nanog mailing list archives

Re: Comcast contact


From: "Livingood, Jason" <Jason_Livingood () cable comcast com>
Date: Wed, 7 Aug 2013 12:38:09 +0000

I have found Comcast rate shapes or resets long running encrypted
sessions such as https.   At $DAYJOB I had to set our SSL VPN system to
re-key via new-tunnels every 5 minutes to keep it under their threshold
of what looks like seven minutes for a tcp session.   After that the
sessions appeared to rate shape down to 128kbps.  It may also only kick
in during local POP congestion.   I am assuming this is DPI trying to do
peer-2-peer mitigation.

We don't have such network practices and are required not to under Open
Internet rules. I have no idea what was causing your VPN issue - I can use
my corporate VPN for hours or days at a time with no issues. Happy to
assist off list if you like.

Jason



Current thread: