Act fibernet is routing 1.1.1.1 to its own servers in Bangalore

  • Thread starter Thread starter madh123
  • Start date Start date
  • Replies Replies 54
  • Views Views 16,744
i could be wrong but that url is to see what datacenter is being used to access the domain.

https://broadband.forum/cdn-cgi/trace would show you which cloudflare cdn is being used on the forum?
 
OP is wrong - they're not hijacking at all. Cloudflare's 1.1.1.1 endpoints are everywhere, not just in Singapore. In this particular case with ACT's internal routing, it's reaching 1.1.1.1 located in Cloudflare's Hyderabad node.

You can verify if that's the case by looking at the link below:

You should see Cloudflare's response with appropriate 'colo' tag along with the datacenter location that's responsible for this. In my and your case, it would be colo=HYD just like yours, because ACT is routing most of Cloudflare to their Hyderabad location.

DNS and http/s are run on different ports. It is possible to firewall only DNS and let http/s to pass through.
 
Here is my traceroute on BSNL FTTH (Pune), here also it is a local Indian location and does not go to Singapore, so I guess Cloudfare has started local DNS server using AnyCast:

Code:
PS C:\WINDOWS\system32> tracert 1.1.1.1

Tracing route to one.one.one.one [1.1.1.1]
over a maximum of 30 hops:

  1    <1 ms    <1 ms    <1 ms  10.0.0.1
  2     1 ms     1 ms     1 ms  192.168.1.254
  3     2 ms     2 ms     1 ms  103.77.240.1
  4     2 ms     2 ms     2 ms  218.248.164.97
  5     3 ms     5 ms     2 ms  218.248.164.122
  6     *        *        5 ms  218.248.235.197
  7     5 ms     5 ms     *     218.248.235.198
  8     *        *        *     Request timed out.
  9    41 ms    40 ms    40 ms  125.17.39.241
 10    38 ms    38 ms    38 ms  182.79.141.44
 11    37 ms    37 ms    38 ms  182.79.223.58
 12    38 ms    35 ms    36 ms  one.one.one.one [1.1.1.1]

Trace complete.
 
Last three IPs in my traceroute before 1.1.1.1 belong to Airtel it seems.
 
DNS and http/s are run on different ports. It is possible to firewall only DNS and let http/s to pass through.

Sure - but why such hassle? Can you even confirm which DNS server is responding when you query something to 1.1.1.1 and compare it with 8.8.8.8 without encryption in play? I highly doubt it. The help link here does indicate 'connectivity' with 1.1.1.1, but how effective is that?

I've replied next page with info that confirms DNS isn't hijacked.

With that said, I'm also on ACT (which is why I jumped in this thread, as I was curious) and I don't believe they're hijacking anything here.
 


Last edited:
If they are not hijacking why is some of the traffic is delibrately routed to US servers. When I change the DNS to 1.1.1.1 if they have anycast local traffic should go to Indian servers. But I observed it is being routed to US servers. Tracert actually does not pass the location info for EDNS to route it correctly so tracert usually take international route correct?
 
One example is speedof.me speedtest site. On Airtel ISP changing DNS to 1.1.1.1 has no effect on this site it still goes to Indian server as expected. But on ACT it is going to US new york. Same is the issue with some other sites. If anycast is enabled and EDNS is working on 1.1.1.1 it should redirect it to nearest server I dont think US is nearest server these guys have servers all over the world and on Airtel it is infact reaching out to Indian server for speedtest.
Download: 2.06 Mbps
Upload: 7.08 Mbps
Latency: 224 ms
Jitter: 240 ms
Test Server: NewYork 1
IP: Removed
Hostname: broadband.actcorp.in
 
Few months ago, I chose Airtel's 8mbps VDSL connection, instead of ACT's 100mbps fiber connection, for multiple reasons. And I am glad I chose Airtel at that time. Airtel is less evil than ACT and Airtel support is only next to my local BSNL exchange staff who solves issues before I reach home. :D:D:D
 
Oh, btw, a much bigger evil is already testing the waters and we might see similar threads more frequently than ever. Be safe, everyone. Good luck.
 

Back