Status
Not open for further replies.
[MENTION=394133]PBCool[/MENTION]

am getting some packet loss as well ( not massive) this on update 200/200 via octotel ( upgraded from 100/100):
COOL-20180503-99762
cisp.co.za
HOST: mint Loss% Snt Last Avg Best Wrst StDev
1.|-- 192.168.1.1 0.0% 1000 0.4 2.6 0.1 27.7 7.5
2.|-- 155.93.250.1 0.1% 1000 4.3 8.1 2.4 120.0 14.8
3.|-- 154.0.1.245 0.5% 1000 23.2 27.9 21.9 167.9 15.5
4.|-- 154.0.4.53 0.4% 1000 24.2 28.6 22.4 186.5 16.4
| `|-- 154.0.3.21
5.|-- 154.0.1.137 1.0% 1000 24.1 28.5 22.4 141.1 14.9
| `|-- 154.0.2.113
6.|-- 154.0.3.226 0.6% 1000 24.1 28.9 22.4 192.8 16.8
7.|-- 154.0.13.95 0.5% 1000 24.0 29.0 22.6 172.1 15.4

apple.com
HOST: mint Loss% Snt Last Avg Best Wrst StDev
1.|-- 192.168.1.1 0.0% 10 0.4 0.4 0.3 0.5 0.0
2.|-- 155.93.250.1 0.0% 10 3.5 4.0 2.9 7.2 1.2
3.|-- 154.0.3.106 0.0% 10 144.0 144.3 143.9 144.6 0.2
4.|-- 195.66.226.145 0.0% 10 145.2 145.7 144.6 146.8 0.8
5.|-- 17.0.11.17 0.0% 10 233.5 232.3 227.6 257.8 9.1
6.|-- 17.1.2.189 0.0% 10 229.9 229.7 228.2 232.3 1.2
7.|-- ??? 100.0 10 0.0 0.0 0.0 0.0 0.0
8.|-- 17.1.0.237 0.0% 10 245.6 230.9 227.8 245.6 5.3
9.|-- 17.0.80.75 0.0% 10 230.9 231.3 230.9 231.8 0.3
10.|-- 17.168.2.161 0.0% 10 232.4 232.5 231.4 235.6 1.3
11.|-- ??? 100.0 10 0.0 0.0 0.0 0.0 0.0

mtr --no-dns --report -c 10 tumblr.com
HOST: mint Loss% Snt Last Avg Best Wrst StDev
1.|-- 192.168.1.1 0.0% 10 0.4 0.4 0.3 0.4 0.0
2.|-- 155.93.250.1 0.0% 10 4.0 6.6 2.5 29.8 8.2
3.|-- 154.0.3.106 0.0% 10 144.2 144.0 143.7 144.4 0.3
4.|-- 195.66.224.115 0.0% 10 146.5 147.3 143.7 161.4 5.3
5.|-- 66.196.68.137 0.0% 10 144.6 145.8 144.6 148.5 1.2
6.|-- 216.115.100.26 0.0% 10 212.0 213.0 211.9 214.6 1.0
7.|-- 216.115.111.24 0.0% 10 223.3 225.4 222.9 231.6 3.0
8.|-- 72.30.223.30 0.0% 10 223.5 223.7 221.7 228.8 2.4
9.|-- 74.6.227.137 0.0% 10 222.8 223.0 221.7 224.2 0.8
10.|-- 74.6.122.41 0.0% 10 223.0 223.8 221.6 227.6 2.1
11.|-- 74.6.64.1 0.0% 10 222.4 222.4 221.8 224.5 0.8
12.|-- 74.6.64.148 10.0% 10 222.6 222.4 221.6 224.0 0.7
13.|-- 74.6.64.145 0.0% 10 221.9 222.8 221.6 225.4 1.3
14.|-- 74.6.64.152 0.0% 10 223.0 222.4 221.7 223.0 0.4
15.|-- ??? 100.0 10 0.0 0.0 0.0 0.0 0.0
Octotel.co.za
mint Loss% Snt Last Avg Best Wrst StDev
1.|-- 192.168.1.1 0.0% 10 0.4 0.4 0.4 0.4 0.0
2.|-- 155.93.250.1 0.0% 10 3.2 3.7 2.7 4.7 0.7
3.|-- 154.0.3.106 0.0% 10 144.1 144.3 143.8 144.7 0.3
4.|-- 216.66.80.169 0.0% 10 143.8 144.9 143.8 147.2 1.2
5.|-- 184.105.64.233 0.0% 10 143.7 145.0 143.7 148.2 1.2
6.|-- 213.248.93.81 0.0% 10 146.6 144.7 143.7 146.6 1.1
7.|-- 62.115.9.174 10.0% 10 144.5 144.3 143.9 144.6 0.2
8.|-- 80.231.62.150 0.0% 10 146.3 145.8 144.8 146.9 0.7
9.|-- 109.74.207.15 0.0% 10 145.2 146.2 145.1 148.1 1.1
10.|-- 139.162.245.207 10.0% 10 148.5 145.9 144.9 148.5 1.2
 
Well it's only on your first trace there was loss on your first hop which would indicate a line thing. But the other traces don't have any loss.
 
Just an update from my side, things are starting to work after waiting overnight. I did some more digging and it seems it might be the change of routes with hitting Akamai CDN which has previous issues with SSL. I'm guessing I might be hitting a different one of their edge servers compared to being on Google DNS / previous provider.

Honestly I'm not sure, I haven't changed any configurations and after constant refreshes on my devices through the course of the night, they just started resolving. I noticed on my desktop that this affected Adobe CC, Steam and Apple.com, all 3 systems which use strong SSL and break otherwise.

Also did a benchmark overnight for DNS and Google DNS is showing up as being much faster on average. Not surprising considering their size but curious to know if there's any reason for using the CISP DNS server over Google DNS? Guessing maybe better local lookups/routing?

I'll give it a few days and then see again since it's still a bit up and down. Just posting here in case anyone else ever experiences issues.

On the positive, after moving to CISP web calls and general browsing has felt snappier, so I'm excited to be on the network.
 
Just an update from my side, things are starting to work after waiting overnight. I did some more digging and it seems it might be the change of routes with hitting Akamai CDN which has previous issues with SSL. I'm guessing I might be hitting a different one of their edge servers compared to being on Google DNS / previous provider.

Honestly I'm not sure, I haven't changed any configurations and after constant refreshes on my devices through the course of the night, they just started resolving. I noticed on my desktop that this affected Adobe CC, Steam and Apple.com, all 3 systems which use strong SSL and break otherwise.

Also did a benchmark overnight for DNS and Google DNS is showing up as being much faster on average. Not surprising considering their size but curious to know if there's any reason for using the CISP DNS server over Google DNS? Guessing maybe better local lookups/routing?

I'll give it a few days and then see again since it's still a bit up and down. Just posting here in case anyone else ever experiences issues.

On the positive, after moving to CISP web calls and general browsing has felt snappier, so I'm excited to be on the network.

Basically using an Open DNS like Googles in the past would bypass any on-net caching, it's always recommended to use your providers DNS resolver.

We have an akamai cluster on net, that being said all of your traces either route to a cluster overseas or directly to Apples network. The CDN providers manage this kind of thing, so might have just been a temporary issue.
 
Basically using an Open DNS like Googles in the past would bypass any on-net caching, it's always recommended to use your providers DNS resolver.

We have an akamai cluster on net, that being said all of your traces either route to a cluster overseas or directly to Apples network. The CDN providers manage this kind of thing, so might have just been a temporary issue.

Cheers for that! I see you mentioned 'in the past', wonder if it's still as applicable now.

Anyways, thanks for the troubleshooting, have a good Friday. Appreciate all the help as always!
 
Cheers for that! I see you mentioned 'in the past', wonder if it's still as applicable now.

Anyways, thanks for the troubleshooting, have a good Friday. Appreciate all the help as always!

Yes so many of them now have the "CDN related" entries which should help with connecting you to the correct source, but it is still always better to use your providers DNS.
 
Yes so many of them now have the "CDN related" entries which should help with connecting you to the correct source, but it is still always better to use your providers DNS.

Have you guys run tests using 1.1.1.1 as your DNS? I could swear browsing is snappier since I switched.
 
Have you guys run tests using 1.1.1.1 as your DNS? I could swear browsing is snappier since I switched.

In Cape Town 1.1.1.1 easily outperform 8.8.8.8 both in dns response times and directing us to an akamai cluster in Cape Town instead of JHB.
 
In Cape Town 1.1.1.1 easily outperform 8.8.8.8 both in dns response times and directing us to an akamai cluster in Cape Town instead of JHB.

Well 8.8.8.8 is only hosted in JHB, which is why you would have a ~20ms overhead obviously :). Whereas Cloudflare is national now with their caches.
 
Well 8.8.8.8 is only hosted in JHB, which is why you would have a ~20ms overhead obviously :). Whereas Cloudflare is national now with their caches.
True that. But also look at 9.9.9.9 which is in CPT too.

dnsbench.png

Lets look at the CDN from these:

CISP 155.93.255.1 (fastest from dnsbench)
Code:
root@monitor ~ # dig cdn.steampowered.com @155.93.255.1 +short
storefront.akamai.steamstatic.com.edgesuite.net.
a1189.g1.akamai.net.
154.0.14.7
154.0.14.9
root@monitor ~ # ping -c4 154.0.14.7
PING 154.0.14.7 (154.0.14.7) 56(84) bytes of data.
64 bytes from 154.0.14.7: icmp_seq=2 ttl=58 time=31.9 ms
64 bytes from 154.0.14.7: icmp_seq=3 ttl=58 time=30.3 ms
64 bytes from 154.0.14.7: icmp_seq=4 ttl=58 time=40.0 ms

--- 154.0.14.7 ping statistics ---
4 packets transmitted, 3 received, 25% packet loss, time 3002ms
rtt min/avg/max/mdev = 30.367/34.104/40.009/4.226 ms

CloudFlare 1.0.0.1
Code:
root@monitor ~ # dig cdn.steampowered.com @1.0.0.1 +short
storefront.akamai.steamstatic.com.edgesuite.net.
a1189.g1.akamai.net.
197.84.130.19
197.84.130.25

root@monitor ~ # ping -c4 197.84.130.19
PING 197.84.130.19 (197.84.130.19) 56(84) bytes of data.
64 bytes from 197.84.130.19: icmp_seq=1 ttl=58 time=2.32 ms
64 bytes from 197.84.130.19: icmp_seq=2 ttl=58 time=2.15 ms
64 bytes from 197.84.130.19: icmp_seq=3 ttl=58 time=2.10 ms
64 bytes from 197.84.130.19: icmp_seq=4 ttl=58 time=2.02 ms

--- 197.84.130.19 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3004ms
rtt min/avg/max/mdev = 2.028/2.155/2.328/0.119 ms

9.9.9.9
Code:
root@monitor ~ # ping -c4 9.9.9.9
PING 9.9.9.9 (9.9.9.9) 56(84) bytes of data.
64 bytes from 9.9.9.9: icmp_seq=1 ttl=59 time=4.17 ms
64 bytes from 9.9.9.9: icmp_seq=2 ttl=59 time=2.18 ms
64 bytes from 9.9.9.9: icmp_seq=3 ttl=59 time=2.10 ms
64 bytes from 9.9.9.9: icmp_seq=4 ttl=59 time=2.80 ms

--- 9.9.9.9 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3003ms
rtt min/avg/max/mdev = 2.103/2.815/4.175/0.832 ms

root@monitor ~ # dig cdn.steampowered.com @9.9.9.9 +short
storefront.akamai.steamstatic.com.edgesuite.net.
a1189.g1.akamai.net.
23.215.102.48
23.215.102.10

root@monitor ~ # ping -c4 23.215.102.48
PING 23.215.102.48 (23.215.102.48) 56(84) bytes of data.
64 bytes from 23.215.102.48: icmp_seq=1 ttl=51 time=272 ms
64 bytes from 23.215.102.48: icmp_seq=2 ttl=51 time=272 ms
64 bytes from 23.215.102.48: icmp_seq=3 ttl=51 time=272 ms
64 bytes from 23.215.102.48: icmp_seq=4 ttl=51 time=273 ms

--- 23.215.102.48 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3001ms
rtt min/avg/max/mdev = 272.534/272.828/273.564/0.564 ms

And so, CloudFlare wins not only in benchmark, but also at good CDN results for Akamai.
 
Yeah so resolution speed looks to almost be identical, and our DNS will point to our on-net cluster in JHB as preference. Akamai used to offer a distributed model of clusters but now have moved to a more "Google model" where they will rather just upgrade a single cluster and expect you to carry the traffic via longhaul. It's actually strange it's pointing you to use an Mweb cluster.
 
Hi Paul,

Did Netflix not route to Local on net server/cdn "akamai" at CISP?
Seems to be routing international now!

netflix.co.za
Tracing route to netflix.co.za [52.210.7.69]

|------------------------------------------------------------------------------------------|
| WinMTR statistics |
| Host - % | Sent | Recv | Best | Avrg | Wrst | Last |
|------------------------------------------------|------|------|------|------|------|------|
| 192.168.1.1 - 0 | 10 | 10 | 0 | 0 | 1 | 0 |
| 155.93.246.1 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.1.125 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.1.13 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.3.106 - 0 | 10 | 10 | 142 | 142 | 143 | 142 |
| 195.66.225.175 - 0 | 10 | 10 | 142 | 154 | 249 | 143 |
| 54.239.100.216 - 0 | 10 | 10 | 142 | 152 | 164 | 147 |
| 54.239.101.99 - 0 | 10 | 10 | 142 | 142 | 145 | 143 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| 54.239.41.212 - 0 | 10 | 10 | 151 | 152 | 154 | 152 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| 52.93.7.168 - 0 | 10 | 10 | 153 | 169 | 181 | 153 |
| 52.93.101.103 - 0 | 10 | 10 | 151 | 152 | 155 | 151 |
| 52.93.101.126 - 0 | 10 | 10 | 154 | 168 | 183 | 154 |
| 52.93.36.175 - 0 | 10 | 10 | 151 | 152 | 155 | 152 |
| 176.32.106.133 - 0 | 10 | 10 | 152 | 152 | 155 | 152 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
|________________________________________________|______|______|______|______|______|______|
WinMTR v0.92 GPL V2 by Appnor MSP - Fully Managed Hosting & Cloud Provider

Using CISP DNS here in Cape Town.
DNS Servers . . . . . . . . . . . : 155.93.255.1
154.0.1.1
 
Hi Paul,

Did Netflix not route to Local on net server/cdn "akamai" at CISP?
Seems to be routing international now!

netflix.co.za
Tracing route to netflix.co.za [52.210.7.69]

|------------------------------------------------------------------------------------------|
| WinMTR statistics |
| Host - % | Sent | Recv | Best | Avrg | Wrst | Last |
|------------------------------------------------|------|------|------|------|------|------|
| 192.168.1.1 - 0 | 10 | 10 | 0 | 0 | 1 | 0 |
| 155.93.246.1 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.1.125 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.1.13 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.3.106 - 0 | 10 | 10 | 142 | 142 | 143 | 142 |
| 195.66.225.175 - 0 | 10 | 10 | 142 | 154 | 249 | 143 |
| 54.239.100.216 - 0 | 10 | 10 | 142 | 152 | 164 | 147 |
| 54.239.101.99 - 0 | 10 | 10 | 142 | 142 | 145 | 143 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| 54.239.41.212 - 0 | 10 | 10 | 151 | 152 | 154 | 152 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| 52.93.7.168 - 0 | 10 | 10 | 153 | 169 | 181 | 153 |
| 52.93.101.103 - 0 | 10 | 10 | 151 | 152 | 155 | 151 |
| 52.93.101.126 - 0 | 10 | 10 | 154 | 168 | 183 | 154 |
| 52.93.36.175 - 0 | 10 | 10 | 151 | 152 | 155 | 152 |
| 176.32.106.133 - 0 | 10 | 10 | 152 | 152 | 155 | 152 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
|________________________________________________|______|______|______|______|______|______|
WinMTR v0.92 GPL V2 by Appnor MSP - Fully Managed Hosting & Cloud Provider

Using CISP DNS here in Cape Town.
DNS Servers . . . . . . . . . . . : 155.93.255.1
154.0.1.1
It depends on the content, it doesn't mean "all" Akamai traffic would come from the on-net cluster.
 
Hi Paul,

Did Netflix not route to Local on net server/cdn "akamai" at CISP?
Seems to be routing international now!

netflix.co.za
Tracing route to netflix.co.za [52.210.7.69]

|------------------------------------------------------------------------------------------|
| WinMTR statistics |
| Host - % | Sent | Recv | Best | Avrg | Wrst | Last |
|------------------------------------------------|------|------|------|------|------|------|
| 192.168.1.1 - 0 | 10 | 10 | 0 | 0 | 1 | 0 |
| 155.93.246.1 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.1.125 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.1.13 - 0 | 10 | 10 | 1 | 1 | 4 | 1 |
| 154.0.3.106 - 0 | 10 | 10 | 142 | 142 | 143 | 142 |
| 195.66.225.175 - 0 | 10 | 10 | 142 | 154 | 249 | 143 |
| 54.239.100.216 - 0 | 10 | 10 | 142 | 152 | 164 | 147 |
| 54.239.101.99 - 0 | 10 | 10 | 142 | 142 | 145 | 143 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| 54.239.41.212 - 0 | 10 | 10 | 151 | 152 | 154 | 152 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| 52.93.7.168 - 0 | 10 | 10 | 153 | 169 | 181 | 153 |
| 52.93.101.103 - 0 | 10 | 10 | 151 | 152 | 155 | 151 |
| 52.93.101.126 - 0 | 10 | 10 | 154 | 168 | 183 | 154 |
| 52.93.36.175 - 0 | 10 | 10 | 151 | 152 | 155 | 152 |
| 176.32.106.133 - 0 | 10 | 10 | 152 | 152 | 155 | 152 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
| No response from host - 100 | 2 | 0 | 0 | 0 | 0 | 0 |
|________________________________________________|______|______|______|______|______|______|
WinMTR v0.92 GPL V2 by Appnor MSP - Fully Managed Hosting & Cloud Provider

Using CISP DNS here in Cape Town.
DNS Servers . . . . . . . . . . . : 155.93.255.1
154.0.1.1

Thats probably to be expected. Netflix's servers in JHB is for streams, not per say their website.
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X