HNHacker News
TopNewBestAskShowJobs

pavel_odintsov

305 karma · joined November 1, 2014

submissionscomments
pavel_odintsov··on Enabling IPv6 support for IPv4-only apps on Linux
Thank you for great feedback! I decided to cover NAT64 and DNS64 gateway setup guide mentioned in this article briefly: https://pavel.network/building-gateway-to-access-legacy-ipv4...
pavel_odintsov··on Enabling IPv6 support for IPv4-only apps on Linux
It was more about way to fix some very broken tool. ssh was just an example. It may be proprietary app without source code available.
pavel_odintsov··on Enabling IPv6 support for IPv4-only apps on Linux
Thank you very much for this question. I've rewrote and improve my article to cover exactly this topic: https://pavel.network/building-gateway-to-access-legacy-ipv4...
pavel_odintsov··on Enabling IPv6 support for IPv4-only apps on Linux
Thank you very much for approving my idea!
pavel_odintsov··on Enabling IPv6 support for IPv4-only apps on Linux
In home network single $70 USD device with 2 daemons running may be clearly too much but for corporate or even office network it's just one more box in addition to dozens of network devices.
pavel_odintsov··on Enabling IPv6 support for IPv4-only apps on Linux
It can be easily sorted out with DNS64 and NAT64: https://pavel.network/building-gateway-to-access-legacy-ipv4...
pavel_odintsov··on Enabling IPv6 support for IPv4-only apps on Linux
Author is here.

Thank you for sharing! Yes, macOS has such logic and it works just fine. The main issue from clatd that it's pretty tricky to setup and it emulates presence of IPv4 on machine which is not very desirable as it tends to hide issues with other tools.

My plan was to explicitly disable IPv4 connectivity for machine and hide it from other app but keep it active for subset of well known broken tools and then fix them one by one and switch to IPv6 only setup.

pavel_odintsov··on Linearly scalable UDP server with BPF based load balancing on Linux
eBPF requires way more tooling which I find excessive for such easy task.

More complicated load balancing protocols may need more complicated balancing microcode and eBPF will be helpful in this case.

One of the main differences between BPF and eBPF is number of allowed instructions and it's very big for eBPF.

I think you can do XDP based DHCP server in theory and keep state in eBPF map. Not sure that it does make any sense but clearly doable.

pavel_odintsov··on Linearly scalable UDP server with BPF based load balancing on Linux
Thank you for your great feedback
pavel_odintsov··on Best way to get default outgoing IP address on Linux
It's very useful information for many low level network application. There are clearly many cases when such information is not useful but there are cases you cannot do without having this information in place.
pavel_odintsov··on Why is DNS still hard to learn?
Great article. Thank you!

I used to develop and maintain one of the World largest DNS services and summarised my experience with DNS protocol in this blog post: https://pavel.network/please-stop-using-dns-protocol-for-you...

pavel_odintsov··on Ask HN: What TSDB database do you use on embedded Linux systems?
I'm Pavel from FastNetMon and we do for sure love Clickhouse as TSDB for embedded systems and we have multiple deployments on ARM64.
pavel_odintsov··on Please do not require AVX support for your software
Thank you for sharing such great insights.
pavel_odintsov··on Please do not require AVX support for your software
Yep that's serious issue and it's similar to our case. Our main product can work just fine even without SSE 4.2 but MongoDB requires it and then indirectly leads to AVX1 support as we use MongoDB as storage. We did PoC with FerretDB last month and I think it may be good option for Gerylog: https://www.ferretdb.io
pavel_odintsov··on Please do not require AVX support for your software
Great feedback, thank you. We have customers in many countries around the World and in many cases even medium sized businesses cannot afford buying new equipment just to make some random software happy about CPU flags.

In multiple countries import tax may reach 50% on top of equipment cost. When multiplied by exceptionally weak local currency even medium level server will cost like racing car.

Old equipment without AVX is perfectly capable running modern workloads and artificial requirement to have AVX hurts people and increases digital divide.

To address such cases we found nice trick by using FerretDB to replace MongoDB in such environments: https://fastnetmon.com/docs-fnm-advanced/using-fastnetmon-ad...

pavel_odintsov··on Enabling IPv6 support for IPv4 only apps on Linux
Great catch. I did not notice it:

dig -t aaaa news.ycombinator.com @8.8.8.8 +short

Returns empty result.

pavel_odintsov··on Enabling IPv6 support for IPv4 only apps on Linux
I have idea of even more hostile environment in my mind. My plan for next phase is to get rid of 127.0.0.1 on lo interface. I've tried it once and I had to reboot my machine as all things stopped working.

As another angle to make it even more interesting but on network scale I've implemented option for Unbound to suppress A records even if they do exist: https://github.com/NLnetLabs/unbound/pull/819 and push dual stack apps to be IPv6 only.

pavel_odintsov··on Enabling IPv6 support for IPv4 only apps on Linux
The main idea of my experiment was to run IPv6 only setup without any IPv4 connectivity: sudo ip route get 8.8.8.8 RTNETLINK answers: Network is unreachable

So I intentionally decided not to have IPv4 connectivity system wide to catch apps with issues in IPv6 only environment and then carefully evaluate issues and report them to authors: https://github.com/mozilla-mobile/mozilla-vpn-client/issues/... https://github.com/signalapp/Signal-Desktop/issues/4121

Dual stack setups tend to hide IPv6 implementation issues and may create illusion that app is IPv6 compatible but in reality it's not.

Clearly my setup is too hostile for home users but as developer I enjoy it a lot.

pavel_odintsov··on Enabling IPv6 support for IPv4 only apps on Linux
Yep GitHub is one of the main reasons why I started work on NAT64 box next day after switching to IPv6.

Most of the services I need for work do support IPv6 and the only exceptions is GitHub.

pavel_odintsov··on Enabling IPv6 support for IPv4 only apps on Linux
It's a great tool for sure. I've tried to find approach to patch naughty IPv4 only apps with my own LD_PRELOAD library and during research phase I found tnat64 and it worked exactly as I expected.
pavel_odintsov··on Curious case of Martian network traffic in Linux
Curious case of Martian network traffic in Linux
pavel_odintsov··on New ‘Meow’ attack has deleted almost 4k unsecured databases
Thank you for raising this question. Well, for my things I use MongoDB because of very convenient integration with programming languages (Go, C++ via Mongo C++) and zero hassle with schema

But I'll be happy to replace it by something else, my load is extremely small and only single requirement is to have DB as network daemon, not as embedded storage as it will be used by 2 applications (main daemon an API).

RethinkDB was really nice candidate for it but it's not alive anymore: https://rethinkdb.com/blog/rethinkdb-shutdown/

pavel_odintsov··on Open source DDoS detection tool with BGP support
Thank you for great question! Unfortunately, false positive alerts are pretty common problem. FastNetMon is threshold / baseline based DDoS detection engine and it requires pretty careful baseline calculation.

Typically, we recommend enabling InfluxDB metrics export for ~1 week (to cover peak times in your region), you can do it this way: https://fastnetmon.com/docs/influxdb_integration/

After that, you can make query to detect peak traffic for packets per second, bytes per second and flow per second metrics. Then you can multiply these value to 2-3 (depends on your capacity) and use as baseline.

Also, it's very good to known limits of your network. For example, if you know that router cannot handle more than 1M packets per second then you need to set threshold way before it. And most important thing is mount of spare capacity from your upstream. If you have only 10G of external capacity utilised up to 90% then your baseline should not exceed amount of your spare capacity.

pavel_odintsov··on Open source DDoS detection tool with BGP support
Thank you for sharing! I'm one of the FastNetMon authors and I will be happy to answer any questions about it.
pavel_odintsov··on XDP: 1.5 years in production [pdf]
If you Like XDP you may check AF_XDP! It's like PCAP but EXTREMELY fast!

It require kernel 4.18+ and you can use my guide to build test application very fast: https://github.com/pavel-odintsov/fastnetmon/wiki/af_xdp-tes...

pavel_odintsov··on OVH CEO: Unlike Amazon, Google, “we will never be in competition with you”
I had very bad experience with physical server at online.net. One time I noticed that my server did not return from reboot. I logged into KVM and discovered that both my SSD drives failed and need replacement.

I immediately backed up all my data and created ticket. I wait for I day. I wait for 2 days. After three days (all this time my server was offline) I got answer "we can't replace your drives and can't replace your server because we do not have stock. And you can wait for end of the month for new server".

Isn't it brilliant? :(

pavel_odintsov··on Fastnetmon DDoS analyzer now available as an official Debian package
After short conversation with GoBGP project they re-lcienses this file in BSD terms: https://github.com/osrg/gobgp/issues/1384

We will update proto file to this version in FastNetMon soon! :)

pavel_odintsov··on Fastnetmon DDoS analyzer now available as an official Debian package
You could read my blog post about it instead: https://translate.google.com/translate?hl=en&sl=ru&tl=en&u=h...

It's in russian but Google trsnalate crashes language baarriers! :)

pavel_odintsov··on Fastnetmon DDoS analyzer now available as an official Debian package
Btw, we have the channel at Freenode! Join us: #fastnetmon at irc.freenode.net! :)
pavel_odintsov··on Fastnetmon DDoS analyzer now available as an official Debian package
You could consider this thing https://github.com/luigirizzo/netmap-ipfw
Page 1 of 2Next →