Crystal Web DSL performance feedback thread Part 4...

I'm on Vumatel ftth with CW and having the same issues this weekend.
 
Yep - horrible issues.

PS4 NAT addressing broke - spent 2 hours mucking around with my firewall settings before eventually undoing all the changes I'd made this morning and switching to Vox - voila! everything working.

Really frustrating
 
My FTTH on CW died. Started having issues yesterday. Is threre a related FTTH thread for CW somewhere?
 
It happens during school holidays and over weekends leading me to believe its a bunch of little kids that saw something on youtube. I would personally love to see them get caught.
 
Is their news server still working. Am getting server rejection errors when trying to connect
 
Same, from around the time my IP was switched from IS to Evonet/Crystal.....
Ddos started when cape Town was switched over. My guess is whoever is behind this is an insider or a customer
 
So, my guess on what just happened:

Crystal Web (and/or their upstream providers) are trying to mitigate the attack by filtering UDP traffic. However, UDP is central to DNS, and thus some UDP traffic at least needs to be allowed.

It seems like that the person doing the DDoS attacks found a way to to use UDP packets that look like DNS requests to get their attack through the filtering, and in response Crystal Web (again, and/or their upstream providers) have taken to trying to further filter illegitimate DNS traffic.

However, this new filtering has resulted in some legitimate DNS traffic being filtered too. I've personally had to route all DNS traffic over a VPN to get reliable name lookups. Before I did that, certain domains could no longer resolve.
 
So, my guess on what just happened:

Crystal Web (and/or their upstream providers) are trying to mitigate the attack by filtering UDP traffic. However, UDP is central to DNS, and thus some UDP traffic at least needs to be allowed.

It seems like that the person doing the DDoS attacks found a way to to use UDP packets that look like DNS requests to get their attack through the filtering, and in response Crystal Web (again, and/or their upstream providers) have taken to trying to further filter illegitimate DNS traffic.

However, this new filtering has resulted in some legitimate DNS traffic being filtered too. I've personally had to route all DNS traffic over a VPN to get reliable name lookups. Before I did that, certain domains could no longer resolve.
Thanks, PIA VPN working fine, just have to set it to use TCP, UDP mode fails to connect.
 
So, my guess on what just happened:

Crystal Web (and/or their upstream providers) are trying to mitigate the attack by filtering UDP traffic. However, UDP is central to DNS, and thus some UDP traffic at least needs to be allowed.

It seems like that the person doing the DDoS attacks found a way to to use UDP packets that look like DNS requests to get their attack through the filtering, and in response Crystal Web (again, and/or their upstream providers) have taken to trying to further filter illegitimate DNS traffic.

However, this new filtering has resulted in some legitimate DNS traffic being filtered too. I've personally had to route all DNS traffic over a VPN to get reliable name lookups. Before I did that, certain domains could no longer resolve.

My guess is it would be a DNS Amplification attack (link 1, link 2)
 
Top
Sign up to the MyBroadband newsletter
X