Categories
Networking Security xISP

Updating your Bind DNS for latest trust anchors

A little Background on the rollover From: https://www.icann.org/resources/pages/ksk-rollover/#overview ICANN is planning to perform a Root Zone Domain Name System Security Extensions (DNSSEC) KSK rollover as required in the Root Zone KSK Operator DNSSEC Practice Statement [TXT, 99 KB]. Rolling the KSK means generating a new cryptographic public and private key pair and distributing the new public component to parties who operate validating resolvers, including: Internet Service Providers; […]

Categories
xISP

Client subnet in DNS requests

Some Light Reading: https://tools.ietf.org/html/draft-vandergaast-edns-client-subnet-00 Many Authoritative nameservers today return different replies based on the perceived topological location of the user. These servers use the IP address of the incoming query to identify that location. Since most queries come from intermediate recursive resolvers, the source address is that of the recursive rather than of the query […]

Categories
WISP xISP

DNS naming convention (Quick Tips)

For years we have done the following naming conventions for our DNS servers. NS is reserved for authoritative name servers DNS is reserved for caching servers. For MTIN we have NS1.MTIN.NET and NS2.MTIN.NET which are authoritative for domains we host. DNS1.MTIN.NET and DNS2.MTIN.NET are for managed DNS customers.

Categories
Uncategorized

Protecting your Mikrotik from DNS Amplification

There are several reasons and benefits to using your Mikrotik as a DNS caching server.  Queries to the client are just a tad faster, which makes the overall user experience seem snappier.  It also allows you to quickly change upstream DNS servers in the even of an outage, attack, etc. There are two main avenues […]

Categories
Uncategorized

MTIN now offers IPv6 DNS

MTIN now offers both forward and reverse IPv6 DNS services. Contact us for details

Categories
FlashBriefing

MTIN Flash briefing January 31 2019

We are trying out something new.  This is aimed at a quick burst of information for ISPs, network operators, and those involved in supporting networks.  These “flash briefings” are aimed to be 2-5 minutes in length.  iTunes and other subscriptions coming shortly. In this flash briefing: Cisco is discontinuing BGPmon in favor of their Crosswork […]

Categories
BGP

NEW Service: IP Space Compliance

MTIN is announcing a new service today for those of you who have Registry assigned IP space. For the low price of $80 a year, MTIN will provide the following services in regards to your IP allocations. Make sure your whois information is correct in the proper registry (ARIN, APNIC, and others) each year. Make […]

Categories
Wireless

IgniteNet Metrolinq 60 new Firmware

https://support.ignitenet.com/portal/kb/articles/firmware-downloads-metrolinq-2-5 New Feature: Added 12 client support for 60GHz radio New Feature: Added MCS12 support for 60GHz radio New Feature: Added STP control New Feature: Added Jumbo frame support for 5GHz radio (up to 7912) New Feature: Added support for RSTP passthrough New Feature: Added L2 and L3 MTU control options Improved:RSSI (signal level) representation […]

Categories
Uncategorized

From the archives – Evolution of a network guy part 2

Being hired as a tech support tech at tctc.com would forever change my life.  It was like being shown who was behind the curtain.  All of a sudden this world of T1 lines, modem banks, and DNS servers was before me.  I couldn’t soak up enough of it.  It was here I met some of […]

Categories
UBNT

UBNT EDGEMAX 1.10.3 update route flushing

From UBNT: New features: Offloading – Add CLI commands to disable flow-table flushing in offloading engine when routing table changes:  set system offload ipv4 disable-flow-flushing-upon-fib-changes set system offload ipv6 disable-flow-flushing-upon-fib-changes Discussed here Prior to 1.10.3 firmware flow-table in offloading engine was always flushed when route was updated in linux routing table. Flow flushing ensured that offloading engine got routing updates instantly but it wasted a lot of CPU time […]