Did you know that 89% of top-level domains are now signed with DNSSEC? Or that over 88% of .GOV domains and over 50% of .CZ domains are signed? Were you aware that over 103,000 domains use DANE and DNSSEC to provide a higher level of security for email? Or that 80% of clients request DNSSEC signature records in DNS queries? All these facts and much more are available in our new State of DNSSEC Deployment 2016 report. —The Internet Society
The post Worth Reading: The state of DNS security appeared first on 'net work.
CCDE Training Agenda of 2017 If you have any question or comment please don’t hesitate to ask in the comment box below. 2016 & 2017 CCDE TRAINING AGENDA Bootcamp Type […]
The post Orhan Ergun 2017 CCDE Training Agenda appeared first on Cisco Network Design and Architecture | CCDE Bootcamp | orhanergun.net.
In the push toward DevOps, much of focus is on software developers and development, but without equal investments on the operations side, progress slows down. In this episode of Talking DevOps, Josh Atwell, Developer Advocate for NetApp SolidFire, emphasizes the concept of balance and the need for adequate attention on the operations side of the equation.
Like Nasuni and Ctera, the startup is rethinking storage for the hybrid cloud.
While Flowspec has been around for a while (RFC5575 was published in 1999), deployment across AS boundaries has been somewhat slow. The primary concerns in deploying flowspec are the ability to shoot oneself in the foot, particularly as poening Flowspec to customers can also open an entirely new, and not well understood, attack surface, and the simple cost of filtering packets. In theory, ASICs can filter packets based on a variety of parameters cheaply. Theory doesn’t always easily translate to practice, however.
Regardless, recent work in Flowspec is quite interesting; particularly the ability to redirect flows, rather than simply filtering them. Of course, the original RFCs did allow for the redirection of flows into a VRF on the local router, but this leaves a good bit to be desired. To make such a system work, you must actually have a VRF into which to redirect traffic; for one-off situations, such as directing attack traffic to a honey pot, building the VRF and populating it can be more work than capturing the traffic is worth. A newer draft, draft-ietf-idr-flowspec-path-redirect, aims to resolve this.
Before getting to the draft specifics, however, it is useful to review the basic concept of Continue reading
The group will act as a clearinghouse for data that is relevant to the Internet of Things.
Paradox: SD-WAN makes some things simpler, but others more complicated.