Re: [swinog] Implementing SPF

2004-08-04 Thread Tobias Orlamuende
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am Mittwoch, 4. August 2004 01:53 schrieb Daniel Lorch: Hi SPF provides a mechanism of designating valid outbound smtp servers for a certain domain. This value is then matched against the Envelope-From (Return-Path) of an e-mail (except for SA

RE: [swinog] VRF + OSPF issue

2004-08-04 Thread Michel Renfer
Hi Ueli what if you use the network-statements to match only the desired interface? The network statement will not suppress the OSPF hello packets... It affects only, which prefixes from directly connected interfaces will be injected into OSPF. cheers, michel

Re: [swinog] Implementing SPF

2004-08-04 Thread Patrick . Guelat
On Wed, 4 Aug 2004, Daniel Lorch wrote: SPF provides a mechanism of designating valid outbound smtp servers for a certain domain. This value is then matched against the Envelope-From (Return-Path) of an e-mail (except for SA 3.0, which also does HELO header-checking, but that's non-standard and

RE: [swinog] VRF + OSPF issue

2004-08-04 Thread Patrick . Guelat
Hi Michel what if you use the network-statements to match only the desired interface? The network statement will not suppress the OSPF hello packets... It affects only, which prefixes from directly connected interfaces will be injected into OSPF. This is correct, but it should also affect the

Re: [swinog] Implementing SPF

2004-08-04 Thread Claudio Jeker
On Wed, Aug 04, 2004 at 01:53:02AM +0200, Daniel Lorch wrote: Hi SPF provides a mechanism of designating valid outbound smtp servers for a certain domain. This value is then matched against the Envelope-From (Return-Path) of an e-mail (except for SA 3.0, which also does HELO

Re: [swinog] Implementing SPF

2004-08-04 Thread Martin Blapp
Hi, NO. Microsoft has a patent pending on something like spf. That's 'Sender-ID', not SPF. These are two different mechanisms. Hopefully 'Sender-ID' will go into the trash soon and nobody uses it. Martin ___ swinog mailing list [EMAIL PROTECTED]

Re: [swinog] Implementing SPF

2004-08-04 Thread Daniel Lorch
Hi there is a bulk page for max 500 domains at a time: http://spftools.infinitepenguins.net/register.php?action=multiple I need to submit 501 domains, though. And the account creation didn't work. I have contacted the author of this website but I'm still waiting for an answer . -- Kind

RE: [swinog] Implementing SPF

2004-08-04 Thread Kurt A. Schumacher
SPF. Not convinced, yet? NO. Microsoft has a patent pending on something like spf. There are millions of pending patents pending out there which are never. SPF or something (very) similar should become RFC (think this in the queue anyway) and the patents discussion will be closed. -Kurt.

Re: [swinog] Implementing SPF

2004-08-04 Thread Daniel Lorch
Hi Sure, one solution would be just to provide the records and not using it on MTA side, but one day you should use it (IMHO asap) and you can't be sure that all senders are providing it at this time. Seems like a chicken-egg-problem... Sort of. It's also called a positive feedback cycle. If

Re: [swinog] Implementing SPF

2004-08-04 Thread Claudio Jeker
On Wed, Aug 04, 2004 at 09:48:11AM +0200, Kurt A. Schumacher wrote: SPF. Not convinced, yet? NO. Microsoft has a patent pending on something like spf. There are millions of pending patents pending out there which are never. SPF or something (very) similar should become RFC (think

Re: [swinog] VRF + OSPF issue

2004-08-04 Thread Pascal Gloor
ok, here we are. Mr TAC said, passive-interface doesnt exist in OSPF while running within a VRF. This is known and the engineers are planning to add this feature (one day :-P), eh... He proposed as a workaround to use an ACL to filter the OSPF multicast packets. In the mean time I've found

Re: [swinog] Implementing SPF

2004-08-04 Thread Fabian Wenk
Hello Daniel Daniel Lorch wrote: The main reason, I guess, for slow SPF adaption is the fear of breaking something. As a hosting-only-provider we were facing the additional problem that many customers are not using our SMTP-server (even though they are advised to do so) but their ISP's. Forcing

Re: [swinog] AS3303 Routing Problem ?

2004-08-04 Thread Michele Marazza
Arnold, Joining with what Pascal says, yes, you can wash traffic when you have some Mbps, not if you have 1Gbps.. (this fill anyway your links before the washing machine which, I suppose, is somewhere central located if you have many border routers). And yes, we have blackholing communities

Re: [swinog] AS3303 Routing Problem ?

2004-08-04 Thread Arnold Nipper
On 04.08.2004 12:04 Michele Marazza wrote: Arnold, Joining with what Pascal says, yes, you can wash traffic when you have some Mbps, not if you have 1Gbps.. you can also wash traffic if it's 1Gbps. Arnold ___ swinog mailing list [EMAIL

Re: [swinog] AS3303 Routing Problem ?

2004-08-04 Thread Sebastian Abt
Hi, * Michele Marazza wrote: Joining with what Pascal says, yes, you can wash traffic when you have some Mbps, not if you have 1Gbps.. (this fill anyway your links before the washing machine which, I suppose, is somewhere central located if you have many border routers). And yes, we have

Re: [swinog] Implementing SPF

2004-08-04 Thread Felix Rauch
On Wed, 4 Aug 2004, Tobias Orlamuende wrote: [...] So what happens when I set up everything but the sender of an email which should be accepted by one's MTA has no such record? I could imagine that this happens now and for the next month in about more than 90 percent of all mail which is received

RE: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Neil J. McRae
This reminds me of a first year college database project! -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Fredy Kuenzler Sent: 04 August 2004 11:34 To: [EMAIL PROTECTED] Subject: [swinog] PeeringDB.com - good initiative ... Please register your

Re: [swinog] AS3303 Routing Problem ?

2004-08-04 Thread Nicolas FISCHBACH
Michele Marazza wrote: Joining with what Pascal says, yes, you can wash traffic when you have some Mbps, not if you have 1Gbps.. (this fill anyway your links before the washing machine which, I suppose, is somewhere central located if you have many border routers). Well, it depends on the

Re: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Fredy Kuenzler
Neil J. McRae wrote: This reminds me of a first year college database project! The database design might be not too sophisticated, but the submitted information should somehow be relevant, shouldn't it? Have a look at AS8220 peering port speeds ;-) F.

RE: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Guentensperger, Robert
Title: RE: [swinog] PeeringDB.com - good initiative ... -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 wow! 65Gig!!! Günti |-Original Message- |From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On |Behalf Of |Fredy Kuenzler |Sent: Mittwoch, 4. August 2004 13:22 |To: [EMAIL

Re: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Fredy Kuenzler
Guentensperger, Robert wrote: wow! 65Gig!!! I want those too? Neil, where could you get them ;-) F. ___ swinog mailing list [EMAIL PROTECTED] http://lists.init7.net/cgi-bin/mailman/listinfo/swinog

RE: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Neil J. McRae
The database design might be not too sophisticated, but the submitted information should somehow be relevant, shouldn't it? Have a look at AS8220 peering port speeds ;-) Relevance is subjective though. Yes I entered those values. Peering port speeds are irrelevant. What is more relevant

RE: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Neil J. McRae
I want those too? Neil, where could you get them ;-) F. You can buy ports from various vendors in a variety of formats, 2x4x10G on the 7609, or several gige cards ;-) Any 1st year engineering student could work it out! Neil. ___ swinog mailing list

Re: [swinog] Implementing SPF

2004-08-04 Thread Daniel Lorch
Hi there is a bulk page for max 500 domains at a time: http://spftools.infinitepenguins.net/register.php?action=multiple .ch is much better than .com. Scientific proof is available here: http://spftools.infinitepenguins.net/register.php My script is running since lunch. I'm only

RE: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Jerome Tissieres
Sunrise : Open Peering Policy ? Robert, let's peer now ! Jerome -Message d'origine- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] la part de Neil J. McRae Envoye : mercredi, 4. aout 2004 13:47 A : [EMAIL PROTECTED] Objet : RE: [swinog] PeeringDB.com - good initiative ...

RE: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Guentensperger, Robert
Title: RE: [swinog] PeeringDB.com - good initiative ... -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Jerome, Where? What? Why? Open to all non-CH. I knew that the day will come where the first sees this. OK, it's changed now to selctive Sorry, we have still the same policy. But the

Re: [swinog] Implementing SPF

2004-08-04 Thread Daniel Lorch
Hi An other problem will arise if ISPs force there customers to use there own SMTP relay server because they are blocking outbound traffic to tcp/25. So this customers can not use the SMTP relay server of there domain hosting provider with SMTP Auth (and hopefully TLS) on tcp/25. Valid

RE: [swinog] Implementing SPF

2004-08-04 Thread David Tschan
I see still to many problems with systems like SPF, to much work for only a little advantage. Because if big domains like gmx or yahoo just put 0.0.0.0/0 in the SPF DNS entry it is just useless. gmx.net ist using set querytype=TXT gmx.net Server: zeus.tschan.ch Address: 212.103.66.131

AW: [swinog] Implementing SPF

2004-08-04 Thread Ralf Zenklusen
Hi, we plan to support SPF soon. Shure it's not perfect as long as the majority of ISPs will not take part or the entries are just wrong or very open. But that's only a question of time and critical mass. As soon as this is reached, everybody not using it will be punished with bad spam filter

Re: [swinog] Implementing SPF

2004-08-04 Thread Daniel Lorch
Hi As soon as this is reached, everybody not using it will be punished with bad spam filter results and that's a selling point. No no no, that's a misconception. I think already Tobias Orlamuende mentioned this question. If the SPF record is missing, you'll simply do nothing. You're not

Re: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Fredy Kuenzler
Kuster, Christian wrote: We are working very hard on it, some OSI layer 10 problems to fix ;-) AKA Teppichetage. Quoting from a recent SwiNOG message: Michel Renfer wrote: Bad things happens, when the carpet floor having their hands on peering stuff. Hopefully the situation with IP-Plus will

Re: [swinog] PeeringDB.com - good initiative ...

2004-08-04 Thread Nicolas Strina
Dont ask for peering they will send a commercial to sell you transit :D Cu, Nico Sunrise : Open Peering Policy ? Robert, let's peer now ! Jerome -Message d'origine- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] la part de Neil J. McRae Envoye : mercredi, 4. aout 2004 13:47 A :

Re: [swinog] Implementing SPF

2004-08-04 Thread Daniel Lorch
Hi I guess you have only one (or maybe 2 or 3) mail server which your customers can use to relay mails trough SMTP Auth. Now you have in every domain you are hosting set up the SPF entry for the IP of your mailserver. How do you proctect customer A to use customer B's domain for sending

Re: [swinog] Implementing SPF

2004-08-04 Thread Daniel Lorch
Hi If the owner of the domain swinog.ch (only as example) [..] Just as a sidenote: As per RFC2606 you're encouraged to use example.net, example.org or example.com in these kind of situations: http://www.rfc-editor.org/rfc/rfc2606.txt Daniel ___

Re: [swinog] Administrivia ... (was: Implementing SPF)

2004-08-04 Thread Fredy Kuenzler
Daniel Lorch wrote: If the owner of the domain swinog.ch (only as example) [..] Just as a sidenote: As per RFC2606 you're encouraged to use example.net, example.org or example.com in these kind of situations: http://www.rfc-editor.org/rfc/rfc2606.txt As this SPF thing has rather a lot to do with

WG: [swinog] Implementing SPF

2004-08-04 Thread Ralf Zenklusen
Well, maybe our views are different or I expressed myself bad :-) Receiving emails with missing SPF record will result in a higher SPAM-rating in our own spam filter system and therefore protecting our customer against spam. As far as I know the following results will be passed on from our mail

Re: [swinog] Implementing SPF

2004-08-04 Thread Rene Luria
On Wednesday 04 August 2004 16.29, Daniel Lorch wrote: I guess you have only one (or maybe 2 or 3) mail server which your customers can use to relay mails trough SMTP Auth. Now you have in every domain you are hosting set up the SPF entry for the IP of your mailserver. How do you proctect

Re: [swinog] AS3303 Routing Problem ?

2004-08-04 Thread Nicolas Strina
As far as i know Easynet France is using such solutions .. We should implement this next year too. Cu, Nico On 04.08.2004 12:33 Neil J. McRae wrote: agree with Arnold, and we've done close to 1G on our anti DDOS platform here. To do it on a big network does require money, time and effort but