I've got a question for Claus: by what policy does your system
assign netwoks to ASes ?
Case in point: I've got a nework that used to belong to an AS
your system blocks. Said network now does not belong to that AS
any more - as per RIPE entry - and is announced via its new AS.
But your system's data inquiry form keeps listing the system as
level 3 blocked and lists *both* ASes for it.
This has been that way for quite some time now. We've tried
improve the RIPE entries, but, so far, to no avail.
So - do you use RIPE data, if yes what fields do you use to maintain
data connection between networks and ASes ? If not, what's your
data source - where do I have to look to get stuff corrected?
And in any case - in what frequency do you update your topology
data from your sources?
Regards
Christoph Weber-Fahr
--
Comments posted to news.admin.net-abuse.blocklisting
are solely the responsibility of their author. Please
read the news.admin.net-abuse.blocklisting FAQ at
http://www.blocklisting.com/faq.html before posting.
Can you give an example Ip or CIDR ?
{That others can look up in the various
stats/ RIR / delegated- RIR -latest files,
IP whois queries, RIS looking glass history,
route announcements, other route histories, ...?}
e.g. 151.189.20.61
ripencc|EU|ipv4|151.189.0.0|65536|19970113|assigned
RIPE IP whois returns:
route: 151.189.0.0/16 , origin: AS6751
route: 151.189.0.0/16 , origin: AS3209
Ripe Prefix dashboard, This prefix has 0 visibility.
Prefix 151.189.0.0/16, AS 3209 , Arcor IP-Network , 2008-08-22 00:01:35 UTC
potaroo announcement history returns:
151.189.0.0/16 (Announced)
ANNOUNCE_Flap , 3209 , + : 0501h 24 Mar 2008 UTC
ORIGIN_Flap , 6751 - 3209 : 0000h 27 Aug 2002 UTC
FIRST_HOP_AS_Flap , 6461 - 3356 : 0300h 26 Mar 2008 UTC
151.189.16.0/20 (NOT Announced)
ANNOUNCE_Flap , - : 0940h 24 Dec 1997 UTC
FIRST_HOP_AS_Flap , 1755 - 3257 : 0940h 23 Dec 1997 UTC
RouteViews returns:
151.189.0.0/16 , AS 3209 , AS Path 5056 3356 3209
Cymru IP whois reutrns AS3209
...
--
E-Mail Sent to this address <Blac...@Anitech-Systems.com>
will be added to the BlackLists.
"E-Mail Sent to this address will be added to the BlackLists" wrote:
> Can you give an example Ip or CIDR ?
Hmm. Are you Claus?
Actually I would like to understand UCEProtect's policy and method,
not bother anyone with a single case that might or might not have
gone wrong and needs fixing.
I'd prefer to do my homework on that first myself.
So - if you are Claus, would you mind answering my question?
If not, what about waiting for him to do so?
And, fwiw, I usually avoid getting into debates with completely
anonymous people on usenet. I understand that in this newsgroup
some feel a need to wield complete anonymity as a shield against
percieved threats, but I'd still prefer to talk to somebody
having a name.
Regards
Christoph Weber-Fahr
N.A.N-A.Bl is not UCEPROTECT not Claus.
There are at least hundreds, if not thousands of people who
read, and sometimes respond to posts in the public usenet
newsgroup News.Admin.Net-Abuse.BlockListing
FYI, I heard (in another post, in another newsgroup) that
Claus was on vacation, and other UCEPROTECT Admins were
at the helm.
--
E-Mail Sent to this address <Blac...@Anitech-Systems.com>
will be added to the BlackLists.
> Christoph Weber-Fahr wrote:
> > Hmm. Are you Claus?
>
> N.A.N-A.Bl is not UCEPROTECT not Claus.
>
> There are at least hundreds, if not thousands of people who
> read, and sometimes respond to posts in the public usenet
> newsgroup News.Admin.Net-Abuse.BlockListing
Curious, where are these statistics coming from?
Claus is on vacation and will be back by 1 th September, so I will try
to answer your question.
As far as I know, UCEPROTECT is using BGP to get informations which
networks belong to an AS.
Heidi Zink
UCEPROTECT-Network
Blacklistmaster of the day
> I've got a question for Claus: by what policy does your system
> assign netwoks to ASes ?
We use the BGP-Data for assigning Networks to AS.
> And in any case - in what frequency do you update your topology
> data from your sources?
These Values are updates twice a day.
So if you find outdated Data there you have to contact your
Upstreamprovider to fix this.
Best Regards
Manfred Hielder
UCEPROTECT-Network Representative
Manfred Hielder wrote:
> Christoph Weber-Fahr schrieb:
> > I've got a question for Claus: by what policy does your system
> > assign netwoks to ASes ?
>
> We use the BGP-Data for assigning Networks to AS.
Thanks for your answer.
My network currently is announced for my AS "A", yet it
gets also listed in your database under AS "B".
Since my net currently has only one peer/upstream (AS "B")
(yet), its AS path always ends in "B" "A". Is that the
reason?
Or - apparently there is a superblock of the network in
question that seems to get announced or aggregated somewhere.
So, if somebody aggergates my network with others and announces
it for AS B, could that be the reason you list my net
under as B as well?
Or, to put it more generally, what criterion do you use to
multiply assign networks to two or more ASes in your database?
Regards,
Christoph Weber-Fahr
Seems likely to me. Why don't you just check & see what
it looks like to the rest of the world, through a public
looking glass, or other route registry / history?
... or give an example IP in the AS, so someone else can
point out the likely issue, to you.
--
E-Mail Sent to this address <Blac...@Anitech-Systems.com>
will be added to the BlackLists.