[124294] in North American Network Operators' Group
Re: IPv4 ANYCAST setup
daemon@ATHENA.MIT.EDU (Phil Regnauld)
Tue Mar 30 05:24:58 2010
Date: Tue, 30 Mar 2010 11:24:20 +0200
From: Phil Regnauld <regnauld@nsrc.org>
To: Randy Bush <randy@psg.com>
In-Reply-To: <m2hbny8fcz.wl%randy@psg.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Randy Bush (randy) writes:
> patience. when things really start to break, and the finger of fate
> points at them, clue may arise.
>
When this issue was brought up on the OARC dns-operations list,
and it was suggested to make some simply factsheets (a bit like
ICANN's IPv6 http://www.icann.org/announcements/factsheet-ipv6-26oct07.pdf),
this was poo-pooed as being useless and a waste of time.
Since the final victim is the end user, I still think it's worth the
effort to try and make security officers and similar network operators
aware of the issues and what they can do to mitigate potential problems.
See for example:
http://www.afnic.fr/actu/nouvelles/240/l-afnic-invite-les-responsables-techniques-reseaux-a-se-preparer-a-la-signature-de-la-racine-dns-en-mai-2010
(Yes, there's an English version too).
Cheers,
Phil