In late June, we added GRE tunnels to netlab, including a Junos implementation. It looked great (as in “everything worked”) until I changed the integration tests to have GRE tunnels between a tested device and a pair of FRR containers. All other implementations worked as before, but Junos failed to establish an OSPFv3 adjacency over the GRE tunnel with FRR.
Stefano Sasso quickly identified the culprit: Junos OSPFv3 process thinks it should send the DBD packets over GRE tunnels with MTU set to zero (the behavior reserved for virtual links)1.
The screen capture shows how sflowgen DDoS attack telemetry appears in the DDoS Protect dashboard. Charts in the dashboard show different types of DDoS attack. You can see normal low level background activity below the red horizontal threshold line. DDoS traffic can be seen ramping up on the udp_flood and ip_flood charts and leveling off once the attack reaches maximum intensity. Notice that as soon as the attack traffic crosses the threshold, the Controls chart indicates that a Pending control has been created to mitigate the attack.
The Controls table shows the udp_flood attack against host 10.10.0.42 using port 443 as the attack vector. In this case the control action is set to drop, i.e. use a Remotely Triggered Black Hole (RTBH) as the mitigation action. The pending status indicates that it is waiting for user confirmation before being applied.The Settings tab has been configured to add a local address group containing the 10.10.0.0/24 and 2001:db8:10::/64 CIDRs used in the default Continue reading
Summer is almost over, and it’s time to resume regular programming with the next example from the Segment Routing workshop I had at ITNOG10: multi-vendor SR-MPLS. I used the same lab topology as in the previous examples but deployed Arista EOS on PE1, FRRouting on P, and SR Linux on PE21
You likely noticed the recent redesign of the Cloudflare Blog. We added dark mode, modernized the look and feel, and made a lot of other small improvements along the way.
What you might not have noticed – well, except for those who are more terminally online – is that the redesign was part of a much bigger migration project. On Wednesday, August 12, we moved the blog to EmDash, a content management system (CMS) built especially to work on Astro and with Cloudflare.
We’ll take you into the migration story – what we learned and how EmDash got better – as well as into the benefits we’re already seeing from a new platform.
At Cloudflare, Cloudflare itself is Customer Zero. This means that we use our products. And – in use – we make them better for ourselves and our customers.
This is a very real cultural value at Cloudflare. The burden of proof is on you if you want to use an external vendor. Why can’t that team support you, what gaps are there, why can’t those gaps be filled, and are those “gaps” true requirements?
This preference is even enshrined in our internal Continue reading
Warning
This post contains interactive examples. To visualize and interact with them, you need to leave your RSS reader.
Imagine you rent office space for a three-day event. You quickly set up a few Ethernet switches and tape some cables on the floor to get everyone online. Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he gets up for coffee. You could add extra cables, but then you’d get a broadcast storm: Ethernet packets that loop and multiply until nothing else gets through.
That’s where the spanning tree protocol (STP) comes in. STP blocks just enough of your spare cables to leave a loop-free tree. When Stan strikes again, it rebuilds the tree in a second, leaving some time for Blobby, your one-person support crew, to reconnect the cable. See for yourself: the diagram below runs a real STP implementation in your browser!
:demo
A1 @0,0 prio=4096
A2 @0,1
A3 @0,2
A4 @0,3
B1 @1,0 prio=8192
B2 @1,1
B3 @1,2
B4 @1,3
C1 @2,0 prio=8192
C2 @2,1
C3 @2,2
C4 @2,3
A1 -- A2 hazard=0
A2 -- A3 hazard=0
A3 -- A4 hazard=0
B1 -- B2
B2 -- B3
B3 -- B4
C1 -- C2 Continue readingImagine you rent office space for a three-day event. You quickly set up a few Ethernet switches and tape some cables on the floor to get everyone online. Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he gets up for coffee. Spare cables would fix that, but a loop turns into a broadcast storm: Ethernet packets multiply until nothing else gets through. That’s where the spanning tree protocol comes in: it blocks just enough of the spare cables to leave a loop-free tree, and rebuilds it in a second each time Stan strikes again.
This content is also available as a text version, with interactive demos that run a real implementation directly in your browser!
This video is an experiment.1 Honestly, except for Radia Perlman reading her poem,2 you should read the original article instead. It presents the same content, but you can play with the interactive examples, which are the main contribution. On the other hand, if you happen to like the video, be sure to tell me in the comments!
I thought automated tools would produce this video in a couple of hours. In the end, it was another rabbit hole Continue reading
The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms find real problems at a scale no human team can match. But when you read the findings closely, a pattern emerges: agents talked into refunds, transfers, and data leaks they had standing authority to perform. Patching the prompt fixes one phrasing until the next model update. Constraining the authority fixes the class. The first job belongs to a red team platform. The second belongs to your runtime, and no scanner will do it for you.
In April 2026, General Analysis raised a $10M seed round on the strength of an uncomfortable demonstration: its adversarial agent attacked 55 live customer service bots and compromised 50 of them. Not lab models, but live systems with real customers and real tool access. This post is about the market behind that demonstration: who now automates the attacker’s role, what the attacks keep finding, and why the fix that lasts is runtime policy rather than a better prompt.
A traditional red team Continue reading
When someone starts singing the Use Digital Twins to Test Your Network hymn (or, more recently, tells you how AI agents can do that to validate their ideas), ask them about these minor details. If they persist, point them (not that it would help) to this long list of gotchas.
That list just got longer: Arista cEOS container does not apply inbound ACLs to control-plane traffic (Arista vEOS VM does).
Danau Lake Denman Basal Cryobrine Corridor merupakan salah satu fenomena alam yang semakin menarik perhatian para ilmuwan dan peneliti dalam beberapa tahun terakhir. Fenomena yang sering disebut dengan istilah denman cryobrine corridor ini merupakan bagian penting dalam studi iklim dan ekosistem ekstrem di Bumi. Artikel ini akan mengupas fakta-fakta unik seputar denman cryobrine corridor yang relevan hingga saat ini dan bagaimana keberadaannya memengaruhi riset ilmiah di berbagai disiplin ilmu.
Denman cryobrine corridor adalah sebuah bagian unik dari sistem glester di sekitar Danau Lake Denman yang dikenal dengan kandungan air garam yang tinggi pada suhu yang sangat rendah. Fenomena ini muncul ketika air garam superdingin membentuk sebuah koridor alami di bawah permukaan es. Keunikan dari denman cryobrine corridor terletak pada kemampuan air garam tersebut bertahan dalam kondisi ekstrem tanpa membeku, sehingga menimbulkan potensi ekosistem mikroorganisme unik yang belum banyak dipahami oleh ilmu pengetahuan.
Saat ini, denman cryobrine corridor sangat menjadi fokus riset karena memberikan wawasan baru terkait adaptasi kehidupan di kondisi ekstrem hingga potensi eksplorasi astrobiologi di planet lain yang memiliki kondisi serupa, seperti Mars atau bulan-bulan es di tata surya.
Pada periode terbaru, penelitian menggunakan satelit dan teknologi bawah Continue reading
Fenomena alam geologi menarik perhatian para ilmuwan dan penggemar sains di seluruh dunia, salah satunya adalah kawasan Clearwater West Shock Vein Zone. Hingga saat ini, fenomena tersebut masih menyimpan banyak misteri yang membuat para peneliti terus mendalaminya. Artikel ini akan membahas secara lengkap dan terbaru tentang fenomena Clearwater West Shock Vein, dari penemuan, karakteristik, hingga implikasi ilmiah dan lingkungan yang relevan pada kondisi saat ini.
Fenomena Clearwater West Shock Vein merupakan sebuah zona nirkon yang ditemukan di kawah Clearwater West, salah satu dari dua kawah yang saling berdekatan di Quebec, Kanada. Fenomena ini dikenal sebagai salah satu contoh nyata dari struktur geologi yang terbentuk akibat benturan meteorit raksasa ke permukaan bumi. Kawah Clearwater West sendiri membentang sekitar 26 kilometer dan dikenal sebagai salah satu situs krater tipe “dual impact” yang unik.
Zona shock vein atau urat kejut adalah lapisan tipis material yang terbentuk dengan pola patahan dan deformasi ekstrem karena tekanan dan suhu sangat tinggi pada saat terjadi benturan meteorit. Wilayah Clearwater West Shock Vein menjadi sangat penting sebagai lokasi studi untuk memahami lebih jauh mekanisme pembentukan material dan batuan akibat benturan luar angkasa.
We’re constantly building for the different goals of our customers. Some customers want to optimize for discovery, while others want to protect their content with the strictest security policy. Among these differing policies, there are multiple ways to mitigate bot traffic. Some mechanisms simply state your preference, assuming best intent from crawlers, and other approaches actually lock down content by outright blocking with a Bot Management solution.
We recognize that it's cumbersome to maintain multiple layers of protection on your website. For example, there are cases in which your robots.txt states that a crawler is Disallowed from accessing your website, while your enforcement rules actually don’t block that crawler. When your stated preferences and your enforced rules disagree, some crawlers treat it as a basis to disregard your preferences or try to bypass your enforced rules.
A couple of years ago, Cloudflare announced an easier way to disallow AI training on your website by tackling two of these layers: a managed value of robots.txt that told a fixed list of major Training crawlers not to train on your content, along with edge-enforced blocks to Training crawlers. On July 1, 2026, we launched easier options to manage different kinds Continue reading
Since June, developers have created thousands of third-party OAuth apps on Cloudflare, with more than a million authorizations since.
OAuth makes delegated access possible. It lets applications act on a user’s behalf without asking them to handle long-lived credentials or hand over a password. That model works well when an application can describe its access needs with a small set of scopes.
Developers use OAuth for SaaS integrations, internal tools, CLIs, and agents. Our permission model has become more granular over time to support better scoping of these different workflows. That is great for security, but it makes a purely all-or-nothing consent screen hard to justify.
Cloudflare OAuth already allows clients to request a subset of their configured scopes. But once the client made that request, the user could not narrow it any further on the consent screen. For the user on the consent screen, the experience was still an all-or-nothing one. If an application requested more access than a user was comfortable granting, their only options were to approve the full request, or deny outright.
MCP servers are a good example of this. An MCP server might request a broad set of permissions, because in Continue reading
Deploying AI for AI Ops, or even just for general use in your network, is very simple–but we often forget that these kinds of new technologies need to be governed. From privacy through cost, operators need to decide how to govern their AI deployments to control costs, ensure accuracy, measure productivity, and make certain these systems are being used effectively. Colin Cosgrove joins Russ and Tom to look at AI governance.
download