1 msgBGP issues qwest in Burbank, CA
1 msgLooking for Yahoo-SOC contact
1 msgCachefly Contact
2 msgauth*.ns.uu.net
1 msgauth00/auth100.ns.uu.net down ?
3 msgPCH BGP Archive down?
1 msgLooking for Flickr contacts
2 msgCharter - Southern Oregon routing issues
1 msgGoogle Contact
1 msgBob Crooks/SaskTel/CA is out of the office.

Microsoft.com PMTUD black hole?
\ Nathan Anderson/FSR (6 May 2008)
. \ Brandon Butterworth (6 May 2008)
. . \ Iljitsch van Beijnum (6 May 2008)
. . . \ Nathan Anderson/FSR (6 May 2008)
. . . . \ Nathan Anderson/FSR (6 May 2008)
. . . . \ Iljitsch van Beijnum (7 May 2008)
. . . . . \ Nathan Anderson/FSR (7 May 2008)
. . . \ Bjørn Mork (7 May 2008)
. . \ Nathan Anderson/FSR (6 May 2008)
. \ Robert Bonomi (6 May 2008)
. . \ Tomas L. Byrnes (7 May 2008)
. . . \ Marshall Eubanks (7 May 2008)
. . . \ Nathan Anderson/FSR (7 May 2008)
. . \ Nathan Anderson/FSR (7 May 2008)
. . . \ Randy Bush (7 May 2008)
. . . \ Glen Turner (7 May 2008)
. . . . \ Mark Newton (7 May 2008)
. . . . \ Patrick Giagnocavo (7 May 2008)
. . . \ Rich Kulawiec (7 May 2008)
. . . . \ Nathan Anderson/FSR (7 May 2008)
. . . . . \ Michael Sinatra (7 May 2008)
. . . . . . \ Iljitsch van Beijnum (7 May 2008)
. . . . . . . \ Tomas L. Byrnes (7 May 2008)
. . . . . . . . \ Nathan Anderson/FSR (7 May 2008)
. . . . . . . . . \ Iljitsch van Beijnum (7 May 2008)
. . . . . . . . . . \ Nathan Anderson/FSR (7 May 2008)
. . . . . . . . . \ Tomas L. Byrnes (7 May 2008)
. . . . . . . . . . \ Iljitsch van Beijnum (7 May 2008)
. . . . . . . . . . . \ Tomas L. Byrnes (7 May 2008)
. . . . . . . . . . \ Nathan Anderson/FSR (7 May 2008)
. . . . . . . \ Tomas L. Byrnes (7 May 2008)
. . . . . . . . \ Nathan Anderson/FSR (7 May 2008)
. . . . . . . \ Bjørn Mork (8 May 2008)
. . . . . . . . \ Joel Jaeggli (8 May 2008)
. . . . . . . . . \ Iljitsch van Beijnum (8 May 2008)
. . . . . . . . . . \ Smith, Donald (8 May 2008)
. . . . . . \ Hank Nussbacher (8 May 2008)
. . . . . \ Deepak Jain (7 May 2008)
. . . . . . \ SML (7 May 2008)
. . . . . . \ Tony Finch (8 May 2008)
. . . . . . . \ Blaine Christian (8 May 2008)
. . \ Stephen Sprunk (7 May 2008)
. \ Iljitsch van Beijnum (7 May 2008)
. \ Nathan Anderson/FSR (7 May 2008)
. . \ Tomas L. Byrnes (7 May 2008)
. . . \ Nathan Anderson/FSR (7 May 2008)
. . . \ Matthew Petach (12 May 2008)
. \ Michael Sinatra (7 May 2008)
. \ Scott Weeks (8 May 2008)
. \ Janet Sullivan (8 May 2008)
. . \ Niels Bakker (8 May 2008)

4 msgStrange network behaviour
1 msgWas Burma off the air due to the Cyclone ?
17 msgOSPF minutia, and, technote publication venues
2 msgDeadline Extension UBICOMM 2008, September 29 -...
1 msg[Fwd: Re: outages]
2 msgoutages
21 msgDid Youtube not pay their domain bill?
9 msgIntroducing latency for testing?
33 msgfair warning: less than 1000 days left to IPv4 ...
Subject:Re: [OPSEC] Microsoft.com PMTUD black hole?
Group:Nanog
From:Smith, Donald
Date:8 May 2008


 
A few comments on your comments below.


RM=for(1)
{manage_risk(identify_risk(product[i++]) &&
(identify_threat[product[i++]))}
Donald.Smith giac

> -----Original Message-----
> From: opsec-bounces [mailto:opsec-bounces]
> On Behalf Of Iljitsch van Beijnum
> Sent: Thursday, May 08, 2008 3:24 AM
> To: Joel Jaeggli
> Cc: guillermo; opsec; NANOG list
> Subject: Re: [OPSEC] [NANOG] Microsoft.com PMTUD black hole?
>
> On 8 mei 2008, at 9:53, Joel Jaeggli wrote:
>
> > Oddly enough there is a draft on the subject of icmp filtering
> > recomendations is making the rounds.
>
> >
> http://tools.ietf.org/wg/opsec/draft-gont-opsec-icmp-filtering-00.txt
>
> > The opsec working group (opsec) and the authors would
> > appreciate feedback from operators on the subject.
>
> Speaking as someone who isn't interested in reading an
> explanation of
> what happens when the message is filtered for every ICMP
> message known
> to man, I find this a completely useless document: I can't find the
> recommendations. Either they're there but impossible to find by
> looking at the table of contents or searching for "recommend", or
> they're not there in which case the title is EXTREMELY misleading.

I believe a table of what to filter where was recommended.
I hope that table includes filtering and ratelimiting from, through, and
to.

However blindly accepting recommendations without understanding the
possibly ramifications
such filtering can have on your network is not wise.

>
> Also:
>
> 2.1.1.5.4. Operational/interoperability impact if blocked Filtering
> this error message breaks the Path-MTU Discovery mechansim described
> in [RFC1191].
>
> This is completely insufficient because it doesn't mention
> that 99% of
> all TCP traffic on today's internet uses PMTUD and filtering these
> messages leads to broken connectivity towards destinations that have
> an MTU lower than the source (lower than 1500 in practice).

I suspect your statistics. I don't believe the number is anywhere near
99% but haven't seen a study that would support any actual % numbers of
traffic that relies on PMTUD. If your aware of such a study/research I
would be interested in reviewing the results.

Again filtering THROUGH a device is probably not advisable filtering TO
your device might be advisable.

>
> Please spell check and five levels of numbering is considered
> bad style.
> _______________________________________________
> OPSEC mailing list
> OPSEC
> https://www.ietf.org/mailman/listinfo/opsec
>


This communication is the property of Qwest and may contain confidential or
privileged information. Unauthorized use of this communication is strictly
prohibited and may be unlawful. If you have received this communication
in error, please immediately notify the sender by reply e-mail and destroy
all copies of the communication and any attachments.

_______________________________________________
NANOG mailing list
NANOG
http://mailman.nanog.org/mailman/listinfo/nanog


© 2004-2008 readlist.com