nanog mailing list archives

Re: Spamhaus vs. Cloudflare


From: ITechGeek via NANOG <nanog () lists nanog org>
Date: Thu, 17 Sep 2026 20:15:04 -0400

Might also be worth mentioning to your customer that while you can
potentially unblock the subnets for your network, they will still be
blocked on other networks if they have users elsewhere.

On Thu, Sep 17, 2026, 18:53 Jon Lewis via NANOG - nanog at lists.nanog.org <
nanog () lists nanog org> wrote:

On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:

 Ah, so you and Cloudflare have a mutual customer being impacted by
their
 use of a Cloudflare IP in one of those ranges?  Have you suggested that
 they complain to Cloudflare and suggest to Cloudflare that they "clean
up
 their network" and reputation?


They already tried to work with Cloudflare and were told that "the
resolution
is for all of their IPs to be specifically allowed."

That's certainly an option.  However you're consuming DROP, you should be
able to whitelist IPs or reject some of the DROP data.

If that's really Cloudflare's position (from the top...not just what some
low level support person suggested), then that's indicative of their
problem.  i.e. That they seem to operate under the belief that there's no
form of Internet abuse too offensive for them to host.  It seems to me,
that's exactly what DROP is for and the solution is for more networks to
use DROP.

----------------------------------------------------------------------
  Jon Lewis, MCP :)              |  I route
  Blue Stream Fiber, Sr. Neteng  |  therefore you are
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________
_______________________________________________
NANOG mailing list

https://lists.nanog.org/archives/list/nanog () lists nanog org/message/P5MUTNNCLJUMHOQJDNME7PHNUSIBFQWC/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/LXDSS53LTHSYDZ5E2PF2HXRNABTOO73D/


Current thread: