nanog mailing list archives

Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours


From: Colin Johnston <colinj () gt86car org uk>
Date: Mon, 20 Jul 2015 20:18:46 +0100

in war you take information at face value and use it if needed to mitigate risk, if there is legit traffic in blocked 
ranges then excemption procedure in place to unblock.

colin

Sent from my iPhone

On 20 Jul 2015, at 19:57, Valdis.Kletnieks () vt edu wrote:

On Mon, 20 Jul 2015 19:42:39 +0100, Colin Johnston said:
see below for china ranges I believe, ipv4 and ipv6

You may believe... but are you *sure*?  (Over the years, we've seen
*lots* of "block China" lists that accidentally block chunks allocated
to Taiwan or Australia or other Pacific Rim destinations).

And remember - asking the NIC doesn't help, because there are almost
certainly blocks allocated that the registration points to Korea or
someplace, but the provider routes a sub-block to China.  And let's
not even get started on blocks allocated by ARIN or RIPE....

(Yes, it *was* a trick question :)



Current thread: