[114476] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Checking bogon status of new address space

daemon@ATHENA.MIT.EDU (Robert E. Seastrom)
Tue May 12 07:55:03 2009

To: James Hess <mysidia@gmail.com>
From: "Robert E. Seastrom" <rs@seastrom.com>
Date: Tue, 12 May 2009 07:54:49 -0400
In-Reply-To: <6eb799ab0905090710r1afc3ca5md61b76e884a4076d@mail.gmail.com>
	(James Hess's message of "Sat, 9 May 2009 09:10:49 -0500")
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


James Hess <mysidia@gmail.com> writes:

>> 29/256 = 11% of the available address space.  My argument is, if
>> someone is scanning you from random source addresses blocking 10%
>> of the scan traffic is reaching a point of very little return for
>> the effort of updating the address lists, and as we all know it is
>> getting smaller and smaller.
>
> Granted, if the filters aren't updated very frequently, they're pretty bad.

That's the usual state of affairs, unfortunately.

> But.. I would suggest, basically, filtering bogons is still great and
> pretty important, it serves as an ongoing deterrant against random
> unruly networks trying to pick up the unassigned  addresses, or
> treating the space as  "Up for grabs" just because some space  happens
> to be unannounced (and unassigned).

Gotta agree with Leo here.  We can't even get people to implement
BCP-38, which is nine years old for crying out loud.  The deployment
level at which bogon filtering is a deterrent to squatting is quite a
bit higher from the point at which it becomes an issue to legitimate
users.

I've considered static bogon filters to be a Worst Current Practice
for years.  If you feel you absolutely must engage in the practice use
a dynamic feed like Cymru's, but honestly, just let it go.

-r










home help back first fref pref prev next nref lref last post