20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Thu Jul 23 18:45:30 UTC 2015


On Thu, 23 Jul 2015 09:25:33 -0400, "Justin M. Streiner" said:

> If a customer is legitimately trying to reach someone in one of the
> affected IP ranges and failing, at some point, they will either a) give up
> and try later, or b) contact their provider to try to find out what's
> going on.

You missed (c) give up after a few days of retrying and figure the destination
has folded and gone dark, and not bother trying anymore.

It's particularly likely to happen if you haven't given *detailed* instructions
to the people who answer your phones *and* a host they can test from *outside*
your blocking.  If your help desk responds with "It doesn't seem to be up
for me either", outcome (c) is almost guaranteed...

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 848 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20150723/8c43cadb/attachment.sig>


More information about the NANOG mailing list