Support Diary: The LAN of 16M Hosts
prgmr.com
prgmr.com
Not surprisingly, they experienced various problems over the next few weeks due to "the firewall" -- including breaking the application they used to provide their vendor remote access for monitoring and maintenance! That had the biggest impact but there were also various web sites they couldn't access, they lost the ability to send and receive e-mails from some other organizations they worked closely with, and so on. Oh, and either Pandora or Spotify (I don't remember which) also stopped working -- she could deal with some of the other stuff but the manager of the organization was NOT happy about that one!
Eventually, a few weeks after the firewall replacement, I was asked to go investigate the issues they had been experiencing since the new firewall had been installed, quickly noticed the incorrect configuration on the interface, and became the hero to everyone (well, except for my $boss, who had to reimburse them for ~27 hours (IIRC) of on-site time, but that's another story).
Subnet masks matter!
I don't record any reliability stats, but I can't remember a time one of my VPSes was down without being announced first. Reboots and downtime do happen because they are extremely on top of Xen security patches, hardware maintenance, and everything else. My favorite prgmr email was last year when a scheduled maintenance got postponed by two days only six hours before it was planned and they sent me an email apologizing that my machine wasn't down just in case I had already planned around it: https://i.imgur.com/yusTBPG.png
Full disclosure: one (only one!) of my prgmr VPSes is billed to me at $0/month because I helped get FreeBSD Xen/PV running at prgmr way back in the FreeBSD 9.0 days when FreeBSD Xen/HVM was rather unusable. These days PV isn't even an option (afaict) for prgmr's VPS and the newest HVM-mode FreeBSD is available straight from them in the management console as a first-class OS alongside CentOS and friends. If that arrangement ever ends I will immediately switch to paying for the same machine and wouldn't even consider shopping around first :)
Personally I never totally 'got' CIDR until I went back and learned what it replaced and why it was needed.
It's frustrating the number of silly things you can do at the command line that persist for backwards compatibility reasons. But we can at least add warnings for them. It would have been much better for the user to have been told at the time they failed to add a netmask that they made a mistake. It would have removed the need for the support ticket entirely (at least, one hopes so.)
mkswap is another example of this. Karel Zak had thoughtfully added warnings in swapon already if you enabled swap with insecure permissions https://git.kernel.org/pub/scm/utils/util-linux/util-linux.g... but nobody had bothered to warn at the time the swap file was actually created. So I had someone add that: https://git.kernel.org/pub/scm/utils/util-linux/util-linux.g...