Page MenuHomePhabricator

Throttle rule for 1Lib1Ref event
Closed, DeclinedPublic

Description

For a 1Lib1Ref event in Knoxville, TN, USA (as directed from this page):

  • Event beginning time: January 31, 2018, 13:00 EST.
  • Event end time: January 31, 2018, 16:00 EST.
  • The IPs to allow:

160.36.0.0/16 (160.36.0.0 - 160.36.255.255)
216.96.128.0/17 (216.96.128.0 - 216.96.255.255)
165.6.192.0/18 (165.6.192.0 - 165.6.255.255)
192.249.0.0/20 (192.249.0.0 - 192.249.15.255)
10.38.0.0/16 (10.38.0.0 - 10.38.255.255)
10.44.0.0/14 (10.44.0.0 - 10.47.255.255)
10.60.0.0/14 (10.60.0.0 - 10.63.255.255)
10.128.0.0/14 (10.128.0.0 - 10.131.255.255)

Event Timeline

Kizule subscribed.

I will create patch tommorrow after providing information which is IP address.

Kizule renamed this task from Wikimedia-Site-request to Throttle rule for 1Lib1Ref event.Jan 28 2018, 10:06 PM
Kizule updated the task description. (Show Details)

IPs to allow:

160.36.0.0/16 (160.36.0.0 - 160.36.255.255)
216.96.128.0/17 (216.96.128.0 - 216.96.255.255)
165.6.192.0/18 (165.6.192.0 - 165.6.255.255)
192.249.0.0/20 (192.249.0.0 - 192.249.15.255)
10.38.0.0/16 (10.38.0.0 - 10.38.255.255)
10.44.0.0/14 (10.44.0.0 - 10.47.255.255)
10.60.0.0/14 (10.60.0.0 - 10.63.255.255)
10.128.0.0/14 (10.128.0.0 - 10.131.255.255)

Change 406603 had a related patch set uploaded (by Zoranzoki21; owner: Zoranzoki21):
[operations/mediawiki-config@master] Add throttle rule for 1Lib1Ref event

https://gerrit.wikimedia.org/r/406603

This will be deployed today between 20-21:00 UTC +1

IPs to allow:
...
10.38.0.0/16 (10.38.0.0 - 10.38.255.255)
10.44.0.0/14 (10.44.0.0 - 10.47.255.255)
10.60.0.0/14 (10.60.0.0 - 10.63.255.255)
10.128.0.0/14 (10.128.0.0 - 10.131.255.255)

Those IP address is private area per RFC 1918.

160.36.0.0/16 (160.36.0.0 - 160.36.255.255)
216.96.128.0/17 (216.96.128.0 - 216.96.255.255)
165.6.192.0/18 (165.6.192.0 - 165.6.255.255)
192.249.0.0/20 (192.249.0.0 - 192.249.15.255)

That's quite a range. They are all associated with University of Tennessee, but does really all of U of tenn really need to be whitelisted. Including ResNet?

I've sent a request for a smaller range to our university IT and will let you know if/when I hear anything.

I have heard back from IT and these are the ones to allow:

160.36.192.0/22
192.249.3.128/25
216.96.128.0/17

This last one is EduRoam (large).

I am sorry, but this change is not deployed in defined time and event is ended.

Change 406603 abandoned by Zoranzoki21:
Add throttle rule for 1Lib1Ref event

Reason:
I am sorry, but this change is not deployed in defined time and event is ended.

https://gerrit.wikimedia.org/r/406603