Background Traffic to Quarantined Network Blocks administered by APNIC

Size: px
Start display at page:

Download "Background Traffic to Quarantined Network Blocks administered by APNIC"

Transcription

1 Background Traffic to Quarantined Network Blocks administered by APNIC March 2011 Geoff Huston George Michaelson APNIC R&D APNIC is now regularly examining the unused state of IPv4 address blocks before they are passed over for general allocation. Experiments are undertaken with these address blocks by advertising a route to the address block, and recording all incoming traffic received in response to the routing advertisements. This document reports on the results of this experiment in the identification of the patterns of such "background" traffic that is being directed to various network blocks that are now being administered by APNIC that were previously identified by APNIC as receiving excessive levels of inbound traffic. The complete list of these network blocks is provided in Appendix A of this report. APNIC expresses its appreciation for the generous assistance provided by NTT Communications in undertaking this experiment. Experiment Details In collaboration with APNIC, AS38639 (NTT Communications) exclusively announced the set of networks listed in Appendix A for the period from 5 March 2011 until 15 March The data collector was unfiltered, and the data collection system was entirely passive, and no packets were generated in response to the incoming traffic. The following networks were NOT tested in the testing setup: / / / / / / / / / /24

2 Distribution of Traffic Across /16s Figure 1 Incoming traffic per /16 in reserved blocks The following figures shows the distribution of traffic across each of the /8 address blocks, divided up into /16 segments. Figure 2 Incoming traffic per /16 in reserved blocks of /8

3 Figure 3 Incoming traffic per /16 in reserved blocks of /8 Figure 4 Incoming traffic per /16 in reserved blocks of /8

4 Figure 5 Incoming traffic per /16 in reserved blocks of /8 Figure 6 Incoming traffic per /16 in reserved blocks of /8

5 Figure 7 Incoming traffic per /16 in reserved blocks of /8 "Busy" networks Using a threshold value of a average incoming traffic rate of more than 8Kbps per /24, corresponding to 32 bits per second per address, or approximately 1 packet on average every 24 seconds per address, then the following /24's exceed this level of traffic. Prefix Average Traffic / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps / Kbps Table 3 Traffic profile for high traffic /24s in the ERX blocks

6 Conclusions The following network blocks should continue be withheld from allocation at present, and rechecked in 3 months time, unless the identified source of the unwanted traffic can be isolated and switched off / / / / / / / / / /24 The following network blocks can be returned to the free pool: / intermittent high volume bursts of SNMP query traffic from /16 The following /32s should be noted as a potential problem, and should not be assigned to end customers. These addresses are attracting a high level of incoming Teredo and 6to4 connection attempts: / / / UDP traffic from addressed to UDP port UDP traffic from addressed to UDP port UDP traffic from , addressed to UDP port UDP traffic from , addressed to UDP port UDP traffic from addresses to UDP port UDP traffic from addresses to UDP port UDP traffic from addressed to UDP port UDP traffic from addressed to UDP port / UDP traffic from various sources in /16 addressed to UDP port /16

7 TCP SYN traffic from various sources TCP SYN traffic from various sources / / / There is a significant proportion of SIP traffic directed to this address, from various sources There is a significant component here of Teredo ICMP6 packets being sent to the equivalent 6to4 IPv6 address of this address, all encapsulated in IPv4 protocol 41 (IPv6-in-IPv4). The teredo packets have a diverse set of IPv4 end addresses in the Teredo packet ICMP backscatter from source address spoofing of Various sources sending to UDP port / There is a significant proportion of UDP traffic from , UDP source port directed to port There is a stream of TCP SYN packets from the single source address directed to port This is a single stream of SYSLOG packets from , possibly due to some form of malconfiguration / / / / / / / There is a significant proportion of UDP traffic from various sources directed to UDP port 4567 at this address / There is a significant proportion of UDP traffic from various sources to directed to UDP port 4605 at this address / / / /24

8 There is a significant proportion of UDP traffic from various sources to directed to UDP port 4605 at this address There is a significant proportion of UDP NetBIOS traffic from 20 sources to directed to this address / / / There is a significant proportion of TCP SYN traffic from various sources directed to TCP Port at this address / There is a significant proportion of UDP traffic from various sources directed to Port at this address This network receives a significant flow of TCP SYN packets from various sources directed to port This network receives a significant flow of TCP SYN packets from various sources directed to port This network receives a significant flow of TCP SYN packets from various sources directed to port This network receives a significant flow of TCP SYN packets from various sources directed to port / / / / / / There is a significant proportion of UDP traffic from various sources directed to various UDP ports at this address / / / There is a single stream of 1416 octet UDP packets being sent from , UDP port 9912 to , UDP port / / / / / /16

9 / / / There is a single stream of UDP packets being sent from , UDP port 1199 to UDP port This address is also attracting DNS query traffic to UDP port 53 from various sources There is a single stream of SYN+ACK packets being sent from , which may be in response to source-spoofed TCP SYN packets being sent to this address. This address is also attracting DNS query traffic to UDP port 53 from various sources There is a stream of NetBIOS UDP traffic being sent to this address. The source of these packets is and , which are spooed sources / / / / / There is a single stream of UDP SYSLOG packets being sent from / / Various sources send bursts of 3 4 UDP packets to port to this address / / / Various sources send bursts of UDP packets to port 3478 to this address. The major sources appear to be , , , and , but other sourvces were also observer / / / There is a single stream of UDP SYSLOG packets being sent from /24

10 A large number of source addresses send minimal size UDP packets to port 6693 at this address / A large number of source addresses send minimal size UDP packets to port at this address / A large number of source addresses send UDP packets to port 4605 at this address, and, in addition, DNS query packets are being sent to UDP port 53 at this address / A large number of source addresses send both UDP and TCP packets to this address, including NetBIOS and NTP UDP packets / A large number of sources use this address to direct their DNS queries A large number of sources use this address to direct their DNS queries A large number of sources use this address to direct their DNS queries.

11 Appendix A Unallocated /16 Addresses Administered by APNIC in the Various Network Blocks / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / / /24

12

Background Traffic to Network /8

Background Traffic to Network /8 Background Traffic to Network 39.0.0.0/8 March 2010 Geoff Huston George Michaelson APNIC R&D research@apnic.net APNIC is now regularly examining the unused state of IPv4 address blocks before they are

More information

"Dark" Traffic in Network /8

Dark Traffic in Network /8 "Dark" Traffic in Network 49.0.0.0/8 September 2010 Geoff Huston George Michaelson APNIC R&D research@apnic.net APNIC is now regularly examining the unused state of IPv4 address blocks before they are

More information

Background Traffic to Network /8

Background Traffic to Network /8 Background Traffic to Network 103.0.0.0/8 April 2010 Geoff Huston George Michaelson APNIC R&D research@apnic.net APNIC is now regularly examining the unused state of IPv4 address blocks before they are

More information

Traffic in Network /8. Background. Initial Experience. Geoff Huston George Michaelson APNIC R&D. April 2010

Traffic in Network /8. Background. Initial Experience. Geoff Huston George Michaelson APNIC R&D. April 2010 Traffic in Network 1.0.0.0/8 Geoff Huston George Michaelson APNIC R&D April 2010 Background The address plan for IPv4 has a reservation for Private Use address space. This reservation, comprising of 3

More information

Measuring IPv6 Deployment

Measuring IPv6 Deployment Measuring IPv6 Deployment Geoff Huston George Michaelson research@apnic.net The story so far In case you hadn t heard by now, we appear to be running quite low on IPv4 addresses! IANA Pool Exhaustion Prediction

More information

Measuring IPv6 Deployment

Measuring IPv6 Deployment Measuring IPv6 Deployment Geoff Huston George Michaelson research@apnic.net Available data sets We have access to dual stack data for: Available data sets We have access to dual stack data for: BGP Route

More information

IPv4 Address Report. This report generated at 12-Mar :24 UTC. IANA Unallocated Address Pool Exhaustion: 03-Feb-2011

IPv4 Address Report. This report generated at 12-Mar :24 UTC. IANA Unallocated Address Pool Exhaustion: 03-Feb-2011 IPv4 Address Report This report generated at 12-Mar-2018 08:24 UTC. IANA Unallocated Address Pool Exhaustion: 03-Feb-2011 Projected RIR Address Pool Exhaustion Dates: RIR Projected Exhaustion Remaining

More information

Measuring IPv6 Deployment

Measuring IPv6 Deployment Measuring IPv6 Deployment The story so far IANA Pool Exhaustion In this model, IANA allocates its last IPv4 /8 to an RIR on the 18 th January 2011 Ten years ago we had a plan Oops! We were meant to have

More information

What s going on in /8. George Michaelson Geoff Huston

What s going on in /8. George Michaelson Geoff Huston What s going on in 1.0.0.0/8 George Michaelson ggm@apnic.net Geoff Huston gih@apnic.net Standard Address TesCng IANA assigns /8 to APNIC RIPE NCC, on APNIC s behalf, announces selected subnets to test

More information

Table of Contents. 1 Intrusion Detection Statistics 1-1 Overview 1-1 Displaying Intrusion Detection Statistics 1-1

Table of Contents. 1 Intrusion Detection Statistics 1-1 Overview 1-1 Displaying Intrusion Detection Statistics 1-1 Table of Contents 1 Intrusion Detection Statistics 1-1 Overview 1-1 Displaying Intrusion Detection Statistics 1-1 i 1 Intrusion Detection Statistics Overview Intrusion detection is an important network

More information

Enhancing DDoS protection TAYLOR HARRIS SECURITY ENGINEER

Enhancing DDoS protection TAYLOR HARRIS SECURITY ENGINEER Enhancing DDoS protection TAYLOR HARRIS SECURITY ENGINEER Overview DDoS Evolution Typical Reactive/Proactive Mitigation Challenges and Obstacles BGP Flowspec Automated Flowspec Mitigation 2 DDoS Evolution

More information

Measuring IPv6. Geoff Huston APNIC Labs, February 2014

Measuring IPv6. Geoff Huston APNIC Labs, February 2014 Measuring IPv6 Geoff Huston APNIC Labs, February 2014 What s the question? How well are we going with the transition to IPv6? What s the question? How well are we going with the transition to IPv6? Measurable

More information

IPv6. Copyright 2017 NTT corp. All Rights Reserved. 1

IPv6. Copyright 2017 NTT corp. All Rights Reserved. 1 IPv6 IPv6 NTT IPv6 Copyright 2017 NTT corp. All Rights Reserved. 1 IPv6 IPv4 IPv6 Copyright 2017 NTT corp. All Rights Reserved. 2 IPv4 http://www.potaroo.net/tools/ipv4/ 2018.3.5 Copyright 2017 NTT corp.

More information

Understanding IPv6 Internet Background Radia6on

Understanding IPv6 Internet Background Radia6on Understanding IPv6 Internet Background Radia6on Jakub Czyz*, Kyle Lady*, Sam Miller*, Michael Kallitsis, Manish Karir, Michael Bailey* *University of Michigan Merit Network Dept. of Homeland Security S&T

More information

More Specific Announcements in BGP. Geoff Huston APNIC

More Specific Announcements in BGP. Geoff Huston APNIC More Specific Announcements in BGP Geoff Huston APNIC What s a more specific? A prefix advertisement that refines a covering advertisement 10.0.0.0/8 10.1.0.0/16 Why advertise a more specific? I: To redirect

More information

More Specific Announcements in BGP. Geoff Huston APNIC

More Specific Announcements in BGP. Geoff Huston APNIC More Specific Announcements in BGP Geoff Huston APNIC What s a more specific? A prefix advertisement that refines a covering advertisement 10.0.0.0/8 10.1.0.0/16 Why advertise a more specific? I: To redirect

More information

BGP The Movie. Geoff Huston September 2004 APNIC

BGP The Movie. Geoff Huston September 2004 APNIC BGP The Movie Geoff Huston September 2004 APNIC 1 IPv4 Routing Table Size Data assembled from a variety of sources, Including Surfnet, Telstra, KPN and Route Views. Each colour represents a time series

More information

IPv6 Background Radiation. Geoff Huston APNIC R&D

IPv6 Background Radiation. Geoff Huston APNIC R&D IPv6 Background Radiation Geoff Huston APNIC R&D Radiation Detection The Holmdel Horn Antenna, at Bell Labs, on which Penzias and Wilson discovered the cosmic microwave background radiation The detailed,

More information

Cisco CCIE Security Written.

Cisco CCIE Security Written. Cisco 400-251 CCIE Security Written http://killexams.com/pass4sure/exam-detail/400-251 QUESTION: 193 Which two of the following ICMP types and code should be allowed in a firewall to enable traceroute?

More information

(DNS, and DNSSEC and DDOS) Geoff Huston APNIC

(DNS, and DNSSEC and DDOS) Geoff Huston APNIC D* (DNS, and DNSSEC and DDOS) Geoff Huston APNIC How to be bad 2 How to be bad Host and application-based exploits abound And are not going away anytime soon! And there are attacks on the Internet infrastructure

More information

IPv6 Pollution Traffic Analysis

IPv6 Pollution Traffic Analysis IPv6 Pollution Traffic Analysis Manish Karir (DHS S&T Cyber Security Division) Jake Czyz, Kyle Lady, Sam Miller, Michael Kallitsis, Michael Bailey (University of Michigan) Internet Pollu+on Darknet sensors

More information

Chapter 7. Denial of Service Attacks

Chapter 7. Denial of Service Attacks Chapter 7 Denial of Service Attacks DoS attack: An action that prevents or impairs the authorized use of networks, systems, or applications by exhausting resources such as central processing units (CPU),

More information

IPv6 Firewall Support for Prevention of Distributed Denial of Service Attacks and Resource Management

IPv6 Firewall Support for Prevention of Distributed Denial of Service Attacks and Resource Management IPv6 Firewall Support for Prevention of Distributed Denial of Service Attacks and Resource Management IPv6 zone-based firewalls support the Protection of Distributed Denial of Service Attacks and the Firewall

More information

Layer 4: UDP, TCP, and others. based on Chapter 9 of CompTIA Network+ Exam Guide, 4th ed., Mike Meyers

Layer 4: UDP, TCP, and others. based on Chapter 9 of CompTIA Network+ Exam Guide, 4th ed., Mike Meyers Layer 4: UDP, TCP, and others based on Chapter 9 of CompTIA Network+ Exam Guide, 4th ed., Mike Meyers Concepts application set transport set High-level, "Application Set" protocols deal only with how handled

More information

Ping of death Land attack Teardrop Syn flood Smurf attack. DOS Attack Methods

Ping of death Land attack Teardrop Syn flood Smurf attack. DOS Attack Methods Ping of death Land attack Teardrop Syn flood Smurf attack DOS Attack Methods Ping of Death A type of buffer overflow attack that exploits a design flaw in certain ICMP implementations where the assumption

More information

Measuring IPv6 ISP Performance. Geoff Huston APNIC Labs July 2016

Measuring IPv6 ISP Performance. Geoff Huston APNIC Labs July 2016 Measuring IPv6 ISP Performance Geoff Huston APNIC Labs July 2016 What are we looking at: How reliable are IPv6 connections? How fast are IPv6 connections? What are we looking at: How reliable are IPv6

More information

Stacking it Up Experimental Observa6ons on the opera6on of Dual Stack Services

Stacking it Up Experimental Observa6ons on the opera6on of Dual Stack Services Stacking it Up Experimental Observa6ons on the opera6on of Dual Stack Services Geoff Huston, APNIC Labs 1 If working with one protocol has its problems 2 Then just how much damage can we do by joining

More information

Configuring attack detection and prevention 1

Configuring attack detection and prevention 1 Contents Configuring attack detection and prevention 1 Overview 1 Attacks that the device can prevent 1 Single-packet attacks 1 Scanning attacks 2 Flood attacks 3 TCP fragment attack 4 Login DoS attack

More information

NAT Command Reference

NAT Command Reference Command Reference Command Hierarchies ISA Configuration Commands on page 639 NAT Service Configuration Commands on page 640 VPRN Commands on page 643 NAT Subscriber Management Commands on page 645 NAT

More information

Chapter 8 roadmap. Network Security

Chapter 8 roadmap. Network Security Chapter 8 roadmap 8.1 What is network security? 8.2 Principles of cryptography 8.3 Message integrity 8.4 Securing e-mail 8.5 Securing TCP connections: SSL 8.6 Network layer security: IPsec 8.7 Securing

More information

Configuring NAT for IP Address Conservation

Configuring NAT for IP Address Conservation This module describes how to configure Network Address Translation (NAT) for IP address conservation and how to configure the inside and outside source addresses. This module also provides information

More information

Computer Security Spring Firewalls. Aggelos Kiayias University of Connecticut

Computer Security Spring Firewalls. Aggelos Kiayias University of Connecticut Computer Security Spring 2008 Firewalls Aggelos Kiayias University of Connecticut Idea: Monitor inbound/ outbound traffic at a communication point Firewall firewall Internet LAN A firewall can run on any

More information

VoIP Gateway Series. Unwanted Call Blocking Service Features (Hacking Call, Illegal Call, etc) AddPac Technology. 2011, Sales and Marketing

VoIP Gateway Series. Unwanted Call Blocking Service Features (Hacking Call, Illegal Call, etc) AddPac Technology. 2011, Sales and Marketing VoIP Gateway Series Unwanted Call Blocking Service Features (Hacking Call, Illegal Call, etc) www.addpac.com Technology 2011, Sales and Marketing Contents Overview Unwanted Call Blocking Service for VoIP

More information

Chapter 02 How Computers Find Each Other on Networks

Chapter 02 How Computers Find Each Other on Networks Chapter 02 How Computers Find Each Other on Networks TRUEFALSE 1. A hexadecimal number is a number written in the base 16 number system. (A) True (B) False 2. DNS follows a centralized database model.

More information

User Datagram Protocol

User Datagram Protocol Topics Transport Layer TCP s three-way handshake TCP s connection termination sequence TCP s TIME_WAIT state TCP and UDP buffering by the socket layer 2 Introduction UDP is a simple, unreliable datagram

More information

Protection Against Distributed Denial of Service Attacks

Protection Against Distributed Denial of Service Attacks Protection Against Distributed Denial of Service Attacks The Protection Against Distributed Denial of Service Attacks feature provides protection from Denial of Service (DoS) attacks at the global level

More information

Technical White Paper June 2016

Technical White Paper June 2016 TLP:WHITE! Technical White Paper June 2016 GuidetoDDoSAttacks! Authored)by:) Lee)Myers,)Senior)Manager)of)Security)Operations) Christopher)Cooley,)Cyber)Intelligence)Analyst) This MultiCState Information

More information

OER uses the following default value if this command is not configured or if the no form of this command is entered: timer: 300

OER uses the following default value if this command is not configured or if the no form of this command is entered: timer: 300 holddown holddown To configure the Optimized Edge Routing (OER) prefix route dampening timer to set the minimum period of time that a new exit must be used before an alternate exit can be selected, use

More information

DPU TDC 463. Scanning, Probing, and Surveying for Internet Hosts and Services. TDC463 Fall 2017 John Kristoff DePaul University 1

DPU TDC 463. Scanning, Probing, and Surveying for Internet Hosts and Services. TDC463 Fall 2017 John Kristoff DePaul University 1 DPU TDC 463 Scanning, Probing, and Surveying for Internet Hosts and Services TDC463 Fall 2017 John Kristoff DePaul University 1 The Probing Challenge To quickly, periodically, safely and accurately discover

More information

Routing Table Status Report

Routing Table Status Report Routing Table Status Report Routing SIG Feb 24 2005 APNIC19, Kyoto, Japan Geoff Huston IPv4 Routing Table Size Data assembled from a variety of sources, Including Surfnet, Telstra, KPN and Route Views.

More information

Rolling the Root KSK. Geoff Huston. APNIC Labs. September 2017

Rolling the Root KSK. Geoff Huston. APNIC Labs. September 2017 Rolling the Root KSK Geoff Huston APNIC Labs September 2017 Will this break the Internet? Why? If we stuff up this trust anchor key roll then resolvers that perform DNSSEC validation will fail to provide

More information

Junos Security. Chapter 4: Security Policies Juniper Networks, Inc. All rights reserved. Worldwide Education Services

Junos Security. Chapter 4: Security Policies Juniper Networks, Inc. All rights reserved.  Worldwide Education Services Junos Security Chapter 4: Security Policies 2012 Juniper Networks, Inc. All rights reserved. www.juniper.net Worldwide Education Services Chapter Objectives After successfully completing this chapter,

More information

ipv6 mobile home-agent (global configuration)

ipv6 mobile home-agent (global configuration) ipv6 mobile home-agent (global configuration) ipv6 mobile home-agent (global configuration) To enter home agent configuration mode, use the ipv6 mobile home-agent command in global configuration mode.

More information

Appendix B Policies and Filters

Appendix B Policies and Filters Appendix B Policies and Filters NOTE: This appendix does not describe Access Control Lists (ACLs) or IPX SAP ACLs, which are additional methods for filtering packets. See Software-Based IP Access Control

More information

APNIC Update. RIPE 60 May Geoff Huston Chief Scientist, APNIC

APNIC Update. RIPE 60 May Geoff Huston Chief Scientist, APNIC APNIC Update RIPE 60 May 2010 Geoff Huston Chief Scientist, APNIC Overview Services Update APNIC 29 Policy Outcomes APNIC Activities R&D Technical Developments IPv6 Program Training Other News Upcoming

More information

IPv6 HD Ratio. ARIN Public Policy Meeting April Geoff Huston APNIC

IPv6 HD Ratio. ARIN Public Policy Meeting April Geoff Huston APNIC IPv6 HD Ratio ARIN Public Policy Meeting April 2005 Geoff Huston APNIC 1 Background Current IPv6 Address Allocation policies refer to the use of the Host Density Ratio as a metric for acceptable utilization

More information

How we measure IPv6. Geoff Huston, Joao Damas George Michalson APNIC. George Michaelson. Geoff Huston. Joao Damas. APNIC Labs

How we measure IPv6. Geoff Huston, Joao Damas George Michalson APNIC. George Michaelson. Geoff Huston. Joao Damas. APNIC Labs How we measure IPv6 George Michaelson Geoff Huston, Joao Damas George Michalson APNIC Geoff Huston Joao Damas APNIC Labs Background Measurement is a big topic in today s Internet Reliable, unbiased, open

More information

CISCO EXAM QUESTIONS & ANSWERS

CISCO EXAM QUESTIONS & ANSWERS CISCO 642-618 EXAM QUESTIONS & ANSWERS Number: 642-618 Passing Score: 800 Time Limit: 120 min File Version: 39.6 http://www.gratisexam.com/ CISCO 642-618 EXAM QUESTIONS & ANSWERS Exam Name: Deploying Cisco

More information

UDP Traffic Management

UDP Traffic Management Packeteer Technical White Paper Series UDP Traffic Management May 2002 Packeteer, Inc. 10495 N. De Anza Blvd. Cupertino, CA 95014 408.873.4400 info@packeteer.com www.packeteer.com Company and product names

More information

Introduction p. 1 The Need for Security p. 2 Public Network Threats p. 2 Private Network Threats p. 4 The Role of Routers p. 5 Other Security Devices

Introduction p. 1 The Need for Security p. 2 Public Network Threats p. 2 Private Network Threats p. 4 The Role of Routers p. 5 Other Security Devices Preface p. xv Acknowledgments p. xvii Introduction p. 1 The Need for Security p. 2 Public Network Threats p. 2 Private Network Threats p. 4 The Role of Routers p. 5 Other Security Devices p. 6 Firewall

More information

CS 421: COMPUTER NETWORKS FALL FINAL January 10, minutes

CS 421: COMPUTER NETWORKS FALL FINAL January 10, minutes CS 4: COMPUTER NETWORKS FALL 00 FINAL January 0, 0 50 minutes Name: Student No: Show all your work very clearly. Partial credits will only be given if you carefully state your answer with a reasonable

More information

Transport: How Applications Communicate

Transport: How Applications Communicate Transport: How Applications Communicate Week 2 Philip Levis 1 7 Layers (or 4) 7. 6. 5. 4. 3. 2. 1. Application Presentation Session Transport Network Link Physical segments packets frames bits/bytes Application

More information

Internet Protocol version 6

Internet Protocol version 6 Internet Protocol version 6 Claudio Cicconetti International Master on Communication Networks Engineering 2006/2007 IP version 6 The Internet is growing extremely rapidly. The

More information

Port Utilization in Unified CVP

Port Utilization in Unified CVP Utilization in Unified CVP Utilization Table Columns, page 1 Unified CVP Utilization, page 2 Utilization Table Columns The columns in the port utilization tables in this document describe the following:

More information

Actual4Test. Actual4test - actual test exam dumps-pass for IT exams

Actual4Test.   Actual4test - actual test exam dumps-pass for IT exams Actual4Test http://www.actual4test.com Actual4test - actual test exam dumps-pass for IT exams Exam : 200-125 Title : CCNA Cisco Certified Network Associate CCNA (v3.0) Vendor : Cisco Version : DEMO Get

More information

ipv6 hello-interval eigrp

ipv6 hello-interval eigrp ipv6 hello-interval eigrp ipv6 hello-interval eigrp To configure the hello interval for the Enhanced Interior Gateway Routing Protocol (EIGRP) for IPv6 routing process designated by an autonomous system

More information

Detecting Specific Threats

Detecting Specific Threats The following topics explain how to use preprocessors in a network analysis policy to detect specific threats: Introduction to Specific Threat Detection, page 1 Back Orifice Detection, page 1 Portscan

More information

Customer Edge Switching & Realm Gateway Tutorial Session Day 2

Customer Edge Switching & Realm Gateway Tutorial Session Day 2 Customer Edge Switching & Realm Gateway Tutorial Session Day 2 Jesus Llorente Santos jesus.llorente.santos@aalto.fi www.re2ee.org August 21 st, 2015 Outline Recap from yesterday Current Internet Model

More information

HP High-End Firewalls

HP High-End Firewalls HP High-End Firewalls Attack Protection Configuration Guide Part number: 5998-2650 Software version: F1000-A-EI&F1000-S-EI: R3721 F5000: F3210 F1000-E: F3171 Firewall module: F3171 Document version: 6PW101-20120719

More information

TCP/IP Filtering. Main TCP/IP Filtering Dialog Box. Route Filters Button. Packet Filters Button CHAPTER

TCP/IP Filtering. Main TCP/IP Filtering Dialog Box. Route Filters Button. Packet Filters Button CHAPTER CHAPTER 11 Main Dialog Box To access this dialog box (Figure 11-1), select Global/Filtering/ from the Device View. Figure 11-1 Main Configuration Dialog Box Route Filters Button This button brings up a

More information

IPv6 HD Ratio. ARIN Public Policy Meeting April Geoff Huston APNIC

IPv6 HD Ratio. ARIN Public Policy Meeting April Geoff Huston APNIC IPv6 HD Ratio ARIN Public Policy Meeting April 2005 Geoff Huston APNIC 1 Background Current IPv6 Address Allocation policies refer to the use of the Host Density Ratio as a metric for acceptable utilization

More information

Time Sensitive Information!

Time Sensitive Information! Time Sensitive Information! These Configuration Changes Must Be Applied Ten Days Prior to Crexendo Cut-Over Sophos Router Configuration For Crexendo Cloud Telephony Deployment Document Version 1.2 March

More information

GARR customer triggered blackholing

GARR customer triggered blackholing GARR customer triggered blackholing Silvia d Ambrosio, Nino Ciurleo Introduction From discussions with the GARR working group on "contrast to DDoS", we understood the importance of a collaboration between

More information

Firewalls. Firewall. means of protecting a local system or network of systems from network-based security threats creates a perimeter of defense

Firewalls. Firewall. means of protecting a local system or network of systems from network-based security threats creates a perimeter of defense FIREWALLS 3 Firewalls Firewall means of protecting a local system or network of systems from network-based security threats creates a perimeter of defense administered network public Internet firewall

More information

Measuring IPv6 Day. Geoff Huston APNIC

Measuring IPv6 Day. Geoff Huston APNIC Measuring IPv6 Day Geoff Huston APNIC My brief for this session... It would be great if you could consider to include following topics in your presentation:! What you observed on World IPv6 day:!! Statistics

More information

DDoS Protection in Backbone Networks

DDoS Protection in Backbone Networks DDoS Protection in Backbone Networks The Czech Way Pavel Minarik, Chief Technology Officer Holland Strikes Back, 3 rd Oct 2017 Backbone DDoS protection Backbone protection is specific High number of up-links,

More information

NETWORK PACKET ANALYSIS PROGRAM

NETWORK PACKET ANALYSIS PROGRAM NETWORK PACKET ANALYSIS PROGRAM Duration: 3 days (21 hours) Mode: 1. Instructor Led Class room Training and Labs 2. Online In this hands-on course, you will receive in-depth training on Protocol analysis

More information

AP WG Policy Proposals Overview

AP WG Policy Proposals Overview AP WG Policy Proposals Overview Policy Development Officer Overview Concluded - IANA Policy for Allocation of IPv6 Blocks to RIRs (2005-09) Ongoing - IPv4-HD-Ratio (2005-01) - IP Assignments for anycasting

More information

Measuring IPv6. Geoff Huston George Michaleson APNIC Labs, May 2013

Measuring IPv6. Geoff Huston George Michaleson APNIC Labs, May 2013 Measuring IPv6 Geoff Huston George Michaleson APNIC Labs, May 2013 What s the question? The Big Question: How well are we going with the transition to IPv6? What s the question? The Big Question: How well

More information

Access List Commands

Access List Commands Access List Commands This module describes the Cisco IOS XR software commands used to configure IP Version 4 (IPv4) and IP Version 6 (IPv6) access lists. An access control list (ACL) consists of one or

More information

HP High-End Firewalls

HP High-End Firewalls HP High-End Firewalls Attack Protection Configuration Guide Part number: 5998-2630 Software version: F1000-E/Firewall module: R3166 F5000-A5: R3206 Document version: 6PW101-20120706 Legal and notice information

More information

Memcached amplification: lessons learned. Artyom Gavrichenkov

Memcached amplification: lessons learned. Artyom Gavrichenkov Memcached amplification: lessons learned Artyom Gavrichenkov 1.7 Typical amplification attack Most servers on the Internet send more data to a client than they receive UDP-based servers

More information

Measuring IPv6. Geoff Huston APNIC Labs, August 2013

Measuring IPv6. Geoff Huston APNIC Labs, August 2013 Measuring IPv6 Geoff Huston APNIC Labs, August 2013 What s the question? The Big Question: How well are we going with the transition to IPv6? What s the question? The Big Question: How well are we going

More information

TCP/IP Networking. Training Details. About Training. About Training. What You'll Learn. Training Time : 9 Hours. Capacity : 12

TCP/IP Networking. Training Details. About Training. About Training. What You'll Learn. Training Time : 9 Hours. Capacity : 12 TCP/IP Networking Training Details Training Time : 9 Hours Capacity : 12 Prerequisites : There are no prerequisites for this course. About Training About Training TCP/IP is the globally accepted group

More information

Advisory Guidelines for 6to4 Deployment

Advisory Guidelines for 6to4 Deployment Advisory Guidelines for 6to4 Deployment draft-carpenter-v6ops-6to4[-teredo]-advisory-03 Brian Carpenter March 2011 1 Acknowledgements Very useful and practical input from at least 20 people: Emile Aben,

More information

ECE4110 Internetwork Programming. Introduction and Overview

ECE4110 Internetwork Programming. Introduction and Overview ECE4110 Internetwork Programming Introduction and Overview 1 EXAMPLE GENERAL NETWORK ALGORITHM Listen to wire Are signals detected Detect a preamble Yes Read Destination Address No data carrying or noise?

More information

Fundamentals of IP Networking 2017 Webinar Series Part 4 Building a Segmented IP Network Focused On Performance & Security

Fundamentals of IP Networking 2017 Webinar Series Part 4 Building a Segmented IP Network Focused On Performance & Security Fundamentals of IP Networking 2017 Webinar Series Part 4 Building a Segmented IP Network Focused On Performance & Security Wayne M. Pecena, CPBE, CBNE Texas A&M University Educational Broadcast Services

More information

Exit from Hell? Reducing the Impact of Amplification DDoS Attacks Marc Kührer, Thomas Hupperich, Christian Rossow, and Thorsten Holz

Exit from Hell? Reducing the Impact of Amplification DDoS Attacks Marc Kührer, Thomas Hupperich, Christian Rossow, and Thorsten Holz Exit from Hell? Reducing the Impact of Amplification DDoS Attacks Marc Kührer, Thomas Hupperich, Christian Rossow, and Thorsten Holz Presented By : Richie Noble Distributed Denial-of-Service (DDoS) Attacks

More information

Adding an IPv6 Access List

Adding an IPv6 Access List CHAPTER 19 This chapter describes how to configure IPv6 access lists to control and filter traffic through the ASA. This chapter includes the following sections: Information About IPv6 Access Lists, page

More information

The IDP system generates logs for device events and security events. Table 1 summarizes options for viewing and managing logs.

The IDP system generates logs for device events and security events. Table 1 summarizes options for viewing and managing logs. IDP Logs Overview The IDP system generates logs for device events and security events. Device event logs are related to the operation of the IDP appliance. By default, the system logs events when it reaches

More information

Internet Noise: a tale of two subnets

Internet Noise: a tale of two subnets Internet Noise: a tale of two subnets Tim Obezuk Cloudflare Who am I? Tim Obezuk Solutions Engineer at Cloudflare Helping Australian organisations build faster and more secure internet properties 10%

More information

Forescout. Configuration Guide. Version 8.1

Forescout. Configuration Guide. Version 8.1 Forescout Version 8.1 Contact Information Forescout Technologies, Inc. 190 West Tasman Drive San Jose, CA 95134 USA https://www.forescout.com/support/ Toll-Free (US): 1.866.377.8771 Tel (Intl): 1.408.213.3191

More information

V Commands. virtual ip, page 2 virtual ipv6, page 5 vrf, page 8. Cisco Nexus 7000 Series NX-OS Intelligent Traffic Director Command Reference 1

V Commands. virtual ip, page 2 virtual ipv6, page 5 vrf, page 8. Cisco Nexus 7000 Series NX-OS Intelligent Traffic Director Command Reference 1 virtual ip, page 2 virtual ipv6, page 5 vrf, page 8 1 virtual ip virtual ip To configure the virtual IPv4 address of an Intelligent Traffic Director (ITD) service, use the virtual ip command. To remove

More information

Configuring attack detection and prevention 1

Configuring attack detection and prevention 1 Contents Configuring attack detection and prevention 1 Overview 1 Attacks that the device can prevent 1 Single-packet attacks 1 Scanning attacks 2 Flood attacks 3 TCP fragment attack 4 Login DoS attack

More information

Network Address Translation (NAT)

Network Address Translation (NAT) The following topics explain and how to configure it. Why Use NAT?, page 1 NAT Basics, page 2 Guidelines for NAT, page 8 Configure NAT, page 12 Translating IPv6 Networks, page 40 Monitoring NAT, page 51

More information

Section 3 - Configuration. Enable Auto Channel Scan:

Section 3 - Configuration. Enable Auto Channel Scan: Enable Auto Channel Scan: Wireless Channel: The Auto Channel Scan setting can be selected to allow the DGL-4500 to choose the channel with the least amount of interference. Indicates the channel setting

More information

How to Make the Client IP Address Available to the Back-end Server

How to Make the Client IP Address Available to the Back-end Server How to Make the Client IP Address Available to the Back-end Server For Layer 4 - UDP and Layer 4 - TCP services, the actual client IP address is passed to the server in the TCP header. No further configuration

More information

Initial results from an IPv6 Darknet

Initial results from an IPv6 Darknet Initial results from an IPv6 Darknet Matthew Ford, Jonathan Stevens 2 and John Ronan 3 British Telecommunications plc, Networks Research Centre, pp HWP276, PO Box 234, Edinburgh, EH2 9UR, UK 2 British

More information

HP A5500 EI & A5500 SI Switch Series Network Management and Monitoring. Configuration Guide. Abstract

HP A5500 EI & A5500 SI Switch Series Network Management and Monitoring. Configuration Guide. Abstract HP A5500 EI & A5500 SI Switch Series Network Management and Monitoring Configuration Guide Abstract This document describes the software features for the HP A Series products and guides you through the

More information

Beyond the IPv4 Internet. Geoff Huston Chief Scientist, APNIC

Beyond the IPv4 Internet. Geoff Huston Chief Scientist, APNIC Beyond the IPv4 Internet Geoff Huston Chief Scientist, APNIC The IETF s ROAD Trip By 1990 it was evident that IPv4 was not going to have a large enough address span for long term deployment And the routing

More information

HP 6125XLG Blade Switch

HP 6125XLG Blade Switch HP 6125XLG Blade Switch Network Management and Monitoring Configuration Guide Part number: 5998-5376a Software version: Release 240x Document version: 6W101-20150515 Legal and notice information Copyright

More information

Memcached amplification: lessons learned. Artyom Gavrichenkov

Memcached amplification: lessons learned. Artyom Gavrichenkov Memcached amplification: lessons learned Artyom Gavrichenkov 1.7 Typical amplification attack Most servers on the Internet send more data to a client than they receive UDP-based servers

More information

HP 5120 SI Switch Series

HP 5120 SI Switch Series HP 5120 SI Switch Series Network Management and Monitoring Configuration Guide Part number: 5998-1813 Software version: Release 1505 Document version: 6W102-20121111 Legal and notice information Copyright

More information

A Question of Protocol

A Question of Protocol A Question of Protocol Geoff Huston APNIC Originally there was RFC791: Originally there was RFC791: Originally there was RFC791: All hosts must be prepared to accept datagrams of up to 576 octets (whether

More information

Network Services. Geoff HUSTON

Network Services. Geoff HUSTON Network Services Geoff HUSTON IP Access is not enough An ISP service also requires: mail & mailing lists DNS web usenet ftp... Mail Services Outgoing Mail server Outbound Mail Outbound Mail POP or IMAP

More information

Exploring TCP and UDP based on Kurose and Ross (Computer Networking: A Top-Down Approach) May 15, 2018

Exploring TCP and UDP based on Kurose and Ross (Computer Networking: A Top-Down Approach) May 15, 2018 Exploring TCP and UDP based on Kurose and Ross (Computer Networking: A Top-Down Approach) May 15, 2018 Exploring TCP Description Capturing a bulk TCP transfer from your computer to a remote server. In

More information

BIG-IP CGNAT: Implementations. Version 13.0

BIG-IP CGNAT: Implementations. Version 13.0 BIG-IP CGNAT: Implementations Version 13.0 Table of Contents Table of Contents Deploying a Carrier Grade NAT... 9 Overview: The carrier-grade NAT (CGNAT) module... 9 About ALG Profiles...10 About CGNAT

More information

Configuring Transparent Redirection for Standalone Content Engines

Configuring Transparent Redirection for Standalone Content Engines CHAPTER 6 Configuring Transparent Redirection for Standalone Content Engines This chapter discusses the following methods for transparently redirecting content requests to standalone Content Engines: Web

More information

IPv4 Unallocated Address Space Exhaustion

IPv4 Unallocated Address Space Exhaustion IPv4 Unallocated Address Space Exhaustion Geoff Huston Chief Scientist APNIC APNIC 24, September 2007 IPv4 IPv4 Current Status of IPv4 Lets look at some charts showing the current status of IPv4 address

More information

Radware DefensePro DDoS Mitigation Release Notes Software Version Last Updated: December, 2017

Radware DefensePro DDoS Mitigation Release Notes Software Version Last Updated: December, 2017 Radware DefensePro DDoS Mitigation Release Notes Software Version 8.13.01 Last Updated: December, 2017 2017 Cisco Radware. All rights reserved. This document is Cisco Public. Page 1 of 9 TABLE OF CONTENTS

More information