home.social

#hurricaneelectric — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hurricaneelectric, aggregated by home.social.

fetched live
  1. eat your hearts out, IPv6 nerds - HE sent me my Sage t-shirt as a lil surprise. excuse me while I *flex* a bit... 💪

    #ipv6 #hurricaneelectric #hedotnet

  2. Looking for a sponsoring LIR for my ASN.
    I run a small non‑commercial network with a WireGuard uplink via Route64 and plan a second upstream (HE POP) for redundancy and BGP/IPv6 learning.
    I can maintain IRR/RPKI. Any LIR willing to sponsor an ASN is welcome.

    #BGP #ASN #IPv6 #Multihoming #HomeLab #NetOps #NetworkEngineering #RIPE #LIR #NOG #PLNOG #DENOG #NLNOG #UKNOF #Routing #Sysadmin #Route64 #HurricaneElectric

  3. Looking for a sponsoring LIR for my ASN.
    I run a small non‑commercial network with a WireGuard uplink via Route64 and plan a second upstream (HE POP) for redundancy and BGP/IPv6 learning.
    I can maintain IRR/RPKI. Any LIR willing to sponsor an ASN is welcome.

    #BGP #ASN #IPv6 #Multihoming #HomeLab #NetOps #NetworkEngineering #RIPE #LIR #NOG #PLNOG #DENOG #NLNOG #UKNOF #Routing #Sysadmin #Route64 #HurricaneElectric

  4. Looking for a sponsoring LIR for my ASN.
    I run a small non‑commercial network with a WireGuard uplink via Route64 and plan a second upstream (HE POP) for redundancy and BGP/IPv6 learning.
    I can maintain IRR/RPKI. Any LIR willing to sponsor an ASN is welcome.

    #BGP #ASN #IPv6 #Multihoming #HomeLab #NetOps #NetworkEngineering #RIPE #LIR #NOG #PLNOG #DENOG #NLNOG #UKNOF #Routing #Sysadmin #Route64 #HurricaneElectric

  5. @openalt Tohle řeším taky. Vodafone modem mám v bridge modu, za ním #turris router s veřejnou statickou IPv4 a s tunelovanou IPv6 od #HurricaneElectric.
    Dospěl jsem k tomu, že turris sám resolvuje DNS přes #kresd, a u ručně udržovaného seznamu adres odebírá IPv6 adresy z odpovědi a potlačuje DNSSEC.

  6. @openalt Tohle řeším taky. Vodafone modem mám v bridge modu, za ním #turris router s veřejnou statickou IPv4 a s tunelovanou IPv6 od #HurricaneElectric.
    Dospěl jsem k tomu, že turris sám resolvuje DNS přes #kresd, a u ručně udržovaného seznamu adres odebírá IPv6 adresy z odpovědi a potlačuje DNSSEC.

  7. @openalt Tohle řeším taky. Vodafone modem mám v bridge modu, za ním #turris router s veřejnou statickou IPv4 a s tunelovanou IPv6 od #HurricaneElectric.
    Dospěl jsem k tomu, že turris sám resolvuje DNS přes #kresd, a u ručně udržovaného seznamu adres odebírá IPv6 adresy z odpovědi a potlačuje DNSSEC.

  8. @openalt Tohle řeším taky. Vodafone modem mám v bridge modu, za ním #turris router s veřejnou statickou IPv4 a s tunelovanou IPv6 od #HurricaneElectric.
    Dospěl jsem k tomu, že turris sám resolvuje DNS přes #kresd, a u ručně udržovaného seznamu adres odebírá IPv6 adresy z odpovědi a potlačuje DNSSEC.

  9. @openalt Tohle řeším taky. Vodafone modem mám v bridge modu, za ním #turris router s veřejnou statickou IPv4 a s tunelovanou IPv6 od #HurricaneElectric.
    Dospěl jsem k tomu, že turris sám resolvuje DNS přes #kresd, a u ručně udržovaného seznamu adres odebírá IPv6 adresy z odpovědi a potlačuje DNSSEC.

  10. @dentangle I have tried to use their ipv6 tunnel broker but every of my servers' IP addresses is marked as "restricted network".
    I have tried VDS in Paris from OWH, dedicated server in Paris from OWH, VDS in Turkie from IsHosting, my home IP address in Russia, my friend's server IP address also in Russia.
    Everything is restricted in HE.
    Also it was a challenge to even create an account on he.net.
    I had to pass through a quest of guessing allowed email address.
    gmail.com - no;
    yandex.ru, yandex.com, ya.ru, ya.com - also prohibited;
    my custom cyrmax.ru domain - prohibited;
    email on internet.ru domain - prohibited;
    mail.ru, list.ru, bk.ru - also not allowed.

    Only with my google address but with gmail replaced with googlemail I have managed to create an account.
    And after that faced this IP address problem when everything I enter is in restricted network.

    Btw nothing about that in their docs.

    #he #hurricaneelectric #henet

  11. @dentangle I have tried to use their ipv6 tunnel broker but every of my servers' IP addresses is marked as "restricted network".
    I have tried VDS in Paris from OWH, dedicated server in Paris from OWH, VDS in Turkie from IsHosting, my home IP address in Russia, my friend's server IP address also in Russia.
    Everything is restricted in HE.
    Also it was a challenge to even create an account on he.net.
    I had to pass through a quest of guessing allowed email address.
    gmail.com - no;
    yandex.ru, yandex.com, ya.ru, ya.com - also prohibited;
    my custom cyrmax.ru domain - prohibited;
    email on internet.ru domain - prohibited;
    mail.ru, list.ru, bk.ru - also not allowed.

    Only with my google address but with gmail replaced with googlemail I have managed to create an account.
    And after that faced this IP address problem when everything I enter is in restricted network.

    Btw nothing about that in their docs.

    #he #hurricaneelectric #henet

  12. @dentangle I have tried to use their ipv6 tunnel broker but every of my servers' IP addresses is marked as "restricted network".
    I have tried VDS in Paris from OWH, dedicated server in Paris from OWH, VDS in Turkie from IsHosting, my home IP address in Russia, my friend's server IP address also in Russia.
    Everything is restricted in HE.
    Also it was a challenge to even create an account on he.net.
    I had to pass through a quest of guessing allowed email address.
    gmail.com - no;
    yandex.ru, yandex.com, ya.ru, ya.com - also prohibited;
    my custom cyrmax.ru domain - prohibited;
    email on internet.ru domain - prohibited;
    mail.ru, list.ru, bk.ru - also not allowed.

    Only with my google address but with gmail replaced with googlemail I have managed to create an account.
    And after that faced this IP address problem when everything I enter is in restricted network.

    Btw nothing about that in their docs.

    #he #hurricaneelectric #henet

  13. @dentangle I have tried to use their ipv6 tunnel broker but every of my servers' IP addresses is marked as "restricted network".
    I have tried VDS in Paris from OWH, dedicated server in Paris from OWH, VDS in Turkie from IsHosting, my home IP address in Russia, my friend's server IP address also in Russia.
    Everything is restricted in HE.
    Also it was a challenge to even create an account on he.net.
    I had to pass through a quest of guessing allowed email address.
    gmail.com - no;
    yandex.ru, yandex.com, ya.ru, ya.com - also prohibited;
    my custom cyrmax.ru domain - prohibited;
    email on internet.ru domain - prohibited;
    mail.ru, list.ru, bk.ru - also not allowed.

    Only with my google address but with gmail replaced with googlemail I have managed to create an account.
    And after that faced this IP address problem when everything I enter is in restricted network.

    Btw nothing about that in their docs.

    #he #hurricaneelectric #henet

  14. Semi useful workaround that I came up with is setting up a #Hurricaneelectric tunnel for my primary mta mx1.ipoac.nl . That way I can control its reverse DNS.

    This works fine for providers that support v6. But for others I have decided to use Ziggo's servers as fallback relay/smarthost. Which seems to work fine.

    Only upside is is that smtp over v4 inbound is not blocked. So it could be worse :P

  15. Semi useful workaround that I came up with is setting up a #Hurricaneelectric tunnel for my primary mta mx1.ipoac.nl . That way I can control its reverse DNS.

    This works fine for providers that support v6. But for others I have decided to use Ziggo's servers as fallback relay/smarthost. Which seems to work fine.

    Only upside is is that smtp over v4 inbound is not blocked. So it could be worse :P

  16. Semi useful workaround that I came up with is setting up a #Hurricaneelectric tunnel for my primary mta mx1.ipoac.nl . That way I can control its reverse DNS.

    This works fine for providers that support v6. But for others I have decided to use Ziggo's servers as fallback relay/smarthost. Which seems to work fine.

    Only upside is is that smtp over v4 inbound is not blocked. So it could be worse :P

  17. omg, #hurricaneelectric #ipv6 tunnel has lower latency to google than #centurylink's ipv6 tunnel, 13-14ms vs 20ms. It's even the same as the native ipv4!

    to other more distant servers not the case though... and #he has notable jitter...
  18. omg, #hurricaneelectric #ipv6 tunnel has lower latency to google than #centurylink's ipv6 tunnel, 13-14ms vs 20ms. It's even the same as the native ipv4!

    to other more distant servers not the case though... and #he has notable jitter...
  19. omg, #hurricaneelectric #ipv6 tunnel has lower latency to google than #centurylink's ipv6 tunnel, 13-14ms vs 20ms. It's even the same as the native ipv4!

    to other more distant servers not the case though... and #he has notable jitter...
  20. omg, #hurricaneelectric #ipv6 tunnel has lower latency to google than #centurylink's ipv6 tunnel, 13-14ms vs 20ms. It's even the same as the native ipv4!

    to other more distant servers not the case though... and #he has notable jitter...
  21. @hugo for accessing remotely, my server and also LXD containers. i have to hardcode the whole ipv6 in the firewall, it would be nice if it could do a partial match. hmm, I suppose I can match interface instead, that should work fine in my setup... 🤔

    but anyway I need to find a 6rd script for mikrotik...

    OR... how about I use #hurricaneelectric's free 6to4 tunnel... They support DDNS *AND* I will have a static prefix! OWO! I wonder if it will be faster or slower than centurylink's 6rd server... I will experiment!!!! :3425_freakouteyes:
  22. @hugo for accessing remotely, my server and also LXD containers. i have to hardcode the whole ipv6 in the firewall, it would be nice if it could do a partial match. hmm, I suppose I can match interface instead, that should work fine in my setup... 🤔

    but anyway I need to find a 6rd script for mikrotik...

    OR... how about I use #hurricaneelectric's free 6to4 tunnel... They support DDNS *AND* I will have a static prefix! OWO! I wonder if it will be faster or slower than centurylink's 6rd server... I will experiment!!!! :3425_freakouteyes:
  23. @hugo for accessing remotely, my server and also LXD containers. i have to hardcode the whole ipv6 in the firewall, it would be nice if it could do a partial match. hmm, I suppose I can match interface instead, that should work fine in my setup... 🤔

    but anyway I need to find a 6rd script for mikrotik...

    OR... how about I use #hurricaneelectric's free 6to4 tunnel... They support DDNS *AND* I will have a static prefix! OWO! I wonder if it will be faster or slower than centurylink's 6rd server... I will experiment!!!! :3425_freakouteyes:
  24. Thanks to the free #HurricaneElectric #IPv6 tunnel service (and a bit if inspiration by @lamp). I could finally enable IPv6 for my server. Yay.

  25. Thanks to the free #HurricaneElectric #IPv6 tunnel service (and a bit if inspiration by @lamp). I could finally enable IPv6 for my server. Yay.

  26. Thanks to the free #HurricaneElectric #IPv6 tunnel service (and a bit if inspiration by @lamp). I could finally enable IPv6 for my server. Yay.

  27. Thanks to the free #HurricaneElectric #IPv6 tunnel service (and a bit if inspiration by @lamp). I could finally enable IPv6 for my server. Yay.

  28. wonder if #hurricaneelectric #ipv6 tunnel might be better than #centurylink #6rd; looks like 1-2 less ms to los angeles
  29. wonder if #hurricaneelectric #ipv6 tunnel might be better than #centurylink #6rd; looks like 1-2 less ms to los angeles
  30. so I'm using #hurricaneelectric's free #ipv6 tunnel. They provide an address for the client tunnel interface, but they also route a different prefix to that address.

    The problem is I want to use addresses from that routed prefix on the host, so I assign one to the eth0 (just like the #netplan example shows https://netplan.readthedocs.io/en/stable/examples/#how-to-connect-to-an-ipv6-over-ipv4-tunnel). But #linux prefers the address on the tunnel interface.

    It seems I can delete that IP and it still works, but is this right? It sounds like it has to be there. Also, it seems I can use other IPs in the subnet of the "client address" (i.e. 2001:470:70:c0::3/64), is that fine?
  31. I set up the #hurricaneelectric #tunnelbroker in #openwrt according to openwrt.org/docs/guide-user/ne - but RX/TX in the interface view stays at 0, and I can't ping my tunnel endpoint either.

    Do I need some additional firewall rules? tcpdump with filtering the IPv4 endpoint address doesn't show anything either.

    Does openwrt connect at all? mh...

  32. I set up the #hurricaneelectric #tunnelbroker in #openwrt according to openwrt.org/docs/guide-user/ne - but RX/TX in the interface view stays at 0, and I can't ping my tunnel endpoint either.

    Do I need some additional firewall rules? tcpdump with filtering the IPv4 endpoint address doesn't show anything either.

    Does openwrt connect at all? mh...