1,569 karma · joined August 23, 2010
Does this mean the subscriber needs to have a forwarded port open to the internet for this to work? Without IPv6, users behind NAT (and specifically behind CGNAT) wouldn't be able to use it.
A very outdated post about my setup : https://www.sajalkayan.com/post/fun-with-mptcp.html
I now have 2 broadband ISPs, and optionally I can hook in my phone's 4g into the mix.
Multipath TCP allows me to "mix" bandwidth of both ISPs at the same time.
If I remember subscribing and haven't attempted to unsubscribe in the past, attempt to unsubscribe. Spending max 10 seconds.
All other situations, hit "mark as spam"
Some traceroutes captured during the incident. The results that show "Target unreachable" were the ones seeing the hijacked paths.
Some traceroutes captured during the incident. The results that show "Target unreachable" are the ones seeing the hijacked paths
From outages mailing list, following subnets were affected.
205.251.192.0 205.251.193.0 205.251.195.0 205.251.197.0 205.251.199.0
The issue has since been fixed, outage lasted for ~2 hours.
If you are still using a single DNS provider for your domain, you should consider having a dual-provider setup.
It appears 1.1.1.1 also does not pass client-subnet, atleast not by default. Queries to my authoritative from Google always includes client subnet, OpenDNS required request for whitelist. For Cloudflare its unclear.
~# mtr --report --address 192.168.2.2 1.1.1.1
Start: Mon Apr 2 16:53:31 2018
HOST: apu Loss% Snt Last Avg Best Wrst StDev
1.|-- 192.168.2.1 0.0% 10 0.9 1.1 0.9 1.2 0.0
2.|-- 10.137.128.1 0.0% 10 11.3 12.8 10.7 17.1 1.8
3.|-- 10.246.253.133 0.0% 10 7.7 8.2 7.5 9.1 0.0
4.|-- 10.185.94.203 0.0% 10 9.1 8.4 6.9 9.4 0.6
5.|-- 10.185.94.25 0.0% 10 9.5 8.7 7.7 10.0 0.5
6.|-- 61-91-220-101.static.asia 0.0% 10 11.7 11.7 8.6 25.7 5.2
7.|-- 58-97-82-116.static.asian 0.0% 10 10.7 10.2 8.6 15.4 1.9
8.|-- ppp-171-102-254-81.revip1 0.0% 10 9.2 9.2 7.1 10.8 0.9
9.|-- ppp-171-102-250-134.revip 0.0% 10 8.4 10.0 8.4 11.3 0.7
10.|-- ppp-171-102-250-149.revip 0.0% 10 9.0 9.7 9.0 10.9 0.3
11.|-- ??? 100.0 10 0.0 0.0 0.0 0.0 0.0
~# mtr --report --address 192.168.2.2 1.0.0.1
Start: Mon Apr 2 16:54:05 2018
HOST: apu Loss% Snt Last Avg Best Wrst StDev
1.|-- 192.168.2.1 0.0% 10 1.2 1.1 0.8 1.3 0.0
2.|-- 10.137.128.1 0.0% 10 12.1 12.8 9.2 18.2 2.4
3.|-- 10.246.253.133 0.0% 10 9.8 9.0 7.5 14.7 2.0
4.|-- 10.185.94.203 0.0% 10 4.4 7.9 4.4 8.8 1.2
5.|-- 10.185.94.17 0.0% 10 9.2 9.1 7.2 10.3 0.9
6.|-- 61-91-220-55.static.asian 0.0% 10 9.7 10.6 8.0 17.2 2.6
7.|-- 58-97-82-120.static.asian 0.0% 10 10.5 9.7 8.2 11.2 0.7
8.|-- ppp-171-102-254-65.revip1 0.0% 10 10.5 9.7 8.8 10.7 0.0
9.|-- ppp-171-102-254-227.revip 0.0% 10 8.9 13.1 8.8 44.0 10.8
10.|-- 61-91-213-130.static.asia 0.0% 10 10.9 9.8 8.3 10.9 0.6
11.|-- TIG-Net242-40.trueinterga 0.0% 10 15.0 14.1 10.9 16.1 1.8
12.|-- TIG-Net245-243.trueinterg 0.0% 10 38.1 38.0 36.4 40.6 0.9
13.|-- 13335.sgw.equinix.com 0.0% 10 37.4 38.6 36.4 48.5 3.5
14.|-- 1dot1dot1dot1.cloudflare- 0.0% 10 36.9 36.3 35.0 36.9 0.5
Edit: FormatingCloudflare consistently times out from these networks.
Netherlands - AS13127 Philippines - AS135132 Thailand - AS17552 (One of the largest consumer internet providers) US - AS7018 (AT&T)
Query times and rechability from 58 locations. 3 locations still can't reach 1.1.1.1, but for most users cached response is faster from Cloudflare.
I think streaming would be useful only if the responses are stateful and it's hard to share it across requests.
Check out the "endpoints" portion in example config : https://github.com/turbobytes/certmon/blob/master/example_co...
I made this tool for our internal use, and posted it here just in case anyone else has similar issues.
Edit: Added screenshot https://github.com/turbobytes/certmon#screenshot
> Write Throughput: $0.0065 per hour for every 10 units of Write Capacity (enough capacity to do up to 36,000 writes per hour)*
> A unit of Write Capacity enables you to perform one write per second for items of up to 1KB in size
As I understand it, for $4.68/month I can only add 36 MB/hour, and thats assuming my objects are in exact multiple of 1KB.
> Also why don't you dump the log data into a NoSQL like dynamoDB instead of S3 ?
Price.
I think flat JSON files wont be efficient. My goal is to have the cache on disk, and each cached file would be big with lots of keys on it. In order to use JSON files, I would either have to keep the whole parsed data in memory, or parse the whole JSON each time I want to lookup a key.
If the data fits in memory then sure JSON is more convenient.
In the current form, I don't directly deal with stale reads. But there is a CheckExpiry [1] method that iterates thru each cached partition, does a HEAD request to the corresponding S3 object and compares Last-Modified. If the cached object is older than the one in S3, the cache will be invalidated. Currently the user needs to invoke this by them-self.
I also plan on having a user configurable TTL per partition, so user could use low TTL for objects they expect to change, i.e. One would think data for today might change soon, but data from 5 years ago wont.
[1] https://godoc.org/github.com/turbobytes/infreqdb#DB.CheckExp...