[29747] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: RBL-type BGP service for known rogue networks?

daemon@ATHENA.MIT.EDU (Karyn Ulriksen)
Thu Jul 6 18:10:46 2000

Message-ID: <0127E258EE29D3118A0F00609765B448317882@subnet-gw-00053.sitestream.net>
From: Karyn Ulriksen <kulriksen@publichost.com>
To: 'Mark Mentovai' <marklist@ggn.net>
Cc: "'nanog@merit.edu'" <nanog@merit.edu>
Date: Thu, 6 Jul 2000 14:13:28 -0700 
MIME-Version: 1.0
Content-Type: text/plain;
	charset="windows-1252"
Errors-To: owner-nanog-outgoing@merit.edu



>You can play tricks with BGP to do this.  Here's how MAPS RBL does it, and
>how you can use it:
>
>http://www.mail-abuse.org/rbl/usage.html#BGP
>
>Mark

That's actually pretty clean, too.  I haven't implemented a route server on
my networks.  But I play around on Cerf Net's sometimes when I tracking down
BGP problems.  What's the consensus on using one at the Tier 2 level?

Karyn  


-----Original Message-----
From: Mark Mentovai [mailto:marklist@ggn.net]
Sent: Thursday, July 06, 2000 1:23 PM
To: nanog@merit.edu
Subject: RE: RBL-type BGP service for known rogue networks?



Karyn Ulriksen wrote:
>What I was saying is that they had already set up some type of blackhole
>system that I was lead to believe they were doing at the router level (not
>mail system level).  When they had us blackhole, we couldn't get past their
>core routers.  I know your next thougt is that they just threw us into
their
>route filter, but my understanding is that they offered a service that you
>subscribed to and the updated the filter on the fly.  Which sounds like it
>would work for what you may be looking for in the "kiddie script network"
>scenario (which I assume means either IRC crapola or DOS crapola in
general)
>or those wonderful .ru sites serving out that hardcore kiddie porn stuff
via
>cgi calls.

You can play tricks with BGP to do this.  Here's how MAPS RBL does it, and
how you can use it:

http://www.mail-abuse.org/rbl/usage.html#BGP

Mark

-- 
Do not reply directly to this e-mail address
--
Mark Mentovai
UNIX Engineer
Gillette Global Network



home help back first fref pref prev next nref lref last post