Crystal Web (NEW ISP) ADSL Feedback

Status
Not open for further replies.
what about http download shaping, will there be any of that?

EDIT: while we staking up the questions will their be enough IPC for the south :P namely cape town and surrounding areas because alot of isp seem to be putting the south way under gauteng :(

No http shaping. And there is more than enough IPC capacity.

To elaborate for my sake. HTTP and HTTPS shaping?

We only shape p2p and nntp traffic. VPN traffic too if we detect that it's being used to bypass shaping.
 
No http shaping. And there is more than enough IPC capacity.



We only shape p2p and nntp traffic. VPN traffic too if we detect that it's being used to bypass shaping.

How would you classify it as being used to bypass shaping? I spend allot of time on a vpn, but it is not to bypass shaping, it might look like it due to high data transfer?
 
I know this is way off topic, just thought I would share this with those interested. http://mybroadband.co.za/vb/showthread.php/627299-XBMC-Add-ons?p=12955957#post12955957

The problem with most "free" addons is they don't use a CDN network, and are usually built quite poorly, as well as having disparate storage systems, and no dedicated delivery systems. The ability to test these services as an ISP is just about 0%, let alone actually prioritise them.

We also can't prioritise everything - we'd love to. Hence why we make it simple - we shape p2p and nntp. We prioritise certain other traffic on our network, and the vast majority of this is real-time video. But we can't prioritise an addon in XBMC for example, as that inevitably involves a hundred different sources and protocols. Unless of course that addon is Netflix, for example.

We'd love to offer unshaped, uncontended at cheap prices but this simply isn't a reality for any ISP. More so for ISPs in SA. When you buy a service that's supposedly unshaped and uncapped, it's NOT uncontended! And I'll be honest with you here, they're desperately hoping that 99% of their users are using only a fraction of their line at any given point in time. If all of their subscribers chucked a few massive 3D Bluray rips and let them go full speed all hours every day, that ISP would be out of business quicker than Mweb go to the competition commission.

Until there are massive reductions in IPC and international bandwidth, but mostly IPC, or until quantum entangled communication becomes a reality (work in SA happening on this right now), we're forever subjected to having to degrade certain performance. The trick is to get this balance right and at the right cost to the ISP and the end user. We believe we've got this right, and we try to make it as simple as humanly possible for our customers. We'll shape your p2p and nntp traffic and try to give you full line speed on everything else at all times.
 
No http shaping. And there is more than enough IPC capacity.



We only shape p2p and nntp traffic. VPN traffic too if we detect that it's being used to bypass shaping.
and you say you only shape top 50% for only p2p/vpn/nntp, does that mean full speed http downloads/streaming during the day(looks at openweb's "when the network is busy" aka 7am-midnighyt)
 
Last edited:
DPI? How would one know if its a "hulu vpn" vs "p2p vpn" ?

Only way that comes to mind to really detect it is by sniffing packets. Depending on the vpn, headers will still be revealed, but secure vpn over SSL would also be a different story, as you would then need to shape the actual protocol.

I am assuming, vpn with maxed out line speed = being used for p2p || nntp, therefor vpn = used to bypass shaping?
 
How would you classify it as being used to bypass shaping? I spend allot of time on a vpn, but it is not to bypass shaping, it might look like it due to high data transfer?

Our upstream providers have an algorithm for this which we share. If it is legitimate traffic and you're affected by it being shaped, then we're more than happy to investigate it and try to fix it for you.

DPI? How would one know if its a "hulu vpn" vs "p2p vpn" ?

Ai necuno, we don't perform DPI. It's not even remotely possible to log everyone's traffic to this sort of extent. Would also hardly serve much benefit to any ISP who did it. It may be beneficial to some ISPs for their very large volume users, but we don't have any intention to ever break the law and log your specific packets. Nor do we have any intention to employ teams to analyse this data if we ever did. :D
 
and you say you only shape top 50% for only p2p/vpn/nntp, does that mean full speed http downloads/streaming during the day(looks at openweb's "when the network is busy" aka 7am-midnighyt)

We only shape p2p and nntp - VPN if we detect it's used to bypass shaping. So yes, customers will attest to the fact that our accounts are fantastic during the day.
 
edited my post to avoid double post seems unnecessary :P

DPI? How would one know if its a "hulu vpn" vs "p2p vpn" ?
you do know there are other ways to access netflix/hulu without a vpn
vpns redirect your whole connection while there are alternatives(DNS services) that just change location data

(i can PM you link if you havnt discovered DNS services yet :P most of them include trials also)

might as well add i do know theres other reasons to use VPN's i just mean that you dont need full line speed for most of those reasons
 
Only way that comes to mind to really detect it is by sniffing packets. Depending on the vpn, headers will still be revealed, but secure vpn over SSL would also be a different story, as you would then need to shape the actual protocol.

I am assuming, vpn with maxed out line speed = being used for p2p || nntp, therefor vpn = used to bypass shaping?

VPN over X or within X is too slow for decent streaming. Besides a good VPN is a lot better than something like Unotelly. VPN used for streaming might also cause near line speed if you stream something that is not sd or "hd", e.g. vimeo's HD streams?

That is what I normally use to test my line speed for drops during streaming because it is a lot more reliable than just simple youtube stream tests.

I suppose its DPI...
 
edited my post to avoid double post seems unnecessary :P

you do know there are other ways to access netflix/hulu without a vpn
vpns redirect your whole connection while there are alternatives(DNS services) that just change location data

(i can PM you link if you havnt discovered DNS services yet :P most of them include trials also)

might as well add i do know theres other reasons to use VPN's i just mean that you dont need full line speed for most of those reasons

You might need to discover a spell checker.

You do know how to manage route tables / routing? It is of course possible to set a secure and non leaking solution with VPN for streaming and or p2p services...
 
VPN over X or within X is too slow for decent streaming. Besides a good VPN is a lot better than something like Unotelly. VPN used for streaming might also cause near line speed if you stream something that is not sd or "hd", e.g. vimeo's HD streams?

That is what I normally use to test my line speed for drops during streaming because it is a lot more reliable than just simple youtube stream tests.

I suppose its DPI...

We're not going to shape your Netflix, so it makes sense to use a DNS rather than a VPN to be honest. Would also avoid the VPN shaping issue entirely if it ever cropped up.
 
Our upstream providers have an algorithm for this which we share. If it is legitimate traffic and you're affected by it being shaped, then we're more than happy to investigate it and try to fix it for you.



Ai necuno, we don't perform DPI. It's not even remotely possible to log everyone's traffic to this sort of extent. Would also hardly serve much benefit to any ISP who did it. It may be beneficial to some ISPs for their very large volume users, but we don't have any intention to ever break the law and log your specific packets. Nor do we have any intention to employ teams to analyse this data if we ever did. :D

sounds good enough for me....just saying, the NSA is watching.

lol, true, packet monitoring for an ISP to that scale would require a full team of analysts or pentesters....O_O...so if you guys ever do that and need someone, let me know :D
 
We're not going to shape your Netflix, so it makes sense to use a DNS rather than a VPN to be honest. Would also avoid the VPN shaping issue entirely if it ever cropped up.

Ja, but then you go and log my news24 habits and gief it to the ANC ;) :D :p

:edit
So there is no detection, only guessing.

if VPN is active and high speed then must be p2p?
 
Last edited:
Ja, but then you go and log my news24 habits and gief it to the ANC ;) :D :p

:edit
So there is no detection, only guessing.

if VPN is active and high speed then must be p2p?

These algorithms will basically use a traffic "estimate" base. Only a file download will use a max amount of data over a set period of time, and with very little altering in download speed. Things like video streaming will alternate is it downloads the required packets, so it will keep fluctuating. So based on that, it will put you on the "naughty" list
 
Ja, but then you go and log my news24 habits and gief it to the ANC ;) :D :p

:edit
So there is no detection, only guessing.

if VPN is active and high speed then must be p2p?

The algo is more complex than that. I'm actually not in a position to really answer your question on this one even if I could. I honestly don't know how the algorithm works. It attempts to detect shaping bypassing is about as much as I know. Even if I knew more I'd probably keep the intricate details to myself. After all, it's only there to catch the naughty ones. :D
 
I have to ask one question then:

Is CW going to be funny with you if you take proper steps to ensure your privacy online?

Afrihost was quite fine with this...

Do I now have to look over my shoulder because you are worried my continuous vpn connections might go a little to fast for a little to long while I browse / stream through it ?
 
These algorithms will basically use a traffic "estimate" base. Only a file download will use a max amount of data over a set period of time, and with very little altering in download speed. Things like video streaming will alternate is it downloads the required packets, so it will keep fluctuating. So based on that, it will put you on the "naughty" list

There's also a lot of historical data upon which to build an algorithm. If you know what legit traffic looks like over a few years, it's not altogether complex to build an algorithm to look for this sort of usage pattern.
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X