Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


OVH DDoS mitigation issue? [original: OVH Canada issue?]
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

OVH DDoS mitigation issue? [original: OVH Canada issue?]

perennateperennate Member, Host Rep
edited October 2014 in Providers

Anyone having issue with OVH Canada DDoS-mitigation system? I'm trying to call them but been on hold for a while, and not seeing anything on the status; all my IP addresses that were on "permanent mitigation" just went down even though they worked after swapping to automatic.

«1

Comments

  • Whilst switched to automatic mode, are the IPs still filtered?

  • perennateperennate Member, Host Rep

    kcaj said: Whilst switched to automatic mode, are the IPs still filtered?

    Sort of -- the automatic mode is the one that comes with SoYouStart, by default it puts traffic outside of the DDoS mitigation infrastructure, but if it detects an attack then it'll enable the DDoS mitigation.

  • perennate said: Sort of -- the automatic mode is the one that comes with SoYouStart, by default it puts traffic outside of the DDoS mitigation infrastructure, but if it detects an attack then it'll enable the DDoS mitigation.

    I know. I'm asking if you actually see traffic routed via their mitigation service whilst in automatic mode?

  • perennateperennate Member, Host Rep
    edited October 2014

    kcaj said: I know. I'm asking if you actually see traffic routed via their mitigation service whilst in automatic mode?

    When it activates it switches the traffic over to the mitigation service, I did see that before. But currently it's not over the mitigation service, which seems to indicate there is no attack.

    Edit: well I called them and they say they can ping it even though it's down from everywhere for me..

  • SplitIceSplitIce Member, Host Rep

    All of our on FR1-DDoS that are on permanant mitigation just went offline as well, it looks like OVH VAC is offline.

  • perennateperennate Member, Host Rep
    edited October 2014

    SplitIce said: All of our on FR1-DDoS that are on permanant mitigation just went offline as well, it looks like OVH VAC is offline.

    Ok, thanks for your reply... their support apparently not aware of this issue. Although I'm on Canada so weird that both went offline.

    Edit: I'm also able to ping 8.8.8.8 but not most places, so seems related to traffic entering their ddos mitigation from level 3 or something.

  • perennateperennate Member, Host Rep

    Yeah I just checked my France server down too x.x

  • VAC VUCKED.

    Thanked by 1ATHK
  • Looks like somebody is pushing a TON of bw out of their BHS facility http://weathermap.ovh.net/usa

  • SplitIceSplitIce Member, Host Rep
    edited October 2014

    @perennate I dont feel that this is a Level3 issue, the loss occurs inside the OVH network.

    13  * * vac2-0-a9.fr.eu.vaccum (178.33.100.97)  390.385 ms
    14  vac1-0-a9.fr.eu (178.33.100.154)  29.606 ms * 178.33.100.96 (178.33.100.96)  28.002 ms
    15  * * *
    16  vac1-0-a9.fr.eu (178.33.100.154)  38.590 ms * *
    17  * * *
    18  * * *
    19  * * *
    20  * vac1-0-a9.fr.eu (178.33.100.154)  41.631 ms *
    21  * * *
    22  178.33.100.96 (178.33.100.96)  44.491 ms * *
    
  • perennateperennate Member, Host Rep

    SplitIce said: I dont feel that this is a Level3 issue, the loss occurs inside the OVH network.

    Yes, I mean issue with DDoS mitigation only for traffic coming from Level 3 maybe. I'm not sure though anyway, but I could ping 8.8.8.8 from IP on their mitigation thing.

  • nexmarknexmark Member
    edited October 2014
  • perennateperennate Member, Host Rep

    Is anyone's DDoS mitigation not down?

  • AlbaHostAlbaHost Member, Host Rep
    edited October 2014

    We are occuring data loss in SBG-1 DC, servers are unavailable...

  • twiigltwiigl Member
    edited October 2014

    OVH issue in my mind. Server in GRA1 and MTR looping often
    |------------------------------------------------------------------------------------------|
    | Host - % | Sent | Recv | Best | Avrg | Wrst | Last |
    |------------------------------------------------|------|------|------|------|------|------|
    | fra-5-6k.de.eu - 32 | 19 | 13 | 14 | 19 | 37 | 16 |
    | sbg-g2-a9.fr.eu - 0 | 39 | 39 | 17 | 23 | 34 | 17 |
    | No response from host - 100 | 8 | 0 | 0 | 0 | 0 | 0 |
    | vac1-0-a9.fr.eu - 89 | 9 | 1 | 0 | 1291 | 1291 | 1291 |
    | No response from host - 100 | 8 | 0 | 0 | 0 | 0 | 0 |
    | No response from host - 100 | 8 | 0 | 0 | 0 | 0 | 0 |
    | No response from host - 100 | 8 | 0 | 0 | 0 | 0 | 0 |
    | vac1-0-a9.fr.eu - 89 | 9 | 1 | 0 | 100 | 100 | 100 |
    | No response from host - 100 | 8 | 0 | 0 | 0 | 0 | 0 |
    | vac1-0-a9.fr.eu - 89 | 9 | 1 | 1401 | 1401 | 1401 | 1401 |
    | No response from host - 100 | 8 | 0 | 0 | 0 | 0 | 0 |
    |________________________________________________|______|______|______|______|______|______|

  • SplitIceSplitIce Member, Host Rep

    @perennate said:
    Is anyone's DDoS mitigation not down?

    Anyone who isnt with OVH :P

    Its times like this why I remember why I categorized OVH as "basic". 1hr 10 minutes without support response to outage that started 1hr 17minutes ago.

  • SplitIceSplitIce Member, Host Rep
    edited October 2014

    For those putting their IP's into "auto" mode to work around the issue until OVH resolve it, you do not need to disable the firewall - it is still working.

    Here is a script for setting an IP to "auto": https://gist.github.com/splitice/5db2b95ee7c80587c340

    100% Hack Job & a large number of dependencies.

    Thanked by 1linuxthefish
  • GreenHostBoxGreenHostBox Member
    edited October 2014

    Hello,

    There is currently a Network issue that has caused many of our servers to become unavailable. This may be affecting your service. The situation should revert to normal very shortly, as our team is working to solve this ASAP. It is our top priority.


    There is a work around for this issue,


    Log into the OVH manager

    Select the IP tab

    Select the cog wheel to the right of the IP

    Temporarily disable the firewall until the issue is resolved.


    You can refer to this web page for updates.

    http://status.ovh.net/?do=details&id=7863


    A network component is currently defective, our team is currently in the process of resolving the issue.

  • SplitIceSplitIce Member, Host Rep
    edited October 2014

    Yeah sure, I am doing that for 129 IPs.

    @GreenHostBox
    Thanks for the link, but:

    EDIT: its http

    http://status.ovh.net/?do=details&id=7863

    7863 is BHS, given 100 of those IPs of mine are RBX....

  • SplitIceSplitIce Member, Host Rep

    Issue affecting RBX appears resolved.

  • perennateperennate Member, Host Rep

    Is anyone else getting problems with this again?

  • AlbaHostAlbaHost Member, Host Rep

    @perennate said:
    Is anyone else getting problems with this again?

    Yes, we are getting problems with them again...

  • I received a VAC DDoS notification email earlier, which is abnormal because I don't get attacked. I wonder if that's relevant to this?

  • perennateperennate Member, Host Rep
    edited November 2014

    Damn, yeah it's similar issue, it works after disabling firewall and switching to auto mitigation. This is really bad, second incident in one month, and anyway their DDoS mitigation often blocks legitimate traffic (I got short attack from a week ago on one IP address, it's still "forced mitigation" now and only HTTP traffic seems to be accepted). Sure it's budget service, but it seemed to work mostly well for a while, at least for me it was still better than other filtering that I tried, but these downtimes are really annoying.

  • AlbaHostAlbaHost Member, Host Rep

    @perennate said:
    Damn, yeah it's similar issue, it works after disabling firewall and switching to auto mitigation. This is really bad, second incident in one month, and anyway their DDoS mitigation often blocks legitimate traffic (I got short attack from a week ago on one IP address, it's still "forced mitigation" now and only HTTP traffic seems to be accepted). Sure it's budget service, but it seemed to work mostly well for a while, at least for me it was still better than other filtering that I tried, but these downtimes are really annoying.

    Well your'e still lucky guy, since from our side even disabling the firewall the ips are still not pingable/reachable...

  • perennateperennate Member, Host Rep

    AlbaHost said: Well your'e still lucky guy, since from our side even disabling the firewall the ips are still not pingable/reachable...

    You both switched to auto mitigation, and also disabled the firewall from OVH IP manager?

  • AlbaHostAlbaHost Member, Host Rep

    @perennate said:
    You both switched to auto mitigation, and also disabled the firewall from OVH IP manager?

    Yes and still nothing.

  • Seeing the same issue affecting our NA Minecraft Nodes, as others have said switching to automatic seems to resolve it.

  • rm_rm_ IPv6 Advocate, Veteran

    With the mitigation issues, did you see this? http://status.ovh.net/?do=details&id=8110

    Thanked by 1marrco
Sign In or Register to comment.