Jump to content

RW_LUNS

Members
  • Posts

    7
  • Joined

  • Last visited

Reputation

5 Neutral

About RW_LUNS

Personal Information

  • Occupation
    Network Engineer
  • Interests
    All forms of geekery

Employer (optional)

  • Company Represented
    LUNS
  1. It's an interesting discussion to have. In what way would you for-see the ability to spoof changing between v4 and v6 though? It's very hard to genuinely spoof addresses over the Internet (if you want to receive the return traffic back, which you'd need for the likes of TCP sessions for spamming etc). If however by spoofing you mean the use of anonymous Internet proxies, I don't see how that situation changes between v4 and v6? If anything, I'd see that getting rid of NAT should make combating spammers etc easier, as by ACLing or cutting off certain IP addresses, you don't run the risk of cutting off a NAT/proxy/service box and thus affecting the connectivity/services of a huge number of users. Rob
  2. I should add, from our routing tables at the moment I'm only seeing the 46.18.48.0/21 route. Does your cisco actually have a direct or static route for the /22 subnets? (do a show route for them) Just adding the network statement to BGP won't advertise those networks unless your router has a route for them itself. You could add a local "reject route" static or aggregate which should make it advertise (assuming virgin are allowing you to advertise any length of prefix within your /21). Rob
  3. Hi Phil What behaviour are you looking for? What part isn't working at the moment? Rob
  4. In terms of the security ramifications - yes it needs thinking about, but it shouldn't be as big a perception shift as many may think. Yes your edge hosts may all be assigned 'global' addresses, but there will still be a border router on your network with a firewall. Just because it isn't NATing doesn't mean it isn't firewalling out all the same malicious ports/performing all the same traffic analysis as it was with v4. It just means that if you make a mistake in your border firewall rules, your edge hosts are more susceptible to being accessible from the outside (as obviously old v4 privates aren't globally routeable which provided a belt and braces to firewall misconfiguration). I see it as a benefit though. NAT does nothing but slow networks down (NAT processing is a lot more expensive than optimised routing) and cause end-to-end connectivity problems. With v6 there is just no need for NAT.
  5. Our talk at the edugeek conference covered (a little) v6 stuff. I think the slides are online here EduGeek Conference June 2011 in Preston « (James Evans) EduTech's Blog (the LUNS talk). But yeah, the advice is basically, audit what you have and when buying new equipment, make sure it is v6 compatible so that when the "time comes" you can support it. Might also be worth finding out if your current ISP/provider offers any v6 or has a roadmap to do so (in the case of LEAs, I'd imagine the info will filter down to you eventually). Rob
  6. Mate, looking at those RTT's and loss, I'd say there is a good chance that there is a loop on your network somewhere. A switch could be looped back to itself with a patch cable or there might be a ring of switches ending up back at the original switch. Have you mapped out your network or anything to check for something like this? You could also try disconnecting portions of your network (out of hours) to narrow down (in a crude way!) which part of the network is causing the problem. Do you get similar ping results if you hit other devices around your network? (this would rule out if the problem was a misbehaving router or an internal network issue) p.s. I should add - the size of your network is well within reasonable levels and I wouldn't necessarily suggest VLANs would help except to possibly break a layer 2 loop
  7. Had a great day at the conference on Thurs and enjoyed listening to all the talks, chatting to everyone, and drinking too much coffee so when it was my turn to talk, I no doubt sounded like I was wired Thanks to all the organisers! Robin
×
×
  • Create New...