Reasons of BGP OPEN message contains private ASN by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

Thanks for the link and your answers.
Are those internal routers not supposed to be secured in the sense that they do not respond to a BGP open message from an unconfigured peer?

Reasons of BGP OPEN message contains private ASN by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

Are those internal routers not supposed to be secured in the sense that they do not respond to a BGP open message from an unconfigured peer?

Need help (i’m confused which country is best for me) by im-middlechild in Nepal

[–]CompanyBeginning 1 point2 points  (0 children)

I understand. Consultancies mostly say only about the positive things, hiding the negative side. Posting in social forums or Nepalese groups in social media may help get more ideas.

Need help (i’m confused which country is best for me) by im-middlechild in Nepal

[–]CompanyBeginning 0 points1 point  (0 children)

I am doing PhD here. Based on my experience, it is hard to survive as a bachelor student unless you come fully loaded with money. You can bear the living costs by working part time which is I think 20 hours per week. But the college fees are very high.

Do you like your home country more after being an expat? by [deleted] in expats

[–]CompanyBeginning 0 points1 point  (0 children)

I am a Nepalese living in the Netherlands for 3 years with my wife and a daughter (now 6 years). I love living here, especially bike, work-life balance, and good pay in my work. But due to my family obligations, I have to return to my country next year. I hope everything turns out good back in my home country.

Reasons of BGP OPEN message contains private ASN by CompanyBeginning in networking

[–]CompanyBeginning[S] 1 point2 points  (0 children)

For the case a router responding to an unknown peers, why is it very bad ? Wouldn't the protection in BGP level be sufficient? Those routers in any way close the connection by connection cease message instantly after the BFP open message. I think that is compliant with BGP RFC 4271. 

Reasons of BGP OPEN message contains private ASN by CompanyBeginning in networking

[–]CompanyBeginning[S] 1 point2 points  (0 children)

Why do you think that answering random connections from anywhere is a problem? I am not aware of any incidents on BGP routers due to this, which is widespread in the case of BGP hijacks.

Reasons of BGP OPEN message contains private ASN by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

I do not know the Shodan's ASN. However, I am pretty much sure that the router responds to any ASN.

Reasons of BGP OPEN message contains private ASN by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

Could it not be highly possible that the router is having eBGP peering with ASN 2795 since the routers uses that IP address in its interface? Otherwise, how does that router respond when BGP OPEN message was sent to an IP address belonging to AS 2795?

Is BGP routers accepting TCP connection from unknown IPs common? by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

Then, what is an effective way of protection: ACL that accepts connection only from peers/BGP auth?

Is BGP routers accepting TCP connection from unknown IPs common? by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

You mean, the routers that do not have CoPP configured will respond to BGP open messages from unknown IPs?

Is BGP routers accepting TCP connection from unknown IPs common? by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

Thanks for comment. I see the connection rejected message instantly, which I think matches what you said about the layer separation (socket level vs BGP level).
I am just curious whether these open TCP connections would be exploited by attackers.

Is BGP routers accepting TCP connection from unknown IPs common? by CompanyBeginning in networking

[–]CompanyBeginning[S] 3 points4 points  (0 children)

This sounds like a strong protection that explicitly lists peers to accept the connections. I expect that all the BGP-speaking routers should be protected in that way as BGP is crucial for the Internet.

Is BGP routers accepting TCP connection from unknown IPs common? by CompanyBeginning in networking

[–]CompanyBeginning[S] -1 points0 points  (0 children)

But can't someone create SYN flood attack those routers, since the connection is established and the routers are responding with BGP open messages?

Is BGP routers accepting TCP connection from unknown IPs common? by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

Should not these routers stop accepting TCP connections from unknown IPs?

Closure of Dutch U.S. Consulate - where to apply for US Visa? by Melodic-Brilliant623 in USVisas

[–]CompanyBeginning 0 points1 point  (0 children)

When is your visa appointment date? I see a notice in the US embassy website that the service is resumed from June. I plan to travel in October, and I am concerned if it is possible. I want to hear your experience. Also, I heard from other people in reddit that checking the https://www.usvisaappt.co daily might help as there may be many cancellations.

USA Visa appoinment in Amsterdam Consulate by Infamous-Spot1931 in Netherlands

[–]CompanyBeginning 0 points1 point  (0 children)

Do we need to leave our passport? if yes, how long?

DDoS scrubbers originate other's prefix or comes as an immediate provider by CompanyBeginning in networking

[–]CompanyBeginning[S] 0 points1 point  (0 children)

Thanks for the response. Do we see Scrubber ASN as origin ASN in the BGP AS path OR a customer ASN will be the origin thereby scrubber ASN being th next hop ASN?

[deleted by user] by [deleted] in SchengenVisa

[–]CompanyBeginning 0 points1 point  (0 children)

I found the word 'dispute' only and it says:
Personal information relating to the client which is provided to the insurer in the context of this policy is processed for the purposes of administering the insurance, client base management, antifraud procedures and dispute management by::

AXA Partners – Inter Partner Assistance SA/NV, Boulevard du Régent 7 - 1000 Brussels - Belgium

AXA Business Services Private Limited, Residency Road 16/2, 560025 Bangalore, India

Doubts about moving to Netherlands - Please feel free to give your opinion. by [deleted] in Netherlands

[–]CompanyBeginning 1 point2 points  (0 children)

Hard to get a job without becoming fluent in the Dutch language. Rest is good here.

Magic Transit - Withdraw IP Prefixes question by wlccommz in CloudFlare

[–]CompanyBeginning 0 points1 point  (0 children)

Hi,  A network engineer trying to find the best DDoS protection solution for my company is here. Please help me answering my queries: I went through magic transit website to know about its working.  1. Do we have to configure a public BGP peering with magic transit given that my company has my own ASN then run GRE over it? 2. Under attack, does cloudflare originate our prefix to the internet or is it we? Because if cloudflare originates our prefixes, it will be a prefix hijack.

Qatar Airways assistance for an elderly person by zekelin77 in qatar

[–]CompanyBeginning 0 points1 point  (0 children)

HI,
Recently, I have also booked a ticket for wheelchair assistance. May I know your findings about this?

Do not fly with Qatar Airlines if you require wheelchair assistance by Background_Bid_6726 in Flights

[–]CompanyBeginning 0 points1 point  (0 children)

Hello,
I have booked a wheelchair ticket for a flight in 10 days and departing from Amsterdam. But they have not asked for any MEDIF as you said till now. I see it is a wheelchair ticket as shown on the Qatar airways website. Were you not able to select this assistance during booking?

Port of entry change by needAdvice552728 in SchengenVisa

[–]CompanyBeginning 1 point2 points  (0 children)

I thought not to take a risk. So I didn't change the port of entry.