They are probably trying to reduce SIP abuse. It's a big problem.
Yeah, running SIP on a standard port without some serious firewall based rate limiting for unknown traffic is almost impossible. I tried running a PBX on UDP 5060 and got >4GiB of logged register attempts in a few hours after opening the port, while asterisk was running at 100% CPU just rejecting the registration attempts the whole time. It's insane compared to any other public service I run.
Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
31–40 of 95 posts
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#32They are probably trying to reduce SIP abuse. It's a big problem.
Ah, yes. The classic "all our customers are morons" approach, with no opt-out for those 0.1% who, in fact, are not. Very typical among ISPs/Telcos. Where I am, we used to have a different, "nerdy" ISP [0], where customer was allowed to bring their own modem; they also provided real IPv4/v6 dual-stack since forever, easy to request a /29, tech-support that's realistic to reach, and staffed with people who know what th…
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#33Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#34Earlier quoted context omitted.
Yeah, running SIP on a standard port without some serious firewall based rate limiting for unknown traffic is almost impossible. I tried running a PBX on UDP 5060 and got >4GiB of logged register attempts in a few hours after opening the port, while asterisk was running at 100% CPU just rejecting the registration attempts the whole time. It's insane compared to any other public service I run.
Have you tried fail2ban[0]? It can take log output from Asterisk and automatically insert iptables DROP rules for the source IP to block the traffic in the kernel. It still shows up on your interface and uses your bandwidth but dropping the packet in the kernel is much more efficient than Asterisk dealing with it (not to mention safer). It should also cause the bad actor to eventually give up on you and move elsewher…
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#35Earlier quoted context omitted.
Ah, yes. The classic "all our customers are morons" approach, with no opt-out for those 0.1% who, in fact, are not. Very typical among ISPs/Telcos. Where I am, we used to have a different, "nerdy" ISP [0], where customer was allowed to bring their own modem; they also provided real IPv4/v6 dual-stack since forever, easy to request a /29, tech-support that's realistic to reach, and staffed with people who know what th…
The opt-out is buy business-class service[0]. My guess is that the 2x price increase Xs4all was charging for their plan was a bridge too far for most customers. It's important to keep in mind that the vast majority of people rent their modem, don't know or care what a /29 is, and is calling tech support because the plug is loose or the modem needs a power cycle. Bulk-blocking SMTP happened because open ports are botn…
When it comes to internet service, "giving a crap about the customer" is a premium add-on from Comcast, but once you commit to opening your wallet for that, they do deliver.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#36Earlier quoted context omitted.
Yeah, in the past I tunneled everything through a VPS. These days I no longer bother, but I'm also getting service via a small ISP. It's a co-op and I got voted onto the board, so I have reasonable confidence against shenanigans.
Yep - VPS tunneling usually through nginx is how I get around it for my use cases. Cheers on the co-op ISP - that's outstanding and I wish more places did that. In so many ways that's living the dream!
I think in absolute numbers there are a lot of people who would value that, but only one or two people in any given area, so no way to service them. (Not considering sattelite for both bandwidth and latency reasons.)
A long time ago I was in some newsgroup or irc channnel and someone from Russia I think it was, was just casually describing their internet connection like it was normal but it was blowing my mind, which was basically some kind of totally home grown adhoc very local lash-up where they had 100M cat5 ethernet right to their appartment and strung between a few neighboring buildings. It wasn't clear who operated or provided the uplink but the switches and last bits of cat5 were just done by the local residents. No real "isp" like a US individual subscribing directly and individually from Comcast etc. Presumably there was some sort of co-op arrangement to share the cost of the actual shared connection.
I don't know at the time the idea of just running your own cat5 among a neighborhoods worth of buildings and getting way way WAY better service than what I could get paying even hundreds of $ as an individual residential consumer just blew my mind. Surely in the US some code inspector or other government official would come along and declare the cables illegal on some pretext or another, and surely the isp would call it some sort of theft or abuse.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#37They are probably trying to reduce SIP abuse. It's a big problem.
That doesn't make what they're doing okay. To see why, imagine that they instead blocked access to all email services except their own, since spam is a big problem.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#38Earlier quoted context omitted.
Yeah, running SIP on a standard port without some serious firewall based rate limiting for unknown traffic is almost impossible. I tried running a PBX on UDP 5060 and got >4GiB of logged register attempts in a few hours after opening the port, while asterisk was running at 100% CPU just rejecting the registration attempts the whole time. It's insane compared to any other public service I run.
Have you tried fail2ban[0]? It can take log output from Asterisk and automatically insert iptables DROP rules for the source IP to block the traffic in the kernel. It still shows up on your interface and uses your bandwidth but dropping the packet in the kernel is much more efficient than Asterisk dealing with it (not to mention safer). It should also cause the bad actor to eventually give up on you and move elsewher…
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#39They are probably trying to reduce SIP abuse. It's a big problem.
Ah, yes. The classic "all our customers are morons" approach, with no opt-out for those 0.1% who, in fact, are not. Very typical among ISPs/Telcos. Where I am, we used to have a different, "nerdy" ISP [0], where customer was allowed to bring their own modem; they also provided real IPv4/v6 dual-stack since forever, easy to request a /29, tech-support that's realistic to reach, and staffed with people who know what th…
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#40Earlier quoted context omitted.
From the wikipedia net neutrality page it looks like the FCC's stance has historically depended on the administration in power. There was the much celebrated 2015 change to title II, which was undone in 2017 i.e. the start of the ajit pai era. Now he is finally gone, but not before casting his vote in a 3-2 decision in 2020 to keep net neutrality dismantled. The new chair is pro-nn and working to undo the damage but…
Lol... I laugh everytime I see Republicans undo things in a matter of weeks and then 3 years later Democrats are like.. we wish we could do something but it takes time.
https://www.opensecrets.org/industries/lobbying.php?cycle=Al...