Arron/Sandy,
You people seem to be advertising an awful lot of crap to us over NZIX;
the following is an example (209.155.82.18 is ftp.cdrom.com):
ba1.acld#ping ftp.cdrom.com
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 209.155.82.18, timeout is 2 seconds:
.!!..
Success rate is 40 percent (2/5), round-trip min/avg/max = 1108/1388/1668 ms
ba1.acld#show ip route 209.155.82.18
Routing entry for 209.155.82.18/32
Known via "ospf 1", distance 110, metric 5000
Tag 9999, type extern 2, forward metric 100
Redistributing via ospf 1
Last update from 203.97.1.70 on ATM5/0.1, 1d00h ago
Routing Descriptor Blocks:
* 203.97.1.70, from 203.97.1.82, 1d00h ago, via ATM5/0.1
Route metric is 5000, traffic share count is 1
ba1.acld#traceroute 209.155.82.18
Type escape sequence to abort.
Tracing the route to wcarchive.cdrom.com (209.155.82.18)
1 ba1-ser0-15.hmtn.clix.net.nz (203.97.1.70) 32 msec 12 msec 16 msec
2 ngthn1-b1.nzix.waikato.ac.nz (140.200.128.9) [AS 681] 136 msec 20 msec 28 msec
3 s6-1.akcr1.netgate.net.nz (202.37.245.125) [AS 4648] 36 msec 32 msec 28 msec
4 f0-0.akbr1.netgate.net.nz (202.37.245.58) [AS 4648] 2144 msec * *
5
This seems bad!
Anybody else seeing this?
I will be blocking OSPF updates from NetGate over NZIX very shortly...
Any feedback or confirmation from anybody else would be most welcome.
Joe
--
Joe Abley
Sorry... My previous (panicy ;) e-mail wasn't at all self-explanatory. The NetGate router 140.200.128.9 is advertising all kinds of /32 routes for things it shouldn't to us. The 9999 tag below indicates a route originating on NZIX alive and well within our interior routing protocol; in this case the route is 209.155.82.18/32, a host route for ftp.cdrom.com. OSPF routes learnt from 140.200.128.9 at the exchange are now being dropped by our routers; this _shouldn't_ hurt any NetGate customers, since we peer directly in Auckland using BGP (and apply filter lists). If any NetGate customer finds themselves unable to reach CLIX by any sensible route through the network, please post details. Thanks, Joe On Mon, Oct 26, 1998 at 09:48:26PM +1300, Joe Abley wrote:
Arron/Sandy,
You people seem to be advertising an awful lot of crap to us over NZIX; the following is an example (209.155.82.18 is ftp.cdrom.com):
ba1.acld#ping ftp.cdrom.com
Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 209.155.82.18, timeout is 2 seconds: .!!.. Success rate is 40 percent (2/5), round-trip min/avg/max = 1108/1388/1668 ms ba1.acld#show ip route 209.155.82.18 Routing entry for 209.155.82.18/32 Known via "ospf 1", distance 110, metric 5000 Tag 9999, type extern 2, forward metric 100 Redistributing via ospf 1 Last update from 203.97.1.70 on ATM5/0.1, 1d00h ago Routing Descriptor Blocks: * 203.97.1.70, from 203.97.1.82, 1d00h ago, via ATM5/0.1 Route metric is 5000, traffic share count is 1
ba1.acld#traceroute 209.155.82.18
Type escape sequence to abort. Tracing the route to wcarchive.cdrom.com (209.155.82.18)
1 ba1-ser0-15.hmtn.clix.net.nz (203.97.1.70) 32 msec 12 msec 16 msec 2 ngthn1-b1.nzix.waikato.ac.nz (140.200.128.9) [AS 681] 136 msec 20 msec 28 msec 3 s6-1.akcr1.netgate.net.nz (202.37.245.125) [AS 4648] 36 msec 32 msec 28 msec 4 f0-0.akbr1.netgate.net.nz (202.37.245.58) [AS 4648] 2144 msec * * 5
This seems bad!
Anybody else seeing this?
I will be blocking OSPF updates from NetGate over NZIX very shortly... Any feedback or confirmation from anybody else would be most welcome.
Joe
--
Joe Abley
Well...
I know that I'm talking to myself here :) but it seems like I overreacted
somewhat; on closer examination, the only erroneous route I can find from
140.200.128.9 is for 209.155.82.18/32. I can't find anything else that
shouldn't be there.
It was just the first thing I tried, and so I assumed the worst :(
209.155/16 is definitely operated by CRL though, and so the host route
for 209.155.82.18/32 _is_ bogus.
Many apologies for casting aspersions on NetGate's OSPF speaker!
Yours in drugs,
Joe
--
Joe Abley
Hi all, sorry Joe, my mistake, doing a little diagnostics at 10:30 Friday night, and forgot I was redistributing statics down at Hamilton ... hence the single host route. Slap on the hand for me !!!! Arron ______________________________________________________ Arron Scott (CCIE #4099) (Phone) ++64-9-3565689 Service Specialist (Fax) ++64-9-3794790 Telecom NZ Ltd (eMail) a.scott(a)netgate.net.nz
-----Original Message----- From: owner-nznog(a)list.waikato.ac.nz [mailto:owner-nznog(a)list.waikato.ac.nz]On Behalf Of Joe Abley Sent: Monday, October 26, 1998 10:43 PM To: arrons(a)netgate.net.nz; s.davidson(a)netgate.net.nz Cc: nznog(a)list.waikato.ac.nz Subject: Re: Arrgh! READ ME
Well...
I know that I'm talking to myself here :) but it seems like I overreacted somewhat; on closer examination, the only erroneous route I can find from 140.200.128.9 is for 209.155.82.18/32. I can't find anything else that shouldn't be there.
It was just the first thing I tried, and so I assumed the worst :(
209.155/16 is definitely operated by CRL though, and so the host route for 209.155.82.18/32 _is_ bogus.
Many apologies for casting aspersions on NetGate's OSPF speaker!
Yours in drugs,
Joe
-- Joe Abley
Tel +64 9 912-4065, Fax +64 9 912-5008 Network Architect, CLEAR Net http://www.clear.net.nz/ --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
participants (2)
-
Arron Scott
-
Joe Abley