nanog mailing list archives
Re: Nachi/Welchia Aftermath
From: haesu () towardex com
Date: Tue, 20 Jan 2004 19:36:16 -0500
yes in concur.. prefix based ones (like FIB) are fine. unfortunately some models from some vendors (tisk tisk) who use slow process path to reprogram the CAM per flow can be quite painful during situations like random dest. dos attacks and worms.. add the E vendor to your list too.. we had summit48i that loved the worm traffic -J On Tue, Jan 20, 2004 at 10:16:03PM -0200, Rubens Kuhl Jr. wrote:
Not all L3-switches are flow-based; prefix-based ones should do just fine. Can people add/correct this initial list ? Flow-based: Foundry with IronCore modules, Cisco Catalyst 6500 with Sup1(A) Prefix-based: Foundry with JetCore modules, Cisco Catalyst 6500/7600 with Sup2(A), Sup3(A/BXL) Rubens ----- Original Message ----- From: <haesu () towardex com> To: "Brent Van Dussen" <vandusb () attens com> Cc: "NANOG" <nanog () merit edu> Sent: Tuesday, January 20, 2004 9:46 PM Subject: Re: Nachi/Welchia Aftermathlesson learned: stop using /makeshift/ layer3 switches (without naming vendor) to run L3 core -J On Tue, Jan 20, 2004 at 02:22:52PM -0800, Brent Van Dussen wrote:Well folks, since the middle of August I've been tracking the spread and subsequent efforts by our community to stop the nachia/welchia infection that took down so many networks. Sadly, by my estimations, only about 20-30% of infected hosts were cleaned. After Jan 1, 2004 it appears that the thousands, (millions?)ofremaining infected hosts were rebooted and the worm removed itself. Network traffic has finally returned to normal. What kind of effects did everyone see from this devastating worm andwhatlessons did we learn for preventing network downtime in the future?-- James Jun (formerly Haesu) TowardEX Technologies, Inc. 1740 Massachusetts Ave. Boxborough, MA 01719 Consulting, IPv4 & IPv6 colocation, web hosting, network design &implementationhttp://www.towardex.com | james () towardex com Cell: (978)394-2867 | Office: (978)263-3399 Ext. 170 Fax: (978)263-0033 | AIM: GigabitEthernet0 NOC: http://www.twdx.net | POC: HAESU-ARIN, HDJ1-6BONE
-- James Jun (formerly Haesu) TowardEX Technologies, Inc. 1740 Massachusetts Ave. Boxborough, MA 01719 Consulting, IPv4 & IPv6 colocation, web hosting, network design & implementation http://www.towardex.com | james () towardex com Cell: (978)394-2867 | Office: (978)263-3399 Ext. 170 Fax: (978)263-0033 | AIM: GigabitEthernet0 NOC: http://www.twdx.net | POC: HAESU-ARIN, HDJ1-6BONE
Current thread:
- Nachi/Welchia Aftermath Brent Van Dussen (Jan 20)
- Re: Nachi/Welchia Aftermath james (Jan 20)
- Re: Nachi/Welchia Aftermath Scott Weeks (Jan 20)
- Re: Nachi/Welchia Aftermath Scott Weeks (Jan 20)
- Re: Nachi/Welchia Aftermath haesu (Jan 20)
- Re: Nachi/Welchia Aftermath Rubens Kuhl Jr. (Jan 20)
- Re: Nachi/Welchia Aftermath haesu (Jan 20)
- Re: Nachi/Welchia Aftermath Paul Vixie (Jan 20)
- Re: Nachi/Welchia Aftermath haesu (Jan 21)
- Re: Nachi/Welchia Aftermath Richard A Steenbergen (Jan 21)
- Re: Nachi/Welchia Aftermath Paul Vixie (Jan 21)
- Re: Nachi/Welchia Aftermath haesu (Jan 21)
- Re: Nachi/Welchia Aftermath Rubens Kuhl Jr. (Jan 20)
- Re: Nachi/Welchia Aftermath Donovan Hill (Jan 20)
- Re: Nachi/Welchia Aftermath Rubens Kuhl Jr. (Jan 20)
- Re: Nachi/Welchia Aftermath Stephen J. Wilcox (Jan 20)
- Re: Nachi/Welchia Aftermath Mikael Abrahamsson (Jan 21)
- Re: Nachi/Welchia Aftermath Donovan Hill (Jan 21)