Afrihost Business Uncapped Feedback

Status
Not open for further replies.
The Mikrotik does support L2TP, just not L2TP without IPSEC

Err - Yes it does.

L2TP is a very common tunneling mechanism (without IPSEC) used by carriers and large scale vpn terminations for years. MWEB Bonded ADSL - L2TP, MTN Static IP ADSL (where they gave you a cisco router) - L2TP, IS Static IP ADSL (where they gave you a cisco router - and later a billion) - L2TP...

The only difference here is Afrihost is selling this as a unmanaged service, where as all the other providers previously, sold this as a managed service where you did not have to setup the VPNs yourself.

If you don't know how to setup L2TP VPNs, go get yourself a managed service from someone else. There is absolutely NOTHING wrong with L2TP for these type of applications.

Frankly, if IPSEC is required for this service, I will more than likely not use it. The overhead and increased load on my (and Afrihost's / MTN's routers for encrypting / decrypting) 1000s of Mbps worth of bandwidth is going to make this so slow that it will be virtually useless.

Edit: For those using cisco's, here's a very basic config to get you started...

pseudowire-class L2TPv2
encapsulation l2tpv2
ip local interface Dialer0

interface Virtual-PPP1
ip address negotiated
no ip redirects
no ip unreachables
ip mtu 1460
ip tcp adjust-mss 1440
ppp pap sent-username blah password blah
no cdp enable
pseudowire remote.vpn.ip.address pw-class L2TPv2
end
 
Last edited:
Mikrotik FYI:

1) Add a static route to ensure that traffic to the VPN server is always routed via your basic PPPoE dialup interface
/ip route add dst-address=1.1.1.1 gateway="PPPoE Dialup Interface"

2) L2TP VPN Client without using IPSEC
/interface l2tp-client add add-default-route=yes allow=pap connect-to=1.1.1.1 disabled=no keepalive-timeout=30 name=Afrihost profile=default user=username password=password

It should come right up without any issues what so ever. If it doesn't, just debug PPP in the logs and see what is failing with the neogotiations.
 
Mikrotik FYI:

1) Add a static route to ensure that traffic to the VPN server is always routed via your basic PPPoE dialup interface
/ip route add dst-address=1.1.1.1 gateway="PPPoE Dialup Interface"

2) L2TP VPN Client without using IPSEC
/interface l2tp-client add add-default-route=yes allow=pap connect-to=1.1.1.1 disabled=no keepalive-timeout=30 name=Afrihost profile=default user=username password=password

It should come right up without any issues what so ever. If it doesn't, just debug PPP in the logs and see what is failing with the neogotiations.

thanks I take it the 1.1.1.1 must be replaced with the VPN server of Afrihost ?
 
@Afriman - does your support team look at PCAP files? Experiencing horrible lags when playing online (Guildwars 2) and logged a ticket (LPG-306-41392). Seems to be more frequent this week then last week. (shockingly I seem to have more lag in online gaming with Afrihost than what I had with MWeb).

I suppose PCAP files of when it happens is about the best choice as pinging an address is really pointless. From the support feedback sofar, it does not look like anyone looks at this in detail (i.e. standard resolution such as "Have you turned it off and on again" or "Phone Telkom to reset port").
 
Err - Yes it does.

L2TP is a very common tunneling mechanism (without IPSEC) used by carriers and large scale vpn terminations for years. MWEB Bonded ADSL - L2TP, MTN Static IP ADSL (where they gave you a cisco router) - L2TP, IS Static IP ADSL (where they gave you a cisco router - and later a billion) - L2TP...

The only difference here is Afrihost is selling this as a unmanaged service, where as all the other providers previously, sold this as a managed service where you did not have to setup the VPNs yourself.

If you don't know how to setup L2TP VPNs, go get yourself a managed service from someone else. There is absolutely NOTHING wrong with L2TP for these type of applications.

Frankly, if IPSEC is required for this service, I will more than likely not use it. The overhead and increased load on my (and Afrihost's / MTN's routers for encrypting / decrypting) 1000s of Mbps worth of bandwidth is going to make this so slow that it will be virtually useless.

Edit: For those using cisco's, here's a very basic config to get you started...

pseudowire-class L2TPv2
encapsulation l2tpv2
ip local interface Dialer0

interface Virtual-PPP1
ip address negotiated
no ip redirects
no ip unreachables
ip mtu 1460
ip tcp adjust-mss 1440
ppp pap sent-username blah password blah
no cdp enable
pseudowire remote.vpn.ip.address pw-class L2TPv2
end

Thanks for this post. Some really valuable info here :)
 
@Afriman - does your support team look at PCAP files? Experiencing horrible lags when playing online (Guildwars 2) and logged a ticket (LPG-306-41392). Seems to be more frequent this week then last week. (shockingly I seem to have more lag in online gaming with Afrihost than what I had with MWeb).

I suppose PCAP files of when it happens is about the best choice as pinging an address is really pointless. From the support feedback sofar, it does not look like anyone looks at this in detail (i.e. standard resolution such as "Have you turned it off and on again" or "Phone Telkom to reset port").

It's pretty unusual to submit that kind of specific data - so I couldn't say. Obviously most of our experienced guys would know about them, but it's more a network engineer level thing. However, I don't really think it's necessary to go to that level of complexity to establish where the issue is. The simplest, most direct testing is usually the most effective.

DM me the ticket number and I will take a look ASAP :)
 
Any issues on the network? only getting 2meg speeds on a 4meg account.

http://www.speedtest.net/my-result/2976749110

Code:
Tracing route to afrihost.com [197.242.144.102]
over a maximum of 30 hops:

  1     1 ms    <1 ms    <1 ms  10.0.0.2
  2    13 ms    13 ms    12 ms  105-236-8-193-esr-lo.mtnbusiness.co.za [105.236.8.193]
  3    15 ms    14 ms    13 ms  41.181.221.254
  4    14 ms    12 ms    12 ms  tb-dca-2.za--qux-c.za.mtnbusiness.net [41.181.198.188]
  5    36 ms    36 ms    36 ms  compj-cpt-1.mtnns.net [196.44.18.2]
  6    15 ms    14 ms    14 ms  ct-cr-2.za--tb-cr-1.za.mtnns.net [196.44.31.134]
  7    35 ms    36 ms    35 ms  ct-cr-2.za--rb-cr-1.za.mtnns.net [196.44.31.69]
  8    36 ms    36 ms    35 ms  jh-dca-2.za--jh-cr-1.za-a.mtnns.net [196.44.0.221]
  9    35 ms    34 ms    35 ms  196.30.1.39
 10    36 ms    37 ms    38 ms  tengigabitethernet1-1.gw20.jnb6.za.mtnbusiness.net [196.31.220.23]
 11    36 ms    35 ms    35 ms  tengigabitethernet5-1.hr15.jnb6.za.mtnbusiness.net [196.31.63.198]
 12    35 ms    38 ms    35 ms  cms-gm.afrihost.com [197.242.144.102]
 
It's pretty unusual to submit that kind of specific data - so I couldn't say. Obviously most of our experienced guys would know about them, but it's more a network engineer level thing. However, I don't really think it's necessary to go to that level of complexity to establish where the issue is. The simplest, most direct testing is usually the most effective.

DM me the ticket number and I will take a look ASAP :)

Thanks - PM'ed you ticket number (LPG-306-41392). I also submitted some more PCAP's this morning and when chatting with some other players they also raised the issue that lag/latency is very high. Perhaps it is a specific routing issue, as Speedtests and other downloads work fine. But for gaming there was up to a 5 second lag between keystroke and action.

The support team suggested that I should try a capped account, but why would a capped account be any different than a business uncapped (I was of the opinion that a business account would outperform a capped account or am I wrong?).
 
Things are RIDICULOUSLY slow this morning (Cape Town) - are there issues on the network? Been running like a dream for the last week and a bit, but all of a sudden today it's like wading through a swamp. Barely managing 2-3mbps.
 
Seems to be a local peering issue too - note the latencies and speeds to server other than MTN: (not that the MTN result is particularly impressive at the moment either)

To SAIX server:

2976942231.png

To MTN server:

2976944951.png
 
Hi guys

Sorry I'm only jumping in here now.
Our network is seeing a huge demand since last night, this is suspected to be multiple Apple device and app updates all running at the same time. The usage is on a fairly high curve at the moment but does seem to be slowing dropping off.
 
Hi guys

Sorry I'm only jumping in here now.
Our network is seeing a huge demand since last night, this is suspected to be multiple Apple device and app updates all running at the same time. The usage is on a fairly high curve at the moment but does seem to be slowing dropping off.

Cool - understandable with the IOS updates killing the network, just wanted confirmation that there was indeed an issue. Thanks for the info!
 
Cool - understandable with the IOS updates killing the network, just wanted confirmation that there was indeed an issue. Thanks for the info!

It's a pleasure, thanks for being so understanding! I'll post further updates as soon as they're available :)
 
Hi guys

Sorry I'm only jumping in here now.
Our network is seeing a huge demand since last night, this is suspected to be multiple Apple device and app updates all running at the same time. The usage is on a fairly high curve at the moment but does seem to be slowing dropping off.

Out of interest: Wouldn't your network cater for some edge/CDN caching when it comes to downloads for certain classes of service (such as fairly static updates) - otherwise Microsoft Patch Tuesdays would regularly affect you - or any other type of update? And wouldn't higher class plans (such as Business or Capped) receive better QoS over others?
 
Out of interest: Wouldn't your network cater for some edge/CDN caching when it comes to downloads for certain classes of service (such as fairly static updates) - otherwise Microsoft Patch Tuesdays would regularly affect you - or any other type of update? And wouldn't higher class plans (such as Business or Capped) receive better QoS over others?

OS updates are generally unshaped on our network, and while most are indeed cached whether it be locally or via Akamai it can still put a fair amount of load on our network should a lot of pull requests take place - like the iOS7 updates, bundled with some app updates needed for the OS update to run.

Shaping allows the network to provide better speeds and general QoS for unshaped services like OS bundles, browsing, streaming etc.
 
It's a pleasure, thanks for being so understanding! I'll post further updates as soon as they're available :)

Here the traceroute

PHP:
traceroute to 206.127.146.48 (206.127.146.48), 64 hops max, 52 byte packets
 1  netgear.muffin.lan (172.16.0.1)  2.967 ms  1.142 ms  1.116 ms
 2  105-236-6-129-esr-lo.mtnbusiness.co.za (105.236.6.129)  358.840 ms  293.829 ms  300.675 ms
 3  ipc-recieve-jh-1a.za.mtnbusiness.net (41.181.178.5)  313.807 ms  269.427 ms  189.940 ms
 4  qux-jh-dca-2.za-b.za.mtnbusiness.net (41.181.165.115)  212.225 ms  165.701 ms  152.794 ms
 5  jh-dca-2.za--qux-b.za.mtnbusiness.net (41.181.165.114)  133.208 ms  136.510 ms  153.637 ms
 6  am-tpr-1.nl--am-cr-1.nl-a.mtn.net (209.212.111.141)  357.239 ms  346.030 ms  318.357 ms
 7  xe-4-1-0.edge5.amsterdam1.level3.net (212.72.41.89)  336.750 ms  346.707 ms  355.350 ms
 8  4.69.162.129 (4.69.162.129)  361.512 ms  376.544 ms
    4.69.162.137 (4.69.162.137)  335.385 ms
 9  ae-56-111.ebr1.amsterdam1.level3.net (4.69.153.185)  349.278 ms
    ae-59-114.ebr1.amsterdam1.level3.net (4.69.153.197)  362.563 ms
    ae-58-113.ebr1.amsterdam1.level3.net (4.69.153.193)  351.470 ms
10  ae-47-47.ebr2.dusseldorf1.level3.net (4.69.143.206)  355.532 ms
    ae-48-48.ebr2.dusseldorf1.level3.net (4.69.143.210)  399.033 ms
    ae-45-45.ebr2.dusseldorf1.level3.net (4.69.143.198)  391.355 ms
11  ae-21-21.ebr1.dusseldorf1.level3.net (4.69.143.181)  314.806 ms
    ae-23-23.ebr1.dusseldorf1.level3.net (4.69.143.189)  353.240 ms
    ae-22-22.ebr1.dusseldorf1.level3.net (4.69.143.185)  351.306 ms
12  ae-48-48.ebr3.frankfurt1.level3.net (4.69.143.178)  334.543 ms  331.555 ms
    ae-45-45.ebr3.frankfurt1.level3.net (4.69.143.166)  341.779 ms
13  ae-93-93.csw4.frankfurt1.level3.net (4.69.163.14)  335.309 ms
    ae-63-63.csw1.frankfurt1.level3.net (4.69.163.2)  375.833 ms  321.500 ms
14  ae-2-70.edge6.frankfurt1.level3.net (4.69.154.74)  318.873 ms
    ae-3-80.edge6.frankfurt1.level3.net (4.69.154.138)  359.192 ms
    ae-1-60.edge6.frankfurt1.level3.net (4.69.154.10)  311.028 ms
15  195.16.161.58 (195.16.161.58)  498.172 ms  514.045 ms  503.822 ms
16  206-127-157-86.plaync.com (206.127.157.86)  496.578 ms  605.655 ms  662.136 ms
17  206-127-157-102.plaync.com (206.127.157.102)  580.107 ms  600.528 ms  594.065 ms
18  206-127-157-102.plaync.com (206.127.157.102)  510.618 ms !X  524.339 ms !X  506.410 ms !X
 
Here the traceroute

PHP:
traceroute to 206.127.146.48 (206.127.146.48), 64 hops max, 52 byte packets
 1  netgear.muffin.lan (172.16.0.1)  2.967 ms  1.142 ms  1.116 ms
 2  105-236-6-129-esr-lo.mtnbusiness.co.za (105.236.6.129)  358.840 ms  293.829 ms  300.675 ms
 3  ipc-recieve-jh-1a.za.mtnbusiness.net (41.181.178.5)  313.807 ms  269.427 ms  189.940 ms
 4  qux-jh-dca-2.za-b.za.mtnbusiness.net (41.181.165.115)  212.225 ms  165.701 ms  152.794 ms
 5  jh-dca-2.za--qux-b.za.mtnbusiness.net (41.181.165.114)  133.208 ms  136.510 ms  153.637 ms
 6  am-tpr-1.nl--am-cr-1.nl-a.mtn.net (209.212.111.141)  357.239 ms  346.030 ms  318.357 ms
 7  xe-4-1-0.edge5.amsterdam1.level3.net (212.72.41.89)  336.750 ms  346.707 ms  355.350 ms
 8  4.69.162.129 (4.69.162.129)  361.512 ms  376.544 ms
    4.69.162.137 (4.69.162.137)  335.385 ms
 9  ae-56-111.ebr1.amsterdam1.level3.net (4.69.153.185)  349.278 ms
    ae-59-114.ebr1.amsterdam1.level3.net (4.69.153.197)  362.563 ms
    ae-58-113.ebr1.amsterdam1.level3.net (4.69.153.193)  351.470 ms
10  ae-47-47.ebr2.dusseldorf1.level3.net (4.69.143.206)  355.532 ms
    ae-48-48.ebr2.dusseldorf1.level3.net (4.69.143.210)  399.033 ms
    ae-45-45.ebr2.dusseldorf1.level3.net (4.69.143.198)  391.355 ms
11  ae-21-21.ebr1.dusseldorf1.level3.net (4.69.143.181)  314.806 ms
    ae-23-23.ebr1.dusseldorf1.level3.net (4.69.143.189)  353.240 ms
    ae-22-22.ebr1.dusseldorf1.level3.net (4.69.143.185)  351.306 ms
12  ae-48-48.ebr3.frankfurt1.level3.net (4.69.143.178)  334.543 ms  331.555 ms
    ae-45-45.ebr3.frankfurt1.level3.net (4.69.143.166)  341.779 ms
13  ae-93-93.csw4.frankfurt1.level3.net (4.69.163.14)  335.309 ms
    ae-63-63.csw1.frankfurt1.level3.net (4.69.163.2)  375.833 ms  321.500 ms
14  ae-2-70.edge6.frankfurt1.level3.net (4.69.154.74)  318.873 ms
    ae-3-80.edge6.frankfurt1.level3.net (4.69.154.138)  359.192 ms
    ae-1-60.edge6.frankfurt1.level3.net (4.69.154.10)  311.028 ms
15  195.16.161.58 (195.16.161.58)  498.172 ms  514.045 ms  503.822 ms
16  206-127-157-86.plaync.com (206.127.157.86)  496.578 ms  605.655 ms  662.136 ms
17  206-127-157-102.plaync.com (206.127.157.102)  580.107 ms  600.528 ms  594.065 ms
18  206-127-157-102.plaync.com (206.127.157.102)  510.618 ms !X  524.339 ms !X  506.410 ms !X

Are you running any other internet activity while running this traceroute? Hop 2 (your exchange) looks like it's seeing higher than normal latency.
 
Are you running any other internet activity while running this traceroute? Hop 2 (your exchange) looks like it's seeing higher than normal latency.

Nope - I will take a couple of traceroutes over the next few days, but the lag is pretty much the same (server IPs obviously rotate), but it does feel in the end like a few seconds (although today is not as bad as last night)
 
Well Afrihost now in my home I will always have a 3G connection on. As my ADSL line is too unstable for constant usage. My wife gets upset when she can't browse youtube/twitter so this way I can be sure that there is always a form of internet active.

Thank you Afrirock
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X