3 ms·
Yawn. Non-telco(*1) Tier 1 provider declines to carry routes for an entity they don't like. Happens all the time. This is why you buy from a Tier 2 instead and
by jauer 3y ago
Yawn. Non-telco(*1) Tier 1 provider declines to carry routes for an entity they don't like. Happens all the time. This is why you buy from a Tier 2 instead and bypass DFZ(*2) politics.
Drop routes from spammers: Spamhaus DROP list.
Drop routes from DDoS sources? All the time.
Even Google wasn't reachable from Cogent over IPv6 for years because of a business dispute.
For all we know someone working at HE was targeted by KF and this is a security response (also generally allowed even if you are a regulated provider).
*1: Cogent & HE thread the needle around being a common carrier (they don't sell voice or TDM service) or a broadband provider, which is why KF's WA state complaint will fail (WA's law only applies to mass-market retail providers, which HE is not).
*2: Tier 1 does not mean "best carrier" it means "carrier that doesn't pay another carrier for routes." DFZ literally means default-free zone as in they don't have a default route to another provider.
- mid-kid 3y ago> Happens all the time. As this is the first time I hear of this, I'm curious. Do you have any examples?
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- 542458 3y agoThe comment you’re replying to lists several examples already, like the use of the Spamhaus DROP list. https://www.spamhaus.org/drop/ https://www.spamhaus.org/drop/
- huggingmouth 3y agoWhat tier-1 provider is irresponsible enough to use this?
- 542458 3y agoSpamhaus is huge. A listed IP will see email bounce rates exceeding 50%, easily. Most large North American ISPs use at least one Spamhaus list. Tier-1s don’t generally advertise which blocklists they use, but the 2010-ish “Stophaus” DDoS attacks went after a number of Tier-1 operators.
- ehhthing 3y agoI'm not entirely sure about this but I believe that HE may have been null routing rather than just dropping routes.
- tortue0 3y agoDidn't someone actually get the configs that showed it was a bgp prefix filter denying accepting the bgp announcement from a customer? Isn't that a far cry from null routing? They're just choosing not to learn it from a customer. And if you buy the "HE is a tier 1" then whatever other peers were announcing the prefix would have been accepted by HE.