deploy SIDR

google again dropped out of the internet because of failure to filter prefixes. SIDR configuration on Cisco gear is really simple - for IOS-XE, IOS-XR. if you have Juniper it takes like half a second of searching. of course configuring is one thing, visiting RIPE and cerfifying your own resources is another thing. then it’s all done. every prefix signed, and every autonomous system checking for certification data is helping. every single one.

March 15, 2015 · Łukasz Bromirski

christmas cleaning part 2

i’m just finishing upgrading my different servers from FreeBSD 9 to FreeBSD 10.1-STABLE. …and i just realized, that my FreeBSD adventure started around 4.1 (well, i may have got older 3.4 CDs, but didn’t install it then yet). and it was 14 years ago today. it was just after i, like thousands of linux users around the world, tried to upgrade glibc libs on the fly on my beloved (at that time and today) Slackware installation. ...

December 28, 2014 · Łukasz Bromirski

christmas cleaning part 1

it seems that F-35 can’t end it’s failure series. despite GAO audits, model of building military equipment for biggest army in the world didn’t change a bit since end of second world war. they’re still ordering and building things that will bring maximum revenue to military vendors and not what military customers actually need. i immediately got back to one of the articles i’ve read recently in ACM Queue - responsive enterprise: embracing the hacker way. it’s great piece and synthezies todays world - not only corporations are dinosaurs of our current times. a big portion of industry is. on normal market, companies that can adapt or use feedback loop tu build better and better products thrive. and those, who need years and still are not able to produce competitive products should vanish in history books. ...

December 27, 2014 · Łukasz Bromirski

canvas fingerprinting... and unbound

some time ago I changed my BIND at home to Unbound, due to the change of the default DNS server in FreeBSD (yes, I do have my own DNS server at home, and it serves all local queries). actually, I have four right now ;) back in BIND times, i used a lot of scripts to add zones containing 127.0.0.1 for domains serving ads. after switching to Unbound - i forgot about it completely. ...

July 24, 2014 · Łukasz Bromirski

standards...

…or who needs them anyway today? there’s interesting article written down by one of Google employees, that perfectly describes how ineffective today standard bodies are, and how less and less influence they have on the market. cisco decided to spearhead new solutions without waiting for multi-year discussions, true to the ‘good description and working code’ motto. if we wouldn’t be doing that, there would be no PVLANs, FabricPath (TRILL) but also protocols like LDP or HSRP/VRRP/GLBP. ...

May 22, 2014 · Łukasz Bromirski

ASA 9.2(1)

…supports BGP and it’s already out. do you like BGP on your firewalls? i don’t. should we have the tool in hand, just in case? well, sometimes it’s handy. but going back again - do you like BGP on your firewalls? ;)

April 27, 2014 · Łukasz Bromirski

ipv6... once again in bad spotlight

all memory and CPU related features in IPv6 world is major challenge even for modern hardware. unfortunately this is emphasized with lack of best practices followed by developers writing code. i just noticed there’s Microsoft Windows problem with IPv6 RA. it seems that actual problem is not limited only to RA, but actually - to the whole networking stack when working with link-local addresses. under Microsoft Windows code is allocating memory pretty recklessly. ...

April 1, 2014 · Łukasz Bromirski

first new year resolution

don’t start your php upgrade at 2:40 in the morning. as you’ll stay awake until 5am :)

December 29, 2013 · Łukasz Bromirski

it's time for GPU in SDN

it seems that GPUs can be reasonably well tasked to handle additional work that x86 CPUs simply can’t. i’m talking about network monitoring and NetFlow processing - good reading when travelling or before sleep.

December 22, 2013 · Łukasz Bromirski

there's nothing interesting in TV...

…so I decided to use youtube to find my favorite Monty Python series, Program will resume soon (quite specific Polish series - BTW, never published on DVD!). i was also able to find archive of our old polish IT magazines - Bajtek, Top Secret and Secret Service. my own archive, collected over years and protected from everyone fell prey one day to suprise ‘cleaning’ organized in the basement where it was stored. i’m still looking for Gambler and Komputer magazines. i strongly believe that there’s no comparision between those articles and magazines that you’ve read from first to last page and todays worthless ‘magazines’ that compete with number of colorful photos and zero interesting content. ...

November 3, 2013 · Łukasz Bromirski