Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] Security group highlights - December 2018

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] Security group highlights - December 2018


Chronological Thread 
  • From: David Farmer <>
  • To:
  • Subject: Re: [Security-WG] Security group highlights - December 2018
  • Date: Mon, 7 Jan 2019 12:32:25 -0600
  • Ironport-phdr: 9a23:12OnORdHxws9SLhJ+xB8CkOslGMj4u6mDksu8pMizoh2WeGdxcS8YR7h7PlgxGXEQZ/co6odzbaO4+a4ASQp2tWoiDg6aptCVhsI2409vjcLJ4q7M3D9N+PgdCcgHc5PBxdP9nC/NlVJSo6lPwWB6nK94iQPFRrhKAF7Ovr6GpLIj8Swyuu+54Dfbx9HiTahYr5+Ngm6oRnMvcQKnIVuLbo8xAHUqXVSYeRWwm1oJVOXnxni48q74YBu/SdNtf8/7sBMSar1cbg2QrxeFzQmLns65Nb3uhnZTAuA/WUTX2MLmRdVGQfF7RX6XpDssivms+d2xSeXMdHqQb0yRD+v6bpgRh31hycdLzM2/2/Xhc5wgqxVoxyvugJxzJLPbY6PKPZzZLnQcc8GSWdDWMtaSixPApm7b4sKF+cPM/xXr5f8p1QTsBCwBROjBPnqyjBWnH/9wKo30+o7HgHc2QwvAcgOvW/JrNXwMqceS/66w7TVzTjaaf5dxDnz6I/Nch87oPGMW6p9cdbRyUYxDQPKkFqQqY3+PzOJyOsNqXKX4PZnVe61lm4nqBl9oiShx8ctlonJmpwaykre+Splx4Y1IMW0RFNlbdOmCpdcqzuWO5dsTs8+W21kpDw2xqEctZKnZiQG1IwrxxjfavyCaYeI7QjvW/qWITd9nH5pZr2yiwqo/US80OHwStO43EpMoyFYkdfMrmgA2wHd58WIUPdw/Uis1SyS2w3X6+xIO144mbbZJpI53LI8ip4evV7AEyL2gkn6krGaelg+9uS17+nqYLPrrYKGOYBukAHxKKEul9S/AesmNggOWHCW+eGg1LL55EH5WLdHgucxkqnYrJDWP9kbpqu/AwNPzIks9gu/Ay+n0NQeg3YHMEpIdA+JgoXmIV3DI//1Ae2ij1mokTpn3e7KMqHjD5nVK3jMirbhfbJz605GzwozyMhS55xOBbEbJfL8RFXxucfFDh88NQy42fjoB8hg1o8GQ2KAHreZML/OsV+P/u8vOPeDa5MIuDbnKvgl+/7vgWY3mF8SZqSp2ZoXaGukHvR9PUmVe3vsgtEdEWgUpAo+SvLliEGcXTJJeXm9Qr88tXkHD9e9AIzeXIGxkfme0w+6GIFbfGZLFgrKHHv1JKueXPJZRCuMI8MpvDUeULW7A9sv3AuruRXS1r9haOfY53tL5trYyNFp6riLxlkJ/jtuApHF3g==

Yes, please add the other stuff.

For IPv4, RFC1918 (Private-Use), RFC6598 (Shared Address Space), RFC3927 (Link-Local), RFC5737 (Documentation), 240.0.0.0/4 Reserved (Class E), 127.0.0.0/8 Loopback, 0.0.0.0/8 

For IPv6, RFC4193 (ULA), RFC3849  (Documentation), RFC6052 (Well-Known local NAT64), RFC8215 (other local NAT64), RFC6666 (Discard Prefix)

On Mon, Jan 7, 2019 at 11:01 AM gcbrowni <> wrote:
Well, unless we change the scope.

Let’s do 1918 and other "well known" bad source addresses. We can worry about "unassigned space" later.

How's that sound?


> On Jan 7, 2019, at 11:59 AM, Adair Thaxton <> wrote:
>
> I believe that only RFC1918 space is in scope for now.  Baby steps!
>
> Adair
>
>
> On 1/7/19 11:58 AM, Michael H Lambert wrote:
>> I fully agree with blocking RFC1918 addresses.  There are lots of other "static" bogon ranges, too, in both modern and legacy IP.  These include documentation and IANA-reserved addresses.  How aggressive should Internet2 (or connectors) be in blocking these in addition to RFC1918?
>>
>> Michael
>>
>>> On 7 Jan 2019, at 11:43, Brad Fleming <> wrote:
>>>
>>> I’m assuming RFC1918 IPs as the source, correct? Regardless of source or destination address I’m good with it. We shouldn’t be leaking that junk, if we are something is broken, and I don’t expect Internet2 or the greater community to deal with our failures. A publicly viewable counter on the firewall filter term could be useful; I could make one of our junior network team check the I2 counter every month to verify we don’t have an internal issue. I’d be fine if that instrumentation wasn’t added until later if I2 staff would like to move quickly on deploying filters but also want to gather more input from the community on exposing FW filter counters in this manner.
>>> --
>>> Brad Fleming
>>> Assistant Director for Technology
>>> Kansas Research and Education Network
>>>
>>>> On Jan 7, 2019, at 10:13 AM, Adair Thaxton <> wrote:
>>>>
>>>> I trust everyone had a nice break, and hasn't been driven up the wall by
>>>> bored children yet.  Our three-year-old reached the "why?" stage just in
>>>> time for break, so if you're still sane, I envy you!
>>>>
>>>>
>>>> - Internet2 is considering blocking all RFC1918 space at ingress links.
>>>> We do not expect this to affect cloud tunnel traffic, or any legitimate
>>>> traffic.  However, we all know the pitfalls of that last statement,
>>>> especially on our networks!  We plan to start by logging RFC1918 traffic
>>>> only, and then move to blocking it.  We also plan to offer opt-outs for
>>>> customers who need them.  We would welcome your input on this, for our
>>>> benefit as well as for the benefit of other customers.
>>>>
>>>>
>>>> - Check your routing tables!
>>>> https://twitter.com/InternetIntel/status/1080466509292621829
>>>>
>>>>
>>>> - Hat tip to researchers at the University of Maryland!
>>>> https://www.theregister.co.uk/2019/01/03/recaptcha_voice_challenge/
>>>>
>>>>
>>>> - A lot of it, as it turns out.
>>>> http://nymag.com/intelligencer/2018/12/how-much-of-the-internet-is-fake.html
>>>>
>>>>
>>>> Happy new year, everybody!
>>>>
>>>> Adair
>>>
>>



--
===============================================
David Farmer              
Networking & Telecommunication Services
Office of Information Technology
University of Minnesota  
2218 University Ave SE        Phone: 612-626-0815
Minneapolis, MN 55414-3029   Cell: 612-812-9952
===============================================



Archive powered by MHonArc 2.6.19.

Top of Page