<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>King of the Potato People &#187; Geek</title>
	<atom:link href="http://www.potato-people.com/blog/category/geek/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.potato-people.com/blog</link>
	<description>Code, photos and ramblings of Rick Hodger</description>
	<lastBuildDate>Fri, 23 Jul 2010 10:03:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>IPv6 Subnetting &#8211; You and your customer</title>
		<link>http://www.potato-people.com/blog/2010/07/ipv6-subnetting-you-and-your-customer/</link>
		<comments>http://www.potato-people.com/blog/2010/07/ipv6-subnetting-you-and-your-customer/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 10:03:33 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[broadband]]></category>
		<category><![CDATA[ip address]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[math]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=108</guid>
		<description><![CDATA[There&#8217;s this great debate in the IPv6 world about how to chop up your allocation into assignments for your customers. Typically, most ISPs are being handed a /32, and general guidelines say to allow for a /48 per DSL/leased line/cable customer. However a lot of people are asking, why not a /64?  Quoted below is [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s this great debate in the IPv6 world about how to chop up your allocation into assignments for your customers. Typically, most ISPs are being handed a /32, and general guidelines say to allow for a /48 per DSL/leased line/cable customer.</p>
<p>However a lot of people are asking, why not a /64?  Quoted below is the sort of answer you&#8217;re likely to receive on NANOG, by one Mark Smith:</p>
<blockquote><p>There are a variety of scenarios where customers, including residential, will benefit from having multiple subnets. They may wish to separate the wired and wireless segments, to prevent multicast IPTV from degrading wireless performance. They may wish to segregate the children/family PC from the adult PC network or SOHO network, allowing the subnet boundary to be an additional Internet access policy enforcement point. They&#8217;ll need separate subnets if they wish to use a different link layer technology, such as LoWPAN. They may wish to setup a separate subnet to act as a DMZ for Internet facing devices, such as a local web server for sharing photos with relatives. Game consoles may be put in a separate subnet to ensure file transfers don&#8217;t interfere with game traffic latency, using the subnet ID as a QoS classifier.</p></blockquote>
<p>This answer is quite simply unrealistic. It&#8217;s the answer of a typical geek with no sense of perspective as to what the average consumer wants<em>.</em> It&#8217;s the opinion of what Mark Smith the network engineer and geek would want.</p>
<p>In the real world, most consumers of domestic internet services have absolutely no concept of IP addresses let alone subnetting, VLANs, segregation or quality of service. Most domestic networks are a single flat subnet with NAT to a single IP address and no servers that would require port forwarding, and rarely an IPTV system, but those are usually setup to use special triple-play routers configured by the ISP. <strong>Most domestic users just want to be able to plug stuff in and have it work. </strong></p>
<p>Now, people will argue that there are more IPv6 addresses than there are atoms in the world. However that argument isn&#8217;t as good when you are assigning 1,208,925,819,614,629,500,000,000 IP addresses for just 2 or 3 devices. It&#8217;s a grossly inefficient waste no matter what you say. Not to mention that if you&#8217;re one of the big cable or DSL providers with millions of customers, it makes much more sense. Each barely used /48 that you throw out contains 256 /64&#8242;s.</p>
<p>As such, I personally am inclined to go for the default of a /64 per  customer, but allow for a /48 should they need it. There is absolutely  no point in issuing a /48 subnet to someone who is never ever going to  use it&#8230; it&#8217;s just laziness, which is what got us into the current situation with IPv4 in the first place.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2010/07/ipv6-subnetting-you-and-your-customer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nvidia Fail</title>
		<link>http://www.potato-people.com/blog/2010/07/nvidia-fail/</link>
		<comments>http://www.potato-people.com/blog/2010/07/nvidia-fail/#comments</comments>
		<pubDate>Fri, 09 Jul 2010 18:00:17 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[8800gts]]></category>
		<category><![CDATA[8800gts 512]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[geforce]]></category>
		<category><![CDATA[nvidia]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=99</guid>
		<description><![CDATA[If you have a system built with the still quite good Nvidia GeForce 8800GTS graphics card, and decide to upgrade by adding a second one and running SLI, beware the Nvidia Fail. Nvidia in their wisdom made an upgraded version of the card called the 8800GTS 512. It is not SLI compatible with the original [...]]]></description>
			<content:encoded><![CDATA[<p>If you have a system built with the still quite good Nvidia GeForce 8800GTS graphics card, and decide to upgrade by adding a second one and running SLI, beware the Nvidia Fail.</p>
<p>Nvidia in their wisdom made an upgraded version of the card called the 8800GTS 512. It is not SLI compatible with the original 8800GTS, and the odds are you won&#8217;t know it until you&#8217;ve bought one and spent an afternoon wondering why SLI won&#8217;t work.</p>
<p>God damn you Nvidia.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2010/07/nvidia-fail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BT Fail :: Part 2</title>
		<link>http://www.potato-people.com/blog/2010/01/bt-fail-part-2/</link>
		<comments>http://www.potato-people.com/blog/2010/01/bt-fail-part-2/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 16:18:20 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[adsl]]></category>
		<category><![CDATA[broadband]]></category>
		<category><![CDATA[bt wholesale]]></category>
		<category><![CDATA[fail]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=90</guid>
		<description><![CDATA[A new level of fail from our friends at BT Wholesale. They have actually willingly provided proof that they do not read fault reports the first time around: Yes.. that is a grand total of 43 seconds from reporting the fault to BT Wholesale rejecting it. This was even reported via KBD, which lets you [...]]]></description>
			<content:encoded><![CDATA[<p>A new level of fail from our friends at BT Wholesale. They have actually willingly provided proof that they do not read fault reports the first time around:</p>
<p><a href="http://www.potato-people.com/blog/wp-content/uploads/2010/01/btfail21.png"><img class="aligncenter size-full wp-image-92" title="btfail2" src="http://www.potato-people.com/blog/wp-content/uploads/2010/01/btfail21.png" alt="" width="571" height="276" /></a></p>
<p>Yes.. that is a grand total of 43 seconds from reporting the fault to BT Wholesale rejecting it. This was even reported via KBD, which lets you confirm that the user has already attempted to replace his router, cables, filters and even tried from the test socket. 43 seconds is not enough time for most people to type that long-winded reply about SFI appointments, let alone for BT to run the necessary diagnostics to determine if there is a fault or not.</p>
<p>At my place of work we have suspected that BT was doing this for a long time as all too often, and 9 times out of 10 blatently obvious faults are rejected with the message &#8220;not due to a network fault&#8221;. Now I have a handful of faults, some where it was customer some, but some where there was genuine faults such as the DSLAM being faulty where BT has denied anything being wrong and cleared the fault in less than a minute.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2010/01/bt-fail-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yet Another Ignorant &#8216;Your ISP is screwing you&#8217; article</title>
		<link>http://www.potato-people.com/blog/2009/11/yet-another-ignorant-your-isp-is-screwing-you-article/</link>
		<comments>http://www.potato-people.com/blog/2009/11/yet-another-ignorant-your-isp-is-screwing-you-article/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 10:09:03 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[ignorance]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=82</guid>
		<description><![CDATA[I hate these articles. They&#8217;re always written from the perspective of a consumer who knows some of the buzzwords but doesn&#8217;t actually bother to take the time to understand any of it or the technology. Bandwidth Throttling One oft-protested behavior of various ISP’s is the throttling &#8211; that is, limiting &#8211; of bandwith at certain [...]]]></description>
			<content:encoded><![CDATA[<p>I hate <a href="http://www.billshrink.com/blog/9-ways-isps-screw-you/" target="_blank">these articles</a>. They&#8217;re <em>always</em> written from the perspective of a consumer who knows some of the buzzwords but doesn&#8217;t actually bother to take the time to understand any of it or the technology.</p>
<p><strong>Bandwidth Throttling</strong></p>
<blockquote><p>One oft-protested behavior of various ISP’s is the throttling &#8211; that is, limiting &#8211; of bandwith at certain times or for certain uses.</p></blockquote>
<p>Yes, some ISPs shape the bandwidth supplied to the customer. There&#8217;s good reason for this however. Residential broadband connections are <strong>contended</strong> services. That means that you share that bandwidth along with a number of other people. In the UK, the standard contention ratio for residential users is 50:1. If bandwidth is not shaped, then just one customer abusing Bittorrent to download pirate movies or games or music can use up all the bandwidth of 50, leaving those other customers shit out of luck. You&#8217;ll also note that the only people who ever complain about shaping are those pirating content.</p>
<p>Imagine that the bandwidth is a 3 lane motorway. If everyone behaves, we can all drive down the motorway at reasonable speeds, occasionally going faster where possible. However, if one driver in an articulated lorry starts swerving all over the road, everyone else has to slow down and be late. Bandwidth shaping is done to preserve the use of the road for everyone.</p>
<p><strong>Deceptive Speed Claims</strong></p>
<blockquote><p>Examine the fine print on most ISP commercials, and you will likely find that the promised Internet speed (say, 10MBPS) has the words “up to” in front of it. As it turns out, this is often a clever means of dodging the truth about the actual speeds you are likely to receive.</p></blockquote>
<p>Again, the service is contended. If you have an 8Mb 50:1 service, you are sharing that 8Mb with potentially up to 50 other people. There&#8217;s also the technology involved; ADSL is distance limited so the further away from the telephone exchange you are the lower it will connect at. &#8220;Upto 8Mb&#8221; covers all of this in two words. You get what you pay for and at £20-25 a month, no ISP could guarantee what this writer is demanding. Let me break it down:</p>
<ol>
<li>ADSL line, up to 8Mb 50:1 &#8211; £11.90/month</li>
<li>Link to ADSL network to cover a single user on 8Mb 50:1 &#8211; £1400/month</li>
<li>8Mb bandwidth &#8211; £176.00/month</li>
<li>Upstream circuit links &#8211; 2x£2,500/month</li>
</ol>
<p>Never mind the infrastructure required to deliver such a service, servers for providing DNS and email, datacentre space, cooling and electricity and so on &#8211; but to give you your 8Mb ADSL without it being shared with anyone would cost somewhere in the region of £6,500 per month to have their own dedicated ISP not shared with anyone else. <strong>NOT </strong>£25. It&#8217;s only by sharing infrastrucure and bandwidth with other customers that cheap broadband actually becomes economical. If you want a dedicated guaranteed 8Mb circuit, feel free to go talk to your ISP &#8211; they&#8217;ll quote you a figure probably somewhere between £10,000 to £12,000 a year, plus probably a £15,000 install.</p>
<p><strong>Targeted Advertising</strong></p>
<blockquote><p>Increasingly, some of the most passionate complaints against ISPs have involved privacy concerns. A case in point is Charter’s decision in 2008 to begin tracking its users’ search behavior and using them to insert ads into their results.</p></blockquote>
<p>Never mind that the example screenshot given is from Google, highlighting Google&#8217;s own advertising which has absoloutely nothing to do with whatever ISP you are using to connect with; the article in question successfully gives a single example of a single large ISP abusing the Phorm advertising system. As far as I am aware the only other ISP to consider using this system is BT in the UK, and they were smacked down for being in breach of privacy laws.</p>
<p>This is tarring all ISPs with the same brush for the sake of a one or two bad apples.</p>
<p><strong>ISP Wiretapping</strong></p>
<blockquote><p>2007’s Communications Assistance for Law Enforcement Act mandated that all ISPs enable the feds to “wiretap” Internet transmissions in much the same way they do phone calls.</p></blockquote>
<p>Note the word &#8220;mandated&#8221;. That&#8217;s not your ISP screwing you over &#8211; that&#8217;s your government. Most ISPs have this capability anyway in order to comply with court orders or police investigations. Do you really want to be responsible for some 3 year old getting raped by a pedophile because it was made illegal for ISPs to help catch sick fucks just so you could download your pirate movies without having to worry that someone <em>might</em> be watching you because the police told them to?</p>
<p><strong>Ad-Filled &#8220;Website Not Found&#8221; Pages</strong></p>
<blockquote><p>Always on the lookout for new sources of revenue (however small), some ISPs have taken to displaying ads in their error pages.</p></blockquote>
<p>Some ISPs do this, however the good ones will give you a source of opting out, and as this is usually DNS based if you don&#8217;t like it you can always either setup your own DNS server or use <a href="http://www.opendns.com/" target="_blank">OpenDNS</a>.</p>
<p><strong>Deep Packet Inspection</strong></p>
<blockquote><p>Another serious gripe privacy advocates have with ISPs is what is known as “deep packet inspection.”</p></blockquote>
<p>That would because privacy advocates don&#8217;t actually understand DPI, which looks for patterns in order to recognize traffic types. The actual content cannot usually be observed, but it can also log when someone is for example, using Bittorrent. These boxes are usually used to packet shape your traffic (see &#8220;bandwidth throttling&#8221; above), but are also extraordinarily expensive &#8211; usually only affordable by quite large ISPs. But wait! There&#8217;s more&#8230;</p>
<blockquote><p>However, it is also been used by ISPs to police copyright infringement by detecting when someone is or may be downloading songs or movies &#8211; and some ISPs go a step further by turning this information over to inquiring record labels.</p></blockquote>
<p>And so we get to the real crux of the issue that the author has with DPI &#8211; pirating movies and music! Of course, if you&#8217;re not doing anything illegal then DPI really isn&#8217;t something you have to worry about. Damn you pesky ISPs! Conforming with the letter of the law and trying to prevent yourselves from being used to commit illegal activties! Grr and much fist-shaking and so on.</p>
<p><strong>Packet Spoofing/Forgery</strong></p>
<blockquote><p>Comcast engaged in what is known as “packet spoofing” (or packet forgery) by interrupting file transfers with bogus packets that killed any P2P downloads a user happened to be engaging in.</p></blockquote>
<p>One ISP does something that contravenes the way that TCP/IP is supposed to work and we all get tarred with the same brush again. I can assure you that few if any ISPs that have any sort of technical savvy would even consider doing this. Comcast are the only ISP known to have deployed this system as it far too heavy handed &#8211; affecting both legitimate and illegitimate traffic. It also opens the ISP up to a certain amount of liability for having demonstrated that they can block certain traffic types, for then not blocking other traffic types such as viruses or spam, which happily leads me to the next point in this ignorant article.</p>
<p><strong>Inadequate Virus/Spyware Protection</strong></p>
<blockquote><p>ISP’s have also come under fire for charging high subscriber fees without adequately protecting consumers from spyware, viruses and other forms of online fraud.</p></blockquote>
<p>As I think I&#8217;ve already demonstrated, most ISPs are not charging &#8220;high subscriber fees&#8221;, and in one sentence the author of this article has demonstrated his complete ignorance of any of the previously mentioned technologies. If you want your ISP to prevent you from idiotically downloading a virus and running it, they have to install what is known as an IDP, or Intrusion-Detection-Prevention device. What is an IDP? Basically, it&#8217;s a Deep-Packet Inspection device configured to look for viruses, trojans, spyware and known hacks. It would then have to use Packet Spoofing to block your attempt to download that virus. So the author wants us to protect him from viruses without actually using any of the known technologies to do so. Does he want us to send someone around to his house to operate his computer for him or what?</p>
<blockquote><p>Generally speaking, service agreements between you and your ISP indemnify them from responsibility for any damage or losses caused by spyware or viruses you get infected with on their network.</p></blockquote>
<p>&#8230;because we all know that it&#8217;s the pesky ISP <em>forcing</em> viruses and spyware onto your computer. Out in reality-world (as opposed to this crack-smoking monkey of an author&#8217;s fantasy world), 9 times out of 10 virus and spyware infections are because the user actively downloaded that cute new screensaver of the puppies doing barrel rolls and installed it, and that screensaver was actually a shell for a massive spyware infection. Or the user received an email from King Mambatu who wanted his help to move $9,843,699 dollars out of the Bank of Nambia and needed him to open this harmless attachment to get the process started. Yup, all the ISPs fault that is. This couldn&#8217;t possibly be the reason why ISPs have had to indemnify themselves against protecting you from viruses and spyware because a certain section of society wouldn&#8217;t sue them into oblivion with frivolous lawsuits over their own stupidity or that when they do offer antivirus or antispam services on email, that the technology cannot guarantee that it will catch everything.</p>
<p><strong>Sneaky Fees</strong></p>
<blockquote><p><a href="http://www.msnbc.msn.com/id/22342063/">MSNBC</a> reports on a telling example back in 2006, when a a $2-$3 per month federal tax on DSL users was taken off the books. But rather than lowering its subscriber fees by $2-$3, Verizon thought better of it and kept fees the same by adding a “supplier surcharge” fee.</p></blockquote>
<p>It&#8217;s hardly a sneaky fee if it&#8217;s listed on the bill. It might be sneaky for the muppets who don&#8217;t bother to read their bills, which is rather disturbing seeing as this is written by someone calling himself &#8220;Bill Shrink Guy&#8221;.</p>
<p>I won&#8217;t deny that doing such a thing isn&#8217;t disreputable, but the real issue here is to make sure you read <em>all</em> your bills and ensure you understand what you&#8217;re paying for. If your gas supplier suddenly adds a &#8220;Boiler Maintenance&#8221; surcharge to your bill and you pay it without question, you&#8217;re an idiot.</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">
<blockquote>
<h2>Bandwidth Throttling</h2>
</blockquote>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2009/11/yet-another-ignorant-your-isp-is-screwing-you-article/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>IPsec VPNs for Mikrotik RouterOS</title>
		<link>http://www.potato-people.com/blog/2009/10/ipsec-vpns-for-mikrotik-routeros/</link>
		<comments>http://www.potato-people.com/blog/2009/10/ipsec-vpns-for-mikrotik-routeros/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 11:08:31 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[Mikrotik]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[routerboard]]></category>
		<category><![CDATA[routeros]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[zywall]]></category>
		<category><![CDATA[ZyXEL]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=70</guid>
		<description><![CDATA[It&#8217;s unfortunate that the Mikrotik RouterOS manual on IPsec is not great &#8211; it&#8217;s sorely lacking in details  and good examples, and what examples it does have are not well explained. Recently I had to setup several Mikrotik RouterOS to ZyXEL VPNs and through I would document how it&#8217;s done. First, a quick diagram to [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s unfortunate that the Mikrotik RouterOS manual on IPsec is not great &#8211; it&#8217;s sorely lacking in details  and good examples, and what examples it does have are not well explained.</p>
<p>Recently I had to setup several Mikrotik RouterOS to ZyXEL VPNs and through I would document how it&#8217;s done.</p>
<p><span id="more-70"></span></p>
<p>First, a quick diagram to explain the setup we&#8217;re going to cover. Just imagine that the 10.0.0.0/24 network in the middle is in fact the internet.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-72" title="diagram" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/diagram1.png" alt="diagram" width="650" height="132" /></p>
<p>We&#8217;ll configure the ZyXEL&#8217;s &#8220;public&#8221; address as 10.0.0.1 and the RB&#8217;s as 10.0.0.2.</p>
<p>First, the ZyXEL. It&#8217;s an older ZyXEL 652H, but the same settings apply to almost all of the VPN enabled ZyXEL devices. Create the VPN as you normally would on the ZyXEL, ensuring to use subnet&#8217;s for your local and remote networks, as well the IP addressess of the ZyXEL and Mikrotik for the Peer IDs:</p>
<p style="text-align: center;"><a href="http://www.potato-people.com/blog/wp-content/uploads/2009/10/zyxel_vpn1.png"><img class="aligncenter size-full wp-image-73" title="zyxel_vpn1" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/zyxel_vpn1.png" alt="zyxel_vpn1" width="370" height="505" /></a></p>
<p style="text-align: left;">And under advanced:<a href="http://www.potato-people.com/blog/wp-content/uploads/2009/10/zyxel_vpn2.png"><img class="aligncenter size-full wp-image-74" title="zyxel_vpn2" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/zyxel_vpn2.png" alt="zyxel_vpn2" width="375" height="376" /></a></p>
<p style="text-align: left;">Now, on RouterOS we start by configuring the policy for this VPN. This is the equivelent of the first page of the ZyXEL configuration. Open the IP-&gt;IPsec window in WinBox, and create a new policy as follows:</p>
<p style="text-align: center;"><img class="size-full wp-image-75   aligncenter" title="ros_policy1" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/ros_policy1.png" alt="ros_policy1" width="313" height="295" /><img class="size-full wp-image-77 aligncenter" title="ros_policy2" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/ros_policy21.png" alt="ros_policy2" width="313" height="295" /></p>
<p style="text-align: left;">Next, switch to the &#8220;Peers&#8221; tab and create a new peer, using the public address of the ZyXEL as the address:</p>
<p style="text-align: left;"><img class="aligncenter size-full wp-image-78" title="ros_peer" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/ros_peer.png" alt="ros_peer" width="577" height="537" /></p>
<p style="text-align: left;">There&#8217;s a few confusing extras here that don&#8217;t appear on the ZyXEL.</p>
<ul>
<li>Proposal Check &#8211; Determines how proposed lifetimes are handled. Setting this to &#8220;Obey&#8221; is the most flexible as it will make RouterOS conform to whatever the remote site proposes.</li>
<li>DH Group &#8211; Mikrotik use the actual algorithm names as opposed to the normal &#8220;DH1&#8243; or &#8220;DH2&#8243;. The table below shows the mapping between these:<br />
<table border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>Diffie-Hellman Group</td>
<td>Name</td>
<td>Reference</td>
</tr>
<tr>
<td>Group 1</td>
<td>768 bit MODP group</td>
<td>RFC2409</td>
</tr>
<tr>
<td>Group 2</td>
<td>1024 bits MODP group</td>
<td>RFC2409</td>
</tr>
<tr>
<td>Group 3</td>
<td>EC2N group on GP(2^155)</td>
<td>RFC2409</td>
</tr>
<tr>
<td>Group 4</td>
<td>EC2N group on GP(2^185)</td>
<td>RFC2409</td>
</tr>
<tr>
<td>Group 5</td>
<td>1536 bits MODP group</td>
<td>RFC3526</td>
</tr>
</tbody>
</table>
<p>Note: I was not able to get group 2 to work. It results in a proposal mis-match error.</li>
<li>Generate Policy &#8211; Appears to dynamically generate the policies depending on what details have been supplied by the remote side. May be of use for dynamic VPNs.</li>
<li>Lifebytes &#8211; Session will be reconnected after X bytes have been encrypted. Best to leave this alone.</li>
<li>DPD &#8211; Mikrotik do not offer any explanation for this, other than that experiments on the official forums seem to confirm that it only appears works with other RouterOS devices.  <a href="http://www.juniper.net/techpubs/software/erx/junose61/swconfig-routing-vol1/html/ipsec-config4.html">Juniper&#8217;s documentation</a> explains that it stands for &#8220;Dead Peer Detection&#8221;.</li>
</ul>
<p>There&#8217;s one last step after this. In RouterOS, NAT is performed <em>before</em> IPsec takes place. This means that any general masquerade or 1:1 NAT rules will take place before the VPN is reached, and the now NAT&#8217;d addresses will not be directed across the VPN. To avoid this we need to add a NAT rule at the very top of the table:</p>
<p><img class="aligncenter size-full wp-image-79" title="ros_nat1" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/ros_nat1.png" alt="ros_nat1" width="623" height="217" /><img class="aligncenter size-full wp-image-80" title="ros_nat2" src="http://www.potato-people.com/blog/wp-content/uploads/2009/10/ros_nat2.png" alt="ros_nat2" width="623" height="217" /></p>
<p>By placing this rule at the top of the NAT table under IP-&gt;Firewall, when a packet is directed from the RouterOS LAN towards the VPN destination subnet, the &#8220;accept&#8221; action will cause the NAT table to stop processing, and thus never reach any other NAT rules.</p>
<p>There is no way to force RouterOS to establish the connection other than by sending traffic.It&#8217;s also important to note that v4.0 of RouterOS appears to suffer from a bug that causes the VPN to establish but not correctly route traffic across it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2009/10/ipsec-vpns-for-mikrotik-routeros/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PSPgo so awful, Sony expects increase in sales of PSP-3000</title>
		<link>http://www.potato-people.com/blog/2009/10/pspgo-so-awful-sony-expects-increase-in-sales-of-psp-3000/</link>
		<comments>http://www.potato-people.com/blog/2009/10/pspgo-so-awful-sony-expects-increase-in-sales-of-psp-3000/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 18:47:25 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[sony why do they still exist corporate dumb]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=68</guid>
		<description><![CDATA[No other company in the world has the balls to attempt what Sony is trying, and I would seriously love to know what crack they&#8217;re on and where I can get some. Sony Schmuck A: So, sales of the PSP-3000 are okay, but not great. Sony Schmuck B: I know! Let&#8217;s make a new version. [...]]]></description>
			<content:encoded><![CDATA[<p>No other company in the world has the balls to attempt what Sony is trying, and I would seriously love to know what crack they&#8217;re on and where I can get some.</p>
<p><em>Sony Schmuck A:</em> So, sales of the PSP-3000 are okay, but not great.</p>
<p><em>Sony Schmuck B: </em>I know! Let&#8217;s make a new version. But lets make that version so god damned hideously awful that people will scramble to buy the old one!</p>
<p><em>Sony Schmuck A: </em>Excellent idea!</p>
<p>&#8230; and so<a href="http://www.joystiq.com/2009/09/30/retailers-pleased-with-psp-go-because-it-helps-sell-the-psp/"> the PSPgo was born</a>. I mean really, it&#8217;ll not be long before the next Sony console shoots acid in your face to try an encourage you to buy a newer/older model.</p>
<p>And just to add insult to injury? The PSPgo is only <em>£25 quid cheaper</em> than a full blown PS3.</p>
<p>Sony have cojones the size of the moon. Seriously.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2009/10/pspgo-so-awful-sony-expects-increase-in-sales-of-psp-3000/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISP fined $32 million for helping sell illegal fake goods</title>
		<link>http://www.potato-people.com/blog/2009/09/64/</link>
		<comments>http://www.potato-people.com/blog/2009/09/64/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 10:28:39 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[copyright]]></category>
		<category><![CDATA[dmca]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[notice.]]></category>
		<category><![CDATA[takedown]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=64</guid>
		<description><![CDATA[In this article, it&#8217;s reported that Louis Vuitton &#8211; a fashion designer &#8211; has sued and won $32 million US from an ISP, Akanoc Solutions Inc, which hosted a customer who was selling forged Louis Vuitton products. This has caused uproar in the ISP community as at first glance it appears as though the ISP [...]]]></description>
			<content:encoded><![CDATA[<p>In this <a href="http://darkreading.com/securityservices/security/cybercrime/showArticle.jhtml;jsessionid=5P4BO3EZ4TBL3QE1GHPSKH4ATMY32JVN?articleID=219501314" target="_blank">article</a>, it&#8217;s reported that <span id="articlebody"><a href="http://www.louisvuitton.com/" target="_blank">Louis Vuitton</a> &#8211; a fashion designer &#8211; has sued and won $32 million US from an ISP, </span><span id="articlebody"><a href="http://www.akanoc.com/" target="_blank">Akanoc Solutions Inc</a>, </span><span id="articlebody"> which hosted a customer who was selling forged Louis Vuitton products.<br />
</span><br />
This has caused uproar in the ISP community as at first glance it appears as though the ISP in question is being held responsable for the acts of it&#8217;s customers, but really they are simply being held responsable for refusing to act against a customer who was involved in an illegal practice.</p>
<p>The court documents detail how Louis Vuitton notified the ISP no less than 15 times &#8211; giving them ample opportunity and evidence to terminate the customer. Instead the ISP allowed that customer to juggles his sites around on different domain names and IP addresses and continue to sell the fake goods. The ISP was found guilty because they were complacent in allowing a customer to use their service to break the law. They tried to claim safe harbour under the DMCA act, however here we are exactly 2 years after the initial filing and the websites listed in the initial claim are still operating in Akanoc IP space.</p>
<p>It&#8217;s a tricky line for ISPs to cross. In my day to day work, I receive notices of copyright infringement from the MPAA/RIAA every week &#8211; but how are we supposed to act? We do not have the technology to actively monitor accused customers as the equipment required ranges into the tens of thousands to the hundreds of thousands of dollars. The MPAA/RIAA provide scant evidence &#8211; evidence which has been shown in the past to be <a href="http://www.afterdawn.com/news/archive/14371.cfm">very, very incorrect at times</a>. We do what we can under UK law, notify the customer that we have received an infringement notice and notify the MPAA/RIAA that the customer has been warned.</p>
<p>The UK government wants to make deep packet inspection boxes mandatory for all ISPs, without regard to the cost  (which will cripple any medium-to-small service provider, if not put them out of business) and on top of that they appear to think that these boxes can log everything and anything regardless of software or encryption &#8211; there isn&#8217;t a DPI box yet which can monitor Second Life traffic&#8230; but that&#8217;s what the UK government is expecting ISPs to do.</p>
<p>However, this is missing a key point in this case in California: The ISP in question was provided with verifiable evidence that thier customer was selling fake, knockoff and illegal goods &#8211; and they declined to act on it (and in fact are still declining to act upon it to this day). Other ISPs spend a great deal of time and money ensuring that they are reacting to spam issues and hacked servers being used to host fake paypal logins. <a href="http://www.akanoc.com/" target="_blank">Akanoc Solutions Inc.</a> took an active decision in deciding to not enforce their rights to terminate an obviously fraudulent customer and allowed them to continue in their business. They deserve everything they got.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2009/09/64/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ghetto Antenna</title>
		<link>http://www.potato-people.com/blog/2009/07/ghetto-antenna/</link>
		<comments>http://www.potato-people.com/blog/2009/07/ghetto-antenna/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 15:10:12 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[antenna]]></category>
		<category><![CDATA[ghetto]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=61</guid>
		<description><![CDATA[Possibly the most ghetto thing I&#8217;ve ever built: The Ghetto Wireless Antenna. Don&#8217;t worry, it&#8217;s only temporary. It&#8217;s a twist tie with an end stripped off, folded over and shoved into the N-type antenna connector. Suprisingly it gives quite good reception, increasing the signal strength to nearby laptops by about 20db.]]></description>
			<content:encoded><![CDATA[<p>Possibly the most ghetto thing I&#8217;ve ever built: The Ghetto Wireless Antenna.</p>
<p><img class="aligncenter size-medium wp-image-62" title="Ghetto Antenna" src="http://www.potato-people.com/blog/wp-content/uploads/2009/07/IMAGE_011-225x300.jpg" alt="Ghetto Antenna" width="225" height="300" /></p>
<p>Don&#8217;t worry, it&#8217;s only temporary. It&#8217;s a twist tie with an end stripped off, folded over and shoved into the N-type antenna connector. Suprisingly it gives quite good reception, increasing the signal strength to nearby laptops by about 20db.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2009/07/ghetto-antenna/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Postfix Mail Queue statistics via SNMP</title>
		<link>http://www.potato-people.com/blog/2009/06/postfix-mail-queue-statistics-via-snmp/</link>
		<comments>http://www.potato-people.com/blog/2009/06/postfix-mail-queue-statistics-via-snmp/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 16:30:21 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Coding]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[mail]]></category>
		<category><![CDATA[postfix]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[snmp]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=55</guid>
		<description><![CDATA[This post documents a small shell script designed to provide basic mail queue statistics via SNMP for Postfix. Requirements Postfix Net-SNMP Installation The code can be downloaded here. To install, place the script anywhere in your system and edit it to provide the correct path to the &#8220;qshape&#8221; perl script that comes with Postfix. Note: [...]]]></description>
			<content:encoded><![CDATA[<p>This post documents a small shell script designed to provide basic mail queue statistics via SNMP for Postfix.</p>
<p><strong>Requirements</strong></p>
<ul>
<li><a href="http://www.postfix.org/">Postfix</a></li>
<li><a href="http://www.net-snmp.org">Net-SNMP</a></li>
</ul>
<p><strong>Installation</strong></p>
<p>The code can be downloaded <a href="http://www.potato-people.com/code/misctools/snmpqshape.sh.gz">here</a>.</p>
<p>To install, place the script anywhere in your system and edit it to provide the correct path to the &#8220;qshape&#8221; perl script that comes with Postfix.</p>
<p><em>Note: Under openSUSE qshape.pl is part of the postfix-docs package and is not installed by default.</em></p>
<p>To configure net-snmp, edit your snmpd.conf line and add a line as follows:</p>
<p><code>pass [oid-of-choice] /bin/snmpqshape.sh [oid-of-choice]</code></p>
<p>For example, due to a quirk in a paticular SNMP monitoring package I use, I had to use an OID belonging to Motorola:</p>
<p><code>pass .1.3.6.1.4.1.17713.2 /bin/snmpqshape.sh .1.3.6.1.4.1.17713.2</code></p>
<p>Net-SNMP will return 3 OIDs on query:</p>
<p><code>.0 :: Incoming<br />
.1 :: Active<br />
.2 :: Deferred</code></p>
<p><strong>MRTG / RRDTool</strong></p>
<p>Since the setup of monitoring / statistics tools such as MRTG or RRDTool is site-specific, no provisions are made on this page to provide a complete usage example. A minimal example for RRDTool:<br />
<code>#! /bin/sh<br />
STR="`snmpwalk -OvQ -r 10 -t 5 -v 2c -c publicommunity hostname.site.com \<br />
.1.3.6.1.4.1.17713.2 | perl -ne 's/^/:/;s/\n//;print'`"<br />
rrdtool update /path/to/rr-database.rrd -t incoming:active:deferred N${STR}</code></p>
<p><strong>DISCLAIMER</strong><br />
This code is free to use and distribute, and the author offers no liability or warranty for it&#8217;s misuse.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2009/06/postfix-mail-queue-statistics-via-snmp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHP :: Convert a string to NATO alphabet</title>
		<link>http://www.potato-people.com/blog/2009/04/php-convert-a-string-to-nato-alphabet/</link>
		<comments>http://www.potato-people.com/blog/2009/04/php-convert-a-string-to-nato-alphabet/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 16:05:43 +0000</pubDate>
		<dc:creator>rick</dc:creator>
				<category><![CDATA[Coding]]></category>
		<category><![CDATA[Geek]]></category>

		<guid isPermaLink="false">http://www.potato-people.com/blog/?p=47</guid>
		<description><![CDATA[Giving a password over the phone to someone is always painful, and I can never remember the NATO alphabet (Whiskey Tango Foxtrot!). The following PHP function will convert any string into the NATO alphabet for easy recitation. function convert_to_nato($word) { $lib['a']="Alpha"; $lib['b']="Bravo"; $lib['c']="Charlie"; $lib['d']="Delta"; $lib['e']="Echo"; $lib['f']="Foxtrot"; $lib['g']="Golf"; $lib['h']="Hotel"; $lib['i']="India"; $lib['j']="Juliet"; $lib['k']="Kilo"; $lib['l']="Lima"; $lib['m']="Mike"; $lib['n']="November"; $lib['o']="Oscar"; [...]]]></description>
			<content:encoded><![CDATA[<p>Giving a password over the phone to someone is always painful, and I can never remember the NATO alphabet (Whiskey Tango Foxtrot!). The following PHP function will convert any string into the NATO alphabet for easy recitation.</p>
<p><span id="more-47"></span></p>
<pre>function convert_to_nato($word) {
     $lib['a']="Alpha";
     $lib['b']="Bravo";
     $lib['c']="Charlie";
     $lib['d']="Delta";
     $lib['e']="Echo";
     $lib['f']="Foxtrot";
     $lib['g']="Golf";
     $lib['h']="Hotel";
     $lib['i']="India";
     $lib['j']="Juliet";
     $lib['k']="Kilo";
     $lib['l']="Lima";
     $lib['m']="Mike";
     $lib['n']="November";
     $lib['o']="Oscar";
     $lib['p']="Papa";
     $lib['q']="Quebec";
     $lib['r']="Romeo";
     $lib['s']="Sierra";
     $lib['t']="Tango";
     $lib['u']="Uniform";
     $lib['v']="Victor";
     $lib['w']="Whiskey";
     $lib['x']="X-Ray";
     $lib['y']="Yankee";
     $lib['z']="Zulu";
     $lib['0']="Zero";
     $lib['1']="One";
     $lib['2']="Two";
     $lib['3']="Three";
     $lib['4']="Four";
     $lib['5']="Five";
     $lib['6']="Six";
     $lib['7']="Seven";
     $lib['8']="Eight";
     $lib['9']="Nine";
     $lib['-']="Dash";

     $nato=array();

     for($i=0;$i
          $letter=substr($word,$i,1);
          if (!empty($lib[$letter])) {
               $nletter=strtolower($lib[$letter]);
          } else {
               if (!empty($lib[strtolower($letter)])) {
                    $nletter=strtoupper($lib[strtolower($letter)]);
               } else {
                    $nletter=$letter;
               }
          }
          $nato[]=$nletter;
     }

     return implode(" ",$nato);
}</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.potato-people.com/blog/2009/04/php-convert-a-string-to-nato-alphabet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
