11 ms·
Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
For several years, I've run 3 VOIP phones from my house. About a week ago they stopped working. SIP REGISTER started failing.
Turns out Spectrum now blocks TCP/UDP port 5060. My workaround is to use a VPN. After that, everything is fine.
This reddit thread https://www.reddit.com/r/networking/comments/t8nulq/spectrum_is_rate_limiting_voipsip_traffic_port/ suggests Spectrum was rate limiting 5060 on 300mbps plans, but not on the 100mbps plans.
I have the 100mbps plan, and it is definitely affected now.
So if you are in SoCal, using Spectrum, and your VOIP phones suddenly stopped working in the last week or so, maybe this will help you.
- matt123456789 4y agoGuess they want you to pay for their bundled phone plan instead. I’m guessing you can bring this to their attention and get some boilerplate response containing words like “abuse” and “safety”. Prognosis: This will go to court on common carrier terms and the block will be lifted in 3-4 years.
- another_comment 4y ago>> Guess they want you to pay for their bundled phone plan instead. I think you are right. But I am waaaay to cheap for that. I'm using Twilio on some Raspberry Pi's with some software I wrote myself. For 3 phone numbers, I'm spending like $10 a month total.
- jeroenhd 4y agoIs that even legal? Blocking network traffic because it competes with their offering?
- jmole 4y agoMaybe they're forwarding the port to an internal service running on the router, instead of blocking it. At the very least, it would be nice if they let you turn it off.
- zbrozek 4y agoCarriers do all kinds of filtering. They've blocked mail, file transfer, network discovery, and others for a long time. cgNAT blocks half of everything.
- peterangular 4y agoYep - best practice is to always tunnel, or reverse proxy out on a random port if you're self-hosting anything. Have had many providers over the years and have anecdotally found that experience to be very true.
- zbrozek 4y agoYeah, in the past I tunneled everything through a VPS. These days I no longer bother, but I'm also getting service via a small ISP. It's a co-op and I got voted onto the board, so I have reasonable confidence against shenanigans.
- peterangular 4y agoYep - VPS tunneling usually through nginx is how I get around it for my use cases. Cheers on the co-op ISP - that's outstanding and I wish more places did that. In so many ways that's living the dream!
- Brian_K_White 4y agoI've certainly dreamed of a co-op / credit union isp. I think in absolute numbers there are a lot of people who would value that, but only one or two people in any given area, so no way to service them. (Not considering sattelite for both bandwidth and latency reasons.) A long time ago I was in some newsgroup or irc channnel and someone from Russia I think it was, was just casually describing their internet connection like it was normal but it was blowing my mind, which was basically some kind of totally home grown adhoc very local lash-up where they had 100M cat5 ethernet right to their appartment and strung between a few neighboring buildings. It wasn't clear who operated or provided the uplink but the switches and last bits of cat5 were just done by the local residents. No real "isp" like a US individual subscribing directly and individually from Comcast etc. Presumably there was some sort of co-op arrangement to share the cost of the actual shared connection. I don't know at the time the idea of just running your own cat5 among a neighborhoods worth of buildings and getting way way WAY better service than what I could get paying even hundreds of $ as an individual residential consumer just blew my mind. Surely in the US some code inspector or other government official would come along and declare the cables illegal on some pretext or another, and surely the isp would call it some sort of theft or abuse.
- throw0101c 4y agoThe terms of service may prohibit running a "service" or "server", for some definition, on a residential contract.
- yummypaint 4y agoFrom the wikipedia net neutrality page it looks like the FCC's stance has historically depended on the administration in power. There was the much celebrated 2015 change to title II, which was undone in 2017 i.e. the start of the ajit pai era. Now he is finally gone, but not before casting his vote in a 3-2 decision in 2020 to keep net neutrality dismantled. The new chair is pro-nn and working to undo the damage but it takes time.
- encryptluks2 4y agoLol... I laugh everytime I see Republicans undo things in a matter of weeks and then 3 years later Democrats are like.. we wish we could do something but it takes time.
- calibas 4y agoNot surprising, the US telecommunications industry spends over $100 million per year on lobbying. They must be getting something in return. https://www.opensecrets.org/industries/lobbying.php?cycle=All&ind=b09 https://www.opensecrets.org/industries/lobbying.php?cycle=Al...
- tchaffee 4y agoRepublicans don't undo things in a matter of weeks. Obamacare is one example. Roe v. Wade is another.
- encryptluks2 4y agoIt takes longer than weeks to plan, but when they enact their plans it doesn't take long. Democrats always play the game of... had we only known they could do that, now our hands our tied. Case in point is when they authorized the COVID-19 pandemic relief and then Trump fired the single person responsible for preventing fraud, and Democrats were like... hmm, we did nazi that coming.
- tchaffee 4y ago
- another_comment 4y agoMy call quality also seems better since I've switched on the VPN. I do not have numerical proof of this, but it sure seems like my voice calls are crystal clear now.
- another_comment 4y agoMy guess is Spectrum has been rate limiting port 5060 for a while, and finally just turned it off. Nice.
- kkielhofner 4y agoWith standard SIP implementations port 5060 is used for signaling and RTP for the actual media uses different (negotiated) ports. Rate limiting 5060 wouldn’t have any impact on call quality.
- relentlesshack 4y agoUse a session border controller if possible to get around the port blocking.
- animitronix 4y agoSue them into the ground
- dylan604 4y agoThey'll just change names again, so your suit will be for a new dead company
- _wldu 4y agoThey are probably trying to reduce SIP abuse. It's a big problem.
- josephcsible 4y agoThat doesn't make what they're doing okay. To see why, imagine that they instead blocked access to all email services except their own, since spam is a big problem.
- Gordonjcp 4y agoThat's basically what domestic ISPs do. You will probably find that outbound traffic on port 25 is blocked, because all of your pwn3d inadequately-patched Windows machines are spam cannons now.
- bombcar 4y agoYep - some block it so hard you have to use other ports to communicate with offsite mail servers (and why various other ports are found, now). Some ISPs will remove the block if you ask.
- chrismeller 4y agoI’ve come to treat residential ISPs as basically a transit for HTTP. As someone else in the thread pointed out that’s all that 99.99% of customers care about, and unfortunately you’re talking about a lowest common denominator here.
- im3w1l 4y agoAnd this is (one of the reasons) why you should design modern protocols to use https as transport layer.
- nousermane 4y agoAh, yes. The classic "all our customers are morons" approach, with no opt-out for those 0.1% who, in fact, are not. Very typical among ISPs/Telcos. Where I am, we used to have a different, "nerdy" ISP [0], where customer was allowed to bring their own modem; they also provided real IPv4/v6 dual-stack since forever, easy to request a /29, tech-support that's realistic to reach, and staffed with people who know what they are talking about, no bulk-firewalling port-25, etc... All for a modest 2x price increase over market average. Alas, they're out of business now. [0] https://en.wikipedia.org/wiki/Xs4all https://en.wikipedia.org/wiki/Xs4all
- Kikawala 4y agoAre they also blocking 5061 SIP-TLS?
- StayTrue 4y agoCan you use port 5061?
- another_comment 4y agoExcellent question. I will try that tomorrow morning and report back.
- gsich 4y ago5061/tcp is preferrable. It also works with TLS.
- thomashabets2 4y agoMy ISP breaks traceroute outside of the network. Their transit is cut out of my traceroutes. Full technical story at https://blog.habets.se/2022/05/Another-way-MPLS-breaks-traceroute.html https://blog.habets.se/2022/05/Another-way-MPLS-breaks-trace...
- ShroudedNight 4y agoHuh, I remember back in the day seeing weird latency cliffs like that when trying to troubleshoot latency issues when playing World of Warcraft. There always seemed to be one between basically any ISP I was connected to and the AT&T network blizzard was running their servers on.
- thomashabets2 4y agoThe weird part is not any latency numbers (TTL exceeded is not handled by a router's fast path), but hops missing. Hops marked with "* * *" do not count as "missing" here.
- mike_d 4y agoIt looks like someone technical from your ISP also replied in the comments of your post and offered to set up a call to explain it to you. That is far better than you can expect from almost any other provider.
- thomashabets2 4y agoYeah, long story short I had a call with him, and he agreed that's probably right but it's not a priority to fix. I hope they'll fix it soon, but not if it delays IPv6. If I had a choice of FTTP providers then IPv6 support would weigh really high on my choice, but only one has dug up the street.
- TheSwordsman 4y agoAt least where I am in SoCal, AT&T literally just deployed fiber with plans up to 5 gigabit/s. I'm so glad to be leaving Spectrum behind, because when moving here I never thought I'd have a cable Internet provider that made me miss Comcast... So hopefully you have some other options soon. :)
- throwaway413 4y agoSaw your comment, went to my ATT internet account, and just upgraded from 1k to 5k! I’m so happy, thanks!
- throwaway413 4y agoSo, interesting stuff! I had my installation appointment, the guy came out and proceeded to tell me that the 5k plan would be useless to me. I asked why - apparently switches have not progressed at the same speed. Latest MBPs for example only support up to ~1300Mbps via wifi (however could support up to 10Gb bandwidth via Ethernet.) Most of my devices I use via wifi anyways. I have 1 Pi plugged in. I guess most hardware only has a 1k switch in it these days? With that new info, I decided to stick to my 1k plan until more hardware catches up.
- achillean 4y agoIt looks like port 5060 is becoming less common on their networks: https://trends.shodan.io/search?query=port%3A5060+org%3Acharter%2Cspectrum#facet/overview https://trends.shodan.io/search?query=port%3A5060+org%3Achar...
- deleted 4y ago[deleted]
- Prolixium 4y agoFWIW, when I lived in Seattle I found that Lumen's DSL service blocked it as well. It wasn't an obvious block, though. It was either some DPI or size-based filtering. I wrote it up here for posterity: https://blog.prolixium.com/2021/01/23/does-centurylink-dsl-block-sip/ https://blog.prolixium.com/2021/01/23/does-centurylink-dsl-b... It worked just fine through Comcast's Xfinity service (although at the time, that service had other critical issues for me..) and I have no problem now with Verizon Fios.
- more_corn 4y agoFuck spectrum. They’re the worst. Drop them for a better carrier. A critical service is nonfunctional. You should not have to VPN for your internet service to work. I can’t believe I even have to say that.