Archive for March, 2008

IPv6 Talks at Amazon

Tom Killalea had invited me to speak on IPv6 at Amazon. Due to ferry silliness, I could not make it for lunch, but got there at 12:30 for a 13:00 talk. There were a lot of folk a fairly large conference room, with a couple of dozen having to stand. I did a version of the IPv6 Operational Reality talk and threw in a modified version of my slides from the IP Addressing and Economics conference earlier in the week. It was interesting to have an audience of geeks from my home culture, they got the humor. They seemed actually interested, and some were toying with how to deploy IPv6 in various parts of Amazon. I managed to finish in exactly one hour, gossiped a bit with Tom, and headed for my car.

Comments off

Signing the IRR, a Contrary View

Robert Kisteleki proposed to use the RPKI to sign most of the IRR. I took the opposite view in the following rough proposal. Geoff Huston and I will be writing up my design in the next week.

Date: Mon, 03 Mar 2008 21:53:30 -0800
From: Randy Bush <randy@psg.com>
To: Robert Kisteleki <robert@ripe.net>
Cc: Resource Cert List <rescert@apnic.net>
Subject: Re: [Rescert] RPSL+RPKI proposals

robert,

i take a somewhat different view.

though i was hacking before ed codd, my mommy trained me to be
extremely wary when the same information is in two places.

but more important, i have a slightly different goal set.  i would ask
what we need to do in order to make the rpki helpful to isps in the
current task of configuring routing filters, but with more assurance of
correctness?

for this we do not need signed route: objects in the irr, as we have
roas and merely need to invert them, just as we do in the irr software,
to form the set of prefixes which each asn _may_ announce.

what we do not have in the rpki, which is in the irr, is the inter-asn
topology.  while josh and jrex would gather it from route-views or ris,
i am willing to stick one toe in the irr cesspool and sign the aut-num:,
probably in a fashion similar to the one you suggest.

but doing more is producing redundant data, transferring trust to a weak
sibling whose long-term survival is not required, and trying to make a
sow's ear into a silk purse when we are not in the silk purse business
anyway.

when we have s-bgp (or whatever), the irr will be completely IRRelevant
<tm>.  i see no need to try to touch it any more than we absolutely
needed to now.

randy

Comments off

Cisco Address/Economics Conference

My presentation today at the Cisco IP-Economics Conference.

Comments off

FBI Report on Cisco Clones

Here is an interesting FBI report on Cisco clones which they consider to be dangerous.

Comments off