20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours

Colin Johnston colinj at gt86car.org.uk
Mon Jul 20 19:18:46 UTC 2015


in war you take information at face value and use it if needed to mitigate risk, if there is legit traffic in blocked ranges then excemption procedure in place to unblock.

colin

Sent from my iPhone

> On 20 Jul 2015, at 19:57, Valdis.Kletnieks at vt.edu wrote:
> 
> On Mon, 20 Jul 2015 19:42:39 +0100, Colin Johnston said:
>> see below for china ranges I believe, ipv4 and ipv6
> 
> You may believe... but are you *sure*?  (Over the years, we've seen
> *lots* of "block China" lists that accidentally block chunks allocated
> to Taiwan or Australia or other Pacific Rim destinations).
> 
> And remember - asking the NIC doesn't help, because there are almost
> certainly blocks allocated that the registration points to Korea or
> someplace, but the provider routes a sub-block to China.  And let's
> not even get started on blocks allocated by ARIN or RIPE....
> 
> (Yes, it *was* a trick question :)
> 



More information about the NANOG mailing list