[135298] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Update Spamhaus DROP list from Cisco CLI (TCL)

daemon@ATHENA.MIT.EDU (Jack Bates)
Thu Jan 20 11:44:44 2011

Date: Thu, 20 Jan 2011 10:44:34 -0600
From: Jack Bates <jbates@brightok.net>
To: Jared Mauch <jared@puck.nether.net>
In-Reply-To: <F3FE11D3-AF84-4A88-A3C1-466F18B9A08F@puck.nether.net>
Cc: "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org



On 1/19/2011 8:19 PM, Jared Mauch wrote:
> This was done once before, it was called MAPS at the time.  Using BGP
> as a signaling mechanic for this stuff can obviously be useful.  The
> challenge has always been balancing the trust with a 3rd party with
> the other operational requirements.

It's only useful if you want to make troubleshooting problems more 
difficult and require remote parties to contact you off-net. 
Conditionals for such blocks are more difficult (abuse@domain 
whitelisted isn't enough, you have to have a specific @domain which the 
filters don't apply to).

I agree that smaller networks are the ones more likely to participate in 
such things.


Jack


home help back first fref pref prev next nref lref last post