IPv6 Internet is broken
adminhacks.com
adminhacks.com
And when turning that one off makes my internet work, and turning it on makes my internet not work, guess what.
Cogent is best used as part of a multihoming strategy, and not as an only route. Even if you take a neutral stance about their role in peering disputes, the fact that they are involved in a lot of them means if you only use them, you're likely to have less connectivity than if you had a different transit provider or multiple transit providers.
Basically, most tier-1 providers allows settlement-free peering with anyone who can meet some physical requirements (like having mutual interconnection in America, Europe and Asia) and legal ones (everyone wants to avoid sanctions). HE clearly meets this requirement. Google also clearly meets this requirement. Both are not connected to Cogent despite both are willing to interconnect to Cogent.
Cogent just allows connections to whoever they feel to connect, they don't have a criteria except for "if we allow them, will they kill our business"?
How so?
I would also add (but this is not email per se) : no adoption for GPG/PGP this makes your cryptographic signature a bare textfile attachement.
both microsoft and gmail spam filter = blackbox.
If people could be trusted to manage their mail server we wouldn't have this problem, but IoT crapware is still listening on port 23 till this very day and the manuals still state that you need to disable the firewall and forward all traffic to your shitty webcam for it to work. Reporting this abuse to the carrying ISPs is about as useless as shouting my complaints down the toilet.
Until both IoT production companies and individual consumers take responsibility for the awful internet created by these maliciously incompetent users and the laughably bad IoT devices they buy, I'm not removing this filter rule from my mail server.
I do usually get a notification that something hit quarantine so if it sounds important I can still see it, but I've never had to release mail banned for this reason so far.
> My mail server occasionally receives mail from residential ISPs and it's literally always spam.
I sent mail from my home isp for years, until people like you made unfeasible.
> I do usually get a notification that something hit quarantine so if it sounds important I can still see it, but I've never had to release mail banned for this reason so far.
Most small operators refused to allowlist me even after making phone calls, etc.
> I sent mail from my home isp for years, until people like you made unfeasible. I've accepted mail from home ISPs for years but a recent-ish (±5 years ago) but short wave of spam from botnets made me turn on the spam filter on my new server.
> Most small operators refused to allowlist me even after making phone calls, etc. With my setup you won't even have to call me because I'll probably whitelist your server anyway. May take a day depending on how recent the latest quarantine report was, but that's no different from normal email anyway. My spam threshold is quite high so if you take the normal measures (SPF/DKIM/reverse PTR/etc.) you probably won't even hit the spam filter.
Nice proving the OP orginal opening statement, well done ....
Is there one that actually states it isn't OK, that I'm unaware of?
It perhaps goes against the spirit of the RFCs and other documentation written at the time, but that is understandable because a lot of that stuff was written from the standpoint of being able to trust people on the Internet, including that they fully understand and have properly secured the hosts under their purview…
I send mail from home just fine, though my connection is through an ISP that is generally identified as offering commercial accounts (AAISP). You do have to make sure that you have SPF and DKIM configured but that is the case elsewhere too.
My machines see quite a lot of activity (SSH login attempts, attempts at brute force logins & scans for known vulnerability in old versions of HTTP(S) hosted software, and more, not just attempts to send junk mail) from what appears to be compromised machines on residential connections.
[1] yes I am aware not all, but unless you are a big player good luck getting gmail or ms to accept your mail
This 'evil corp blocks my SMTP server' superstition really needs to stop. False positives hurt them as much as it does you, so you bet that there is 0 incentive to block emails from your IP.
If the email is properly DKIM aligned for the domain, it really does not matter which IP address the email is originating from.
IP addresses (especially with IPv6) are ephemeral, and email providers have figured this our years ago. If spam filters were IP based and persistent, they would have blocked the entire IPv4 internet by now. So they don't.
Spam filters (not the one you run at home, but proper ones used by Google and MS) use the email's content and domain reputation. Most of it is ML driven. IP addresses are irrelevant, unless when you force the receiver to fall back to IP assessment by not signing your email.
TL;DR: if your SMTP service is being blocked by 'large evil corp', it is because your domain and/or SMTP service are not properly configured.
Also, not being able to set a reverse DNS for a domestic IP is not Google's fault, it is your ISP not allowing you to 'own' an IP, and not allowing you to set a reverse DNS for the IP they lease to you.
This is why ISP offer business packages. These will allow you to own the IP (block), and set reverse-DNS for it.
https://www.datacenterknowledge.com/archives/2009/10/22/peer...
Everyone in the ISP/Transit world does it though, trying to double dip by charging their customers for service then trying to charge other to peer with them unless it’s in their favor to peer freely.
Peering should be best effort, and as close to free as possible when you already have a presence in a location. I understand some cost to cover the hardware necessitated by peering, but the only person being charged should be the customer you’re providing a service in my opinion.
As a transit supplier, they’re both pretty low quality, suited to bulk traffic only. Anything latency/loss sensitive goes over other providers.
HE and Cogent both are best suited to their roles as carrier of last resort. If you as a customer depend primarily on either of them, that’s a particularly unfortunate situation that should be remediated if possible.
https://lg.tetaneutral.net/detail/h7/ipv6?q=HE_FRANCEIX_PARI...
162016 IPv6 routes from HE. Current IPv6 full view about 166926 routes.
Cogent will not peer with you.
If you're starting an ISP: buy cogent and another transit, peer with HE on your local IX, you should be good to go.
I'm sorry, but how is the quality of HE's performance in any way relevant to the issue of Cogent refusing to follow industry norms for settlement-free / equal cost-sharing peering? Cogent isn't refusing to peer with HE (and Google btw) because of latency/loss. Cogent is notorious for trying to squeeze every penny out of other networks through peering, HE is the exact opposite.
I tried raising a complaint as their SLA states about packet deliverability/guarantees - and I said "well, you have 100% packet loss to HE"... I didn't get very far and they basically just blamed it on HE - but, I wonder if someone had more time, if they could make a complaint down this avenue?!
At least Cogent charges low prices for their shit.
(It's also far from the only issue you'll get as a Cogent customer, they're generally, uh, pretty shit.)
IMVHO many giants obstacle IPv6 NOT because it's hard and not so nice BUT because they fear loosing their privileged position. Oh, sure most people do not have TODAY a homeserver but how much would it take to see pre-packaged pseudo-FLOSS homeservers like we see for android "pirate-TV minicomputers"?
Try weighting that before judge.
I'm on Zen in the UK and have both a static IPv4 (with additional IP's available for a relatively lot fee in blocks of 8 or more) and a /48 IPv6 block.
Before OVH, I also was with another similarly-cheapo ISP that gave me one IPv4 for free until they decided to start charging for it (and I left).
It's just a matter of time. Of course if your ISP is expensive enough they'll just keep eating the cost for more years, but .. what's the point? One IPv4 is not that costly yet that is worth an expensive ISP over it...
All we need is IMVHO a general culture on IT and it's evolution, to push politicians MANDATE no throttling, routing tricks etc with public watchdogs that sanction all anti-users behaviors in tech, not just for ISP but for instance in terms of communications service: you are a company and decide to offer a new "modern chat" service with a new protocol? Ok, no issues. Do it if you want BUT if the protocol is closed source or design in a way to makes third party "peering" hard you get significant income slice ALL THE TIME this design persist. Let's say you state "ah but file-sharing pass on our servers and bandwidth and storage are costly. That's good. So allow third party "caching services" or direct IP2IP sharing or pay the sanction for having chosen an anti-user design.
Since all this "features" and "anti vs pro" can't be written in laws up front that's the simple way to go: from the PUBLIC academia a watchdog who listen FLOSS associations, citizens, users in general and keep watching not impeding, but sanctioning. Enough to allow free ALSO commercial innovation, but not enough to makes some behaviors interesting for any business.
Dynamic DNS has been around for decades and provides a solution if you really want to run a home server behind NAT. If someone wanted to market a home server box, they would just need to implement something like DDNS... and Plex basically does just that.
But most people have limited upstream bandwidth, such that it's impractical to serve much content from home, except maybe to yourself as a 'road warrior' via VPN, or video streams via Plex, stuff like that.
If home broadband was symmetric, even with NAT, we would see many more applications taking advantage of that upstream bandwidth.
Nice in theory, but some ISPs (mine included) will happily give you a /56 via prefix delegation, but if your connection drops, you will possibly get a different prefix, and so your IP unfortunately changes.
Slovak Telekom (Deutsche Telekom Subsidiary, same as Czech T-Mobile/T-Com) - FTTx, DSL, WISP
Orange (French Orange S.A. subsidiary) - FTTx, DSL, WISP
O2 (The Czech HQ'd PPF owned, not the UK one) - WISP
And even the more regional, but still big, aren't much better.
UPC (Liberty Global subsidiary) - Cable
Antik (Slovak company) - FTTx, Cable, WISP
SWAN (also Slovak company) - DSL, FTTx, WISP
But I have to shout out my dad's ISP, it's called RadioLAN, it's a slovak company, provides WISP and FTTx and also IPv6 to everyone by default. So far the only one I've found. Funny thing is, the peering in our country is handled by two IXs: SIX and NIX both natively supporting IPv6 interconection. If I've messed some terminology or I've outdated info, I'm sorry. As you said, nod to until we live in a very very specific location, we're left with just one ISP, or basically the same one in blue. I'm less than 10km behind the capital's outer borders, yet I have a huge problem getting FTTH ran here. It's literally connected at the both ends of our street, just not here. I've considered doing something about it myself, it's just simply too expensive.
Orange does support IPv6 on FTTH and DSL (do not know about mobile network); they use DS lite and allow user port mapping for IPv4 (!), provide /56 by default. They didn't migrate existing customers, they just started with new ones (2016 for DSL, 2018 for FTTH), which is reasonable. There's also an issue with IPTV service, which runs over IPv4 multicast, so new customers with TV service (or those who ask explicitly) get IPv4-only anyway.
UPC (Liberty Global) has exactly the same issue as the Czech one: DS lite and you get /64 only. It is the same design, shared by all UPCs, (the Czech one is just a recent acquisition from them by Vodafone).
Slovak Telecom "is planning" (since 2020). TBH, I would expect ST to get rid of PPPoE on FTTH first ;)
Swan supposedly supports IPv6 now, at least in their core. They claim IPv6 support in their materials (at least in those communicated to business customers).
Note that ST/Orange/O2 are not WISPs; they are mobile networks. With WISP, the understanding is that they would use wireless radios like Radiolan does (i.e. Radiolan is WISP).
> I'm less than 10km behind the capital's outer borders, yet I have a huge problem getting FTTH ran here.
This is common and not that surprising. If you check availability for the FTTH in the capital's city center, you will find that the situation is the same (or similar: chances are, that the end of the street is not connected). It is residential areas with high density that have the good coverage.
My home ISP certainly can route packets to both HE and Cogent:
root@tranzistor:~# ping cogentco.com PING cogentco.com(cogentco.com (2001:550:1::cc01)) 56 data bytes 64 bytes from cogentco.com (2001:550:1::cc01): icmp_seq=1 ttl=56 time=21.1 ms ^C --- cogentco.com ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0msrtt min/avg/max/mdev = 21.107/21.107/21.107/0.000 ms root@tranzistor:~# ping he.net PING he.net(he.net (2001:470:0:503::2)) 56 data bytes 64 bytes from he.net (2001:470:0:503::2): icmp_seq=1 ttl=49 time=164 ms ^C --- he.net ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 164.454/164.454/164.454/0.000 ms root@tranzistor:~#
Why are packets from cogent to HE not routed via my ISP?
To the point that I've set up an IPv4-over-IPv6 tunnel out, for when IPv4 breaks.
$ wgetnull www.cogentco.com
--2022-12-12 06:40:42-- http://www.cogentco.com/
Resolving www.cogentco.com (www.cogentco.com)... 2001:550:1::cc01, 38.100.128.10
Connecting to www.cogentco.com (www.cogentco.com)|2001:550:1::cc01|:80... failed: Connection timed out.
Connecting to www.cogentco.com (www.cogentco.com)|38.100.128.10|:80... failed: Network is unreachable.
(I'm on an HE tunnel, and v4 doesn't work either since I use NAT64, so their site is just dead for me.)I ask because providers in the EU have some other laws as USA for example. Or is this peering globally the same ?
I know I've seen some carrier names that come up in those disputes a lot, often the incumbent telco for a particular country. But you've got a lot of countries there and most of them had their own nationalized phone company, and only one or two end up having public spats over peering. There's similar stuff in some countries in Asia, where some of the incumbent telcos refuse to peer locally. (and of course, China has the GFW)
Last-Modified: Fri, 13 Aug 2021 04:23:25 GMTOf course they will claim that the whole world is "doing it wrong", despite the collective failure of humanity to roll out IPv6 for decades and decades.
If your argument for adopting new technology is basically "you must eat your vegetables" then your technology has failed.
That said, IPv6 is a horrible implementation.
v6 is much easier (and cheaper) to deal with than layers and layers of NAT everywhere.