New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Comments
Only WMD disk available.
What's your use case? If you're aiming for low latency to Iranians, you're going to be paying an eyewatering amount because you'll need TIC, only TIC, and nothing but TIC.
Exservers
Hostiran?
Just read that they are blocking those providers due to the conflict?
As long as they are not powered by nuclear energy you should have no problems
FYI, my VPS from itpiran is down and the support does not reply.
Their panel works, but not the host node.
https://radar.cloudflare.com/ir
@zGato I'm aware of the shutdown as well. It quite possibly (and most likely) due to censorship, but their (billing) panel still works.
Is their billing's IP in Iran?
It's behind Cloudflare.
https://client.itpiran.net/
I read that Iran government deliberately slowed down the internet to discourage people from posting videos. But the speed is still fine for ssh
It's not really slowed down, but outright blocked. Outgoing connections from Iranian VPSs (or standard ISP) are blocked, but some incoming connections from X ranges are accepted (and thus you make a tunnel). It's actually quite stable but unpredictable since this seems to be some whitelist they have.
There is a specific DC in Tehran that incoming traffic is not whitelisted, but outgoing is still blocked
This is probably hosted in one of their Hetzner boxes or their other locations outside of Iran. It's timing out cause it's trying to connect to their cluster most likely (alpha-cloud.itpiran.net)
Either node is down or its network is down, since not even whitelisted ranges can ping it.
I saw that you were talking about this @zGato @ValdikSS . Just so you know a few days after my post about internet status in Iran it got worse, most data centers in Iran got full intranet and didn't had incoming and outgoing access to foreign IPs (even google.com), only a small count of ip ranges were able to access outside, but 2 data centers (AminIDC and Tebyan) were able to access outside easily, although they dropped some connections once in a few hours but after all this was fine. About other DCes after 1 day seemed that it got a little better, connection to google.com got available again but and other data centers seemed to open outgoing access to foreign IPs but not incoming, so people who ran vpn started to run ping tunnels and 6TO4 tunnels and that worked well. Until now tunnels have the issue of dropping connections once in a few hours but as it doesn't get fully disconnected it's fine. But about Valdik Iran server , I think you will not be able to connect to it until they disable the firewall, who knows
Interesting.
So some DCs are able to establish an outgoing connection but incoming traffic will be dropped ?
So people are running VPN Tunnels to an outgoing connection ?
I’ve tried to reach some Hosts but the only AS which is partly available is irancell.
Even the Speedtest server in Teheran is still
Working.
Yes exactly. And as you said Irancell server was available, I don't know why but seems they're getting back to normal, even TCI servers on check-host.net got online again
Apparently the host's panel does not work due to large TLS ClientHello with ML-KEM (Kyber) cipher, and disabling Kyber support allowed me to log into the panel and access the VPS over KVM.
TCP is generally totally blocked, but ICMP is not. I managed to set up a tunnel.
Used Tor Relays as a source of fairly diverse IP ranges, scanned them by connecting, sending TLS ClientHello and waiting for a reply (as the block allows connection and sending the handshake, but filters the reply).
Here are working Relays, hence IP ranges, so far:
This one is mine btw. So proud of him
Thank you for your research. If you need access to this for testing IP, contact me in DMs.
Is ML-KEM enabled in TLS by default? I thought it's still a draft.
It is, in all browsers. I spotted that the panel opens with curl by accident, and started to investigate why. Guess it's part of the censorship.
That's awesome
Technical discussion is in https://github.com/net4people/bbs/issues/484
Here's my
sshguard
logs for anyone to help as well:Looks like most of the working relays are from South Africa. So our exit TOR relays should still work?
Is from @zGato in Singapore. We already knew it was working.
All the other ones (including mine) are from Host Africa. It looks like they didn't block HostAfrica IP range properly.
It's worth trying yours @MAXKO_Hosting but I doubt they will work.
@MAXKO_Hosting based on my tests, 102.211.56.0/24 is at least not whitelisted. You have a /22, so there's a small chance (but I highly doubt) that other /24s are whitelisted. Whitelisted ranges are only from previously used ones that got whitelisted for X/Y reasons and if your /22 is fresh from AFRINIC then there's 0 chance.