Thursday, May 14, 2026
[Transparency Report #005][OPERATIONS] Name servers moved into FurrIX
What are Transparency Reports?
As a community operated and governed virtual internet exchange, FurrIX has
to maintain and foster open and honest communication with our exchange
members. This means that from time to time, there will be items that come
up during our operations that could or do affect the exchange and our team
will publish notices in order to keep everyone in the know. As a community
internet exchange hobby project, FurrIX aims to have fully open communication
where practical.
What Happened?
FurrIX has completed the planned transition of its hybrid name servers from
MFN’s legacy network and DNS zone into full FurrIX operational control. This fulfills
the February 2026 agreement between MFN and FurrIX to migrate DNS operations while
maintaining continuity for all members. The move consolidates name server governance,
improves operational clarity and aligns DNS identity with the rest of the FurrIX
infrastructure.
We consulted with the operator of the newly scoped MFN project and mutually agreed to
leave their zone and glue records unchanged at the registry for now. Operationally, however,
FurrIX.zone no longer relies on NS entries from the MFN zone and the MFN operator is now
free to manage their DNS zone independently without requiring support from the FurrIX team.
Why this rework is needed:
With FurrIX taking over the network components previously operated under MFN, several
updates were required to maintain a clean governance boundary and preserve FurrIX’s
independent project status:
- Name server identity:
NS1 and NS2 now operate solely under the FurrIX namespace, retiring the hybrid MFN/FurrIX
state used during the transition period. (MFN’s NS entries remain available for their own use.)
- Operational ownership:
FurrIX now maintains full control of NS configuration, monitoring and security posture
completing the handoff from MFN and allowing the vIX to manage these servers as needed
- NS Records:
FurrIX NS glue records have been updated.
What this means for members of the exchange:
- No member impact —
This is a backend operational change and members should not experience any
difference in network behavior.
Are exchange operations affected?
Functionally, nothing member facing has changed.
Wednesday, April 22, 2026
[Transparency Report #002][OPERATIONS] Name and mail server changes!
What are Transparency Reports?
As a community operated and governed virtual internet exchange, FurrIX has
to maintain and foster open and honest communication with our exchange
members. This means that from time to time, there will be items that come
up during our operations that could or do affect the exchange and our team
will publish notices in order to keep everyone in the know. As a community
internet exchange, FurrIX aims to have fully open communication standards
as best as possible.
What Happened?
As part of FurrIX going forward and rebuilding itself in a better documented and
run exchange, there have been parts of the network that we have kept from
Marbled Fennec Networks. The biggest things we have kept are the web, mail
and name servers. But all of these have been needed some reconfiguration to
fully move into our name space and management plane.
We are currently working on making some of the needed changes.
What this means for members of the exchange:
- NS1 and NS2 are in a hybrid state, answer DoH and DoT
on both the marbledfennec.net and furrix.zone domains to
maintain network operations and compatibility - FurrIX can now be emailed without going through Marbled Fennec
Networks. The email server has been reconfigured to service both
domains going forward, as MFN will retain email service
Are exchange operations affected?
This should not have any visible affect on our exchange members. The
network should just keep humming right along all peachy.
Saturday, March 28, 2026
Ongoing Name Server Attacks
FurrIX is seeing attacks on our name servers that have not let
up for a few hours now and as a result we have had to tighten
our rate limits and start dropping excessive traffic.
The way things are going, we will not be letting up on our rate
limits any time soon.
If you are being affected by these changes, you can send an
email off to ‘nameservers at marbledfennec dot net’ and request
a whitelisting that will bypass the limits. We will require knowing
you use case, however.
Wednesday, March 25, 2026
[Name Servers] Updated Configuration
We have been seeing a lot of DNS amplification attacks ongoing
during the past few weeks and have adjusted our name server
configuration to start rate-limiting and dropping request a fair
bit sooner.
We have also changed the graphs that we are showing for
the server status page.
Tuesday, March 3, 2026
[Incident Report #028][DNS] Name Server Attack
Update Two:
Going scorched Earth wasn’t the best approach and resulted
in our servers falling off of the OpenNIC list. We have removed
these network rules for the time being.
Update:
AS20473 is still attempting to throw a large amount of traffic at
our name servers, but our drop rules are in place and appear to
be working as intended.
What Happened?
From around 0600 to 0730EST this morning, our name servers
were hit with a large amount of traffic originating from a data center
in the Netherlands under AS20473. The traffic was spread across
multiple IPv6 subnets and volume was high enough the it saturated
the virtual bridges that our name servers are operating behind. This
is the fourth attack of this kind that our network seen in the past
two weeks.
Upon looking at the traffic reaching the name servers, it appears that
a handful of IPs originating from AS20473 are performing scattered
shot lookups for all kinds of domain NS records with no rhyme or
reason to the data they are requesting and they are doing so at a
rate that is affecting the usability of our network rate limited services.
What damages Resulted?
During the attack, we saw the following issues:
- Accounting service lost contact with NS2
- Legitimate name lookups were being dropped or timed out
- The NMS lost SNMP contact with NS1 and NS2 momentarily
- High CPU load on Nardoragon router
What are we doing to deal with this?
As a result of repeated abuse from this provider, we have:
- Applied drop rules at edge router for Phy One, dropping AS20473
- Applied drop rules at edge router for Phy Two, dropping AS20473
The FurrIX vIX will not tolerate abuse of our services to the point in
which it affects our operations internally or causes issues for members
of our exchange and going forward, we will be quicker to start dropping
abusive traffic all together.