Afrihost - Pure Fibre Feedback Thread

Status
Not open for further replies.
My R1 also arrived with fw v1.0.0. While significantly more stable than the abortion that was my G1, the 5ghz still regularly falls over at least 2-3 times per week.
Today I loaded this test build onto my R1. Once I'm satisfied it hasnt caused any major issues I'll share a link

No issues on my G1 with 3.0.6
 
My R1 also arrived with fw v1.0.0. While significantly more stable than the abortion that was my G1, the 5ghz still regularly falls over at least 2-3 times per week.
Today I loaded this test build onto my R1. Once I'm satisfied it hasnt caused any major issues I'll share a link

The one I'm busy with is for my uncle so I just disabled 5ghz, only a 10mb connection anyway so can't comment on the stability
 
Agree with you on that bud, But let us be honest here, the only way this DDos could have been successful was because of the lack of mitigating risks and so many open ports on their network, that is why it was so successful. I mean even SNMP v2 can be hacked on switches with close eyes lols. Let's not even get started about the mac flooding that must have happened on these networks this weekend...


I’m not sure the concept of DNS amplification attacks has been clearly explained. It’s not a hack. It’s not a multicast broadcast storm or MAC flood. These pale in comparison.

Whenever you want to visit a website, you type in a domain name which is resolved by a DNS server. The DNS server (take Google’s 8.8.8.8) responds to your legitimate request request (let’s say for blizzard.com) with its IP record for that domain. You can also ask a normal DNS server for its entire DNS record list- which it will happily share.

DNS amplification works like this: There are countless devices on the internet that are DNS servers, or act like DNS servers (a few name brand routers come to mind). These devices are programmed to reply to any DNS request they receive. If a host (A) spoofs it’s IP to be that of It’s target (B), in this case an IP re-advertised by Liquid Telecom as a transit provider (This can be any IP on AH, WA or Axxess networks, amongst all the other Liquid transit clients) and sends a tiny (few bytes) request to a DNS server asking for its full DNS table, the server replies to the spoofed IP (B) with its full record (a few dozen KB - tens of thousands of times larger than the initial request from A). In this way, host (A) can create an immense amount of legitimate DNS responses (IE legitimate traffic) to address B. That’s one host amplifying it’s traffic to a single target (B) with ease. Now multiply this by tens of thousands of hosts multiplying traffic to millions of open DNS responders on the internet. The net traffic from each DNS responder to a target is less than 50-100 KBps- but an attack like this uses hundreds of thousands, if not millions of dns responders. To a single host (b), this can quickly saturate its port and even the service provider’s edge capacity. To multiple targets (carpet bombing), this can cripple any network.

DDos mitigation tools can do little to nothing against these attacks, remember- these attacks are simply perfectly normal DNS responses that appear to respond to requests on the target’s network. These attacks have taken down some of the largest networks in the world. These attacks appear to be perfectly legitimate traffic. How does your ISP decide which traffic to allow and which not to? We’re not China, we don’t censor in SA and ISPs don’t get that freedom. ISPs choose to limit DNS and suddenly services start failing on networks. So most scrubbing services will analyse traffic (takes a few secs), determine whether traffic is bad, add it to a blacklist, update edge routers and block the traffic (more secs). Multiply this by millions of hosts and it adds up to downtime. All the while, the traffic is still getting to the edge routers, just not being traversed in the network, but saturating ports.

Liquid acts as a transit service for these target networks. It wasn’t attacked. It merely succumbed to the load of traffic that millions of responses (usually tiny packets) that it fielded on its large edge network throughout the world.

Amplification attacks in theory can generate Tbps levels of traffic. Even if you scrub this at the edge, your ports are still saturated, preventing clean traffic from entering the transit network and finding their way to clients..

Blaming networks for being ill equipped and lazy is not an answer here
Blame hardware vendors for their incompetence in putting millions of DNS responders on the internet without protocols to control this in place.

The security world is frantically looking for solutions to amplification attacks. There aren’t any good ones at the moment except for throwing larger networks at the problem (Cloudflare and Microsoft offer this as a very expensive service) where the sheer number of edge locations they have can filter this traffic out at the source and allow good traffic Through and to its destination.
 
I followed the WA support staffs guide and uploaded the firmware from the .co.za site and it said invalid firmware. The point was not how smart I am but rather that their support should know giving out Russian DIR-825s that the co.za firmware doesn't work.

At least you got *a* quip in about how smart -you- are. :)

[edit] https://prnt.sc/pq7nav -- there's me being a real smart ass, getting kicks out of being the brainy one, nothing to do with trying to point out to AH that they have the wrong info of course.

ftp://ftp.d-link.co.za/DIR/dir825%20(new)/firmware/G1_BlueWhiteGui/ welcome to show me where the RevR1 russian firmware is on that link

Yeah... So me being a snarky jackass left me with egg on my face. I had to update the same router yesterday, and only found the stuff on your link. Please accept my apologies for being a d00s.

And thanks for the link :)
 
Yeah... So me being a snarky jackass left me with egg on my face. I had to update the same router yesterday, and only found the stuff on your link. Please accept my apologies for being a d00s.

And thanks for the link :)
No worries
 
Does anyone know how long it takes to be up and running on AH Pure once your line is returned to the pool? I am hoping my previous ISP stick to their word and release the line tonight at midnight. Ill contact AH to let them know, and then I assume I just wait for the log-in details? All my internets are cancelled from tonight, and I am concerned I wont have internet to watch the Rugby on the weekend if the process is delayed. TIA
 
Does anyone know how long it takes to be up and running on AH Pure once your line is returned to the pool? I am hoping my previous ISP stick to their word and release the line tonight at midnight. Ill contact AH to let them know, and then I assume I just wait for the log-in details? All my internets are cancelled from tonight, and I am concerned I wont have internet to watch the Rugby on the weekend if the process is delayed. TIA

No down time. Just use your AH pppoe details as soon as the others stop. Line will still work in the holding pool. I would strongly suggest you keep following up about the migration to avoid it being suspended in the holding pool. I'm guessing this is Openserve right?
 
No down time. Just use your AH pppoe details as soon as the others stop. Line will still work in the holding pool. I would strongly suggest you keep following up about the migration to avoid it being suspended in the holding pool. I'm guessing this is Openserve right?
Correct, Openserve. Just resent request to release the line. I will also get hold of AH to send me the details as soon as possible to try your suggestion. Thank you.
 
No internet since yesterday afternoon TTConnect Bedfordview area.
Network status page didn't indicate any maintenance / outages.
 
@AfriMan

I downgraded to 100/100 on the 15th of October. My line's still at 200/200 and my AH clientzone says the package is 200/200. I don't know if it just hasn't been actioned yet or what, but I don't want to be billed for 200/200 when I downgraded in time.
 
Anyone else having higher pings than usual tonight? Usually see about 12ms to 1.1.1.1 and tonight there is huge increase all of a sudden to cloudflare.ixp.capetown (196.10.140.198) and 1.1.1.1 after that

734603

The packet loss on my router is normal (it only allows a few pings before blocking requests).
Also a few speedtest servers in Cape Town are now showing slower download speeds than usual and MyBB speedtest Cape Town server also normally shows 12ms ping but tonight showing +-45ms ping

Edit: Ping settled at around 9:40pm back at +-12ms for that cloudflare.ixp and 1.1.1.1 hop and all speed test servers in CPT showing low pings again, praying this isn't going to be a daily occurrence.
 
Last edited:
@AfriMan

I downgraded to 100/100 on the 15th of October. My line's still at 200/200 and my AH clientzone says the package is 200/200. I don't know if it just hasn't been actioned yet or what, but I don't want to be billed for 200/200 when I downgraded in time.

Seems it was actioned early this morning. I trust I won't be billed for the 3 days on 200/200.
 
2 month's in and still very happy with my move, I saw my old isp brought their prices more in line with some of the other Openserve providers recently and even with that I have zero desire to move back to them. :)

My line has been for the most part flawless and while I'm not a heavy downloader, it's reallllly nice to have the extra speed when you need to do an update or want to watch something.

That said, I do have one or two queries @AfriMan

Firstly, is it possible Openserve is throttling international downloads? I've noticed this on a couple of occasions lately when updating games which I assume have their patches served from international servers.

For example, I am busy updating Battlefield V at the moment, on a 100mb line it starts at around 12MB/s which is correct, however halfway through and its down to 6MB/s, almost exactly half... if I pause and resume it goes back up to 12MB/s and then slowly drops back down to 6MB/s.. hmm.

Almost exactly the same thing happened when I reinstalled Rainbow Six Siege, which suggests to me that it's not a line issue or a server issue, but rather that the line is being artificially limited... if I immediately switch to a download served from local servers, IE from Steam (JHB/CPT), I get the full line speed for the duration of the download.

Secondly, on the whole topic of routing and online games, I know you must be sick of these already and I know you guys are working on it, but is there any way it could be stressed to whoever does the routing through Europe that even though on paper 20-30ms is a very insignificant number, in practice, when you are already pushing the limits by playing on international servers, 20-30ms is a huge number that is definitely noticeable.

Throw into that random packet loss or other players with spotty connections and a game quickly goes from enjoyable to unplayable.

With my old ISP thew best ping I could get to Rainbow Six servers in London was around 190ms, now with Afrihost, I'm averaging around 160ms, so using that as an example, the difference is literally night and day.

While I'm sure Ubisoft has made netcode improvements since I last played, at 160ms the game is highly playable to me and if I didn't know I was on an EU server it would be hard for me to tell.

Contrast that to another game I play with servers in Amsterdam, which I used to get a ping of around 160ms to, I now average 220ms... I tried it over the weekend, it was awful, I'm not exaggerating when I say I needed to lead targets a full bodies width at point-blank range to get hit markers and even then, with a weapon that's usually a 3 hit kill, I had to use an entire magazine to get the kill because 90% of shot's didn't register...

A similar thing happens in Overwatch, where with hitscan heroes I can see my aim is solid, but the shot's get dusted and enemies take no damage.

I'm not sure if you've ever seen any of the Battle(non)sense netcode video's on youtube, but he explains perfectly in one of his videos, how for example, Battlefield doesn't allow shot's coming from a user with very high ping, the difference between a shot being counted and disallowed, for local players can sometimes be just 20 or 30ms.

I love you guy's, Im not going anywhere, but please, as someone who use's their line mostly for gaming, better routing would be a huge improvement, even if it's just prioritizing routing of game traffic, I don't mind waiting an extra 20ms for my Netflix movie to load. Thanks in advance :)
 
Last edited:
@AfriMan does AH plan on offering the connection speed combos for OpenServe that MWEB is currently offering?

The 40/10 and 100/20 combos are quite nice options.
 
2 month's in and still very happy with my move, I saw my old isp brought their prices more in line with some of the other Openserve providers recently and even with that I have zero desire to move back to them. :)

My line has been for the most part flawless and while I'm not a heavy downloader, it's reallllly nice to have the extra speed when you need to do an update or want to watch something.

That said, I do have one or two queries @AfriMan

Firstly, is it possible Openserve is throttling international downloads? I've noticed this on a couple of occasions lately when updating games which I assume have their patches served from international servers.

For example, I am busy updating Battlefield V at the moment, on a 100mb line it starts at around 12MB/s which is correct, however halfway through and its down to 6MB/s, almost exactly half... if I pause and resume it goes back up to 12MB/s and then slowly drops back down to 6MB/s.. hmm.

Almost exactly the same thing happened when I reinstalled Rainbow Six Siege, which suggests to me that it's not a line issue or a server issue, but rather that the line is being artificially limited... if I immediately switch to a download served from local servers, IE from Steam (JHB/CPT), I get the full line speed for the duration of the download.

Secondly, on the whole topic of routing and online games, I know you must be sick of these already and I know you guys are working on it, but is there any way it could be stressed to whoever does the routing through Europe that even though on paper 20-30ms is a very insignificant number, in practice, when you are already pushing the limits by playing on international servers, 20-30ms is a huge number that is definitely noticeable.

Throw into that random packet loss or other players with spotty connections and a game quickly goes from enjoyable to unplayable.

With my old ISP thew best ping I could get to Rainbow Six servers in London was around 190ms, now with Afrihost, I'm averaging around 160ms, so using that as an example, the difference is literally night and day.

While I'm sure Ubisoft has made netcode improvements since I last played, at 160ms the game is highly playable to me and if I didn't know I was on an EU server it would be hard for me to tell.

Contrast that to another game I play with servers in Amsterdam, which I used to get a ping of around 160ms to, I now average 220ms... I tried it over the weekend, it was awful, I'm not exaggerating when I say I needed to lead targets a full bodies width at point-blank range to get hit markers and even then, with a weapon that's usually a 3 hit kill, I had to use an entire magazine to get the kill because 90% of shot's didn't register...

A similar thing happens in Overwatch, where with hitscan heroes I can see my aim is solid, but the shot's get dusted and enemies take no damage.

I'm not sure if you've ever seen any of the Battle(non)sense netcode video's on youtube, but he explains perfectly in one of his videos, how for example, Battlefield doesn't allow shot's coming from a user with very high ping, the difference between a shot being counted and disallowed, for local players can sometimes be just 20 or 30ms.

I love you guy's, Im not going anywhere, but please, as someone who use's their line mostly for gaming, better routing would be a huge improvement, even if it's just prioritizing routing of game traffic, I don't mind waiting an extra 20ms for my Netflix movie to load. Thanks in advance :)


Just a few points. BFV or anything origin is local. It might be a disk IO issue with updating and downloading happening the same time. Afrihost does not shape or throttle anything trust me I tested and after 8-9TB just on torrents with download and seeding 24/7 the connection did not skip a beat. Openserve itself as a cable provider does not shape or throttle although there might be contention on their side but I don't think we have reached prices where fibre contention will play a role just yet. The 100Mbps and 200Mbps lines are just not that affordable and people rather go for the 10 or 20Mbps lines.

Latency to London is great because it goes to CPT then over WACS to the UK. With the rest of EU it goes via ESSAY or SEACOM around the East coast and lands in France. Despite the latency at 159ms when it lands in France for some reason the latency is 20-30ms higher as it goes into EU.
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X