Re: AS3356 Announcing 2000::/12

2022-12-13 Thread Job Snijders via NANOG
The Internet delivers when we need it the most! :-) https://is2000slash12announcedagain.com/ Props to Ben Cartwright-Cox

Re: AS3356 Announcing 2000::/12

2022-12-10 Thread Geoff Huston
> On 10 Dec 2022, at 11:24 am, Matthew Petach wrote: > > > > As I said--I'm probably being overly paranoid, but I can't help but > wonder what packets such a collector might see, if left to run for a > week or two... ^_^; > A decade ago it looked like this…

Re: AS3356 Announcing 2000::/12

2022-12-09 Thread Matthew Petach
On Thu, Dec 8, 2022 at 9:35 AM Randy Bush wrote: > while i think the announcement is, shall we say, embarrassing, i do not > see how it would be damaging. real/correct announcements would be for > longer prefixes, yes? > > randy > Putting on a probably-overly-paranoid hat for a moment... If

Re: AS3356 Announcing 2000::/12

2022-12-09 Thread Randy Bush
> I know of a few people in a Discord that filter out anything bigger > than /16 routes, would this be wise to implement as a best practice? once upon a time, a very large provider took two /8s and announced as a /7. a vendor who thought a /8 was as short as they would ever see had routers fall

RE: AS3356 Announcing 2000::/12

2022-12-09 Thread Ryan Hamel
: AS3356 Announcing 2000::/12 On Thu, Dec 8 2022 at 12:38 PM, Job Snijders mailto:nanog@nanog.org> > wrote: Hi all, On Wed, Dec 07, 2022 at 08:24:54PM -0800, Ryan Hamel wrote: AS3356 has been announcing 2000::/12 for about 3 hours now, an aggregate covering over 23K pr

Re: AS3356 Announcing 2000::/12

2022-12-09 Thread Warren Kumari
On Thu, Dec 8 2022 at 12:38 PM, Job Snijders wrote: Hi all, > > On Wed, Dec 07, 2022 at 08:24:54PM -0800, Ryan Hamel wrote: > > AS3356 has been announcing 2000::/12 for about 3 hours now, an aggregate > covering over 23K prefixes (just over 25%) of the IPv6 DFZ. > > A few months ago I wrote:

Re: AS3356 Announcing 2000::/12

2022-12-08 Thread Job Snijders via NANOG
Hi all, On Wed, Dec 07, 2022 at 08:24:54PM -0800, Ryan Hamel wrote: > AS3356 has been announcing 2000::/12 for about 3 hours now, an aggregate > covering over 23K prefixes (just over 25%) of the IPv6 DFZ. A few months ago I wrote: "Frequently Asked Questions about 2000::/12 and related routing

Re: AS3356 Announcing 2000::/12

2022-12-08 Thread Randy Bush
while i think the announcement is, shall we say, embarrassing, i do not see how it would be damaging. real/correct announcements would be for longer prefixes, yes? randy

Re: AS3356 Announcing 2000::/12

2022-12-07 Thread Don Beal
That would be a nice start :-) On Thu, Dec 8, 2022 at 6:45 AM Heasley wrote: > > > Am 12/7/22 um 22:25 schrieb Don Beal : > >  > How can RPKI / OV prevent such a leak when there is no ROA for 2000::/12, > > > If all ASes participated, no „unknowns“, unknowns could be dropped, …. >

Re: AS3356 Announcing 2000::/12

2022-12-07 Thread Christopher Morrow
On Thu, Dec 8, 2022 at 1:45 AM Heasley wrote: > > > > Am 12/7/22 um 22:25 schrieb Don Beal : > >  > How can RPKI / OV prevent such a leak when there is no ROA for 2000::/12, > > > If all ASes participated, no „unknowns“, unknowns could be dropped, …. > yea that might be a tad dangerous today :(

Re: AS3356 Announcing 2000::/12

2022-12-07 Thread Heasley
Am 12/7/22 um 22:25 schrieb Don Beal :How can RPKI / OV prevent such a leak when there is no ROA for 2000::/12,If all ASes participated, no „unknowns“, unknowns could be dropped, …. what would 6762|2914|174|* invalidate against? Until a future where everything is 'valid', RPKI is unable to pare

Re: AS3356 Announcing 2000::/12

2022-12-07 Thread Don Beal
How can RPKI / OV prevent such a leak when there is no ROA for 2000::/12, what would 6762|2914|174|* invalidate against? Until a future where everything is 'valid', RPKI is unable to pare out less-specific conflicts. It does look like 3356 pulled the announcement, which is good. On Thu, Dec 8,

RE: AS3356 Announcing 2000::/12

2022-12-07 Thread Ryan Hamel
These as well: 3257 3356 3491 3356 They probably leaked a hold down route. Ryan Hamel -Original Message- From: Christopher Morrow Sent: Wednesday, December 7, 2022 8:48 PM To: r...@rkhtech.org Cc: nanog@nanog.org Subject: Re: AS3356 Announcing 2000::/12 On Wed, Dec 7, 2022 at 11:25

Re: AS3356 Announcing 2000::/12

2022-12-07 Thread Christopher Morrow
On Wed, Dec 7, 2022 at 11:25 PM Ryan Hamel wrote: > > AS3356 has been announcing 2000::/12 for about 3 hours now, an aggregate > covering over 23K prefixes (just over 25%) of the IPv6 DFZ. > > interesting that this is leaking outside supposed RPKI OV boundaries as well. For example: 6762 3356