Firewall Wizards mailing list archives

Re: egress/ingress filtering


From: Bill_Royds () pch gc ca
Date: Fri, 16 Feb 2001 12:06:00 -0500

The following entries on the 65/8 IP block show that is belongs to the @home
cable modem empire so it seems the 24/8 block is almost used up. Blocking it
becuase it was "reserved" would soon mean that you would block cable modem users
(which might be alright with your security policy though :-)).

point% dig -x 65.0.0.0

; <<>> DiG 8.3 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUERY SECTION:
;;      0.0.0.65.in-addr.arpa, type = ANY, class = IN

;; AUTHORITY SECTION:
0.0.65.in-addr.arpa.    1D IN SOA       nocns.home.net. hostmaster.home.net. (
                                        102071649       ; serial
                                        1H              ; refresh
                                        20M             ; retry
                                        1W              ; expiry
                                        1D )            ; minimum


;; Total query time: 82 msec
;; FROM: point to SERVER: default -- 127.0.0.1
;; WHEN: Fri Feb 16 12:03:33 2001
;; MSG SIZE  sent: 39  rcvd: 119

point% whoNS home.net
The Data in Network Solutions' WHOIS database is provided by Network
Solutions for information purposes, and to assist persons in obtaining
information about or related to a domain name registration record.
Network Solutions does not guarantee its accuracy.  By submitting a
WHOIS query, you agree that you will use this Data only for lawful
purposes and that, under no circumstances will you use this Data to:
(1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail
(spam); or  (2) enable high volume, automated, electronic processes
that apply to Network Solutions (or its systems).  Network Solutions
reserves the right to modify these terms at any time.  By submitting
this query, you agree to abide by this policy.

Registrant:
Home Network (HOME5-DOM)
   425 Broadway St.
   Redwood City, CA 94063  US

   Domain Name: HOME.NET

   Administrative Contact, Technical Contact:
      Kiewlich, Daniel  (DKF336)  abuse () HOME COM
      @Home Network
      425 Broadway St
      Redwood City, CA 94063  US
      650-556-5399 650-556-6666
   Billing Contact:
      Du, Trung  (TD2157)  trung () CORP HOME NET
      @Home Network
      425 Broadway Street
      Redwood City, CA 94063-3126
      650-569-5437 (FAX) 650-569-5100

   Record last updated on 14-Dec-2000.
   Record expires on 19-May-2006.
   Record created on 18-May-1995.
   Database last updated on 15-Feb-2001 20:35:21 EST.

   Domain servers in listed order:

   NS1.HOME.NET                 24.0.0.27
   NS2.HOME.NET                 24.2.0.27




"Crist Clark" <crist.clark () globalstar com> on 02/15/2001 06:34:34 PM
                                                              
                                                              
                                                              
 To:      "Irwin R. Naumann" <irwin () thinkage ca>              
                                                              
 cc:      firewall-wizards () nfr com(bcc: Bill                  
          Royds/HullOttawa/PCH/CA)                            
                                                              
                                                              
                                                              
 Subject: Re: [fw-wiz] egress/ingress filtering               
                                                              





Because "Reserved" does not mean what you think in all cases. For
example, Ms. Irwin put up a list of "reserved" IP addresses at the
conference. For the conference, she had had to submit her slides
months in advance. I noticed that some of the "reserved" blocks
she mentioned, IIRC 65/8 is an example, were no longer reserved.
In the time since she had completed her slides, that block had
been assigned. In fact, CERT/CC,

  http://www.cert.org/tech_tips/whois_by_ipaddr.html

Has not kept all of their docs up to date. Note the differences
between it and the ISI URL you give above.





_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: