Diagnosing TSPU impact
Telecom operators are required to install TSPU in their networks — technical systems for analyzing and filtering transit traffic; for details, see the What is TSPU section. TSPU can affect traffic transfer speed and cause connection issues for certain protocols.
If traffic transfer issues have signs of TSPU impact, you can diagnose TSPU impact and take certain actions based on the diagnostic results.
What is TSPU
TSPU, or technical means for countering threats, are DPI complexes installed at the request of Roskomnadzor at telecommunication nodes to filter passing traffic. TSPU can block or slow down traffic based on various criteria: IP addresses, SNI (Server Name Indication), QUIC metadata, protocol signatures, and others.
Large mobile, broadband, and satellite service providers, as well as Internet Exchange Point (IXP) operators, are required to install TSPU in their networks. All user traffic must pass through TSPU. TSPU equipment is managed by the Main Radio Frequency Centre (or the Centre for Monitoring and Control of Public Communications Network); service providers do not have access to it.
TSPU are used within the country, as well as at cross-border communication nodes where traffic enters and leaves Russia. At such points, analysis and filtering may occur both within the provider's network and at the junction of national and international infrastructure, which allows for filtering traffic at network borders.
Due to TSPU operations, both permanent and intermittent issues with the transmission of certain types of traffic may be observed within Russia and during cross-border data exchange.
Signs of TSPU impact
TSPU can cause connection issues over SSH, HTTP/HTTPS, VPN, and sometimes RDP protocols. At the same time, the server responds to ICMP requests and checks using the mtr, telnet utilities run successfully. In rare cases, network speed issues may occur when connecting over these protocols. Connection and speed issues can be either permanent or intermittent.
Issues are most often observed when a dedicated server uses a public shared IP address. In rare cases, issues also occur with addresses from a dedicated public subnet.
Perform a TSPU impact diagnosis
To receive full diagnostic data, you need to perform a diagnosis for two servers between which connection issues are observed. One of the servers must be located within Selectel infrastructure:
- destination server (destination) — the server you are trying to connect to;
- source server (source) — the server from which you are trying to connect to the destination server.
The diagnosis must be performed in two directions—from the source server to the destination and from the destination server to the source. If you cannot connect to one of the servers, perform the diagnosis only from the second one.
- Run diagnostics from the source server to the destination server.
- Run diagnostics from the destination server to the source server.
- Send us the diagnostic results.
- If the diagnostic results suggest TSPU impact, you can take action based on the diagnostic results.
1. Perform a diagnosis from the source server to the destination
The diagnostic process depends on the protocol experiencing issues.
SSH
HTTP/HTTPS
Linux
Windows
-
Connect to the source server. If the server is in the Selectel infrastructure, use the Connect to server instructions.
-
Create a text file to save the diagnostic results.
-
Check destination server availability:
3.1. Check destination server availability. The check will show whether ICMP packets are passing:
ping <destination_ip_address>Specify
<destination_ip_address>— destination server IP address.3.2. Save the output to the diagnostic results file you created in step 2.
-
Check the SSH connection:
4.1. Connect to the destination server via SSH with verbose output information about the connection:
ssh -v root@<destination_ip_address>Specify
<destination_ip_address>— destination server IP address.4.2. Save the output to the diagnostic results file you created in step 2.
-
Scan destination server ports:
5.1. Install the
nmaputility; for details, see the Linux Distributions article in the nmap documentation.5.2. Perform a port scan without checking server availability first:
nmap -Pn <destination_ip_address>Specify
<destination_ip_address>— destination server IP address.5.3. Save the output to the diagnostic results file you created in step 2.
-
Check TCP connection on port
22:6.1. Install the
telnetutility; for details, see the Telnet Applications article in the telnet documentation.6.2. Connect to the destination server via TCP:
telnet <destination_ip_address> 22Specify
<destination_ip_address>— destination server IP address.6.3. Save the output to the diagnostic results file you created in step 2.
-
Perform a traceroute to the destination server:
7.1. Install the
mtrutility. For details, see mtr on GitHub.7.2. Perform a traceroute to the destination server:
mtr --address <destination_ip_address> -bwzrc 100 <source_ip_address>Specify:
<destination_ip_address>— destination server IP address;<source_ip_address>— source server IP address.
7.3. Save the output to the diagnostic results file you created in step 2.
-
Collect a traffic dump to the destination server:
8.1. Install the
tcpdumputility; for details, see thetcpdumpdocumentation.8.2. Collect a traffic dump. The command will create a file in
.pcapformat:tcpdump --count 1000 -w dump_<source_ip_address>_<destination_ip_address>.pcap host <destination_ip_address>Specify:
<source_ip_address>— source server IP address;<destination_ip_address>— destination server IP address.
2. Perform a diagnosis from the destination server to the source
Linux
Windows
-
Connect to the destination server. If the server is in the Selectel infrastructure, use the Connect to server instructions.
-
Perform a traceroute to the source server:
2.1. Install the
mtrutility; for details, see mtr on GitHub.2.2. Perform a traceroute:
mtr --address <source_ip_address> -bwzrc 100 <destination_ip_address>Specify:
<source_ip_address>— source server IP address;<destination_ip_address>— destination server IP address.
2.3. Save the output to the diagnostic results file you created in step 1.
-
Collect a traffic dump to the source server:
3.1. Install the
tcpdumputility; for details, see thetcpdumpdocumentation.3.2. Collect a traffic dump. The command will create a separate data file in
.pcapformat:tcpdump --count 1000 -w dump_<destination_ip_address>_<source_ip_address>.pcap host <source_ip_address>Specify:
<destination_ip_address>— destination server IP address;<source_ip_address>— source server IP address.
3. Send diagnostic data
-
Create a ticket and specify the following information in the ticket:
-
describe the problem you encountered in as much detail as possible;
-
specify the pair of IP addresses between which connection issues are observed and for which you performed the diagnosis;
-
if the issue is observed with an HTTP/HTTPS connection, specify whether a VPN server is located at the specified IP addresses;
-
attach the files with the diagnostic results.
-
-
Wait for a response from a Selectel support engineer. We will perform additional diagnostics on our end and update you on the results.
-
Optional: if our diagnostics confirm that TSPU may be affecting traffic, you can additionally request confirmation from the service providers regarding the presence of TSPU on the traffic route. Selectel can send a written request only to the service providers (uplinks) that are connected directly to our data centers. Contacting service providers does not guarantee that traffic issues will be resolved. You can independently contact the service providers from the server located outside the Selectel infrastructure.
3.1. On the source server, start traffic towards the destination server. Do not stop the traffic for at least 7 days; this is required for diagnostics on the provider's side:
ping <destination_ip_address>while true; do <protocol> -o ConnectTimeout=5 user@<destination_ip_address> exit; sleep 60; doneSpecify:
<destination_ip_address>— destination server IP address;<protocol>— the protocol experiencing issues:sshfor SSH,curlfor HTTP/HTTPS.
3.2. In the ticket, state that you have started the traffic. We will send a written request to the service provider that is connected directly to the Selectel infrastructure and through whose channel the started traffic passes. 2
3.3. Optional: contact the communication service provider to which the server outside Selectel infrastructure is connected, yourself.
4. Follow the actions based on the diagnostic results
Selectel does not manage traffic filtering settings on the side of network operators and cannot directly influence TSPU operation outside of its infrastructure. If diagnostics confirm the effect of TSPU, you can:
-
contact the support of the network operator through whose network the issue is observed and request a check for possible excessive traffic filtering. If necessary, the operator can contact regulatory authorities themselves and submit an application in the technological network owner's personal account. The request does not guarantee that the traffic issue will be resolved;
-
you can also change the IP address on your server in Selectel. Changing the IP address does not guarantee that the traffic issue will be resolved:
- request a different public shared IP address; to do this, create a ticket;
- or order a public dedicated subnet.