Afrihost - Pure Fibre Feedback Thread Part 2

@AfriNatic @Afrigirl -- intermittent DNS lookup failures timeouts acrosss Google, Cloudflare, OpenDNS, and Afrihost's own DNS is non- funtcional. Any ideas?
8.8.8.8 timeouts 100%
8.8.4.4 timeouts about 30%
1.1.1.1 timeouts 100%
1.0.0.0.1 timeouts 100%
others about 30% timeouts
Afrihosts DNS servers timeouts 100%
 
Last edited:
This should be resolved, it affected a few of our Openserve clients in a specific range earlier.
Yes much better now thank you. Connection dropped, restarted ONT and Router, and then unreliable DNS. What was the problem?
 
This should be resolved, it affected a few of our Openserve clients in a specific range earlier.
Cloudflare DNS is still unreachable.
Google DNS is still unreachable.
Afrihost DNS is still unreachable.

Others intermittent. As if traffic on port 53 is being rate limited.
 
Last edited:
This sounds like an outage or line issue rather than a DNS issue. What does a traceroute to 8.8.8.8 look like?
Nope. Internet is working, but it's luck of the draw whether a page loads or not - if it doesn't then it's because of DNS lookup failure, refresh a few times and it works.

At the moment these DNS servers work:
209.212.97.1
129.250.35.251
208.67.222.222


Code:
pi@raspi3 ~> tracepath 8.8.8.8
 1?: [LOCALHOST]                      pmtu 1500
 1:  10.0.0.1                                              0.952ms
 1:  10.0.0.1                                              0.759ms
 2:  10.0.0.1                                              0.749ms pmtu 1492
 2:  no reply
 3:  no reply
 4:  no reply
 5:  102.67.177.31                                         5.741ms asymm  9
 6:  no reply
.
.
.
30:  no reply
     Too many hops: pmtu 1492
     Resume: pmtu 1492


Code:
pi@raspi3:~$ ping 1.1.1.1
PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
^C
--- 1.1.1.1 ping statistics ---
102 packets transmitted, 0 received, 100% packet loss, time 101007ms
 
Nope. Internet is working, but it's luck of the draw whether a page loads or not - if it doesn't then it's because of DNS lookup failure, refresh a few times and it works.

At the moment these DNS servers work:
209.212.97.1
129.250.35.251
208.67.222.222


Code:
pi@raspi3 ~> tracepath 8.8.8.8
 1?: [LOCALHOST]                      pmtu 1500
 1:  10.0.0.1                                              0.952ms
 1:  10.0.0.1                                              0.759ms
 2:  10.0.0.1                                              0.749ms pmtu 1492
 2:  no reply
 3:  no reply
 4:  no reply
 5:  102.67.177.31                                         5.741ms asymm  9
 6:  no reply
.
.
.
30:  no reply
     Too many hops: pmtu 1492
     Resume: pmtu 1492


Code:
pi@raspi3:~$ ping 1.1.1.1
PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
^C
--- 1.1.1.1 ping statistics ---
102 packets transmitted, 0 received, 100% packet loss, time 101007ms

Dropped you a pm for details so I can have a look for you.
 
Please Note the below change is currently in progress.

Vumatel Change #CHG-000008156 | Multiple Sites; No Connectivity ; Service Migration

Cutover services from the current legacy 12700 in Rondebosch (wc-trct-hw-me1) to the new 12700, also migrate Reach subscribers off the current BNG's to the new BNG's.


Sites affected:

- Teraco_Rondebosch: Stellenbosch, Somerset West, Macassar, Sitari Estate, CTFS_Blue_downs, Blue Downs 1, Blue Downs 2, Mfuleni, Mitchells, Tafelsig, Montague Gardens

- Teraco_Brackenfell:
Port Elizabeth: Algoa Park, Arcadia, Kwa Nobuhle, Motherwell.
IS_East London: Buffalo Flats, Mdantsane, Gonubie,

Change Impact: No connectivity

Window : 2025/06/19, 22:00 to 2025/06/20, 06:00
 
@Afrigirl Had an issue about 2-3 weeks ago where ping to the first 2 hops NNI & behind that was very high. You asked me to exclusively use Afrihost DNS servers, but started having issues with my email webmail.

For some reason, the Afrihost DNS servers don't have entries for some things. See below:

Code:
** server can't find deref-mail.com: NXDOMAIN
> server 169.1.1.3
Default server: 169.1.1.3
Address: 169.1.1.3#53
> deref-mail.com
Server:        169.1.1.3
Address:    169.1.1.3#53

** server can't find deref-mail.com: NXDOMAIN
> server 1.1.1.1
Default server: 1.1.1.1
Address: 1.1.1.1#53
> deref-mail.com
Server:        1.1.1.1
Address:    1.1.1.1#53

Non-authoritative answer:
Name:    deref-mail.com
Address: 74.208.232.57
>
 
Any chance any rep is online able to do a Openserv port reset?
 
Seems AfriHost provided internet is failing every few minutes for the past 30 minutes or so, at least in Pretoria East. anyone else?
 
Yeah my Mikrotik complains about MTU issues. #AfrihostUpandDown in Pretoria (East)
 
Hi All

We are doing an Emergency roll back until the Vendor of our new BNGs can release a firmware update for us.
 
Testing in production?

We have been testing these for a while now. Almost a year in fact. The issues that are being observed now didn't present until we loaded the BNG's with a lot of subscribers.

Vendor acknowledged the issue and is working on a release for us. In the meantime, to mitigate the impact we are rolling back and will attempt the migration again once the BNG's are updated.
 
@Afrigirl @AfriNatic

Hi, I am having intermittent issues with Microsoft services hosted on their Azure Front Door CDN (msedge) service over IPv6. This issue has been happening for a few days now, both on the new BNGs and old BNGs. I've rebooted both my ONT and my router. I'm using Afrihost's DNS servers. This issue persisted on both the new and old BNGs, across different IPv6 prefixes. It seems to work fine over IPv4.

Some of the services affected over IPv6:
  • code.visualstudio.com (Visual Studio Code can't update, and can't load code.visualstudio.com in a normal web browser or via cURL)
  • wcpstatic.microsoft.com (microsoft.com, minecraft.net can't TLS handshake to this)
  • cdn.botframework.com (azure.microsoft.com can't TLS handshake to this)
  • launcher.mojang.com (Minecraft Launcher tries to do update check before showing UI but can't so it doesn't show the UI at all)
  • js.monitor.azure.com
  • s-part-0028.t-0009.t-msedge.net (commonality across all of these)
These all resolve down to s-part-0028.t-0009.t-msedge.net with IPv6 address 2620:1ec:bdf::56

When trying to load over HTTPS in the browser, client apps (Visual Studio Code, Minecraft Launcher, etc...) or even via cURL in the terminal, it hangs in the middle of the TLS handshake:

Code:
host [~]$ curl -Lvk6 https://s-part-0028.t-0009.t-msedge.net
* Host s-part-0028.t-0009.t-msedge.net:443 was resolved.
* IPv6: 2620:1ec:bdf::56
* IPv4: (none)
*   Trying [2620:1ec:bdf::56]:443...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):

And when using plaintext HTTP, it hangs while waiting for a response from the server:

Code:
host [~]$ curl -Lvk6 http://s-part-0028.t-0009.t-msedge.net
* Host s-part-0028.t-0009.t-msedge.net:80 was resolved.
* IPv6: 2620:1ec:bdf::56
* IPv4: (none)
*   Trying [2620:1ec:bdf::56]:80...
* Connected to s-part-0028.t-0009.t-msedge.net (2620:1ec:bdf::56) port 80
* using HTTP/1.x
> GET / HTTP/1.1
> Host: s-part-0028.t-0009.t-msedge.net
> User-Agent: curl/8.14.1
> Accept: */*
>
* Request completely sent off

Strange part: if you use cURL and it hangs at first, cancel it and immediately run cURL again - sometimes it will actually successfully load and work for a short while after that. And then break again.

I don't know where the issue lies - with Afrihost or with Microsoft (or somewhere else) - but this has been broken for quite a few days :(
 
Top
Sign up to the MyBroadband newsletter
X