Afrihost - Pure Fibre Feedback Thread Part 2

**Notice**

On the 9th of April at 2am we will be migrating the @Afrihost..co.za Openserve realm to the new BNG's. This migration is to move off the legacy Telkom IPC model onto the new Openserve L2TP model.

We do not expect major impact however due to fundamental changes we can not use the existing IP ranges. Clients might see new sessions with natted IPv4 addresses. Ipv6 prefix length will change and now include a bigger prefix.
Hi.

This migration has been moved to Tuesday next week.

It will only be for Johannesburg for now.
 
Last edited:
It loads on my end.
Super strange...


Code:
curl -v https://carmag.co.za
* Host carmag.co.za:443 was resolved.
* IPv6: (none)
* IPv4: 104.21.80.1, 104.21.112.1, 104.21.96.1, 104.21.48.1, 104.21.32.1, 104.21.64.1, 104.21.16.1
*   Trying 104.21.80.1:443...
* Connected to carmag.co.za (104.21.80.1) port 443
* ALPN: curl offers h2,http/1.1
* (304) (OUT), TLS handshake, Client hello (1):
*  CAfile: /etc/ssl/cert.pem
*  CApath: none
* (304) (IN), TLS handshake, Server hello (2):
* (304) (IN), TLS handshake, Unknown (8):
* (304) (IN), TLS handshake, Certificate (11):
* (304) (IN), TLS handshake, CERT verify (15):
* (304) (IN), TLS handshake, Finished (20):
* (304) (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / AEAD-CHACHA20-POLY1305-SHA256 / [blank] / UNDEF
* ALPN: server accepted h2
* Server certificate:
*  subject: CN=carmag.co.za
*  start date: Mar 20 01:36:55 2025 GMT
*  expire date: Jun 18 02:34:36 2025 GMT
*  subjectAltName: host "carmag.co.za" matched cert's "carmag.co.za"
*  issuer: C=US; O=Google Trust Services; CN=WE1
*  SSL certificate verify ok.
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://carmag.co.za/
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: carmag.co.za]
* [HTTP/2] [1] [:path: /]
* [HTTP/2] [1] [user-agent: curl/8.7.1]
* [HTTP/2] [1] [accept: */*]
> GET / HTTP/2
> Host: carmag.co.za
> User-Agent: curl/8.7.1
> Accept: */*
>
* Request completely sent off
< HTTP/2 403
< date: Wed, 09 Apr 2025 10:00:00 GMT
< content-type: text/html
< server: cloudflare
< vary: Accept-Encoding
< cf-cache-status: DYNAMIC
< cf-ray: 92d927aa4adc1380-JNB
< alt-svc: h3=":443"; ma=86400
<
<html>
<head><title>403 Forbidden</title></head>
<body bgcolor="white">
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx</center>
</body>
</html>
* Connection #0 to host carmag.co.za left intact
 
Super strange...


Code:
curl -v https://carmag.co.za
* Host carmag.co.za:443 was resolved.
* IPv6: (none)
* IPv4: 104.21.80.1, 104.21.112.1, 104.21.96.1, 104.21.48.1, 104.21.32.1, 104.21.64.1, 104.21.16.1
*   Trying 104.21.80.1:443...
* Connected to carmag.co.za (104.21.80.1) port 443
* ALPN: curl offers h2,http/1.1
* (304) (OUT), TLS handshake, Client hello (1):
*  CAfile: /etc/ssl/cert.pem
*  CApath: none
* (304) (IN), TLS handshake, Server hello (2):
* (304) (IN), TLS handshake, Unknown (8):
* (304) (IN), TLS handshake, Certificate (11):
* (304) (IN), TLS handshake, CERT verify (15):
* (304) (IN), TLS handshake, Finished (20):
* (304) (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / AEAD-CHACHA20-POLY1305-SHA256 / [blank] / UNDEF
* ALPN: server accepted h2
* Server certificate:
*  subject: CN=carmag.co.za
*  start date: Mar 20 01:36:55 2025 GMT
*  expire date: Jun 18 02:34:36 2025 GMT
*  subjectAltName: host "carmag.co.za" matched cert's "carmag.co.za"
*  issuer: C=US; O=Google Trust Services; CN=WE1
*  SSL certificate verify ok.
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://carmag.co.za/
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: carmag.co.za]
* [HTTP/2] [1] [:path: /]
* [HTTP/2] [1] [user-agent: curl/8.7.1]
* [HTTP/2] [1] [accept: */*]
> GET / HTTP/2
> Host: carmag.co.za
> User-Agent: curl/8.7.1
> Accept: */*
>
* Request completely sent off
< HTTP/2 403
< date: Wed, 09 Apr 2025 10:00:00 GMT
< content-type: text/html
< server: cloudflare
< vary: Accept-Encoding
< cf-cache-status: DYNAMIC
< cf-ray: 92d927aa4adc1380-JNB
< alt-svc: h3=":443"; ma=86400
<
<html>
<head><title>403 Forbidden</title></head>
<body bgcolor="white">
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx</center>
</body>
</html>
* Connection #0 to host carmag.co.za left intact
On which line?
 
For a moment, I got the Cloudflare Human test, and then immediately after that, 403.

So I believe for some reason, my IP must have been flagged for some reason
 
  • Wow
Reactions: BCR
For a moment, I got the Cloudflare Human test, and then immediately after that, 403.

So I believe for some reason, my IP must have been flagged for some reason

please switch off the router, keep it off for 5 minutes
Then, power it back up for a new IP allocation
 
Got a new IP address, website works now. But the issue now it the IP is CGNAT, and I have the parentals Mikrotik connecting to mine via L2TP VPN. And with CGNAT, things are broken.
Please reboot to claim the public IP.
 
Top
Sign up to the MyBroadband newsletter
X