sysadmin assistance? What timezones, and what communication method? (Also, there's AusNOG if you want to get local

Re: turning on comcast v6

2014-01-03 Thread Matt Palmer
On Fri, Jan 03, 2014 at 12:40:42AM -0800, Doug Barton wrote: Further, by far the common case is for network gear to _already_ be configured to avoid permitting hosts to act as DHCP servers unless they are supposed to be. It's rare to even find a network device that has RA Guard capabilities,

Re: Juniper SSL VPN

2013-12-31 Thread Matt Palmer
On Tue, Dec 31, 2013 at 04:19:24PM -0500, valdis.kletni...@vt.edu wrote: On Tue, 31 Dec 2013 23:09:58 +0200, Eugeniu Patrascu said: We need an emergency fix because a piece of software unexpectedly hit an end-of-life date? Didn't we learn anything 14 years ago??!? Juniper just

Re: The Making of a Router

2013-12-28 Thread Matt Palmer
On Fri, Dec 27, 2013 at 08:47:25PM -0500, Jon Sands wrote: On 12/27/2013 8:18 PM, Baldur Norddahl wrote: Brocade NetIron CER 2024F-4X goes for about $21k As one last aside, if you're paying 21k, you're paying a little more than twice too much. Call Brocade and get yourself a real quote.

Re: The Making of a Router

2013-12-28 Thread Matt Palmer
On Sat, Dec 28, 2013 at 08:53:53AM -0600, Chris Adams wrote: There is a significant value in just plug it in and it works, and if you don't figure your time investment (both up-front and on-going) into the cost, you are greatly fooling yourself. What ISP-grade router are you using that is

Re: The Making of a Router

2013-12-27 Thread Matt Palmer
On Fri, Dec 27, 2013 at 10:18:47AM -0500, Jon Sands wrote: On Dec 27, 2013 10:08 AM, Baldur Norddahl baldur.nordd...@gmail.com wrote: We are an upstart and just buying the fancy Juniper switch times two would burn half of my seed capital. Then you didn't ask for nearly enough capital.

Re: The Making of a Router

2013-12-26 Thread Matt Palmer
On Thu, Dec 26, 2013 at 05:21:11PM +, Warren Bailey wrote: Not to mention the fact that this router will require support. The build before buy people are silly. Let the smart router guys do their thing and use their box accordingly. When it breaks call to inform them it broke and they

Re: Is there a method or tool(s) to prove network outages?

2013-12-01 Thread Matt Palmer
On Sun, Dec 01, 2013 at 05:56:51PM +0100, Notify Me wrote: Please I have a very problematic radio link which goes out and back on again every few hours. The only way I know this is happening is from my gateway device: a Sophos UTM that sends email anytime there's been an outage. The ISP

Re: minimum IPv6 announcement size

2013-09-27 Thread Matt Palmer
On Fri, Sep 27, 2013 at 02:10:47AM -0400, Ryan McIntosh wrote: I don't respond to many of these threads but I have to say I've contested this one too only to have to beaten into my head that a /64 is appropriate.. it still hasn't stuck, but unfortunately rfc's for other protocols depend on the

Re: iOS 7 update traffic

2013-09-25 Thread Matt Palmer
On Mon, Sep 23, 2013 at 08:36:30PM -0500, Joe Greco wrote: That's just the typical Bittorrent /client/, but the idea of using Bittorrent means the /protocol/. A special Bittorrent client could be written for ISPs with uploads disabled and Apple could also disable them on the

Re: Opening Discussion: Speculation on BULLRUN

2013-09-08 Thread Matt Palmer
On Sun, Sep 08, 2013 at 03:50:33PM -0400, Jean-Francois Mezei wrote: Here is what the politicians forget: Because the economy is moving to the internet, losing trust in the internet is akin to losing trust in the banking system. If the last five years have left anyone with a shred of trust in

Re: google mail problems?

2013-06-26 Thread Matt Palmer
On Wed, Jun 26, 2013 at 01:57:10PM -0500, Blair Trosper wrote: But, as usual, everything is totally fine according to the GApps status page: http://www.google.com/appsstatus#hl=env=statusts=1372272841152 Status pages, at least for any service big enough to matter, are nothing more than a

Re: Fwd: [Filtering of NTP-access to swisstime.ethz.ch as of July 1st, 2013]

2013-06-25 Thread Matt Palmer
On Tue, Jun 25, 2013 at 06:38:05PM -0500, Larry Sheldon wrote: What is it about people that makes them free-load on services like NTP chimes and DNSBLS but refuse to stay in contact with(or at least contactable by) the providers when important stuff is pending? It's on the Internet. Therefore

Re: High throughput bgp links using gentoo + stipped kernel

2013-05-20 Thread Matt Palmer
On Sun, May 19, 2013 at 04:42:23PM -0700, Seth Mattinen wrote: On 5/19/13 4:27 PM, Ben wrote: Do you actually need stateful filtering? A lot of people seem to think that it's important, when really they're accomplishing little from it, you can block ports etc without it. I believe PCI

Re: High throughput bgp links using gentoo + stipped kernel

2013-05-19 Thread Matt Palmer
On Sun, May 19, 2013 at 11:48:17AM -0400, Nick Khamis wrote: We do use a statefull iptables on our router, some forward rules... This is known to be on of our issues, not sure if having a separate iptables box would be the best and only solution for this? I don't know about only, but it'd have

Re: It's the end of the world as we know it -- REM

2013-04-25 Thread Matt Palmer
On Thu, Apr 25, 2013 at 07:49:03PM -0700, Michael Thomas wrote: On 04/25/2013 07:27 PM, Owen DeLong wrote: AWS stands out as a complete laggard in this area. Heh... that's why I put all kinds of question marks and hedges :) That's disappointing about aws. On the other hand, if aws lights up

Re: BCP38 tester?

2013-04-01 Thread Matt Palmer
On Mon, Apr 01, 2013 at 12:31:05PM -0400, Jay Ashworth wrote: From: Jimmy Hess mysi...@gmail.com Ah, but did you actually test your guess on a reasonably large variety of NAT platforms? He may not have, but now that I'm thinking (caffeine is a wonder drug), I have: I've worked on, for

Re: Security reporting response handling [was: Suggestions for the future on your web site]

2013-01-22 Thread Matt Palmer
On Mon, Jan 21, 2013 at 11:23:16PM -0500, Jean-Francois Mezei wrote: This article may be of interest: http://arstechnica.com/security/2013/01/canadian-student-expelled-for-playing-security-white-hat/ Basically, a Montreal student, developping mobile software to interface with schools

Re: Suggestions for the future on your web site: (was cookies, and before that Re: Dreamhost hijacking my prefix...)

2013-01-20 Thread Matt Palmer
On Sat, Jan 19, 2013 at 03:54:37PM -0800, George Herbert wrote: On Jan 18, 2013, at 7:52 PM, Matt Palmer mpal...@hezmatt.org wrote: On Fri, Jan 18, 2013 at 09:41:41AM +0100, . wrote: On 17 January 2013 23:38, Matt Palmer mpal...@hezmatt.org wrote: .. By the way, if anyone *does* know

Re: Suggestions for the future on your web site: (was cookies, and before that Re: Dreamhost hijacking my prefix...)

2013-01-20 Thread Matt Palmer
On Sat, Jan 19, 2013 at 06:33:33PM -0600, Jimmy Hess wrote: On 1/18/13, Matt Palmer mpal...@hezmatt.org wrote: Primarily abuse prevention. If I can get a few thousand people to do something resource-heavy (or otherwise abusive, such as send an e-mail somewhere) within a short period

Re: Suggestions for the future on your web site: (was cookies, and before that Re: Dreamhost hijacking my prefix...)

2013-01-19 Thread Matt Palmer
On Thu, Jan 17, 2013 at 02:55:59PM -0800, Scott Weeks wrote: --- mpal...@hezmatt.org wrote: --- From: Matt Palmer mpal...@hezmatt.org [Cookies on stat.ripe.net] On Wed, Jan 16, 2013 at 11:36:25AM -0800, Shrdlu wrote: The cookie stays around for a YEAR (if I let it), and has

Re: Suggestions for the future on your web site: (was cookies, and before that Re: Dreamhost hijacking my prefix...)

2013-01-19 Thread Matt Palmer
On Fri, Jan 18, 2013 at 09:41:41AM +0100, . wrote: On 17 January 2013 23:38, Matt Palmer mpal...@hezmatt.org wrote: .. By the way, if anyone *does* know of a good and reliable way to prevent CSRF without the need for any cookies or persistent server-side session state, I'd love to know

Re: Suggestions for the future on your web site: (was cookies, and before that Re: Dreamhost hijacking my prefix...)

2013-01-17 Thread Matt Palmer
[Cookies on stat.ripe.net] On Wed, Jan 16, 2013 at 11:36:25AM -0800, Shrdlu wrote: The cookie stays around for a YEAR (if I let it), and has the following stuff: Name: stat-csrftoken Content: 7f12a95b8e274ab940287407a14fc348 [...] To your credit, you only ask once, but you ought to ask

Single IP routing problems through Level3

2008-06-15 Thread Matt Palmer
We're seeing some really weird issues with connections that go through / to Level3 IP space. Basically, certain pairs of IPs (particular L3 IPs coupled with particular IPs of ours) have dodgy/nonexistent connectivity, but if you change the IP at either end everything's hunky dory. I've sniffed

Re: comcast

2008-06-12 Thread Matt Palmer
On Thu, Jun 12, 2008 at 06:02:52PM -0700, Thompson, Taeko wrote: Does anybody heard if comcast is having problems today? Since I got on shift two hours ago, I've done nothing but stare at traceroutes into and out of Comcast space trying to reassure dozens of customers that we're not down,

Re: bandwidth providers and pricing in China

2008-03-07 Thread Matt Palmer
On Fri, Mar 07, 2008 at 10:22:32AM -0800, matthew zeier wrote: Looking for anyone who has experience deploying a network in China. I'm getting 1500RMB/Mbps with a 10Mbps commit that I'm already bumping up against. Moving to 20Mbps is going to drop me to 1200RMB/Mbps or about $3400 USD

<    1   2