RE: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-04-01 Thread Adam Thompson
> -Original Message- > From: NANOG On > Behalf Of Joe Maimon > Sent: Thursday, March 31, 2022 6:20 PM > Subject: Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 > times > > [...] > I think more and perhaps different knobs were and still are needed

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-31 Thread Joe Maimon
Matthew Petach wrote: Unfortunately, the reason crazy-long prepends actually propagate so widely in the internet core is because most of those decisions to prefer your peer's customers are done using a relatively big and heavy hammer. IOW if your peer or customer has prepended 5 times or

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-31 Thread Matthew Petach
On Thu, Mar 31, 2022 at 3:16 PM Joe Maimon wrote: > > > Joe Provo wrote: > > On Fri, Mar 25, 2022 at 11:08:01AM +0300, Paschal Masha wrote: > >> :) probably the longest prepend in the world. > >> > >> A thought though, is it breaking any standard or best practice > procedures? > > > > That said,

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-31 Thread Joe Maimon
Joe Provo wrote: On Fri, Mar 25, 2022 at 11:08:01AM +0300, Paschal Masha wrote: :) probably the longest prepend in the world. A thought though, is it breaking any standard or best practice procedures? That said, prepending pretty much anything more than your current view of the Internet's

RE: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-29 Thread Adam Thompson
og Subject: Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times Mostly what Matt said. ( I should have also said 'ride the 0/0 train INTO the DFZ, my mistake.) Essentially, if ASN X is announcing a prefix with an excessive number of prepends, they are saying to the world 'This path

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-27 Thread Baldur Norddahl
On Sun, 27 Mar 2022 at 18:31, Jon Lewis wrote: > Is prepending used for any purpose other than TE? The point I think Joe > was trying to make was prepending once or even a few times has uses. > Prepending more than a few times is unlikely to accomplish anything a few > prepends didn't get done.

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-27 Thread Jon Lewis
On Fri, 25 Mar 2022, Baldur Norddahl wrote: On Fri, 25 Mar 2022 at 17:32, Joe Provo wrote: That said, prepending pretty much anything more than your current view of the Internet's diameter in ASNs is useless in practice. That is one way of viewing it. But prepending can also be

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-26 Thread Tom Beecher
Innovation Drive > Winnipeg, MB, R3T 6A8 > (204) 977-6824 or 1-800-430-6404 (MB only) > athomp...@merlin.mb.ca > www.merlin.mb.ca > > > > *From:* NANOG *On Behalf > Of *Tom Beecher > *Sent:* Friday, March 25, 2022 4:13 PM > *To:* Paschal Masha > *Cc:* nanog &g

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-26 Thread Matthew Petach
On Fri, Mar 25, 2022 at 6:19 PM Amir Herzberg wrote: > Hi Matthew and NANOG, > > I don't want to defend prepending 255 times, and can understand filtering > of extra-prepended-announcements, but I think Matthew may not be correct > here: > >> Anyone that is prepending to do traffic engineering

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Amir Herzberg
Hi Matthew and NANOG, I don't want to defend prepending 255 times, and can understand filtering of extra-prepended-announcements, but I think Matthew may not be correct here: > Anyone that is prepending to do traffic engineering is > doing *differential* prepending; that is, a longer number > of

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Matthew Petach
On Fri, Mar 25, 2022 at 2:59 PM Adam Thompson wrote: > Tom, how exactly does someone “ride the 0/0” train in the DFZ? > It's not so much "ride the 0/0 train" as much as it is "treat excessive prepends as network-unreachable" Think of prepends beyond say 10 prepends as a way to signal

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Brian Knight via NANOG
> (204) 977-6824 or 1-800-430-6404 (MB only) > athomp...@merlin.mb.ca > www.merlin.mb.ca > > From: NANOG On Behalf Of Tom > Beecher > Sent: Friday, March 25, 2022 4:13 PM > To: Paschal Masha > Cc: nanog > Subject: Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN pr

RE: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Adam Thompson
omp...@merlin.mb.ca> www.merlin.mb.ca<http://www.merlin.mb.ca/> From: NANOG On Behalf Of Tom Beecher Sent: Friday, March 25, 2022 4:13 PM To: Paschal Masha Cc: nanog Subject: Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times The best practice with regards to as_path lengt

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Tom Beecher
The best practice with regards to as_path length is to have an edge filter that dumps any prefix with a length longer than say 10. Depending on the situation, might even be able to go smaller. At a certain point, keeping that route around does nothing for you, just shoot it and ride the 0/0

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Baldur Norddahl
On Fri, 25 Mar 2022 at 17:32, Joe Provo wrote: > That said, prepending pretty much anything more than your current view > of the Internet's diameter in ASNs is useless in practice. > That is one way of viewing it. But prepending can also be used for traffic engineering. I could prepend 1 to my

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Joe Provo
On Fri, Mar 25, 2022 at 11:08:01AM +0300, Paschal Masha wrote: > :) probably the longest prepend in the world. > > A thought though, is it breaking any standard or best practice procedures? Many popular BGP implementations have historically had weaknesses with excessively long AS-paths. Best

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Bjørn Mork
Paschal Masha writes: > :) probably the longest prepend in the world. > > A thought though, is it breaking any standard or best practice procedures? Don't think so. But there is this draft suggesting max 5: https://datatracker.ietf.org/doc/draft-ietf-grow-as-path-prepending/ Bjørn

Re: DMARC ViolationAS21299 - 46.42.196.0/24 ASN prepending 255 times

2022-03-25 Thread Paschal Masha
:) probably the longest prepend in the world. A thought though, is it breaking any standard or best practice procedures? Regards Paschal Masha | Engineering Skype ID: paschal.masha - Original Message - From: "Erik Sundberg" To: "nanog" Sent: Friday, March 25, 2022 6:43:38 AM