Crystal Web DSL performance feedback thread Part 4...

AfricanTech

Honorary Master
Joined
Mar 19, 2010
Messages
40,369
Yep - horrible issues.

PS4 NAT addressing broke - spent 2 hours mucking around with my firewall settings before eventually undoing all the changes I'd made this morning and switching to Vox - voila! everything working.

Really frustrating
 

kripstoe

Expert Member
Joined
Sep 15, 2012
Messages
3,820
My FTTH on CW died. Started having issues yesterday. Is threre a related FTTH thread for CW somewhere?
 

kohlhtor

Expert Member
Joined
Jul 19, 2010
Messages
1,161
I have problem with my VoIP wich not working it’s connect but no voice it works on webafrica
 

kohlhtor

Expert Member
Joined
Jul 19, 2010
Messages
1,161
Sunday and they are. The udp not working is a sign of the ddos mitigation

Yes but the problem starts last night and update on the webpage I chatted to them and to update the status their must speak to the management
 

S.Claus

Expert Member
Joined
Nov 14, 2017
Messages
1,827
It happens during school holidays and over weekends leading me to believe its a bunch of little kids that saw something on youtube. I would personally love to see them get caught.
 

getafix33

Expert Member
Joined
Nov 16, 2006
Messages
1,722
Is their news server still working. Am getting server rejection errors when trying to connect
 

new_in_za2

Senior Member
Joined
Sep 25, 2012
Messages
610
So, my guess on what just happened:

Crystal Web (and/or their upstream providers) are trying to mitigate the attack by filtering UDP traffic. However, UDP is central to DNS, and thus some UDP traffic at least needs to be allowed.

It seems like that the person doing the DDoS attacks found a way to to use UDP packets that look like DNS requests to get their attack through the filtering, and in response Crystal Web (again, and/or their upstream providers) have taken to trying to further filter illegitimate DNS traffic.

However, this new filtering has resulted in some legitimate DNS traffic being filtered too. I've personally had to route all DNS traffic over a VPN to get reliable name lookups. Before I did that, certain domains could no longer resolve.
 

Syphonx

Expert Member
Joined
Jun 25, 2008
Messages
3,864
So, my guess on what just happened:

Crystal Web (and/or their upstream providers) are trying to mitigate the attack by filtering UDP traffic. However, UDP is central to DNS, and thus some UDP traffic at least needs to be allowed.

It seems like that the person doing the DDoS attacks found a way to to use UDP packets that look like DNS requests to get their attack through the filtering, and in response Crystal Web (again, and/or their upstream providers) have taken to trying to further filter illegitimate DNS traffic.

However, this new filtering has resulted in some legitimate DNS traffic being filtered too. I've personally had to route all DNS traffic over a VPN to get reliable name lookups. Before I did that, certain domains could no longer resolve.
Thanks, PIA VPN working fine, just have to set it to use TCP, UDP mode fails to connect.
 

SilverCode

Expert Member
Joined
Feb 26, 2004
Messages
1,218
So, my guess on what just happened:

Crystal Web (and/or their upstream providers) are trying to mitigate the attack by filtering UDP traffic. However, UDP is central to DNS, and thus some UDP traffic at least needs to be allowed.

It seems like that the person doing the DDoS attacks found a way to to use UDP packets that look like DNS requests to get their attack through the filtering, and in response Crystal Web (again, and/or their upstream providers) have taken to trying to further filter illegitimate DNS traffic.

However, this new filtering has resulted in some legitimate DNS traffic being filtered too. I've personally had to route all DNS traffic over a VPN to get reliable name lookups. Before I did that, certain domains could no longer resolve.

My guess is it would be a DNS Amplification attack (link 1, link 2)
 
Top