Re: need help about switch montior

2011-03-14 Thread Alain Hebert
- Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 03/14/11 15:17, Brent Jones wrote: On Mon, Mar 14, 2011 at 9:07 AM, Jason

Re: need help about switch montior

2011-03-14 Thread Alain Hebert
it takes about 1m to process. We mainly placed threshold on Environment reading, Traffic High/Low, Discards and other Errors on each ports. You should check Cacti licensing, I think it is still GPL. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50

Re: Security reporting response handling [was: Suggestions for the future on your web site]

2013-01-22 Thread Alain Hebert
of internet security when it comes to XSS/SQL Injection (see OWAPS/etc). PS: Being in Montreal, too bad someone already offered him a job :( I may have some part-time work for a bright kid soon. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St

Re: switch 10G standalone TOR, core to DC

2013-01-29 Thread Alain Hebert
with better documentation and support. Good luck with your project =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: Ddos mitigation service

2013-01-31 Thread Alain Hebert
Look up DOSArrest. (dosarrest.com) 3 permanent cases easily solved with them. And no, I'm not one of their sales rep =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W

Re: Muni fiber: L1 or L2?

2013-02-08 Thread Alain Hebert
Hi, If by FTTH you mean the ADSL2+/VDSL offering they packaged as Fibe (yes the named it that). It is available to resellers... /wave - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield

Re: Interesting debugging: Specific packets cause some Intel gigabit ethernet controllers to reset

2013-02-08 Thread Alain Hebert
an happy weekend. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 02/06/13 15:47, Jay Ashworth wrote: - Original

Re: bgp for ipv6 question

2013-02-14 Thread Alain Hebert
, Uses 2047140 bytes Number of Neighbors Configured: 6, UP: 5 Number of Routes Installed: 40326, Uses 3468036 bytes Number of Routes Advertising to All Neighbors: 34987 (34987 entries), Uses 1679376 bytes Number of Attribute Entries Installed: 31290, Uses 2816100 bytes - Alain Hebert

About private networks (Was Re: NYT covers China cyberthreat)

2013-02-20 Thread Alain Hebert
-contract that to lets says... some Chinese outfit =D TLDR: Feasable, hella costly. PS: http://spybusters.blogspot.ca/2010/11/fiber-optics-easier-to-wiretap-than.html Enjoy this week end of the world news. - Alain Hebertaheb...@pubnix.net PubNIX Inc

Re: Open Resolver Problems

2013-03-25 Thread Alain Hebert
Well, Why would you only go after them? Easier target to mitigate the problem? That might be just me, but I find those peers allowing their customers to spoof source IP addresses more at fault. PS: Some form of adaptive rate limitation works for it btw =D - Alain

Re: Open Resolver Problems

2013-03-25 Thread Alain Hebert
Hi, Well... On 03/25/13 12:51, Nick Hilliard wrote: On 25/03/2013 16:35, Alain Hebert wrote: That might be just me, but I find those peers allowing their customers to spoof source IP addresses more at fault. that is equally stupid and bad. In my eyes, those peers

Re: Open Resolver Problems

2013-03-25 Thread Alain Hebert
. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: Open Resolver Problems

2013-03-26 Thread Alain Hebert
Well, And why not targeting all that animosity to the peers allowing source IP spoofing? DNS Servers don't attack you, people letting their customers spoof source IP do. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles

Re: Open Resolver Problems

2013-03-26 Thread Alain Hebert
Well, On 03/26/13 11:38, Nick Hilliard wrote: On 26/03/2013 15:06, Alain Hebert wrote: And why not targeting all that animosity to the peers allowing source IP spoofing? I do - and I gave a bunch of talks in europistan over the last 12 months which included explicit encouragement

Re: Open Resolver Problems

2013-03-27 Thread Alain Hebert
they where always rate-limited... But a few of my clients where for an amount around ~80Mbps of amps. And got fixed within the hour. Now about the struggling about BCP38... - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box

Re: Open Resolver Problems

2013-03-27 Thread Alain Hebert
today's drama. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: BCP38 needs advertising

2013-03-27 Thread Alain Hebert
bcp38.org coming soon =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 03/27/13 11:20, Jack Bates wrote

Re: BCP38 needs advertising

2013-03-27 Thread Alain Hebert
Noted. But today's contribution by Eric M. Caroll might end up on the front page =D. I got the domains... Now I just need a few free hours to setup something useful. As always, don't be shy to drop me contribution offlist. - Alain Hebert

Re: BCP38 needs advertising

2013-03-29 Thread Alain Hebert
, the registrar or even the hosting location. Hopefully this can become usefull =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: BCP38.info is now active

2013-03-29 Thread Alain Hebert
Well, Usual failure from my part =D. But I think I see what's happening... ns1.bcp38.org ns2.bcp38.org Are not yet registered. I've move them to production servers until it complete. Let me know. - Alain Hebertaheb...@pubnix.net

Re: BCP38 tester?

2013-03-31 Thread Alain Hebert
or security concerns or whatever. Why can't they help the cause by implementing some sort of RFC'ified BCP38 thing? An easy target would be anti-virus/trojan/security software providers that could add a BCP38 check to their software =D - Alain Hebertaheb

Re: BCP38 tester?

2013-04-01 Thread Alain Hebert
; ( I'm looking around for more CPE I could use, for testing =D ) PS: I'm not promoting the listed vendor, products. Its only a quick test with what I had on my hand during breakfast. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St

Re: BCP38 tester?

2013-04-01 Thread Alain Hebert
Hi, http://spoofer.csail.mit.edu/ is really the best place to certify for BCP38. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.net

Re: BCP38 tester?

2013-04-01 Thread Alain Hebert
On 04/01/13 10:09, valdis.kletni...@vt.edu wrote: On Mon, 01 Apr 2013 09:34:31 -0400, Alain Hebert said: I'm sad to confirm that my spoof test was successful with a: . SageMCom modem+router, which is used by a big TelCo around my part, for both their residential and commercial

Re: Quad-A records in Network Solutions ?

2013-04-09 Thread Alain Hebert
Hi, At least I know the infrastructure is not ready to accept IPv6 for NS registration. I tried with NetSol and GoD. Which remind me... I'm still waiting on my NSx.BCP38.ORG from GoD? Grr... (hate when someone is right) - Alain Hebert

Re: Mitigating DNS amplification attacks

2013-05-01 Thread Alain Hebert
query; . Dynamic ACL them; then . Give a talk to your customers =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514

Re: facebook spying on us?

2011-09-29 Thread Alain Hebert
( Being this is a Windows box) Want to scare yourself silly? . Power off the PC; . Plug it a switch; . Mirror the PC port into a Unix box running Wireshark; . Boot the PC Enjoy all the info leakages from all the apps you installed over the years. - Alain Hebert

ARIN and Legacy IPv4 Assignement from CA*Net (Canarie)

2011-10-25 Thread Alain Hebert
:( Thanks. PS: Check your ARIN records if you have subnets in the 198., 199. and 205. just in case. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http

Re: 10G switchrecommendaton

2012-01-27 Thread Alain Hebert
. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 01/27/12 03:32, Erik Bais wrote: We have a full purple network, so my answer

Re: common time-management mistake: rack stack

2012-02-17 Thread Alain Hebert
Hi, Or sometimes you don't let a hazardous task like handling a Carrier Class Router to your CCNA in case they injure themself. Or worst... drop it =D ( From an actual experience ) - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St

Re: Programmers with network engineering skills

2012-03-05 Thread Alain Hebert
Trunking and VRRP to your list... I spent many hours explaining those to no avail on many occasion. Sad. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http

Re: SORBS?!

2012-04-04 Thread Alain Hebert
username/password as https://www.us.sorbs.net. You can follow up there with your ticket #, if their robot is being a bit too fascist. ( ecarbonel was the guy that help us in our case ) PS: The ticketing system is not that fast, so be patient. /wave Chris - Alain Hebert

Re: ASN source when using -A with traceroute

2012-05-16 Thread Alain Hebert
= getenv (RA_SERVICE); if (!service) service = DEF_RADB_SERVICE; n = snprintf (buf, sizeof (buf), %s\r\n, query); Yadi, yada... So unless radb croak... you'll be fine. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box

Re: Peer1/Server Beach support for BGP on dedicated servers

2012-05-19 Thread Alain Hebert
On Sat, May 19, 2012 at 3:23 AM, Anurag Bhatia m...@anuragbhatia.com wrote: Was wondering if there's anyone from Server Beach/Peer1 here. We have a dedicated server with them which we primarily use for DNS. I am adding support for anycasting on that one but seems like Peer1 is not supporting

Re: Spam from inteliquent.com subject nanog

2012-05-22 Thread Alain Hebert
changed their name to Accenture (yuck) after that unfortunate incident. PS: I know they merge =D I'm just not a big fan of their new name. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7

Re: Constant low-level attack

2012-06-29 Thread Alain Hebert
... they are not about to lose customers to something as trivial as computer security. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 06/28/12 17

Re: FYI Netflix is down

2012-07-09 Thread Alain Hebert
that because everything can be categorized as software that someone point is invalid. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 07

Re: Verizon FiOS - is BGP an option?

2012-08-03 Thread Alain Hebert
that kind of tunnel to bypass some belligerent TelCo. But if you're going to drop your T1 for Cable/DSL get 2 of them using different technology and from different provider (aka 1 Cable and 1 DSL =D). Have fun. - Alain Hebertaheb...@pubnix.net

Re: vyatta for bgp

2011-09-15 Thread Alain Hebert
for it. It end up being a choice between risk and cost and being that you can get your hand on second hand iron for cheap these days... Why risk it. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W

Open Resolvers pseudo Honey Pot (Was: Open Resolver Problems)

2013-05-09 Thread Alain Hebert
1090 . IN ANY +E 24.244.248.57 1364 . IN ANY +E 82.132.226.216 1079 . IN ANY +E 69.162.97.99 1601 . IN ANY +E - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec

Re: Open Resolvers pseudo Honey Pot (Was: Open Resolver Problems)

2013-05-09 Thread Alain Hebert
It looks like to be a service and some of their customers. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 05

Re: Open Resolvers pseudo Honey Pot (Was: Open Resolver Problems)

2013-05-10 Thread Alain Hebert
On 05/09/13 19:03, Mark Andrews wrote: In message 518bd982.60...@pubnix.net, Alain Hebert writes: ( Ok, ok, another bad customer =D ) Starting today at 5h15m EST... There is a bigger than usual DDoS amplification against the IP's listed below. Granted root servers query

Re: PDU recommendations

2013-06-24 Thread Alain Hebert
. They should always be behind some sort of firewall with rules limiting its access. PS: Ours are a few years old, I'm sure APC added some sort of security since then, you may want to look 'em up. Happy 24th to all. - Alain Hebertaheb...@pubnix.net PubNIX

Friday Hosing

2013-07-12 Thread Alain Hebert
. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: Friday Hosing

2013-07-12 Thread Alain Hebert
markets. As this being in Canada... They can easily bury any legal action in suits for centuries =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http

Re: WaPo writes about vulnerabilities in Supermicro IPMIs

2013-08-16 Thread Alain Hebert
into they own VLANs+Subnets. Meaning: PCI DMZ Zone has its own DMZ iBMC VLAN/Subnet/FW Rules, PCI DB Zone has its own iBMC VLAN/Subnet/FW Rules, etc. It is a few more VLAN/Subnets... but modern Firewall can handle this easy. PS: proposed as in not giving them a choice =D - Alain Hebert

Re: d6991.com traffic

2013-09-23 Thread Alain Hebert
be pretty easy to track down the domain build for the purpose of DNS DDoS, Just saying... - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax

Need offlist contact for relay.globetrotter.net

2013-10-10 Thread Alain Hebert
as usual. Have fun. -- - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: CNAME issue

2013-12-12 Thread Alain Hebert
$ORIGIN abcd.com. yadiyada TTL SOA $INCLUDEdomains/abcd.com.all Just make sure nothing is the .all has the .abcd.com. (dots are important). Without bind: Good luck. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles

Re: Best practice on TCP replies for ANY queries

2013-12-12 Thread Alain Hebert
The internet will be better without ISP refusing to apply BCP38. end of comment This is a pointless argument since the majority of the industry prefer going after the flavor of the month UDP flood instead of curbing the problem at its source once and for all. - Alain Hebert

Re: NetSol opts domain customers into $1800 Security program?

2014-01-23 Thread Alain Hebert
. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 01/23/14 00:19, John Levine wrote: I suppose they COULD move their domain

Re: bcp38.info wiki signup problem

2014-01-24 Thread Alain Hebert
=Main+Page You're right, directly to [Sign up] wont work. Sorry :( - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990

About ddos-respo...@nfoservers.com

2014-01-24 Thread Alain Hebert
of communication they are not changing their procedures :( Anyone else receiving those emails? - Since most providers (at any level) are not putting any effort on BCP38. Is there a [Spoofing Tracking Squad] out there? ( We're on GT-T/nLayer/Tinet ) -- - Alain Hebert

Re: About ddos-respo...@nfoservers.com

2014-01-24 Thread Alain Hebert
Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 01/24/14 09:36, Jared Mauch wrote: On Jan 24, 2014, at 9:22 AM, Alain Hebert

While on the subject of IRR and route objects

2014-01-31 Thread Alain Hebert
solutions, there seems to be no commercial package. Any lead will be appreciated. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514

Re: While on the subject of IRR and route objects

2014-01-31 Thread Alain Hebert
On 01/31/14 10:02, Nick Hilliard wrote: On 31/01/2014 13:58, Alain Hebert wrote: IRRToolset 5.0.1 (rtconfig really) finally gave out on a pretty messy RPSL parse. of direct relevance to this: https://lists.isc.org/pipermail/irrtoolset/2011-April/000736.html tl;dr: rpsl itself is a mess

Re: While on the subject of IRR and route objects

2014-01-31 Thread Alain Hebert
Yes, its the first thing I tried. Iti's still ~82k =D The as-set included some of his peering as export too. We're both looking into it. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770

Re: 7206 VXR NPE-G1 throughput

2014-02-10 Thread Alain Hebert
I have one but I never ran that much BW thru mine. But the CPU usage is what will kill you. Also the entire platform is rate for 1.8Gbs aggregated which mean depending on which interface you have, and which bus they are connected to, 900Mbps might be its limit. - Alain Hebert

Re: The somewhat illegal fix for NTP attacks

2014-02-24 Thread Alain Hebert
, but the corporations involved have more money than the small guy you'll bash for having the balls of running a resolver for his roaming customers. This false debate will never end... - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770

BCP38, DNS Reflection and IPv6

2014-03-07 Thread Alain Hebert
queries then stopping for 10s to a minute. I have a good idea why. -- - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: Serious bug in ubiquitous OpenSSL library: Heartbleed

2014-04-08 Thread Alain Hebert
a way to use the HB before satisfying the verify. I might be wrong. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514

Re: Phase 4.

2014-04-24 Thread Alain Hebert
Well, Sorry Bryan, Your post is just to awful to take seriously. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514

Re: Dealing with auditors (was Re: We hit half-million: The Cidr Report)

2014-05-01 Thread Alain Hebert
that QSA didn't let you keep that telnet facing any public interface without any protection. PS: Same deal with SSH ... encryption != protection since keylogging is way easier than sniffing packets. But at least you can limit SSH authentication to public keys. - Alain Hebert

Re: We hit half-million: The Cidr Report

2014-05-01 Thread Alain Hebert
Hey, I worked for them (AA) in the early 90's =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 05/01/14

Re: We hit half-million: The Cidr Report

2014-05-02 Thread Alain Hebert
was asked to fill the cubicle for 2 month doing nothing. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 05/01/14 18:43

Re: US patent 5473599

2014-05-08 Thread Alain Hebert
was never attracted to OpenBSD for some gut reason... I know why now =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443

Re: New Zealand Spy Agency To Vet Network Builds, Provider Staff

2014-05-14 Thread Alain Hebert
They already have all the information and did it for you. You are just not aware of it. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http

Off Topic Friday

2014-05-30 Thread Alain Hebert
, like the vendor did it on purpose to milk all the money they could from the spec :). As usual, off-list would be best. PS: I'll forward a summary of the information to the people interested by this subject. -- - Alain Hebertaheb...@pubnix.net PubNIX

Re: FW: Public Notice: FCC asks for comments on network security

2014-07-30 Thread Alain Hebert
Should. It is a few million$ in man hours thou. ( Not necessary spent, but budgeted ) And still no BCP38 recommendation. I wonder: 1. If they taught of it; 2. What was their process to not include it; Oh well. - Alain Hebert

Re: Huawei Atom Router

2014-08-04 Thread Alain Hebert
... That's maybe why not many people are talking about their products in our corner of the world =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.net

Re: Huawei Atom Router

2014-08-05 Thread Alain Hebert
Was more a statement of fact. As if it was warranted. I do not know. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514

Re: Fwd: [ PRIVACY Forum ] An Iranian Grand Ayatollah Issues Fatwa Stating High Speed Internet is against Sharia

2014-09-02 Thread Alain Hebert
Eric Brunner-Williams wrote: see also: http://www.al-monitor.com/pulse/originals/2014/09/iran-3g-phones-filter-unsanitary-water.html# restated slightly, video, the primary vehicle for porn, needs minders, text, the primary vehicle for ideas, does not. What about ASCII porn? It was

Re: old-school wiring nightmares

2014-09-03 Thread Alain Hebert
On 09/03/14 15:11, Christopher Morrow wrote: On Wed, Sep 3, 2014 at 2:29 PM, Daniel Corbe co...@corbe.net wrote: Christopher Morrow morrowc.li...@gmail.com writes: imagine the probably almost constant outages in the winter months due to ice buildup on the lines... This still happens.

Re: 2000::/6

2014-09-10 Thread Alain Hebert
As of 8h30m EST. *i 2000::/6 ipv6 peer1001000 3257 3549 i Last update to IP routing table: 21h23m56s - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec

Re: Saying goodnight to my GSR

2014-09-22 Thread Alain Hebert
Well, I think it was just blind fear talking. Properly configured, it is less a security issue than newer devices. Pretty impressive from Matthew to have the patience/skills to not simply reload that fridge over the years. On 09/20/14 16:25, Keith Medcalf wrote: And what,

Re: update

2014-09-24 Thread Alain Hebert
On 09/24/14 18:50, Jim Popovitch wrote: On Sep 24, 2014 6:39 PM, Michael Thomas m...@mtcc.com wrote: On 9/24/14, 3:27 PM, Jim Popovitch wrote: On Wed, Sep 24, 2014 at 6:17 PM, Brandon Whaley redkr...@gmail.com wrote: The scope of the issue isn't limited to SSH, that's just a popular example

Re: large BCP38 compliance testing

2014-10-02 Thread Alain Hebert
On 10/02/14 06:10, Mikael Abrahamsson wrote: Hi, To fix a lot of the DDOS attacks going on, we need to make sure BCP38 compliance goes up. Only way to do this I can think of, is large scale BCP38 testing. One way of doing this, is to have large projects such as OpenWRT, RIPE Atlas project,

Re: large BCP38 compliance testing

2014-10-02 Thread Alain Hebert
On 10/02/14 08:37, Roland Dobbins wrote: On Oct 2, 2014, at 7:16 PM, Alain Hebert aheb...@pubnix.net wrote: BCP38 compliance is the exception not the norm. I'm not sure that's actually the case, practically-speaking. NAT is an awful thing for many reasons, and it's negative in terms

Re: large BCP38 compliance testing

2014-10-03 Thread Alain Hebert
Well (beware it is friday), On the 1st of January 2015: . Refuse every routes; . Start accepting only those passing some sort of BCP38 specs performed by some QSA =D; . ??? . Profit; On 10/03/14 15:03, Mikael Abrahamsson wrote: On Fri, 3 Oct 2014,

Re: large BCP38 compliance testing

2014-10-06 Thread Alain Hebert
On 10/03/14 19:36, Jay Ashworth wrote: - Original Message - From: Alain Hebert aheb...@pubnix.net PS: About that uRPF Convo, we could dump all that knowledges into lets say... some comprehensive wiki page maybe =D That way when the topic arise we could just link to it. Gee, Alain

Re: Shipping bulk hardware via freight

2014-11-07 Thread Alain Hebert
On 11/05/14 13:02, Jason wrote: I'm interested in talking with someone who has experience shipping hardware that has been pulled from a working environment. The assumption is that it would not use a normal carriers such as UPS of Fedex, but via private freight. Assuming that 20 x 1U

Re: Craigslist hacked?

2014-11-24 Thread Alain Hebert
Well, NetSol? Is it just me or they came up a few times lately (past year) in high profil case of DNS Hijacking? On 11/23/14 23:06, Mehmet Akcin wrote: yes it's been hijacked thru registrar level and someone was able to change name servers, now it's back to normal but you will

Re: How our young colleagues are being educated....

2014-12-25 Thread Alain Hebert
Well let start with: Happy Holidays. In my line of work anyone with a CCNA get put at the bottom of the pile =D We're looking for proactive associates and found that applicants which present themselves as a CCNA engineer foremost are only just that: Someone that could follow the course and

Re: Cisco Routers Vulnerability

2015-04-14 Thread Alain Hebert
they get a paper cut every time we sent out a report about that security risk ) But I'm still curious what was the attack vector... As for my ~20ish Cisco device in the wild, they're all pretty healthy. - Alain Hebertaheb...@pubnix.net PubNIX Inc

Re: Low Cost 10G Router

2015-05-20 Thread Alain Hebert
path as their larger subnet, I have to put up more time on that bench thou ) - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990

Re: Low Cost 10G Router

2015-05-19 Thread Alain Hebert
Well, Hardly low cost =D - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 05/19/15 13:31, Randy Carpenter

Re: Synful Knock questions...

2015-09-15 Thread Alain Hebert
the Cisco one pre-deployement), would be the method I would use. ( We're doing it quarterly in some cases ) - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http

Re: Netflix banning HE tunnels

2016-06-08 Thread Alain Hebert
Well, They're clearly to " enraged " to accept/comprehend the situation. Lets go back talking about how to help deploy IPv6 and break the paradigm that was build during the silent film era. ----- Alain Hebertaheb...@pubnix.net

Re: syslog server

2016-06-07 Thread Alain Hebert
Well, I'll say an ELK stack, but seeing the original question... I got to ponder on the capacity of the OP. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514

MPLS Reference Designs

2016-05-27 Thread Alain Hebert
Hi, ( it might be a bit much to look for that here, but meh its Friday ) Goals Usual Multi-point L2 services, with L3 path(s) to the Internet -and/or- inter-site L3 routing (VRF per customer). This is a simple project involving upgrading a L2 MAN into and more flexible and

Re: ICYMI: FBI looking into LA fiber cuts, Super Bowl

2016-01-19 Thread Alain Hebert
ard to aviation assets supporting the event, allow unauthorized video coverage of events, or pose a risk of injury to event-goers if an operator loses control." - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770

Re: Shared cabinet "security"

2016-02-15 Thread Alain Hebert
you need. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 02/14/16 08:48, Mike Hammett wrote: > *nods* I've seen h

Re: mrtg alternative

2016-03-09 Thread Alain Hebert
Hi, Cacti works... Biggest case I know, ~180 devices. A few issues with THold plugin but nothing that can't be fixed. And they are working on a new release (available thru github) which include most of the useful plugins. - Alain Hebertaheb

Re: Arista Routing Solutions

2016-04-28 Thread Alain Hebert
Well, Once you eliminate the ~160k superfluous prefixes (last time I checked)... This is a none issue. Some work on some sort summary function would keep those devices alive... but we all know there is more money to be made the faster the device become obsolete :( - Alain

Friday's Random Comment - About: Arista and FIB/RIB's

2016-04-29 Thread Alain Hebert
way to say that the best path of a subnet is the same as his supernet. And yes I'm aware of the Weekly Routing Report, I was just curious to see it by country =D. ----- Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfie

Re: EVERYTHING about Booters (and CloudFlare)

2016-07-28 Thread Alain Hebert
Well, I do not think feeding the trolls is a good exercise for a representative of any company that is taking this subject seriously. Don't you think? - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770

Re: Cloudflare, dirty networks and politricks

2016-08-01 Thread Alain Hebert
/sh Obviously that host is not accessible at the moment. (GG OVH?) I'm suspecting that the CC used to create that VM got declined on the 1st, which is often the case for payload distribution. ----- Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Char

Re: Host.us DDOS attack -and- related conversations

2016-08-03 Thread Alain Hebert
ty of ISPs into BCP38 and the like. We need to keep educating them at every occasion we have. For those that actually implemented some sort of tech against it, you are a beacon of hope in what is a ridiculous situation that has been happening for more than 15 years. ----- Al

Re: Host.us DDOS attack -and- related conversations

2016-08-03 Thread Alain Hebert
syndicated cartoons. On a humorous note: The DDoS protection lobby is our NRA. - Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax

Re: Host.us DDOS attack -and- related conversations

2016-08-03 Thread Alain Hebert
ove Humans. ----- Alain Hebertaheb...@pubnix.net PubNIX Inc. 50 boul. St-Charles P.O. Box 26770 Beaconsfield, Quebec H9W 6G7 Tel: 514-990-5911 http://www.pubnix.netFax: 514-990-9443 On 08/03/16 10:40, James Bensley wrote: > On 3 August 2016 at

  1   2   3   >