Category: Network

Post dealing with changes to how we route packets and configure our network.

DNS Changes

Our team has moved all but our v6 edge router over to using one of our DNS servers at
dns.fenfox.run and as far as we can tell, everything is running as it should and the move was
transparent without any hiccups. The means all of our project members and end users will
now have access to both ICANN and OpenNIC domains.

Marbled Fennec Networks is currently working on testing out our own pair of DNS servers
for servicing the network. So far things look like they are running well and response times are fair.
If the testing continues to work as expected, we are considering switching all routers over to using
the servers “dns.fenfox.run” and “dns2.fenfox.run” as their upstream DNS.

These changes, if they happen (won’t know for another few hours), should be completely transparent
to our project members and end users.

NMP has been updated!

Our “Network Management Policy” has been updated to reflect some changes
that had to be put in place regarding the operation of our two public DNS
servers. Project members and end users who make use of the public DNS servers
should take a quick glance over the policy and make note of the changes.

In short, Marbled Fennec Networks will react to sudden increases in DNS traffic
and, where warranted, will block the resolution of queries headed for what is
known as “Command and Control” servers when it comes to suspected malware.
Our team will do their best to research the domains behind the traffic spikes
before applying any network rules.

Progress on Updates…

Our network fennec found a few issues in our network stack that need to be resolved. One router ran out of space because debugging was left enabled and another because ntopNG hadn’t been cleared out recently. Some old rules were found from old tenants and SSL certs had expired. I guess things happen when you take a month off from upkeep.

Our team is working to resolve these issues and restore performance back to Ikus and CX routers. So far, the old firewall rules have been removed, a ton of logging data was chunked out and most SSL certs have been brought up to date.