Monday, August 3, 2026
Status Update
The routing stack across the exchange just got a fresh round of updates and a bit of
reconfiguration in response to the IR we posted earlier. Both name servers are now
running the same configuration, traffic shaping is in place where it actually matters
for the exchange, geoblocking has been added for the region where the bulk of the
attack traffic originated and the DNS rate‑limit profiles are now consistent across the
board. Everything within the exchange is back to normal day‑to‑day operation.
Among the changes:
- We’re now enforcing traffic shaping on the opnsense routers that interface
with the name servers, capping DNS networking at 15 Mbps.
- The RRL catch‑net for IPv6 has been widened from /56 to /48.
- The PHYTWO edge router (Groot) has finally been brought up to the latest firmware.
– This included converting older rules to the new UI.
- Not yet reflected in our policies: FurrIX will now retain NS logs for up to 48 hours
for debugging and network configuration work.
Hopefully this cleans up what we were dealing with over the past few days.