Some time ago, an interesting discussion was started at a well-known forum, a man from the Russian hinterland asked a quite sensible, in my opinion, question:
Cold Synthesis:
“Good day to the forum users. Indeed, I did not know where to create the theme, but for people like me, I made a whole section, thanks for that.
In short, I live in a remote wilderness, where they select a business and do not give anything to do quietly ... and then I got the idea to make a server for hosting services or something else.
Interested in such questions:
* What you need to start, what equipment, programs, etc.
* What you need to buy to start
* Which budget can fit
Maybe there are "znavtsy" this topic. to tell me what and how? ... "
And of course, in the best traditions of the beginning, the srach began:
')
pavellift:
"Cold Synthesis, maybe better to move?"
voltamper:
“TS, you shouldn’t pry, if you don’t understand it at all.
Brutan and generally without pants will remain. "
sladkydze:
“The author, I support comrades who do not advise to meddle.
Something to catch here:
1. Having knowledge in the field and experience.
2. With at least $ 10,000 in initial investments. And the best from $ 50,000. The rest is ploping in a puddle. ”
[umka]:
“This is how to start a car rental company, having VAZ 2106 as the“ original equipment ”. Well, plus the site, of course.”
And there were many such advisers. Yes, of course, it could be the desire to crush a new competitor, since the majority of those who mentioned such advice are existing hosting providers. If it were not for one thing ... These people were completely convinced that it was impossible to organize a hosting project without possessing special knowledge or a large budget, only a few people gave advice on the matter.
I immediately remembered how I started, and it became just unbearably sad for such advice, because people were mistaken, everything is possible without a budget, and without basic knowledge. Because this is exactly how ua-hosting appeared. And then I will tell a small story of success and disappointment ...
The goal was not at all in creating a hosting project ...
I discovered the Internet for myself in 2001, back in the era of dial-up, when access speeds were only up to 28 Kbps and you had to pay huge bills for the Internet and telephone - about half a dollar per hour during the day and 10-20 cents at night. Access to information was extremely expensive and I could only afford 10-20 hours “online” per month and a small page on free narod.ru, as the first experience of posting information on the network.
In 2003, they became first-year students of the department of astronomy and space physics of the Faculty of Physics of the Kiev National University. Taras Shevchenko, in fact never having come up against web design and the notion of hosting (narod.ru is not counted), I wanted to create a scientific educational project, or rather, I realized the need for it. After all, the same books, published several decades ago, but the information in which was conceptually important and relevant, was incredibly difficult to find, not everyone had access to a good library, especially far from research centers. For example, the 1969 edition devoted to the theory of radiation transfer in the frequencies of spectral lines is still relevant today. After all, the solution of a number of problems of applied mathematical physics at the physical level of rigor is, perhaps, the basis for those who wish to fully pursue science.
Receiving a scholarship of about $ 7 a month, I could only afford to register a domain name, which I did in the spring of 2004. I was able to launch the project much later - only in 2006. The usual hosting did not fit, only e-books for 2 years were collected and created several hundred, and most hosting providers of that time forbade file archives when placed on shared-hosting.
As a result, a virtual server was rented:

Moreover, the initial tariff plan was not enough, since the same squirrelmail, a mailer with a web interface, was very noticeable. It's funny that I didn’t even know in which directory I had to upload the site files (public_html) and how to assign the index page. My fellow student Cyril, who at that time had already created a site about free domain names, helped me to understand this, which was also very relevant for many webmasters of that time. Moreover, it essentially became the first client of the “hosting”, since the resources on the VDS were significantly more than the project required at that time and the content of the virtual north had to be paid for somehow.
I was a complete zero in administration, but nevertheless I realized then that it would be much cheaper to contact the administrator with a specific task (at that time the prices for permanent maintenance were space - from $ 100) than to connect maintenance for all the time, because the correctly configured server can work for a long time without failures. Of course I learned and improved my skills. I still remember the phrase Valentine, the administrator and owner of HostBizUA, as it turned out:
- If I had delivered FreeBSD to you, you would have already shot yourself, because to deliver a package in FreeBSD you need to know it from A to I, I delivered you CentOS because you can put any package with the command:
yum install WHAT *
-----------------
And he was right, working with CentOS was not at all difficult.
And even then I realized that high-quality support is possible even when the services are provided by one person, the main thing is inspiration and the right attitude to business, because Valentine somehow miraculously managed to respond to the ticket at any time of the day for 5-10 minutes. The person literally lived on the Internet despite the fact that he was the owner of a rather large data center. Soon he sold his offspring, which, unfortunately, was not in any way successful without its mastermind owner. It's funny that so far the tariff plans on the site have not changed and even become worse in many respects in terms of price:

The first dedicated server and bad experience with the channel without traffic
With the beginning of the era of dedicated lines and higher speeds of access to the Internet in Ukraine and Russia, VDS simply lacked, the same media archive required more space and, most importantly, a higher bandwidth channel. There is a need to purchase a dedicated server, and at the same time - search for clients from the side, since the project is non-commercial and did not have enough profit from advertising and selling SEO links (then there was a very popular topic).
At that time, I had already begun to understand something and could provide a quality service not only to friends, but also site visitors, because many people were interested in creating their own page on the Internet:

Yes, I didn’t know very much, but I knew people to whom I could turn for help to solve a particular task if necessary and could correctly formulate the essence of the problem, which in most cases was already a large part of the solution.
Soon, despite the fact that site traffic was low - up to 300 people per day, the first ten clients among resource users were found and over time the client base only grew, since site visitors trusted me, because they were placed in the same place as the project . At the end of 2006, I was able to afford the purchase of a dedicated server and placing it on collocation in the same data center where I rented a virtual one.
Moreover, the offer at that time was very profitable, for $ 76.5 a month they promised a channel of 100 Mbps without traffic, not only in the Ukrainian segment of the UA-IX network, but also in the foreign one:

The E2160 was purchased with four 250 GB hard drives and 4 GB of RAM, the server cost almost $ 1,000, but not only paid for its placement, but also began to bring good profits (about $ 70 per month). However, the happiness did not last long ... As soon as I added a large media archive to the website and scored a channel in the regiment, they limited the channel to the world to 5 megabits and left only 10 megabits to Ukraine ... At the same time, Valentin changed the tariff grid to the web the site, motivating it by hoping for “honest” consumption and the channel costs more:

The media archive had to be very limited, and the dedicated server lost its usefulness in this data center. At the same time, it was simply not profitable to move the server somewhere, since the same Volya, one of the largest data centers in Kiev, began to offer dedicated servers for rent at an accommodation price. At last, the Western business model began to work in Ukraine, when the server was rented for virtually free, and only the channel was paid.
Nevertheless, anything suitable on the “Will” cost much more money than the clients and the site brought, only their maximum tariff plan for 1399 hryvnia per month (about $ 280) was suitable, since a guaranteed outgoing channel was needed at a speed of at least 100 megabit without traffic:

And in order to be able to afford it, it was necessary to increase profits by 4 times, increase the client base even more, transfer clients temporarily to a reliable virtual server and sell the current physical one. The action plan is simple and clear, it was enough just to work.
I was lucky with the server, after half a year of work I was lucky to sell it for more money than I was given for it when I bought it, but cheaper than the average price it had on the market. So everyone was pleased.
But with the choice of a new hosting provider and the growth rate of the client base less fortunate.
Processor and memory is not the most important resource of a virtual server or why the disk quota is 0
In May 2007, a provider such as vds64, specializing in virtual servers for quite adequate money at that time, entered the market. The equipment was placed in the DataGroup Incom data center - a very high-quality Kiev site, which was very helpful and I decided to try their services. Actually, I analyzed the consumption of resources, I came to the conclusion that all my clients could fully fit on the virtual server “Start” for $ 20 a month:

But I was not accustomed to saving and decided to take "Optima" (resources with a reserve), for quite not small, as for a virtual server, money - 35 dollars a month. And what was my surprise when customers at some point began to complain that their websites are slowing down ... I checked the processor and memory, and we don’t use half ...
By the way, many of the providers today continue to breed marketing bullshit on small resources, convincing customers that a virtual server with less than 1 GB of RAM and less than 1 GHz of resources is very bad and not enough, because more servers need to be sold. And then on this virtual server about 30 sites worked very successfully and there was enough resources with a margin. But now it's not about that.
The reason for the inhibition of the sites was not the shortage of processor resources or RAM, but that the disk array became overloaded. It is now well known to me that the SATA disk provides only about 70 I / O operations or read / write operations per second (IOPS) at best, and at that time it was a discovery for me, probably, as for the creators of “vds64 "Because reviews about the inhibition of sites on their virtual servers have become global in nature. RAID did not save the situation. The storage, which was not occupied and half - was overloaded.
Realizing this, I “asked” to transfer me to another node that was less loaded by IOPS, switching to an even more expensive “Portal” tariff plan for $ 50 a month, so that the provider would not be so offensive. It helped for a while. At that time, unfortunately, SSD drives that provide tens of thousands of IOPS, unlike hard drives, for adequate money simply did not exist and it goes without saying that vds64 would not solve the problem once and for all. It was more than obvious, and I began searching for a dedicated server for rent, because I did not want to disappoint customers who trusted me, and problems and complaints arose more and more often.
I wanted “Will”, I wanted it badly, since it was the most optimal data center for my tasks. Only $ 280 was not there ... Of course, it would be possible to stretch for 3-4 months with the proceeds from the sale of the server, but what to do next if the project does not achieve a payback? So it was impossible to risk.
Individual approach changes everything: the purchase of services in the data center through a partner, not directly
In February 2008, there was a way out. It turned out that for nearly a year their partner, Data-Hata Company, has been successfully cooperating with Volya, locating both its own equipment and offering the data center servers for rent. And they are one of their largest clients, plus they have much more flexibility ... For example, outgoing traffic is unlimited even for the minimum tariff plan, and not just for the tariff for $ 280 (UAH 1399) and basic configuration and maintenance is provided:

Placing your server is cheaper than renting a server in a data center. In addition, a unique solution is offered - server rental with redemption, after 12 months the server is redeemed for only hryvnia and it remains to pay only for accommodation and traffic:

In general, of course, this scheme is inefficient in the long term - customers forget that the equipment becomes outdated and sometimes fails. But it warms the soul of those who want to own the equipment in the property and the ability to migrate the server between data centers quickly. The guys adjusted the service so much that they could provide magic logistics with migration for an hour (they shut down the server, loaded, transported, hooked up), and at the same time collaborated with several of the best data centers in Kiev.
But most importantly - they offered an individual approach. The minimum server cost from $ 100 per month (499 hryvnia) and unfortunately did not meet my requirements, but it was clearly stated that Data Hut was ready to find an acceptable option. I needed at least 4 disks and 4 GB of RAM, and the cost of the server should not exceed $ 90, it was just the money the project was bringing at that moment. And I decided to discuss this possibility by sending a request and explaining in detail why and what is needed.
Alexander, the director of Data Hut, did the discount I needed at that time and went to the meeting - temporarily reduced the amount of incoming foreign traffic from 30 to 20 GB, while leaving the outgoing traffic unlimited, provided the necessary parameters, helped with the configuration and even the transfer customers. And when I almost lost data because of my inexperience (the server was configured with RAID5 to save disk space, and I did not notice how the disk failed and the array started to work in critical mode, resulting in the second disk failing) , spent a sleepless night trying to save at least something. And he succeeded. Unfortunately, the databases could not be saved from binary logs - the data was mixed, the file system was damaged. But here files and scripts could be saved, for the most part. Fortunately, most customers backed up databases, as the backup was easy to download because of the small size, but not all files backed up due to the low bandwidth of the home Internet. Some kept copies on the same server, and some did not backup at all, relying on RAID, so people were happy with at least that outcome.
This incident taught me and my clients an important rule: there are people who do not back up and those who are already doing.I was very grateful to Alexander and was so impressed with such care that on the same day I left him a review:
"Thank. I am simply amazed, in a good sense of the word, by the attitude of your company and you, as a manager, to me, as a client. + The quality of services you really excel! I regret only that I did not stumble upon your site earlier ... "
This review is among the reviews of his clients to this day, indicating that I am the owner of such a portal, despite the fact that this portal, unfortunately, stopped developing in 2009, I had to devote myself entirely host, time to work on the portal was not thereafter.
Goodbye science, hello, business?
But then, in the autumn of 2008, the hosting project, together with a scientific resource, was essentially a hobby and far from the main focus of work. After graduating, I worked at the department and was engaged in the distribution of ozone in the atmosphere, the study of the circum-polar vortex and its effect on the climate in Antarctica. There was a prospect to go to the winter at the Ukrainian station Akademik Vernadsky for half a year or even a year to conduct more detailed scientific research. The only thing is that at our station the Internet was completely absent, and having a project on the network and quite a few living customers (about a hundred at that time) - I could not afford such luxury, even for the sake of scientific research and quite good promising wages - up to $ 2,000 month. The truth is that probably all the same, I didn’t like the cold and the isolation and loved my clients too much and could no longer live without my little hobby.
In 2008, despite the fact that I worked alone, I brought the level of service to perfection. No, of course there were problems, but they were solved very quickly and the most individual approach to customers was. Consultations were given even outside of the ordered services. The result of these efforts were the first reviews:
“Technical support at the highest level, stability also, in comfort there are small drawbacks with payment, but this is tolerable.”
“Excellent (operational!) Support service.
+
Good price / performance ratio. ”
“I've been using hosting since June 2008. For all the time, there were no serious complaints against them. Already that site is not, with whom I then hosted. From the positive sides I can name a good tariff plan, at low prices. Better I have not seen anywhere. Plus, a good support service, if it’s not clear, they’ll sort it out and help. The servers are really good and the speed is excellent. Significant deficiencies in the hosting did not notice. "
People really thought that the whole team was working. In fact, until 2009, except for me, no one ever communicated with clients. However, sometimes punctures happened:
“There are three sites with this provider. This morning I discovered that the sites are not working. Apache HTTP page. (This is the HTTP server that has been installed. This is what the Apache HTTP server is working properly.) Support for soap is not answers, is silent and the sales department in ICQ, did not find any phones. Hosting seems to be supported by one person and he is the sales department. ”
It's funny that this review is already from 2010, when the hosting server was monitored by administrators and in fact hosting was already supported not only by me. But when I really had to deal with all alone - I managed to avoid such situations, although at a high price - sometimes I had to work more than 18 hours a day, which was a bit uncomfortable.
In general, the Antarctic somehow did not attract, there certainly is to visit at least once in my life and research - interesting and cool, but in our realities imply a certain level of fanaticism, which I manifested in a completely different area, different from ozone research.
I really enjoyed my hobby - providing hosting services and attracting new customers. Sometimes I just began to advise people on the forums on issues in which I was already well-informed and felt confident, even without the thought of selling something, and sometimes with a thought :). Sometimes I entered into interesting discussions in order to learn something new and test myself, or simply ignite throwing ... between the participants. After all, only then you can see the true face and level of professionalism, you need to piss off ...
I'm not very clever in physics and I need to make more efforts to solve these or other problems. Despite the fact that in programming a complete zero, in due time I managed to save half a year of work of my colleagues by automating the processing of ozone data. So I was not completely useless in science, but it was impossible to continue this way. I clearly realized that science had faded into the background a long time ago and seriously I will not deal with it, since I can not give it either time or money. Yes, it is extremely sad to realize, but in order to do science in Ukraine, we need money. And the last can be realized in two ways - to go abroad and make a career as a scientist there, which takes quite a lot of time and effort (besides, it is not always washed away), or build a successful business, which was probably interesting to many, but not to me. It is necessary to realize that to build and for what ... And to build something for the sake of money is boring for me.
Both options are not suitable. We were taught at the university the most important thing, as it seemed to me then - to think and learn independently. They said this to us on August 31, 2003, after enrollment to the 1st course:
“We will not teach you physics, we will teach you to think and be able to learn. Physicists are universal people and having realized the essence you will be able to work anywhere. ”
But there was no awareness. I did not find myself after receiving a diploma in 2008, and working at the department for $ 150 a month, and even with dubious prospects to thunder in Antarctica or to go a long way to a scientist abroad - obviously did not deceive. Moreover, I lost fanaticism to science even a couple of years before, when, at the seminar of Professor Schulman, for 1.5 hours we were recorded the equation of motion of dust particles in the same diffusion model of plasma tails of comets. Yes, it is incredibly cool that a man devoted his life to science, such people deserve deep respect, but I am not like that, I could not just sit and go with the flow and spend a lot of energy on dust particles. It was necessary to find oneself, and for this to put oneself in an unfavorable environment, for only then it is possible to overcome laziness, force oneself to do something and become better. True, but the fact that people change only when the suffering caused by leaving the comfort zone exceeds the suffering of change. That is what I wanted to do with myself.
Unfavorable environment can be favorable
I flew away with almost no means to return in case of failure. In the beginning was Egypt, then Indonesia, England. In warm countries, I tried to find myself in diving, as it then seemed to me - a heavenly profession. I remember going through the course of a divemaster-guide, I was offended by my instructor because she dumped all the dirtiest work on me, and in fact in this way she showed me the hard realities and costs of the profession. It is fun to fly in and dive for a week, but when you are a guide for a group of certified divers of different levels who have not always received quality training, but many of whom believe that everyone can (especially drink the day before) - is another matter. It is necessary to collect all, bring-bring, spend 3-4 dives per day, and sometimes more, in very different locations and conditions and keep track of all. And so every day, practically without days off and for many weeks, and so that everyone would survive ...
And still own unconsciousness and razdolbaystvo can have a huge negative impact, you can not survive yourself, get out, making a series of mistakes. God, thanks to my instructors for meeting in my life and giving me a brain. Most have no luck. , .
( )
( , Trimix ), :). , , . — , , , . , , .
, , . , . , «-», — 50 . , , , 1-2 . - , .
, - , ( ) :
« ? , ! :)»
, , , . , . , , 400 , — , , , . - , -, IT-c, , .
, - , . , , . , , , .
, , «ua-hosting», .
2009- - «» «ua-hosting»
, , , . , .
, , - , , , . . - , 700 , — 50-70 / . .
, . , , , , , .
, DNS, — - -, :
: . , , , - . , , , , .
: , . , . , ( ).
: — . , — . : best-hoster.ru, kinghosting.net . . - — ua-hosting — .
«-», , - «», : , -. . , -.
, - . , — , , . — , «-» - , . , , - , . .
2009- 6 , 6000 (750 ) 10% -. 2 , , , -.
- . — . . , , :
Iv@nhoe: . , . . . , . . .
, , , , , — , , , … , — , , . 10- , , , — - .
- «» . , , . - , — marketing bullshit. , , , , . , , .
— , —
, — . — , . . :
Mantius: , , 100 , 127$. , , , , -, . , 127$ , , , =) .
Marts: . , , ( ). ! , «». - — FTP . , + . . . . , . , . Thank! , .
. , , , ,
— , . , .
2010- , , . . . ,
2010- «hosting.ua» , 3 ,
«» (piluli.ua) 100 000 , , - . — , . , , .
: «SeCom»
, — 10-20 , -, .
2010- — , - , , -, . , , . , - «» , . «KirHost», «» «SeCom», , . , c «SeCom» . , — . -.
«SeCom» , , — . . .
.
2010- . ( , ), , . 2 . . , . — , 5 . , , . , . , . , . . , . , , . , .
, 2010-, 29 , 4- 4 / :
*** netgear-2 ***
1-p -->
2-p -->
3-p -->
4-p --> ovod-switch-12 (1 )
5-p --> switch-10 (8 )
6-p -->
14-p --> ovod-switch-14 (24 )
22-p --> ovod-switch-17 (1 )
*** switch-10 ***
2-p --> ovod:ua-hosting-x21 (eth0)
4-p --> ovod:ua-hosting-x12
5-p --> ovod:ua-hosting-x
6-p --> ovod:ua-hosting-x11
7-p --> ovod:ua-hosting-x3
8-p --> netgear-2 (5 )
9-p --> ovod:ua-hosting-x4
10-p --> ovod:ua-hosting-x14
11-p --> ovod:ua-hosting-x6
12-p --> ovod:ua-hosting-x2
14-p --> ovod:ua-hosting-x20 (eth1)
15-p --> ovod:ua-hosting-x10
16-p --> ovod:ua-hosting-x8
17-p --> ovod:ua-hosting-x13
18-p --> ovod:ua-hosting-x9
19-p --> ovod:ua-hosting-x23 (eth0)
20-p --> ovod:ua-hosting-x7
21-p --> ovod:ua-hosting-x15
23-p --> ovod:ua-hosting-sua
24-p --> ovod:ua-hosting-x5
*** switch-12 ***
1-p --> netgear-2 (4 )
4-p --> ovod:ua-hosting-x24 (eth1)
5-p --> ovod:ua-hosting-x19 (eth1)
6-p --> ovod:ua-hosting-x22 (eth0)
9-p --> ovod:ua-hosting-x20 (eth0)
10-p --> ovod:ua-hosting-x21 (eth1)
11-p --> ovod:ua-hosting-x26 (eth1)
13-p --> ovod:ua-hosting-a2
17-p --> ovod:ua-hosting-a1
19-p --> ovod:ua-hosting-x22 (eth1)
21-p --> ovod:ua-hosting-x26 (eth0)
22-p --> ovod:ua-hosting-x23 (eth1)
23-p --> ovod:ua-hosting-x24 (eth0)
24-p --> ovod:ua-hosting-x19 (eth0)
*** switch-14 ***
8-p --> ovod:ua-hosting-x28
9-p --> ovod:ua-hosting-x32 (eth0)
11-p --> ovod:ua-hosting-x33 (eth1)
13-p --> ovod:ua-hosting-x33 (eth0)
14-p --> ovod:ua-hosting-x32 (eth1)
15-p --> ovod:ua-hosting-x34 (eth1)
16-p --> ovod:ua-hosting-x34 (eth0)
24-p --> netgear-2 (14 )
*** switch-17 ***
1-p --> netgear-2 (22 )
3-p --> ovod:ua-hosting-x29 (eth1)
4-p --> ovod:ua-hosting-x29 (eth0)
5-p --> ovod:ua-hosting-x30 (eth0)
6-p --> ovod:ua-hosting-x30 (eth1)
7-p --> ovod:ua-hosting-x31 (eth0)
-, , 36 000 (4500 usd / ), , , .
, , , - «Utel», 10+ / , ?
Despite the growth, we still didn’t have our own administrators and sales staff, besides the two of us. Besides, we could not officially hire anyone. Informally - we did not need it. In the case of sales support, we were confident that we were working better than a dozen managers of any provider. Outsourcing inquiries were handled by SeCom, according to the agreement between the two business entities. Among other things, for different tasks, specialists of different levels were required, we were able to find them and set the tasks correctly.
So one of the major clients had to combine about 17 dedicated servers into a cluster, the cluster was written with 0, a specialist with many years of experience in this field. As a result, the client received a fail-safe solution implemented within the time frame of the month, moreover, for very little money (less than 4,000 US dollars). Keeping a specialist of this level on a permanent basis would be costly (the level of wages is about $ 2,500 per month), and then the cost of such a service would increase severalfold, so that we would save money primarily on our clients. Among other things, specialists of this level should grow and develop, enrich their experience, and this is impossible when tasks arise rarely.
People trusted us and we always found solutions for them. And we were trusted by very large projects, such as Kinopoisk. I contacted Dmitry Sukhanov through the Hostobzor forum when he was looking for a reliable partner in order to rent the infrastructure in Ukraine. Alas, the Russian external channels were stupid, as a result, the Ukrainian audience could not normally watch movie trailers on the website kinopoisk.ru and a local solution was needed for Ukrainians. On May 16, 2011, we entered into an agreement with Vitaliy Sergeyevich Taciy on providing infrastructure for streaming movie trailers for the Ukrainian audience of the Kinopoisk website. And later, for the entire audience, as soon as they began to provide services in the Dutch data center “EvoSwitch”. The cooperation was long, until October 2013, when, as it turned out, Dmitry and Vitaly sold the project to Yandex for $ 80 million, which I learned only this year, when I saw the terrible design of the new Kinopoisk, where Dmitry in response to the message "Probably the former owners spit, despite this," wrote to "well, there is such."
But while 2011 was the year and the customer base grew rapidly. In the course of working with large clients, we are faced with such an unpleasant phenomenon as DDOS-attacks. There was no hardware protection in the Volia data center, we could not buy such equipment - it was too expensive, and we began working with the Utel data center, renting a cabinet and Juniper Netscreen 5400 from them to ensure filtering attacks at the hardware level , at least within 2 gigabits, where most of the attacks of that time fit.
We protected against the following types of attacks:
icmp-flood
udp flood
port-scan
tear-drop
syn-flood
ip-spoofing
ping death
land
ip-bad-option
icmp-fragment
icmp-large
syn-ack-ack-proxy
block-frag
icmp-id
icmp-flood threshold 100
udp-flood threshold 1500
syn-flood timeout 10
syn-flood attack-threshold 5000
syn-flood source-threshold 200
syn-flood destination-threshold 5000
And naively believed that a hardware firewall is the best solution. But it turned out that you should only defend yourself against some attacks only programmatically or not at all, and it is cheaper to wait. After all, in order to withstand the network equipment, it was necessary to apply distributed expensive cluster software filtering solutions.
Very soon we realized the phrase, from the manual to the hardware firewall, in practice:
- Dozens of attacks do not need to be able to prevent traffic.
The client got http get, DDOS to port 80 and it was not setting up connections. The only thing we could do on the hardware was to limit the number of sessions to 1 ip, which was done. After that, the load dropped from 110 thousand sessions to 10-12 thousand. At the same time, the Netscreen 5400 processor load was 88% (during normal operation - 2%). Therefore, during the attack, there were problems with the removal of SNMP, and we could only report the number of sessions (before the inclusion of the limit - 150 thousand) and the total number of filtered packets.
ICMP flood protection 2177
UDP flood protection 1390
SYN flood protection 241528872
SYN Flood (same source) 31637861
SYN Flood (same destination) 968289628
TCP packet without flags protection 5207
Fragmented packet protection 21582144
—————————————————
For some time this helped, but not for a long time, the attack was strengthened, more than 10 gigabits came to the root routers of the data center and the subscriber had to be temporarily turned off, as the attack started to create problems for other clients.
Alas, in such cases it was cheaper to wait. For the organization of the attack also costs money, the attacker can not carry out the attack indefinitely. Sometimes filtering attempts can bring more damage than the attack itself, which the attackers are counting on. This recommendation was given to the client and it worked, saving a lot of money to our subscriber. Later we learned that other large projects suffered from this botnet, and those who tried to fight did not overcome it anyway, having received an attack with a capacity of over 100 gigabits, spending tens of thousands of dollars on defense attempts and a lot of nerves.
Moving to the data center "Ukrtelecom" or how to buy servers for half a million
Remember, I said above, that operators sell channels cheaper, on the basis of fair consumption, and that customers often do not use the entire dedicated channel fully? And that such sales should be done carefully?
In the data center "Volya" did not think about it. They offered a Media tariff plan for traffic generators, where for every 100 megabits of outgoing traffic, a free incoming megabit abroad is given by the bonus, which allows you to generate foreign traffic in even larger amounts, because outgoing traffic is free under the terms of the tariff, only incoming megabits are paid for only a small fee per port. The offer was excellent and worked like a good marketing, until the file-cleaner came to them.
She generated over a hundred gigabits to Ukraine, thus having received a huge channel abroad. Free on the ball. The data center bought a foreign channel for huge money and its reserve immediately ran out. Regular customers did not see any significant problems, but the streaming subscribers could not help but notice it. The speed of the stream to Russia decreased at peak hours from 2 Mbps to 400 Kbps and less. This situation has become regular, but most importantly, the data center could not find the cause, or did not want to look for it.
Later, when they lost us as a subscriber (we moved to Ukrtelecom) and a subscription fee of over 80,000 hryvnias ($ 10,000 per month), they found that the file dumper bought about fifty servers in the data center and distributed the generated traffic. Probably later they understood what was the matter, but simply did not want to lose them, since they had purchased servers for them.
But it was late, in January of 2012, we began to move everyone gradually to Utel, renting 2 cabinets, buying a good Cisco Catalyst WS-C2960G-48TC-L and 8 Gbit / s on the Internet, because our customers had already generated about 6 gigabit traffic during peak hours. And so, as we had mostly traffic generators - we did not use more than half of the space in the cabinets, so this part was given to our partner, “Hut”, so that they could host the servers of their subscribers for more profitable money and we did not lose resources. Now our servers were more than “Huts”, over 50.
Purchase of iron is a separate topic. There were no options, as well as money for so many servers at once. Fortunately, some of the servers belonged to our partner and we paid for the rent, gradually buying them, and for the rest we found a way out - offered subscribers magic conditions with a long-term payment (for a year, almost at cost). The supplier, in turn, gave installments to carry out payment for 3 months, since the purchase was wholesale. Customers who have worked with us for 2-3 years trusted us, and therefore most of them happily switched to the new data center and to the new scheme of work with payments once a year. In addition, Ukrtelecom expanded the external channels to the world by 200 gigabits for the upcoming EURO 2012 and the quality of the stream was simply magical - up to 20 Mbit / s and more (Ukrtelecom bought the channel to provide streaming matches).
Problems in working with Ukrtelecom and in general with Ukraine
Ukrtelecom was good, but it suffered from a terrible bureaucracy, sometimes it was impossible to quickly install the subscriber's server in a cabinet or carry out a quick replacement of components, as their managers left for lunch, left work at 5 pm (business day to 5), or simply fulfilled the plan on the installation of new servers today and did not want to strain. Sometimes they simply did not let our people on the site, citing the refusal that they needed to get additional permission or access was allowed only to the 1st employee, but not the one who arrived. Nevertheless, adequate people worked there too and often the problematic bureaucratic moments were resolved positively, albeit with the expense of our nerves and the nerves of our customers. After all, it is difficult to explain to the client that we cannot replace the drive for him, due to the fact that employees of the data center are having lunch and the engineer will not work without an act issued by the manager.
Nevertheless, many of our subscribers treated these situations with understanding, because the price was magic and the number of our servers only grew. In March, we wanted to expand the channel by purchasing additional 8 gigabits, but they refused to connect us, explaining that the channel is reserved for EURO and can only be sold with an additional cabinet, a maximum of 2 gigabits per cabinet, and not 8, which is not suited us. Therefore, we had to post some of the subscribers for the same “Will”, which had solved quality problems by that time.
At some point searches in Ukraine, seizures of special servers, have become frequent. services, invitations of owners to the police and the Security Service of Ukraine, and we realized that rather unfavorable conditions were forming. We simply could not work with very large clients, although there were requests. After all, it was necessary to purchase several dozens of servers for them at once and then, if during the year nothing happens to the channels and the servers do not withdraw the specials. service for some contrived reason, it was possible to go to 0 and start earning.
Risks have become incommensurable. We began to look for a foreign partner, especially since more and more of our clients were interested in the possibility of hosting sites for adults who were considered almost a crime in Ukraine, although everyone was watching, including law enforcement officers. This is how the retarded legislation hinders the development of networks, Ukraine could become a Mecca of the Internet with a greater level of freedom of the Internet space than in Europe, but it did not work out ...
Looking for a partner abroad or how we found "LeaseWeb" and "LeaseWeb" found us
There was a NewTelco company with its own data centers in Kiev and Germany, our partner in Kiev has already successfully cooperated with them, but due to limitations of German law (the same adult sites are only possible with paid access), it did not suit us, plus us it required good connectivity with subscribers in Russia and Ukraine, which was very expensive there. We didn’t want to buy our own hardware - it’s almost senseless and stupid to depreciate it in Europe unless there is extra money you want to throw out and invest with a payback period of 5 years, having received an outdated server fleet of total and the problem of replacing it with a new hardware.
Drawing attention to the Netherlands, as the most liberal country, we began to search for a reliable service provider among many Amsterdam operators. The Netherlands really turned out to be the Mecca of the Internet, all the channels converged here and there was good connectivity with both America, Russia and Ukraine, but the most important thing was clear and reliable liberal legislation.
But who to work with? There are so many data centers ... We really needed a reliable partner, because we have so many clients, to transfer them from Ukraine is not a small work. And even more - do not miss the quality and vice versa improve it, otherwise why move? How to convince customers of the need to move, not to lose them and make them even more satisfied than they are now?
One of the largest data centers in the Netherlands - «EvoSwitch», we immediately liked. In the meet-me-room of the data center, all the European first-level backbone providers were represented, and there were many peerings, a total of several dozen, which seemed a miracle to us.
For comparison, the data center "Volya" used only TWO! uplink of the second level, which at one point became unavailable at the same time, when the first-level trunk provider of the first level, which provided services to these two operators, came down.
The total capacity of the EvoSwitch inclusions exceeded 2 Tbit / s, against 60 gigabits per world on the “Will”, and the AMS-IX exchange point was located nearby. Here are just a data center worked only with large customers and only with colo. Our few racks were fading there, you had to immediately buy gage for 48 cabinets or work indirectly. We, unfortunately, could not yet afford this, because our servers could take only about 10% of the space at best.
LeaseWeb, a company that works with individual clients and small hosting providers, is essentially the owner and creator of the data center, and was also a member of the Ocom group of companies, but specialized primarily in dedicated services. After reading reviews on the Internet, they concluded that they were not a very reliable company, people complained about very frequent changes in working conditions, traffic and servers were quite expensive, prices were not lower than Ukrainian ones. What is the advantage? The question had to be postponed.
But a month later we rented a server for $ 339 / month through one of their partners, since LeaseWeb introduced a profitable traffic offer (100TB servers with a 1 Gbit / s channel) and reduced prices. It was decided to organize a hosting node for customers wishing to host websites abroad, in particular customers with projects for adults. So we started the work. Highly successful.
But after 2 months, the data center changed the conditions (I immediately recalled the review and previous experience with cheap traffic). For new orders, streaming from such servers has become banned, and some current LeaseWeb customers have been denied service. The reason was banal. Online cinemas that came to the data center consumed the channel fully and by 100%, and not by 10-30%, as it was calculated, differed by the unevenness of this consumption - at night the load was several times lower or absent in everything. In fact, they consumed gigabit, and paid only for a third, this was the problem. So the data center decided to get rid of all such unwanted customers, although it would be much more sensible to just put a limit of 330 Mbit / s, thereby making the figures profitable, to avoid failures and negative reviews.
Shortly afterwards, Emrah Aydin wrote a letter to us, their development manager, who found us and became interested in the development of their services in Ukraine, was about to fly to Kiev and asked for a meeting:
======
Hello,
My name is Emrah, I am a business development manager of Leaseweb. I think you are a customer of 100TB servers, however I couldn't find your account in our system.
I will be in Kiev on the next day. We are looking for a partner to grow in Ukraine. Would it be possible?
Emrah C. Aydin
Business Development Manager - Leaseweb BV
======
Although we were not in Ukraine, we planned to be in Kiev at that time, because they said that the meeting was possible. I explained to Emrakh who we are and that we, as we work, told about our cooperation with another company, Data-Hat, that if we place something in them, we will do it together, since we are not competitors and, first of all, partners who always cooperate successfully and together we are larger, we have a greater level of discounts and advantages in data centers than working separately. He was glad to hear that between us, essentially competitors, such a very successful partnership has developed.
I also explained the reason why he could not find our account, since we rented that only server in LeaseWeb not directly. He described the situation in Ukraine with channels and servers, that in the Netherlands at their prices 100 TB servers are not for streaming now very few people will be interested, since they have a ban on it. And gigabit for huge money - at that moment about 600 euros, against $ 200-300 in Ukraine, they will take only projects for adults, because everything else is possible in Ukraine and for cheap, and so far we have no such clients, due to the limitations of Ukrainian and Russian legislation. However, he said that nevertheless their low-cost servers might be of interest to our current customers and interest may arise if there is a special offer, the price tag is much lower than in Ukraine.
I have been thinking about whether it is worth going to a meeting at all or canceling it. Is it worth spending our time and time Emrah, discussing cooperation, which may not take place, because "LeaseWeb" is not very flexible. Not so long ago, “Khata” told us that, at the request of their large potential client, who wanted to take 25 gigabits at once, “LeaseWeb” could not make a decent offer. The price still turned out to be much higher than in Ukraine, and not much lower than theirs on the website, and a contract was required - an additional disadvantage.
, 2- , «-» , « , ». , .
A meeting
, . 4 , , .
one). , ? , .
2). . ?
3). , ? , , / .
4). — . . — :). ?
— - ?
— , ?
— -?
— ? ? ..
— . ? ? ? ?
— ? ? ? Who else?
— / ? ?
— ? — ? ?
— , ( )?
— ? ? ? ?
— ? ?
— ( ), ?
, , . , - , , 600 . , , . , , , .
,
, «LeaseWeb». 100 Mbps Unmetered. . , — 10 000 , , . , , - . , , .
— -, , . , , , , , .
- . 2012- 20 , 3 . , IT, 3-1230 , . , , .
— , , , , . 160 .
- — , , — , , . , , , . , . 40 — -. - .
, , , , . free-lance , . .
2012- - , . . -, . , , :
« , - EvoSwitch» .

. , , - , , . . , , . , SLA , , . . , . - , - , SLA ( ) , .
, «». - -, , . , . , , - 50- , 1%. -, , . .
, , , , , 150 — - . . - , . , , , . , , . , , , , .
, , , , - . , .
2013- , , 500. «» - . 2013-, , , , .
: -
- , . ?
, , , , -, — . , , , , , , , — …

2013-, «» , , , , Jay Devin, , «COPT DC-6-EvoSwitch/LeaseWeb (Manassas)», « -, ».
, -. - :
, - «COPT DC-6-EvoSwitch/LeaseWeb (Manassas)».10- , -
2013- — 10 / , - .
, , , , « »:


, :
http://habrahabr.ru/company/ua-hosting/blog/191558/, , .
, , — , 2011- .
, , Kernel Video Sharing , , . — . , , .
- , , . , . . , , , , .
, , , — . ( 500 , ) . , , . .
, — , . «» , , , .
, - , … . , , , , 10- , 3 …
, . , - 40% . , .
A month later, a private cabinet was built for us and the first 80 gigabits were installed. The project was successful. Some subscribers were moved to a cheaper connection and as a result, we were able to reduce the costs of the data center and start offering new servers at an adequate price.Additional managers and motivation
The work of the manager, perhaps, is one of the most difficult. In our business, a good manager is not only a person who quickly and efficiently processes orders, gives recommendations on the choice of a technical solution, but also a psychologist who can support a client in a difficult situation will sincerely empathize with him.
It was very difficult for me to entrust customer care to someone else, primarily psychologically. Therefore, until the fall of 2013, I could not communicate with clients any more. Nevertheless, I began to realize that as the number of servers grows, we just need more managers who will not be as good as we do, but pay attention to customers and process orders. After all, even with maximum automation, people are needed. The technical department solves technical problems, but sometimes even they need to be controlled. Unfortunately, the two of us are not enough in the future.
Since the fall of 2013, additional people have appeared in the team. I will not say that the level of care became immediately better or worse. On the way we faced new problems that still had to be solved. First of all, motivational. Yes, people received a decent reward for their work, but unfortunately this does not always motivate everyone. Sometimes people get something extremely easy, people don’t appreciate what they have.
Sometimes people just do not perform their tasks. People have problems with the so-called “follow direction”. It is very difficult for an adult to follow the path that is given to him. We say: “this is the way, we are following it”. We can give way, open the door, but we can not force a person to enter.
There are bumms for various reasons, but mostly they happen when a person does not have 100% commitment: somehow you want it, but if it did, it would be nice, but if not, you can live like that. Do something? Here the difficulties begin ... Failure does not come from the fact that there is no ownership of some subtle points, but from the fact that the principles of fundamental successful behavior are violated. Slavery hack, technology violations in us sitting.
We need people to do simple, elementary things on a regular basis and then there will be a miracle. Because a miracle happens only there, where even though you are a little bit, but every day and in the right direction. And then a miracle comes. It is because of this that we pay special attention to the development, encourage employees to learn something new, both during working hours and simply through life. After all, the logistics that we give in the end can be successfully applied everywhere. And in my opinion, the following phrase should always serve as a good motivation:
How to motivate yourself to do something? No way - stay in the ass.
- Artemy Lebedev
Data Center "Switch AMS1" - we did what our clients lacked so much!
By providing premium quality services to thousands of subscribers, it is usually impossible to achieve customization to the full. Someone wants a permanent IP-KVM, someone has a higher bandwidth channel, but with limited traffic, someone to connect servers to each other in a local network, or just be able to expand the channel at the right time. It happens that a person does not even understand what he wants, and already during the discussion of the order he comes to the understanding that nothing from the standard iron is suitable in principle. And often it happens, because of poor planning or excessive budget saving, that the server is needed “for yesterday”, and not just a server, but a custom built solution.
With a company like LeaseWeb, we unfortunately could not find a common solution. There was a different business model and other volumes. Solutions sharpened to standardize. Deviation from the standards was very expensive. We have repeatedly discussed this problem with our manager at LeaseWeb, who soon quit and opened his own transport company.

Having earned money and remembering the problem, Murat Bayhan notified us of his intention to organize his own platform and invited us to cooperate, because first of all he needed orders and he knew that we could provide this. Successfully working together in the past, we agreed to work together, because we could completely trust this person. But they immediately said that we will not transfer customers from other sites, but will only place new orders that really need customization, since we don’t want to spoil relations with LeaseWeb and let them down as a partner, returning servers. Murat replied that he was glad that his past work still brings dividends to LeaseWeb, because he raised us - a reliable partner, and I am glad that we are not changing the amount of cooperation because of the better conditions with him.
But there was another reason. Apart from the fact that Murat did not have huge working capital at the beginning - he was still not “LeaseWeb”, we knew that since the site is new, there will be problems and it will be better if fewer subscribers experience them. It would be better if Murat had the resources to resolve. As a result, this is what happened - after a few months, DDOS flew to Murata in 100+ gigabits, for which no one was ready. Whether it was an attack on a client or simply the revenge of pissed off competitors is not important, but a sufficiently large number of subscribers suffered. Murat had to quickly change the network topology and install additional equipment in order to be able not to go to bed completely during such attacks.
Nevertheless, the decision as a whole was successful and our customers are very pleased with this second platform in the Netherlands. More like to learn about the benefits and possible technical solutions, you can read the article:
http://habrahabr.ru/company/ua-hosting/blog/239253/1000+ servers: traffic generation by our subscribers exceeded 256 Gbit / s!
In October 2014, the total number of servers of our subscribers confidently approached 1000, only at the Dutch site EvoSwitch, and the traffic generated by our subscribers reached a quarter of terabits.
Quarter terabit, is it a little or a lot?
Approximately as much external Internet traffic was consumed at that time by Belarus.
Actually, as a statistics amateur, I did not bypass this significant event and published the news in our blog: The
generation of traffic by our subscribers exceeded 256 Gbit / s!Of course, most of the traffic is the traffic generated by our 10 Gigabit solutions, the total number of which exceeded 50 at that time. Good statistical data appeared indicating that in the case of working with individual subscribers whose projects do not consume traffic in the regiment, there are the opportunity to save about 50% of the channel in such broadband solutions, which for the future could serve as a good background for building your own inclusion, with even more attractive prices for such customers.
Of course, there is always a risk that a large traffic generator, for example, a file server, which once ordered 10+ ten-gigabit servers from us once, will come to the cheap one, but it is possible to work with such subscribers on a different business scheme to cost peer-to-peer connections to the providers of this traffic. After all, not only the generator can pay for the traffic, but also the provider who receives this traffic. With this individual approach, you can significantly reduce the cost of delivering traffic to certain destinations. Savings can be huge. Perhaps we will be able to implement this project in the future.
"Ua-hosting.company" today
"Ua-hosting.company" is no longer a Ukrainian company and the team is becoming more and more international. Today, the project involves over 20 specialists from Ukraine, Russia, Belarus, the Netherlands, the USA, Canada and Turkey. Administrators, managers, journalists and editors, programmers and designers work for you. We are constantly developing and improving skills. All new and new specialists are involved in the project.
We cannot present everyone to you now, but we will show at least some “ua-hosting in persons”:

We work for you and love our work very much!
Our work allows us not to be geographically tied and to work from wherever there is Internet. Some time ago we worked from, perhaps, the most distant country on the planet - French Polynesia, it was then that I got the idea to write the article
“Messages in depth: an amazing history of the underwater Internet” , because even on one of the most remote atoll islands in Fakarava, the world over 5000+ miles from the “Big Land”, where the population is only a few hundred people and increases 10 times during the mooring of a cruise ship, was Wi-Fi. And we do not always appreciate this ...
Over the past year, we also organized joint visiting work sessions to Egypt, Indonesia, Singapore, the Netherlands, where we had the opportunity not only to work together, but also to have a good time. For example, for 2 months, our office was a house on the Red Sea in Dahab, where we managed to gather most of the managers in order to improve teamwork skills.
And despite the crisis in the world - we are growing, primarily intellectually. After all, the crisis is a new opportunity, an incentive to change approaches and it becomes better. Yes, it was difficult for us to work in the last year, since most of our clients were from Russia and from Ukraine and we had to reconsider solutions for them, due to the current economic situation (in some months the clients returned us up to hundreds of servers). But now we will all continue to grow more confidently, including in the foreign direction, because our principle is an individual approach and the happiness of our clients. We love our customers because they love us and are always happy to make them happier.
In the near future, plans include not only the expansion of points of presence, the introduction of new services, but also a return to basics - the beginning of work on our own web projects. Indeed, there are so few truly good informational specialized websites, the purpose of which is primarily not in making money, but in providing high-quality content. We, as a hosting provider, have a full technical base for this.
In conclusion, I want to say separately about the reliability of solutions, as the main principle of success. Never save on what you can afford. I do not agree with the opinion of businessmen who write: “if you can not buy something, do not buy”. Their goal in making money, no more. In my opinion, the project should be useful primarily for people, and money is only a measure of utility, and you shouldn’t save money on the comfort of someone, be it a client or an employee. Yes, we could use Windows for work or lease low-cost servers, they would be better bought. But as soon as we could, we chose the best for our employees, for example, Apple computers - after all, this is not only convenience in work, but also data security for our clients. And it seems that even the cat was able to appreciate the advantages of Mac:

As for low-cost servers, this is not our market; we understand this and don’t regret it. For example, we will never provide, as OVH, marketing bullshit:
j1900 / 16 GB DDR3 / 1 TB HDD WD RE4 / 100 mbit / 1 IPv4 = $ 25 / m
After all, RAM on this gland is not very effective. And we try to always explain this to users on the Internet, giving rise to new, interesting discussions:



That's why we work, not to “sell something cheaper and no matter what, just to sell”, but in order to always find magical solutions, be able to argue them. It is for this - for the fact that I have a constant opportunity to develop and learn something new, to participate in such interesting discussions, share experience with clients, and sometimes learn from their experience, and I love my work.