Tag Archives: networking

uceprotect lists subnets that never sent mail

uceprotect.net claims to provide a blacklist of IP addresses that send spam. SMTP server operators can query the blacklist, and know to refuse mail from these IP addresses. That’s the theory. But there’s a problem though: uceprotect blocks IP address … Continue reading

Posted in Stuff | Tagged , , , , , | Leave a comment

FRR says “Finite State Machine Error” for IPv6 BGP on Linux

If you turn off link-local addresses for the interface (those horrible 169.254.50.231 type addresses, and also the IPv6 fe80::dead:beef:4:f00d/64 things), FRR goes sulky. In netplan, it looks like this: When FRR is sulky, it says it will advertise IPv6 subnets, … Continue reading

Posted in Stuff | Tagged , , , , , | Leave a comment

IPv4 port routing for scaleable no-CGNAT NAT

The CGNAT problem is that a big box at the ISP has to track the state of all communications on the network. This is expensive. It is also unnecessary. It’s 2025-10-13, and here’s an answer. Executive summary for TL;DR: Port … Continue reading

Posted in Stuff | Tagged , , , | Leave a comment

Workaround for Neighbour Discovery failure, for static-configured IPv6 on Linux: Use IPv4 gateway mac for IPv6

Here’s a shell script to figure out what the IP4 gateway MAC address is, and to set that as the IP6 gateway MAC: This was necessary for a machine where the gateway decided that responding to neighbour solicit requests was … Continue reading

Posted in Stuff | Tagged , , , , , , | Leave a comment

Ignoring out-of-band network policy systems with iptables

I’ve been working on parental controls using an out-of-band policy engine. It is easy to subvert, if you care to, since the controls it implements are very light, and it is not actually part of the conversation between you and … Continue reading

Posted in Stuff | Tagged , , , , | Leave a comment

What are the IP addresses for NS records of co.za?

In short? 99.8% of the time, they are these: ns1.coza.net.za. IN A 66.135.62.20 ns.coza.net.za. IN A 206.223.136.200 ns4.iafrica.com. IN A 196.7.142.131 ns0.is.co.za. IN A 196.4.160.17 ns0.neotel.co.za. IN A 41.160.0.4 coza1.dnsnode.net. IN A 194.146.106.74 And the remaining 0.2% of the time?  … Continue reading

Posted in Stuff | Tagged , , , , , , , | Leave a comment

Invasion of the evil androids

Google says you are too stupid to rule your own life.  They say this by their Android phone operating system, in which they do not give you, the owner and operator of the device, root permissions.  This means: You cannot … Continue reading

Posted in Stuff | Tagged , , , , , , , , | Leave a comment

The sound of outage

Here’s a song to sing the next time your network goes down.  Click the play button on the youtube karaoke, and sing it yourself: Hello outage my old friend I’ve come to talk with you again Because of vulnerability creeping … Continue reading

Posted in Songs, Stuff | Tagged , , , , | Comments Off on The sound of outage

VMWare + ipfix + NAT = intermittent fail

So I put all of these things together a while ago for bandwidth reporting: VMWare‘s netflow reporting – I configured a virtual distributed switch to send netflow reporting to a collector.  Every time some machine runs up its internet usage, the … Continue reading

Posted in Stuff | Tagged , , , , , | Comments Off on VMWare + ipfix + NAT = intermittent fail

Netgear STP bug (or something)

I found a fun bug today. We have a stack of netgear switches in our office – and we keep getting disconnected at odd times. I already found a switch which did not have STP enabled, and turned that on, … Continue reading

Posted in Stuff | Tagged , , , , , | Comments Off on Netgear STP bug (or something)