Skip to content

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone

I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

Uncategorized
6 4 3
  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

    @stefano Disgusting! Today it's a luxury to have a real and untempered internet connection. About 16 years ago I saw Vodafone compressing my images which I uploaded to an FTP server. It's just stupid...

  • @stefano Disgusting! Today it's a luxury to have a real and untempered internet connection. About 16 years ago I saw Vodafone compressing my images which I uploaded to an FTP server. It's just stupid...

    @finn I agree. I don't need Vodafone to sniff my traffic and decide if it's "secure" or not. Years ago that service wasn't Active by default. Then something changed and I started to see, from time to time, those "this site isn't secure" pages. I asked to disable it and they did it. But I remember that I read somewhere they're reenabling it and now it cannot be disabled as "it's for our security".

    All I ask is that they stop messing with my traffic.

  • stefano@mastodon.bsd.cafeundefined stefano@mastodon.bsd.cafe shared this topic
  • @finn I agree. I don't need Vodafone to sniff my traffic and decide if it's "secure" or not. Years ago that service wasn't Active by default. Then something changed and I started to see, from time to time, those "this site isn't secure" pages. I asked to disable it and they did it. But I remember that I read somewhere they're reenabling it and now it cannot be disabled as "it's for our security".

    All I ask is that they stop messing with my traffic.

    @stefano Amen brother! Just give us pure unfiltered internet. If someone wants any "security extras" they can opt-in for that.

  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

    @stefano

    > I even briefly asked an AI (I know, I know...)

    LLMs being used as a search engine "on steroids" is actually a good use case, IMHO.

    You don't have to blindly trust the output, but instead have something to keep searching for an answer.

  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

    @stefano residential line ?

    Here in Belgium they filter out the ports 80/443 by default: "security measure".

    > I even briefly asked an AI (I know, I know...),

    to realize that it doesn't help. :)


Gli ultimi otto messaggi ricevuti dalla Federazione
Post suggeriti
  • 0 Votes
    1 Posts
    1 Views
    New blog post: Managing FreeBSD Jails with Ansible.I wrote jailexec - an Ansible connection plugin that lets you manage FreeBSD jails without running SSH inside each one. It connects to the jail host via SSH and uses jexec to run commands, just like you would manually. Features: • Single Python file, easy install • Supports doas and sudo • Secure two-stage file transfers • Works with any jail managerBlog: https://blog.hofstede.it/managing-freebsd-jails-with-ansible-the-jailexec-connection-plugin/Code: https://github.com/chofstede/ansible_jailexec#FreeBSD #Ansible #DevOps #SysAdmin #Jails #Automation
  • 0 Votes
    1 Posts
    2 Views
    Have you worked with tags on your jails yet?One nice benefit of using tags is that you can also TARGET by tag name, meaning you can group like systems and maintain those separate from others.`bastille tags help`Usage: bastille tags TARGET [add|delete] tag1,tag2bastille tags TARGET list [TAG]#FreeBSD #BastilleBSD #SysAdmin #DevOps
  • 0 Votes
    1 Posts
    7 Views
    Under the hood update!I’ve finally retired the old cron + sh setup for the weather bots. It served us well, but it had a major flaw: if I rebooted the server while it was posting, the job just died halfway. If the server was down during a scheduled slot, the forecast was lost forever.So, I wrote a custom Python daemon to run inside the FreeBSD Jails.It’s stateful now. If a crash happens at city 15 of 50, it resumes exactly there on reboot.If the server naps/is rebooting during a scheduled run, the bot realizes it missed a slot and runs immediately upon waking up.#FediMeteo #SysAdmin #Python #FreeBSD #Coding #SelfHosted #OwnYourData #StayTuned
  • 0 Votes
    8 Posts
    18 Views
    @jana I'm usually using them only as 4g routers. I'm usually managing the failover at a higher level, using the main router (so directing the traffic to the 4g one only if the main routes are down). Sometimes I use the 4g as a "power up" solution, when clients have some traffic spikes. Sometimes, I send all the "guest" traffic to 4g, to keep the main traffic paths empty