4 ms·
Ask HN: Anyone else having IPv6 issues with Cloudflare?
Got a bunch of pings from updown.io saying there are IPv6 timeouts to sites using cloudflare, they seem to be intermittent for about the past 30 minutes, nothing on the cloudflare status page though.
- ammmir 4y agoYeah, I just woke up to some alerts, too. Sometimes I get the feeling people don't take IPv6 seriously!
- deleted 4y ago[deleted]
- bbu 4y agosame for me :/ since 1:41 CET https://status.ioverlander.com/ https://status.ioverlander.com/
- luisrudge 4y agooh, so that's why I have 200 emails in my inbox? I use the same combo: updown.io and cloudflare. can it be related to updown.io?
- bbu 4y agothat might be possible. I don't have ipv6 where i am right now, so I can't test it myself. it's also only at certain locations.
- johnny81 4y agoIt is not just them: https://status.appbeat.io/ https://status.appbeat.io/
- rwky 4y agohttps://status.updown.io/issue/1e196616-1368-43a0-8c04-82cffb24a07f https://status.updown.io/issue/1e196616-1368-43a0-8c04-82cff... Same thing with uptown.io some issue with vultr to cloudflare triggering false positives...unless you're connecting from vultr of course
- palmeida 4y agoI have a personal monitoring system (uptime kuma) running on Hetzner (Germany data center) and since around 5am UTC today I am seeing intermittent timeouts only on services proxied by cloudflare so not just Vultr affected it seems…
- johnny81 4y agoDo you have IPv6 AAAA records in DNS? Or does this happen also for A records?
- palmeida 4y agoIt was happening in A records. Around 1 hour ago everything went back to normal. I assume there was indeed some issue in Cloudflare side. Would love to know what happened but cloudflare status did not report any issue during the event so…
- johnny81 4y agoIssue seems to be resolved now: https://status.appbeat.io/ https://status.appbeat.io/
- adrienjarthon 4y agoadrien from updown.io here. Sorry about this, I still don't have any answer or explanation from Vultr or CloudFlare at this point. Most likely cause IMO is that CloudFlare (accidentally?) blocked one or many big ranges of IPs belonging to Vultr (and maybe some other providers as people seems to say Vultr was not the only impacted). I noticed during the incident this morning for example that I could ping CloudFlare IPv6 (ICMP) but not connect through TCP (port 443). So this sounds more like a firewall than a routing issue from what I could see. I'll update once I have anything else in https://status.updown.io/issue/1e196616-1368-43a0-8c04-82cffb24a07f https://status.updown.io/issue/1e196616-1368-43a0-8c04-82cff.... For the moment I'm keeping the mitigation in place just in case. If you have more details about this from CloudFlare or elsewhere I'll be happy to hear it :)
- rwky 4y agoThat's a bit weird, normally when cloudflare blocks things you get an error page not a timeout, hopefully you hear something tomorrow when everyone is back at work. Appreciate you looking into this :)
- adrienjarthon 4y agoQuick update here: Vultr is still ignoring us, and Cloudflare said to one of my clients: "some IPv6 traffic from Vultr was being dropped by a DDoS mitigation system as we were receiving malicious traffic from Vultr. The issue has since been resolved, and updown should be reporting availability correctly now." So this confirms what I suggested above, I suppose they choose not to respond with an HTML page here because it would generate too much traffic, and maybe it was a lower level TCP attack. This also probably explains why Vultr doesn't want to answer me if they were "responsible" for the DDoS attack that got them blocked.