OpenBSD blocked at the routers?

September 22th, 2014

When I spend my weekends at my parents I usually do all network things as usual on my netbook. Just that my parents have a different provider (DTAG or aka Deutsche Telekom). Here is a traceroute from my parents house to my VPS io.solarscale.de:

                                       Packets               Pings              
 Host                                Loss%   Snt   Last   Avg  Best  Wrst StDev 
 1. fritz.box                         0.0%    28    7.5   7.5   6.1   8.5   0.3 
 2.                      3.7%    27   60.0  56.3  53.1  70.1   3.3 
 3.                       0.0%    27   57.5  58.2  51.7  73.2   3.9 
 4. f-ed4-i.F.DE.NET.DTAG.DE          0.0%    27   60.9  63.2  58.2  77.5   5.1 
 5.                     3.7%    27   61.0  60.1  57.3  62.1   1.0 
 6. core4.hetzner.de                  7.4%    27   61.0  60.6  58.0  64.3   1.2 
 7. core21.hetzner.de                 3.8%    27   64.6  65.6  61.6  79.8   3.3 
 8. juniper3.rz10.hetzner.de          0.0%    27   67.9  66.1  61.1  76.7   3.2 
 9. hos-tr1.ms-ex3k1.rz13.hetzner.de  7.4%    27   66.4  66.3  63.2  73.1   1.7 
10. io.solarscale.de                  0.0%    27   64.9  64.7  61.9  67.6   1.1 

The return route looks like this:

traceroute to (, 64 hops max, 52 byte packets
 1  static. (  0.914 ms  1.288 ms  0.909 ms
 2  hos-tr2.juniper3.rz10.hetzner.de (  0.319 ms  0.372 ms  0.291 ms
 3  core22.hetzner.de (  0.337 ms  0.334 ms
    core21.hetzner.de (  0.333 ms
 4  core4.hetzner.de (  4.976 ms  4.952 ms  4.961 ms
 5  juniper4.ffm.hetzner.de (  5.054 ms  5.036 ms  5.034 ms
 6 (  5.098 ms (  5.102 ms  5.059 ms
 7  f-sb1-i.F.DE.NET.DTAG.DE (  11.048 ms  13.225 ms  11.980 ms
 8  wue-ea1-i.WUE.DE.NET.DTAG.DE (  12.899 ms  12.667 ms  13.767 ms
 9  wue-sc2-i.WUE.DE.NET.DTAG.DE (  11.224 ms (  11.609 ms  11.867 ms
10  p54AAACEF.dip0.t-ipconnect.de (  56.456 ms !X  56.265 ms 

Now then I connected an SSH and ran tmux. Switching windows causes larger SSH packets and I noticed that they get re-transmitted, when dumping on the outgoing interface on io.solarscale.de (re0). Here is what they look like:

Notice on packets #378 through #388 there is three retransmissions of a 966 byte length packet. This was captured on io.solarscale.de. On #390 which was captured on fritz!box's interface it's sent out to the netbook in question. The fritz!box does not receive the three retransmissions on it's PPPoE interface as the next screenshot shows of it's PPPoE packet dump:

Notice on packet #175 the 984 byte length packet arrives. Why is it 8 bytes larger? Because of the nature of PPPoE. Notice in the #175 vicinity no retransmissions make it to the PPPoE interface. From this I can deduct that it is not the Fritz!Box router.

Now then. It gets worse. A Linux box on my parents' LAN has absolutely no problems with SSH on io.solarscale.de. It only affects my OpenBSD netbook.

Could there be something such as a TCP OS Fingerprinting firewall that uses discrimination against OpenBSD TCP stacks? It would need to be done on a flow basis if such a thing exists.

This is really annoying me as I'm inviting laughs and denial that anything is wrong.


Equinox in three days

September 20th, 2014

Equinox is in three days! At equinox the earth is exactly perpendicular if you were to draw a cross, with lines between the north and the south pole, and the equator and the sun. After equinox as this is the southward equinox favouring the direction of the tropic of capricorn, the northern hemisphere will fall into autumn, and countries north of the equator will have longer nights than days. The sun at high noon will continue to dip everyday as it has been since the June solstice, until the December solstice at which point it will start to rise again. Isn't the earth wonderful? I love this!


Purchased some Reggae

September 17th, 2014

I have purchased the downtown riddim from itunes. A long favourite of mine on youtube, I finally have it on my ipod now.


The Enforcers of the Internet?

September 12th, 2014

Some government body in Bavaria is writing warnings and threats to Internet companies that don't use STARTTLS in their mail servers. I don't think it's right to threaten Internet operators with fines when they don't encrypt. Instead they should give Incentives to Internet companies to start encrypting. Pretend you run your own mail server that doesn't have crypto built in... I think this is the wrong methods the state is using just to "protect" its citizens.


Moon finally gone

September 10th, 2014

The VPS in Hong Kong is gone. Here is the last message I saw from it.

You have new mail in /var/mail/pjp
[pjp@76er ~]$ Write failed: Broken pipe
that was from 76er.virgostar.net one of its jails.

I'd like to thank the people of Hong Kong, the city of Hong Kong, NTT and Host Virtual (vr.org) for making this VPS possible for me for 20 dollars a month. Hong Kong has good infrastructure IMO, especially near the HKIX internet exchange, although I can only guess about it really. It was my pleasure staying there for 2 years. As they would say in france, a bientot!

I'll now remove the mentions of moon.virgostar.net from my DNS.


Venus (computer) has 4 more interfaces

September 7th, 2014

This morning my dad and I transplanted my Soekris 6501 (aka venus) from its small case to a 19" rackmount case and added a lan1841 to it. It now has 8 gigabit interfaces. When I return home I'll have some time to configure the new ports and add my rpi to it. Giving me 3 open ports in the hallway and 2 open ports in my office (by taking the rpi out). I'm very happy.


Donation time again

September 2nd, 2014

After a long break from donations of any kind I activated donations again. I've written a transfer for OpenBSD which I'll bring to the bank this friday. The amount is for 100 Euros. This will be the last for OpenBSD for this year and brings the amount to 300 if I'm not mistaken. It's a little less than the previous years but I'm also facing less income this year due to currency exchange. Hoping for a raise soon. :-)


Purchased Soekris Addons

September 1st, 2014

Happy September! I have purchased a 19" soekris case with internal powersupply and one quad ethernet addon card for my 6501. What I plan to do with this is place venus into my office and uranus into the hallway. I gain 2 ports on both locations that way, and I can possibly put the raspberry pi back in the hallway. Once I get the gear I'll have to wait for the right time to do the operation from venus's (my soekris 6501) old case to the new case. Anyone interested in buying a normal soekris 6501 case (metal) with external power supply should make me an offer preferably if you live in europe.


War in Europe

August 29th, 2014

I think it's fair to say that we have war in Europe. This is the most devastating piece of news, after Chernobyl, I have come across concerning Europe in my life. Now is a good time to stop and listen to the UN.


Holidays coming to an end

August 29th, 2014

I had 2 weeks holidays and I didn't do very much except veg. I did write a bit of code but not the bit of code I wanted to write. It'll have to be written another time.


