Web Squad ISP

Status
Not open for further replies.
I know the problem as the local suppliers like to rip the ring on these platforms.
I import my own x86 platforms that have multiple NICs and starting with a desktop one that can support encryption from 400mbs and then a rack one that goes up to about 2.5gbs.
I use them for my own sd-wan platforms and was thinking of making them available for generic use but don't know if it is worth the effort. I've been asked to do the rack ones. People will spend a huge amount on their gaming or desktop systems but skimp on the networking.
This is the desktop:
View attachment 1287294
This is the rack variant. Can be used as a VPN aggregator running stuff like wireguard/strongswan in addition to pfsense, etc. (Both have AES).
rack.png
 
What would the cost be? Running gigabit so would need more than 400. Would certainly be something I'm interested in.
My cost used to start at about R5.5k but I have shaved R1k off the cost on the latest shipments. That includes Intel CPU, intel ethernet controller, power supply, SSD, and memory.
The ports are all gig but the spec of 400mbs is for AES encryption offload which is the VPN/tunnel throughput. It will do a ookla speedtest at minimum 950mbs. That is the normal router/FW throughput. Sometimes you find the encryption rate listed separately on products but mostly its hidden. Its the Intel AES chip https://en.wikipedia.org/wiki/AES_instruction_set and at what rate it can do the encryption but in a home environment that might not be important. Any consumer router regardless will max out the CPU to 100% when encryption is enabled and be a dog incl. the mikrotiks because they don't have AES.
The rack one does encryption at 2.5gbs and the ookla speedtest is 10gbs when a SFP+ is used.
 
My cost used to start at about R5.5k but I have shaved R1k off the cost on the latest shipments. That includes Intel CPU, intel ethernet controller, power supply, SSD, and memory.
The ports are all gig but the spec of 400mbs is for AES encryption offload which is the VPN/tunnel throughput. It will do a ookla speedtest at minimum 950mbs. That is the normal router/FW throughput. Sometimes you find the encryption rate listed separately on products but mostly its hidden. Its the Intel AES chip https://en.wikipedia.org/wiki/AES_instruction_set and at what rate it can do the encryption but in a home environment that might not be important. Any consumer router regardless will max out the CPU to 100% when encryption is enabled and be a dog incl. the mikrotiks because they don't have AES.
The rack one does encryption at 2.5gbs and the ookla speedtest is 10gbs when a SFP+ is used.
Does IDS/IPS/DPI/etc tank performance like it does on the unifi gateways (gigabit lan throttled to around 200-300Mbit)? VPN is pretty irrelevant for my use case but the security stuff isn't.
 
Does IDS/IPS/DPI/etc tank performance like it does on the unifi gateways (gigabit lan throttled to around 200-300Mbit)? VPN is pretty irrelevant for my use case but the security stuff isn't.
That depends on the code being used. I have a DPI agent that runs no more than 2% of cpu on a gig lan. The security stuff is also at linespeed if configured or used correctly. As an example I have loaded a nffilter IPSET of 500k entries and it operated at line rate. However, stuff like snort, etc still use cpu but its a lot better on a intel than other processors especially when running single threads. I also stopped using NTOPNG as it was a cpu killer when any advanced functionality was used.
I haven't tested the performance of the various pfsense functions.
 
Anyone else’s internet down?
Wondering if it’s just affecting me due to the rains in KZN.

Vumatel Trenched


Edit: seems to be back
 
Anyone else’s internet down?
Wondering if it’s just affecting me due to the rains in KZN.

Vumatel Trenched
JHB Bound NLDs failed. Traffic shifted to CPT NLD, however some BGP sessions didn't survive the move. These needed to re-establish and re-converge, which takes a few mins. Our network team are investigating to see why these sessions didn't stay up. Traffic is currently on KZN<>CPT path, so expect a slightly higher latency.
 
JHB Bound NLDs failed. Traffic shifted to CPT NLD, however some BGP sessions didn't survive the move. These needed to re-establish and re-converge, which takes a few mins. Our network team are investigating to see why these sessions didn't stay up. Traffic is currently on KZN<>CPT path, so expect a slightly higher latency.
Thank you. I was worried because there is a lot of flooding in my area. Was not sure if that may have caused it
 
View attachment 1288142

Been intermittently all day... @websquadza what's going on.
Just to this IP or other IPs too? Judging by this, the IP's owner is either experiencing peering issues at NAP JHB or black-holing your traffic. Haven't seen any loss to this IP in an hour of testing, so I'd say the latter. Drop me a PM with more details for us to investigate.
 
Last edited:
KZN Update: Morning All - at this point, most of the fibre infrastructure in and around Teraco Riverhorse area, as well as several other areas is under water. We are working to find alternate paths. In addition, evaluate the extent of metro outages. More updates to follow
 
KZN Update: Morning All - at this point, most of the fibre infrastructure in and around Teraco Riverhorse area, as well as several other areas is under water. We are working to find alternate paths. In addition, evaluate the extent of metro outages. More updates to follow
KZN Update: Various metros are still down. Core services are back to 100% operation. Will keep updating as we hear more.

Our thoughts go out to the community in KZN. We are seeing some terrible pictures of flooding and destruction.
 
MFN PMB been offline since 2:20am, not sure if it's due to the floods?
I'm in PMB on Vuma (except I'm with Cool Ideas), my line has also been down since 00:30 last night. PPPoE is just stuck on "connecting". I'm hoping they can get it fixed today.
 
My internet seems to be back. Just noticed it now while running my Generator. Some services like Slack are quite slow, but I guess it is expected due to so much infrastructure being down.
 
@websquadza not sure if the NLD's from KZN are damaged from the floods and you have us on alternative routes at the moment, but speeds outside of Teraco Durban are terrible. I'm on MFN PMB, as you can see speeds are great to Teraco, but from there it goes pearshaped :(

Speedtest.jpg
 
@websquadza not sure if the NLD's from KZN are damaged from the floods and you have us on alternative routes at the moment, but speeds outside of Teraco Durban are terrible. I'm on MFN PMB, as you can see speeds are great to Teraco, but from there it goes pearshaped :(

View attachment 1289556
Unfortunately KZN NLDs are pretty much all down at the moment. N3 routes to JHB are severely damaged (possibly in multiple places) and the N2 route to Cape Town is damaged. It is impossible to know how much damage and how many breaks there are until techs can reach the first break and test onwards. The N2 north route (via Richards Bay) was restored around 22:30 last night, however it seems to be experiencing issues of its own. We are waiting for feedback on the high latency on this path - just a reminder that all KZN traffic is running over few remaining paths at this point.

All NLD vendors have declared force majeure. Every picture of a road coming from KZN includes some bit of fibre ducting protruding from the rubble. More updates to follow.

Our thoughts and prayers go out to everyone affected by this disaster.
 
Unfortunately KZN NLDs are pretty much all down at the moment. N3 routes to JHB are severely damaged (possibly in multiple places) and the N2 route to Cape Town is damaged. It is impossible to know how much damage and how many breaks there are until techs can reach the first break and test onwards. The N2 north route (via Richards Bay) was restored around 22:30 last night, however it seems to be experiencing issues of its own. We are waiting for feedback on the high latency on this path - just a reminder that all KZN traffic is running over few remaining paths at this point.

All NLD vendors have declared force majeure. Every picture of a road coming from KZN includes some bit of fibre ducting protruding from the rubble. More updates to follow.

Our thoughts and prayers go out to everyone affected by this disaster.
Useless info, but I see full line speed and normal latencies to our branch in Pinetown from JHB on Liquid Telecom since about 4am this morning.
 
Unfortunately KZN NLDs are pretty much all down at the moment. N3 routes to JHB are severely damaged (possibly in multiple places) and the N2 route to Cape Town is damaged. It is impossible to know how much damage and how many breaks there are until techs can reach the first break and test onwards. The N2 north route (via Richards Bay) was restored around 22:30 last night, however it seems to be experiencing issues of its own. We are waiting for feedback on the high latency on this path - just a reminder that all KZN traffic is running over few remaining paths at this point.

All NLD vendors have declared force majeure. Every picture of a road coming from KZN includes some bit of fibre ducting protruding from the rubble. More updates to follow.

Our thoughts and prayers go out to everyone affected by this disaster.
KZN Update: one of the KZN<>JHB NLDs have been restored so traffic has shifted back to that path. Latency and performance issues on the northern N2 path have also been resolved.
 
@websquadza seems something broke with international traffic:
1649860788949.png

I just realized this means nothing to you since you can't see the destination :)
It's to my company's VPN - I think I've dm'd the URL to you previously.

EDIT #2: Issue seems to be resolved!
 
Last edited:
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X