Live data from Hacker News

DDoS protection

wiki.hetzner.de

31–40 of 175 posts

Re: DDoS protection

#31
post #18

Earlier quoted context omitted.

You can get server grade hardware with the PX line at Hetzner, which is a bit more expensive of course. And an internal network is possible as well from what I read, though you have to pay for the Flexi pack because it counts as a modification of your server.

The internal network is a joke, it only works if you have all of your servers in one rack and you need to rent a switch to connect all of them. Online.net has a real RPN where you can add SAN storage to it etc etc. The PX line is a Fujitsu Desktop PC with a server CPU and ECC Ram. For me that's a compromise I don't really like. Also the network is a bit shitty since they don't route through DTAG (largest german carri…

regarding DTAG it's wrong (or outdated ?), we have a peering through HOPUS (hopus.net) since a few months with them :

  mma@duvel:(~) mtr -rwc4 93.210.14.100
  Start: Thu Sep  1 12:45:41 2016   
  HOST: duvel                            Loss%   Snt   Last   Avg  Best  Wrst StDev  
    1.|-- 62.210.128.13                     0.0%     4    0.3   0.3   0.3   0.4   0.0  
    2.|-- 195.154.1.20                      0.0%     4    0.4   0.4   0.3   0.4   0.0  
    3.|-- 195.154.1.16                      0.0%     4    0.8   0.8   0.7   0.9   0.0  
    4.|-- lag-online-1.dc3-1.rt.hopus.net   0.0%     4    0.4   0.4   0.4   0.5   0.0  
    5.|-- lag-pop-dc3-2.dc3-1.rt.hopus.net  0.0%     4    9.1   2.8   0.4   9.1   4.2  
    6.|-- lag-pop-std-1.dc3-1.rt.hopus.net  0.0%     4    0.7   0.9   0.7   1.5   0.0  
    7.|-- 62.159.61.37                      0.0%     4    1.7   2.8   1.7   4.5   1.2  
    8.|-- 62.159.99.230                     0.0%     4   22.1  22.0  22.0  22.1   0.0  
    9.|-- 87.186.202.209                    0.0%     4   22.9  22.9  22.9  22.9   0.0  
   10.|-- p5DD20E64.dip0.t-ipconnect.de     0.0%     4   48.5 119.1  48.3 329.9 140.6
  
Mik (Network Manager Online.net)

Re: DDoS protection

#32
post #19

Cloudflare is a major source of centralization. The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example. It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"

[disclaimer: I work for CF] CloudFlare also regularly speaks about attacks and mitigations, therefore is helping the community to build better defences. Other providers stay shy and never disclose their magic. We believe DDoS is an internet wide problem and one of the ways to solve it is to spread the mitigation know how. Examples: - DNS attacks https://www.youtube.com/watch?v=UcAygzNSxlI&t=2h13m20s - Iptables is gre…

Cloudflare gets so much undeserved hate on HN. You guys do amazing work, provide an incredible service and your writeups are awesome. Thank you.

Re: DDoS protection

#33
post #31
post #18

Earlier quoted context omitted.

The internal network is a joke, it only works if you have all of your servers in one rack and you need to rent a switch to connect all of them. Online.net has a real RPN where you can add SAN storage to it etc etc. The PX line is a Fujitsu Desktop PC with a server CPU and ECC Ram. For me that's a compromise I don't really like. Also the network is a bit shitty since they don't route through DTAG (largest german carri…

regarding DTAG it's wrong (or outdated ?), we have a peering through HOPUS (hopus.net) since a few months with them : mma@duvel:(~) mtr -rwc4 93.210.14.100 Start: Thu Sep 1 12:45:41 2016 HOST: duvel Loss% Snt Last Avg Best Wrst StDev 1.|-- 62.210.128.13 0.0% 4 0.3 0.3 0.3 0.4 0.0 2.|-- 195.154.1.20 0.0% 4 0.4 0.4 0.3 0.4 0.0 3.|-- 195.154.1.16 0.0% 4 0.8 0.8 0.7 0.9 0.0 4.|-- lag-online-1.dc3-1.rt.hopus.net 0.0% 4 0.…

[deleted]

Re: DDoS protection

#34
post #31
post #18

Earlier quoted context omitted.

The internal network is a joke, it only works if you have all of your servers in one rack and you need to rent a switch to connect all of them. Online.net has a real RPN where you can add SAN storage to it etc etc. The PX line is a Fujitsu Desktop PC with a server CPU and ECC Ram. For me that's a compromise I don't really like. Also the network is a bit shitty since they don't route through DTAG (largest german carri…

regarding DTAG it's wrong (or outdated ?), we have a peering through HOPUS (hopus.net) since a few months with them : mma@duvel:(~) mtr -rwc4 93.210.14.100 Start: Thu Sep 1 12:45:41 2016 HOST: duvel Loss% Snt Last Avg Best Wrst StDev 1.|-- 62.210.128.13 0.0% 4 0.3 0.3 0.3 0.4 0.0 2.|-- 195.154.1.20 0.0% 4 0.4 0.4 0.3 0.4 0.0 3.|-- 195.154.1.16 0.0% 4 0.8 0.8 0.7 0.9 0.0 4.|-- lag-online-1.dc3-1.rt.hopus.net 0.0% 4 0.…

I was talking about the Hetzner network, not yours :-)

Re: DDoS protection

#35
post #34
post #31

Earlier quoted context omitted.

regarding DTAG it's wrong (or outdated ?), we have a peering through HOPUS (hopus.net) since a few months with them : mma@duvel:(~) mtr -rwc4 93.210.14.100 Start: Thu Sep 1 12:45:41 2016 HOST: duvel Loss% Snt Last Avg Best Wrst StDev 1.|-- 62.210.128.13 0.0% 4 0.3 0.3 0.3 0.4 0.0 2.|-- 195.154.1.20 0.0% 4 0.4 0.4 0.3 0.4 0.0 3.|-- 195.154.1.16 0.0% 4 0.8 0.8 0.7 0.9 0.0 4.|-- lag-online-1.dc3-1.rt.hopus.net 0.0% 4 0.…

I was talking about the Hetzner network, not yours :-)

ho sorry, misread you :)

Re: DDoS protection

#36
post #10

PEARLS ==> SWINE

[parent commenter complained about 8 hour long downtimes and otherwise bad experience with Hetzner. He/she has since replaced the comment with insults to other HN users.] Counter experience: 4 years with Hetzner from small VPS to huge machines and based on traceroute servers in different sections/buildings of their datacenters. No hardware issues or hourlong downtimes you describe (other than myself messing up softwa…

This is not accurate. The complaint was about downtimes only.

Nowhere did the original comment mention "otherwise bad experiences", in fact it mentioned the good value that you get for the price.

The "insults" were clearly directed at the downvoters, thus at a small but nasty subset of HN users.

Re: DDoS protection

#37
post #30
post #26

Earlier quoted context omitted.

They have very competitive pricing and I haven't had major issues with them, polite and fast support as well. The only thing that rubbed me the wrong way is that they downright refuse to delete your credit card from their system when you terminate your (fully paid) account.

Yes, such shenanigans suck. But they are not the only ones (not that this makes it good)... Linode did the same to me, I asked kindly after their latest data breach and they refused to do so.

Tell your card issuer. That should get their attention quite promptly.

Re: DDoS protection

#38

We used to run some basic infrastructure on Hetzner. The support was appalling – any requests for help were swiftly met with short answers such as "Unfortunately we can not help you here". That makes me question how responsive and understanding Hetzner's staff will be in case of an on-going DDoS that their automated systems are unable to detect and take care of. What sort of scenario would benefit from the announced…

Any server would profit from it, you don't need to have a public website to be DDoSd

Re: DDoS protection

#39
I host at Hetzner and have noticed reduced Fail2ban notifications and shorter Logwatch emails recently.

If this has kicked it, I guess that might explain it.

Re: DDoS protection

#40
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

Looks much better than Hetzner.

What caught my eye is, if you scroll down long enough on dedicated servers page [1], you will eventually see GaaS - "Geek As A Service". This made me giggle far more than I am wiling to admit :)

[1]: https://www.online.net/en/dedicated-server

Post reply on HN