AS overview
Test target: 2a03:e600:100:2::6 · appliedprivacy.net · address space: PA · prefixes announced: 1
prefix(es): 2a03:e600:100::/48
Targets & per-vantage-point probe results (1 target(s) across 7 vantage point(s))
Source codes (hover any badge for full description): CUR=curated · NS/SOA/MX=DNS records · SPF=SPF TXT · DRV=holder-derived (www, ns1, mail, gw, …) · ATL=RIPE Atlas · PDB=PeeringDB · WHOIS=RIPE whois · RDAP=RIPE RDAP · HIT=IPv6 Hitlist · RTR=in-prefix path hop (router) · PRB=static prefix probe · SYN=synthetic prefix::1 fallback
| Target IP / hostname | Source | SRB host (SOX, Belgrade) | DE host (Berlin) | DE host (Düsseldorf) | NL host (go6lab) | ITA host (Karsolink) | SLO host (6connect) | SLO host (T-2) | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ||
2a03:e600:100:2::6appliedprivacy.net | drv | ✓ | ✓ | open | open | ✓ | ✓ | ✗ | open | open | ✓ | ✓ | ✗ | open | open | - | ✓ | ✓ | open | open | ✓ | ✓ | ✓ | open | open | ✓ | ✓ | ✓ | open | open | ✓ | ✓ | ✓ | open | open | ✓ |
VIX / AAIX / SAIX / TIROL-IX / ERA-IX peering
Not an VIX / AAIX / SAIX / TIROL-IX / ERA-IX member, but our traceroute path crosses the VIX / AAIX / SAIX / TIROL-IX / ERA-IX LAN from SLO host (T-2) - reached via an VIX / AAIX / SAIX / TIROL-IX / ERA-IX-resident transit operator.
RPKI & ASPA
1 of 1 prefix(es) covered by a valid ROA.
| Prefix | RPKI state | Reason | Covering VRP(s) |
|---|---|---|---|
2a03:e600:100::/48 | ✓ valid | matched VRP (correct origin, length within maxLength) | AS208323 /48 maxLen 48 (ripe); AS1764 /29 maxLen 32 (ripe) |
ASPA: this AS has published an ASPA record listing 4 upstream provider(s) that are authorized to propagate routes from it: AS1764, AS5405, AS47147, AS47692. Routes from this AS that arrive via any other upstream are considered ASPA-invalid by validators that enforce ASPA.
ICMPv6 Type 2 (Packet Too Big) acceptance - active test
Vantage points disagree about Type 2 acceptance - transit ASes on one path may be filtering Type 2 even though the destination's stack accepts it on another path:
- SRB host (SOX, Belgrade): Type 2 honored. Forged PTB accepted; next response shrunk. (ICMPv6 Echo + forged PTB)
- DE host (Berlin): Type 2 NOT honored. Forged PTB had no effect (filtered en route or stack ignored it). (TLS handshake + forged PTB)
- DE host (Düsseldorf): Type 2 NOT honored. Forged PTB had no effect (filtered en route or stack ignored it). (TLS handshake + forged PTB)
- NL host (go6lab): Type 2 honored. Forged PTB accepted; next response shrunk. (ICMPv6 Echo + forged PTB)
- ITA host (Karsolink): Type 2 honored. Forged PTB accepted; next response shrunk. (ICMPv6 Echo + forged PTB)
- SLO host (6connect): Type 2 honored. Forged PTB accepted; next response shrunk. (ICMPv6 Echo + forged PTB)
- SLO host (T-2): Type 2 honored. Forged PTB accepted; next response shrunk. (ICMPv6 Echo + forged PTB)
Why they disagree - different probe methods: These vantages picked different probe methods, so their verdicts are not directly comparable. The active test tries methods in order (icmp6-echo → dns-tcp → tls → http) and stops at the first that produces a definitive verdict; if the chosen method differs, the underlying evidence differs too. Most often this is because the path PMTU on one vantage is below 1500 B, so the natural Echo Reply is already fragmented and the icmp6-echo method falls through to a TCP-based one. This is largely a measurement artifact, not a destination-behaviour difference.
Failure detail - what to grep in your logs
| vantage | our source | your target | method | result | tested (UTC) |
|---|---|---|---|---|---|
| belgrade | 2a09:ab81::91 | 2a03:e600:100:2::6 | icmp6-echo | honored | 2026-09-24T13:32:05Z |
| berlin | 2a06:d1c1:10b::cccc | 2a03:e600:100:2::6 | tls | not_honored | 2026-09-24T13:32:05Z |
| duseldorf | 2a06:d1c1:10d::aaaa | 2a03:e600:100:2::6 | tls | not_honored | 2026-09-24T13:32:08Z |
| go6lab | 2a00:8642:42::75 | 2a03:e600:100:2::6 | icmp6-echo | honored | 2026-09-24T13:32:42Z |
| karsolink | 2a12:d8c0:105a:9001::a154 | 2a03:e600:100:2::6 | icmp6-echo | honored | 2026-09-24T13:31:58Z |
| odin | 2607:fae0:a000::42 | 2a03:e600:100:2::6 | icmp6-echo | honored | 2026-09-24T13:32:09Z |
| t2 | 2a01:261:313:b814:2a0:98ff:fe5b:13e4 | 2a03:e600:100:2::6 | icmp6-echo | honored | 2026-09-24T13:32:07Z |
Attempt log (belgrade):
icmp6-echo→ honored (honored by fragmenting its reply into 2 via the IPv6 Fragment Header, rather than resizing)dns-tcp→ no_tcp: connect failed: [Errno 111] Connection refusedtls→ not_honored (reply shrank 1428→1428 B)http→ inconclusive (reply 352 B before PTB): natural max segment 352B already <= 1220B; nothing to shrink
Attempt log (berlin):
icmp6-echo→ inconclusive (reply 1460 B before PTB): no Echo Reply after PTB (probe 1500B)dns-tcp→ no_tcp: connect failed: [Errno 111] Connection refusedtls→ not_honored (reply shrank 1428→1428 B)http→ inconclusive (reply 352 B before PTB): natural max segment 352B already <= 1220B; nothing to shrink
Attempt log (duseldorf):
icmp6-echo→ inconclusive (reply 1460 B before PTB): no Echo Reply after PTB (probe 1500B)dns-tcp→ no_tcp: connect failed: [Errno 111] Connection refusedtls→ not_honored (reply shrank 1428→1428 B)http→ inconclusive (reply 352 B before PTB): natural max segment 352B already <= 1220B; nothing to shrink
Attempt log (go6lab):
icmp6-echo→ honored (honored by fragmenting its reply into 2 via the IPv6 Fragment Header, rather than resizing)dns-tcp→ no_tcp: connect failed: timed outtls→ not_honored (reply shrank 1428→1680 B)http→ inconclusive (reply 352 B before PTB): natural max segment 352B already <= 1220B; nothing to shrink
Attempt log (karsolink):
icmp6-echo→ honored (honored by fragmenting its reply into 2 via the IPv6 Fragment Header, rather than resizing)dns-tcp→ no_tcp: connect failed: [Errno 111] Connection refusedtls→ not_honored (reply shrank 1428→1428 B)http→ inconclusive (reply 352 B before PTB): natural max segment 352B already <= 1220B; nothing to shrink
Attempt log (odin):
icmp6-echo→ honored (honored by fragmenting its reply into 2 via the IPv6 Fragment Header, rather than resizing)dns-tcp→ no_tcp: connect failed: [Errno 111] Connection refusedtls→ partial (reply shrank 2856→1428 B)http→ inconclusive (reply 352 B before PTB): natural max segment 352B already <= 1220B; nothing to shrink
Attempt log (t2):
icmp6-echo→ honored (honored by fragmenting its reply into 2 via the IPv6 Fragment Header, rather than resizing)dns-tcp→ no_tcp: connect failed: [Errno 111] Connection refusedtls→ not_honored (reply shrank 1428→1428 B)http→ inconclusive (reply 352 B before PTB): natural max segment 352B already <= 1220B; nothing to shrink
To match the corresponding ICMPv6 packet on your side (host firewall, AS edge, or transit tap), look for our PTBs around the timestamps above:
sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a01:261:313:b814:2a0:98ff:fe5b:13e4 or src host 2a06:d1c1:10b::cccc or src host 2a06:d1c1:10d::aaaa or src host 2a09:ab81::91 or src host 2a12:d8c0:105a:9001::a154)'
If you see our PTBs arriving but the destination's TCP/Echo flow does not shrink, the drop is in the destination kernel (cause 3 below). If you don't see them at all, drop is upstream of you (cause 2). If you only see them from some of our source IPs but not others, the drop is path-asymmetric - at least one transit on the differing route is filtering.
What does "Type 2 not honored" actually mean? - click to expand
What this test does
Using the tls method, we open a TLS handshake to your TCP server, observe its TCP segment size, forge an ICMPv6 PTB declaring path MTU=1280, and observe whether subsequent segments shrink. RFC 4890 requires hosts and intermediate networks not to filter ICMPv6 Type 2; the destination's TCP/UDP stack must act on a received PTB by lowering its Path MTU cache for that destination, which makes subsequent segments smaller.
What we measured
The TCP segment size your server emitted before our forged Type 2 was 1428 B; after, it was 1428 B. No change. RFC 4890 ("Type 2 messages MUST NOT be filtered") expects subsequent segments to shrink to fit a Path MTU of 1280 B.
Three plausible causes
- Your host firewall is dropping ICMPv6 Type 2 inbound. Many default firewall rule sets only allow Echo Request/Reply and Neighbor Discovery, silently dropping all other ICMPv6 types - including Packet Too Big.
- An upstream / transit network is dropping ICMPv6 Type 2 before it reaches you. Some transit ASes filter ICMPv6 messages other than Echo at the edge. The forged PTB never arrives, so your stack never has a chance to act on it.
- Your kernel is ignoring the PTB. Linux / BSD stacks normally accept ICMPv6 PTB and update the route cache, but a few sysctls (or a hardened kernel) can be configured to ignore PMTU updates - typically as part of an over-aggressive anti-spoofing or uRPF policy.
How to check & fix (Linux examples)
1. Confirm Type 2 is not blocked at the host firewall:
sudo ip6tables -L INPUT -nv | grep -iE 'icmpv6|packet-too-big' sudo nft list ruleset 2>/dev/null | grep -A1 'icmpv6'
If you see rules dropping ICMPv6 unconditionally, change them to permit at least icmpv6 type packet-too-big (and destination-unreachable, time-exceeded, parameter-problem per RFC 4890).
2. Confirm the kernel accepts incoming PTB:
sudo sysctl net.ipv6.conf.all.accept_redirects net.ipv4.ip_no_pmtu_disc net.ipv6.route.mtu_expires
The defaults (accept_redirects=1, ip_no_pmtu_disc=0) are the right values for honoring PTB.
3. Live trace: while we have an open TCP flow with a small MSS (we run our test from 2607:fae0:a000::42 on odin, 2a00:8642:42::75 on go6lab, 2a12:d8c0:105a:9001::a154 on karsolink, 2a09:ab81::91 on belgrade, 2a01:261:313:b814:2a0:98ff:fe5b:13e4 on t2, 2a06:d1c1:10a::bbbb on amsterdam, 2a06:d1c1:10d::aaaa on duseldorf and 2a06:d1c1:10b::cccc on berlin), watch for our forged Type 2 arriving on your interface:
sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a12:d8c0:105a:9001::a154 or src host 2a09:ab81::91 or src host 2a01:261:313:b814:2a0:98ff:fe5b:13e4 or src host 2a06:d1c1:10a::bbbb or src host 2a06:d1c1:10d::aaaa or src host 2a06:d1c1:10b::cccc)'
If you see our PTBs arriving but TCP segments still stay big, the drop is in your kernel or NIC offload (cause 3). If you don't see them at all, the drop is upstream of you (cause 2) - ask your upstream(s) to permit ICMPv6 Type 2.
4. If your test target above (2026-09-24T13:32:05Z) is a host that you don't own (e.g. a third-party DNS / TLS server you happen to operate prefixes for), the verdict reflects that specific host's behaviour - try the test against a server you do own and we'll happily re-run.
RFC 4890 references: §4.3.1 (Packet Too Big - MUST NOT be dropped), and RFC 8201 for the broader PMTUD requirement.
Where the path divergence is
Mixed disagreement. At least one pair of vantages used the same probe method and disagreed (real Type 2 asymmetry); other pairs used different methods (probe-availability noise). The path-divergence summary below covers all pairs; the AI interpretation focuses on the real cases.
Per-vantage probe + verdict (headline):
- belgrade: probe
icmp6-echo→ verdicthonored - berlin: probe
tls→ verdictnot_honored - duseldorf: probe
tls→ verdictnot_honored - go6lab: probe
icmp6-echo→ verdicthonored - karsolink: probe
icmp6-echo→ verdicthonored - odin: probe
icmp6-echo→ verdicthonored - t2: probe
icmp6-echo→ verdicthonored
Full per-method matrix (all four methods run at each vantage):
| vantage | icmp6-echo | dns-tcp | tls | http |
|---|---|---|---|---|
| belgrade | honored | no_tcp | not_honored | inconclusive |
| berlin | inconclusive | no_tcp | not_honored | inconclusive |
| duseldorf | inconclusive | no_tcp | not_honored | inconclusive |
| go6lab | honored | no_tcp | not_honored | inconclusive |
| karsolink | honored | no_tcp | not_honored | inconclusive |
| odin | honored | no_tcp | partial | inconclusive |
| t2 | honored | no_tcp | not_honored | inconclusive |
✓ All vantages agree on method(s): icmp6-echo - the headline-method spread above is dispatcher noise, not a real Type 2 disagreement.
These vantage-level disagreements are rooted somewhere in the forward paths. Joining each per-vantage traceroute against the IP→AS lookup from our global yarrp mesh, the first hop where the paths land in different ASes is the most likely site of the offending filter / unreachable AS / Type 2 drop.
Suspect transit ASes (ranked by how often they appear at the divergence point on the path of the worse-classifying vantage): AS47147, AS1764, AS208323.
- From belgrade (open/Type-2=honored) the path enters AS208323 at hop 8; from berlin (echo_only/Type-2=not_honored) the same hop is in AS47147. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From belgrade (open/Type-2=honored) the path enters AS208323 at hop 8; from duseldorf (echo_only/Type-2=not_honored) the same hop is in AS47147. Last common AS: AS47147. The disagreement is most likely rooted in one of those two transit ASes.
- From belgrade (open/Type-2=honored) the path enters AS208323 at hop 8; from go6lab (open/Type-2=honored) the same hop is in AS47147. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From belgrade (open/Type-2=honored) the path enters AS208323 at hop 8; from karsolink (open/Type-2=honored) the same hop is in AS6939. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From belgrade (open/Type-2=honored) the path enters AS47147 at hop 7; from odin (open/Type-2=honored) the same hop is in AS1764. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From belgrade (open/Type-2=honored) the path enters AS47147 at hop 7; from t2 (open/Type-2=honored) the same hop is in AS1764. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From berlin (echo_only/Type-2=not_honored) the path enters AS208323 at hop 9; from duseldorf (echo_only/Type-2=not_honored) the same hop is in AS47147. Last common AS: AS47147. The disagreement is most likely rooted in one of those two transit ASes.
- From berlin (echo_only/Type-2=not_honored) the path enters AS9002 at hop 5; from go6lab (open/Type-2=honored) the same hop is in AS47147. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From berlin (echo_only/Type-2=not_honored) the path enters AS9002 at hop 5; from karsolink (open/Type-2=honored) the same hop is in AS6939. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From berlin (echo_only/Type-2=not_honored) the path enters AS9002 at hop 4; from odin (open/Type-2=honored) the same hop is in AS5603. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From berlin (echo_only/Type-2=not_honored) the path enters AS47147 at hop 7; from t2 (open/Type-2=honored) the same hop is in AS1764. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From duseldorf (echo_only/Type-2=not_honored) the path enters AS47147 at hop 8; from karsolink (open/Type-2=honored) the same hop is in AS6939. Last common AS: no shared transit. The disagreement is most likely rooted in one of those two transit ASes.
- From duseldorf (echo_only/Type-2=not_honored) the path enters AS47147 at hop 7; from odin (open/Type-2=honored) the same hop is in AS1764. Last common AS: no shared transit. The disagreement is most likely rooted in one of those two transit ASes.
- From duseldorf (echo_only/Type-2=not_honored) the path enters AS47147 at hop 7; from t2 (open/Type-2=honored) the same hop is in AS1764. Last common AS: no shared transit. The disagreement is most likely rooted in one of those two transit ASes.
- From go6lab (open/Type-2=honored) the path enters AS47147 at hop 5; from karsolink (open/Type-2=honored) the same hop is in AS6939. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From go6lab (open/Type-2=honored) the path enters AS47147 at hop 6; from odin (open/Type-2=honored) the same hop is in AS1764. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From go6lab (open/Type-2=honored) the path enters AS47147 at hop 7; from t2 (open/Type-2=honored) the same hop is in AS1764. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From karsolink (open/Type-2=honored) the path enters AS6939 at hop 6; from odin (open/Type-2=honored) the same hop is in AS1764. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
- From karsolink (open/Type-2=honored) the path enters AS6939 at hop 8; from t2 (open/Type-2=honored) the same hop is in AS208323. Last common AS: AS208323. The disagreement is most likely rooted in one of those two transit ASes.
Diagnosis is path-level, not packet-level: it tells you which transit AS is the prime suspect, not exactly which firewall rule is to blame. Use the tracepath6 output below (when available) for per-hop PMTU evidence on the same path.
✨ Diagnostic interpretation
tracepath6 per-hop PMTU drilldown
For each target where Type 2 verdicts disagreed across vantages, tracepath -6 ran from every vantage to capture per-hop PMTU evolution along that vantage's actual forward path. A pmtu change entry on a hop means that hop's router generated a PTB and we observed the shrink; absence of any change combined with a not_honored verdict suggests a router somewhere downstream is silently dropping >MTU packets (an RFC 4890 violation) rather than sending a PTB.
Target 2a03:e600:100:2::6
amsterdam - verdict ?
(no hops captured)
belgrade - verdict honored
verdict = honored; final pmtu = 1500
| # | hop IP | pmtu change |
|---|---|---|
| 1 | <span class='muted'>no reply</span> | |
| 2 | 2001:7f8:1e:8::3a | |
| 3 | 2001:7f8:1e:8::3d | |
| 4 | 2a02:2d8:0:a00e:232a:: | |
| 5 | 2a02:2d8:0:a014:232a::1 | |
| 6 | 2a00:11c0:47:1:47::252 | |
| 7 | 2a00:11c0:47:8::75 | |
| 8 | 2a00:11c0:47:8::75 | |
| 9 | 2a03:e600:100:2::6 |
berlin - verdict not_honored
verdict = not_honored; final pmtu = 1500
| # | hop IP | pmtu change |
|---|---|---|
| 1 | <span class='muted'>no reply</span> | |
| 2 | 2a06:d1c0::dead:beef:1c02 | |
| 3 | 2001:7f8:19:1::232a:1 | |
| 4 | 2a02:2d8::57f5:e0b7 | |
| 5 | 2a02:2d8:3:e001:232a::1 | |
| 6 | 2a00:11c0:47:1:47::146 | |
| 7 | 2a00:11c0:47:1:47::151 | |
| 8 | 2a00:11c0:47:8::75 | |
| 9 | 2a03:e600:100:2::6 |
duseldorf - verdict not_honored
verdict = not_honored; final pmtu = 1500
| # | hop IP | pmtu change |
|---|---|---|
| 1 | <span class='muted'>no reply</span> | |
| 2 | 2001:4ba0:92f4:3::1 | |
| 3 | <span class='muted'>no reply</span> | |
| 4 | 2001:4ba0:ffe9:115::3 | |
| 5 | 2001:4ba0:ffe9:4f::1 | |
| 6 | 2001:7f8::6e4:0:1 | |
| 7 | 2a01:190:1764:5c::2 | |
| 8 | 2a00:11c0:47:1:47::145 | |
| 9 | 2a00:11c0:47:1:47::151 | |
| 10 | 2a00:11c0:47:8::75 | |
| 11 | 2a03:e600:100:2::6 |
go6lab - verdict honored
verdict = honored; final pmtu = 1500
| # | hop IP | pmtu change |
|---|---|---|
| 1 | <span class='muted'>no reply</span> | |
| 2 | 2a00:8642:1000:f000::1 | |
| 3 | 2a00:8642:dc1:2::b | |
| 4 | 2001:7f8:1::a504:7147:1 | |
| 5 | 2a00:11c0:47:1:47::213 | |
| 6 | 2a00:11c0:47:1:47::211 | |
| 7 | 2a00:11c0:47:1:47::130 | |
| 8 | 2a00:11c0:47:1:47::151 | |
| 9 | 2a00:11c0:47:8::75 | |
| 10 | 2a03:e600:100:2::6 |
karsolink - verdict honored
verdict = honored; final pmtu = 1500
| # | hop IP | pmtu change |
|---|---|---|
| 1 | <span class='muted'>no reply</span> | |
| 2 | 2a12:d8c0:109f:121::a1 | |
| 3 | 2a12:d8c0:101f:6::1 | |
| 4 | <span class='muted'>no reply</span> | |
| 5 | 2001:470:e:69::2 | |
| 6 | 2001:470:e:dd::2 | |
| 7 | <span class='muted'>no reply</span> | |
| 8 | 2001:470:0:7e0::2 | |
| 9 | <span class='muted'>no reply</span> | |
| 10 | 2a01:190:1764:5c::2 | |
| 11 | 2a01:190:15ff:5f::2 | |
| 12 | 2a03:e600:100:2::6 |
odin - verdict honored
verdict = honored; final pmtu = 1500
| # | hop IP | pmtu change |
|---|---|---|
| 1 | <span class='muted'>no reply</span> | |
| 2 | 2607:fae0:a000:2::2 | |
| 3 | 2a00:ee1:800:9::1 | |
| 4 | 2a00:ee0:1:10::2 | |
| 5 | 2a00:ee0:1:15::2 | |
| 6 | 2a01:190:1764:5c::2 | |
| 7 | 2a01:190:15ff:5f::2 | |
| 8 | 2a03:e600:100:2::6 |
t2 - verdict honored
verdict = honored; final pmtu = 1500
| # | hop IP | pmtu change |
|---|---|---|
| 1 | <span class='muted'>no reply</span> | |
| 2 | 2a01:260:1::225 | |
| 3 | 2a01:260:1:1::9c | |
| 4 | 2a01:260:1:1::c | |
| 5 | 2001:7f8:30:0:1:1:0:1764 | |
| 6 | 2a01:190:1764:5c::2 | |
| 7 | 2a01:190:1764:5c::2 | |
| 8 | 2a03:e600:100:2::6 |
Multi-vantage path map
Every hop of all vantages’ traceroutes toward the target, drawn left→right, grouped into per-AS bubbles (a hop seen from several vantages is one shared bubble, so converging paths merge). It answers two questions per vantage — shown on each source bubble as echo ✓/⚠/✗ · trace ✓/✗: did the destination reply to ICMPv6 Echo (✓ honored, ⚠ replied but PTB not honored, ✗ no reply), and did the traceroute reach it. A line to the target is drawn only when that vantage got an echo reply — solid if the PTB was honored, dashed if not (reachable but a broken-PMTUD / RFC 4890 violation). The path depth still shows how far the traceroute itself got, and runs of unanswered (* *) hops collapse into one dashed “silent” bubble. Open full size ↗
- ● SRB host (SOX, Belgrade)
- ● DE host (Berlin)
- ● DE host (Düsseldorf)
- ● NL host (go6lab)
- ● ITA host (Karsolink)
- ● SLO host (6connect)
- ● SLO host (T-2)
- ── solid line = echo reply, PTB honored (clean reach)
- — — dashed line = echo reply but PTB not honored (RFC 4890 violation)
- no line = no echo reply (never reached)
- ◉ target: green = clean, amber = reachable-but-violation / unreachable
- ⚠ suspected drop AS
- ⋯ silent (unanswered) hops
- ● IXP hop
From SRB host (SOX, Belgrade) openRFC 4890 ✓
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | 2a09:ab81::1 | 3.2ms | 0%* | AS60733 | PERKE-NET - ZORAN PEROVIC trading as Agencija Perke.NET, RS |
| 2 | sox-pn.sox.rs 2001:7f8:1e:8::3a | 0.4ms | 0% | AS13004 | SOX - Serbian Open Exchange DOO, RS |
| 3 | 2001:7f8:1e:8::3d | 1.3ms | 0% | AS13004 | SOX - Serbian Open Exchange DOO, RS |
| 4 | 2a02:2d8:0:a00e:232a | 12.7ms | 0% | - | |
| 5 | GW-AS47147.retn.net 2a02:2d8:0:a00d:232a::1 | 11.1ms | 0% | AS9002 | RETN-AS - RETN Limited, GB |
| 6 | 2a00:11c0:47:1:47::252 | 13.1ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 7 | 2a00:11c0:47:1:47::128 | 11.6ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 8 | 2a03:e600:100:2::6 | 12.6ms | 0% | AS208323 | APPLIEDPRIVACY-AS - Foundation for Applied Privacy, AT |
tracepath -6
1?: [LOCALHOST] 0.011ms pmtu 1500
1: _gateway 0.385ms
1: _gateway 0.307ms
2: sox-pn.sox.rs 0.832ms
3: 2001:7f8:1e:8::3d 0.504ms asymm 2
4: ae8-930.RT.IRX.VIE.AT.retn.net 12.907ms asymm 3
5: 2a02:2d8:0:a014:232a::1 11.267ms asymm 6
6: 2a00:11c0:47:1:47::252 13.385ms
7: 2a00:11c0:47:1:47::128 13.248ms asymm 4
8: 2a00:11c0:47:8::75 16.906ms asymm 5
9: 2a03:e600:100:2::6 15.004ms reached
Resume: pmtu 1500 hops 9 back 6 From DE host (Berlin) echo onlyRFC 4890 ✗
filter likely at: destination AS208323 (APPLIEDPRIVACY-AS) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | xe-0-0-13-178.gw01.ber01.as59645.net 2a06:d1c1:100:b::1 | 0.3ms | 0%* | AS59645 | WYBT-NET - Tobias Fiebig, DE |
| 2 | ae0-2453.cr10.ber01.lwlcom.net 2a06:d1c0::dead:beef:1c02 | 0.6ms | 0%* | AS59645 | WYBT-NET - Tobias Fiebig, DE |
| 3 | retn.bcix.de 2001:7f8:19:1::232a:1 | 10.4ms | 0% | - | NA |
| 4 | RT.ESH.FKT.DE.retn.net 2a02:2d8::57f5:e0b7 | 10.9ms | 0% | AS9002 | RETN-AS - RETN Limited, GB |
| 5 | GW-AS47147.retn.net 2a02:2d8:3:e001:232a::1 | 11.0ms | 0% | AS9002 | RETN-AS - RETN Limited, GB |
| 6 | 2a00:11c0:47:1:47::146 | 11.1ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 7 | 2a00:11c0:47:1:47::151 | 69.4ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 8 | 2a00:11c0:47:8::75 | 24.7ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 9 | 2a03:e600:100:2::6 | 24.0ms | 0% | AS208323 | APPLIEDPRIVACY-AS - Foundation for Applied Privacy, AT |
tracepath -6
1?: [LOCALHOST] 0.035ms pmtu 1500
1: xe-0-0-13-178.gw01.ber01.as59645.net 0.615ms
1: xe-0-0-13-178.gw01.ber01.as59645.net 0.524ms
2: ae0-2453.cr10.ber01.lwlcom.net 1.085ms
3: retn.bcix.de 10.944ms asymm 5
4: RT.ESH.FKT.DE.retn.net 11.177ms asymm 5
5: GW-AS47147.retn.net 11.193ms asymm 4
6: 2a00:11c0:47:1:47::146 11.355ms asymm 5
7: 2a00:11c0:47:1:47::151 27.844ms asymm 10
8: 2a00:11c0:47:8::75 24.061ms asymm 7
9: 2a03:e600:100:2::6 22.809ms reached
Resume: pmtu 1500 hops 9 back 8 From DE host (Düsseldorf) echo onlyRFC 4890 ✗
filter likely at: past AS47147 (AS-ANX) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | xe-0-0-12-142.gw01.dus01.as59645.net 2a06:d1c1:100:d::1 | 0.2ms | 0%* | AS59645 | WYBT-NET - Tobias Fiebig, DE |
| 2 | eth1-0-12-h5594.edge5-dus1.bb.wiit.network 2001:4ba0:92f4:3::1 | 1.0ms | 0% | AS24961 | MYLOC-AS - WIIT AG, DE |
| 3 | * | - | - | - | |
| 4 | lag11.core3-dus1.bb.wiit.network 2001:4ba0:ffe9:115::3 | 0.3ms | 0% | AS24961 | MYLOC-AS - WIIT AG, DE |
| 5 | lag8.core1-dus-ix.bb.wiit.network 2001:4ba0:ffe9:8::2 | 0.4ms | 0% | AS24961 | MYLOC-AS - WIIT AG, DE |
| 6 | ae3-1337.bbr02.anx25.fra.de.anexia-it.net 2001:7f8::a5e9:0:3 | 4.0ms | 0% | - | NA |
| 7 | 2a00:11c0:47:1:47::148 | 6.9ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 8 | 2a00:11c0:47:1:47::146 | 26.0ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 9 | 2a00:11c0:47:1:47::151 | 21.4ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
tracepath -6
1?: [LOCALHOST] 0.017ms pmtu 1500
1: xe-0-0-12-142.gw01.dus01.as59645.net 0.300ms
1: xe-0-0-12-142.gw01.dus01.as59645.net 0.338ms
2: eth1-0-12-h5594.edge5-dus1.bb.wiit.network 1.112ms
3: no reply
4: lag30.core3-dus1.bb.wiit.network 0.377ms
5: lag2.core1-dus-ix.bb.wiit.network 0.590ms
6: de-cix.r60.inx.fra.de.nextlayer.net 3.964ms
7: 2a00:11c0:47:1:47::143 10.184ms
8: 2a00:11c0:47:1:47::146 5.164ms asymm 4
9: 2a03:e600:100:2::6 22.594ms reached
Resume: pmtu 1500 hops 9 back 11 From NL host (go6lab) openRFC 4890 ✓
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | 2a00:8642:42::2 | 2.1ms | 0% | AS203993 | GNA-DC1-AS - S.J.M. Steffann, NL |
| 2 | gw.friends.steffann.nl 2a00:8642:1000:f000::1 | 2.0ms | 0%* | AS203993 | GNA-DC1-AS - S.J.M. Steffann, NL |
| 3 | ccr2-ccr1.dc1.nogalliance.org 2a00:8642:dc1:2::b | 1.6ms | 0% | AS203993 | GNA-DC1-AS - S.J.M. Steffann, NL |
| 4 | ae3-1337.bbr02.anx63.ams.nl.anexia-it.net 2001:7f8:1::a504:7147:1 | 6.8ms | 0% | - | NA |
| 5 | 2a00:11c0:47:1:47::213 | 25.8ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 6 | 2a00:11c0:47:1:47::136 | 28.0ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 7 | 2a00:11c0:47:1:47::130 | 30.5ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 8 | 2a00:11c0:47:1:47::128 | 38.5ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 9 | 2a00:11c0:47:8::75 | 28.4ms | 0% | AS47147 | AS-ANX - Anexia Cloud Solutions GmbH, AT |
| 10 | 2a03:e600:100:2::6 | 21.8ms | 0% | AS208323 | APPLIEDPRIVACY-AS - Foundation for Applied Privacy, AT |
tracepath -6
1?: [LOCALHOST] 0.030ms pmtu 1500
1: 2a00:8642:42::2 1.863ms
1: 2a00:8642:42::2 1.594ms
2: gw.friends.steffann.nl 2.967ms
3: ccr2-ccr1.dc1.nogalliance.org 5.521ms asymm 2
4: ae3-1337.bbr02.anx63.ams.nl.anexia-it.net 7.478ms asymm 5
5: 2a00:11c0:47:1:47::156 9.364ms asymm 6
6: 2a00:11c0:47:1:47::136 31.165ms asymm 11
7: 2a00:11c0:47:1:47::130 30.746ms asymm 11
8: 2a00:11c0:47:1:47::135 33.254ms asymm 12
9: 2a00:11c0:47:8::75 34.151ms asymm 13
10: 2a03:e600:100:2::6 23.019ms reached
Resume: pmtu 1500 hops 10 back 14 From ITA host (Karsolink) openRFC 4890 ✓
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | * | - | 0%* | - | |
| 2 | * | - | 0%* | - | |
| 3 | 2a12:d8c0:101f:6::1 | 9.8ms | 30% | AS204471 | KARSOLINK - 2S Computers SRL, IT |
| 4 | * | - | - | - | |
| 5 | be47.core1.mil2.he.net 2001:470:e:69::2 | 11.9ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 6 | be1.core1.zrh2.he.net 2001:470:e:dd::2 | 15.4ms | 20% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 7 | * | - | - | - | |
| 8 | be1.core3.zrh3.he.net 2001:470:0:7e0::2 | 16.3ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 9 | * | - | - | - | |
| 10 | ip6-ae1-0-r01.fern.vie.nextlayer.net 2a01:190:1764:5c::2 | 21.2ms | 0% | AS1764 | NEXTLAYER-AS - Next Layer Telekommunikationsdienstleistungs- und Beratungs GmbH, AT |
| 11 | 2a01:190:15ff:5f::2 | 31.1ms | 0% | AS1764 | NEXTLAYER-AS - Next Layer Telekommunikationsdienstleistungs- und Beratungs GmbH, AT |
| 12 | 2a03:e600:100:2::6 | 30.7ms | 0% | AS208323 | APPLIEDPRIVACY-AS - Foundation for Applied Privacy, AT |
Rate-limited ICMPv6: hop 3, hop 6 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).
tracepath -6
1?: [LOCALHOST] 0.028ms pmtu 1500
1: no reply
2: no reply
3: 2a12:d8c0:101f:6::1 10.357ms
4: no reply
5: be47.core1.mil2.he.net 11.725ms
6: be1.core1.zrh2.he.net 15.923ms
7: no reply
8: be1.core3.zrh3.he.net 15.759ms
9: no reply
10: ip6-ae1-0-r01.fern.vie.nextlayer.net 20.964ms asymm 12
11: 2a01:190:15ff:5f::2 33.238ms
12: 2a03:e600:100:2::6 30.091ms reached
Resume: pmtu 1500 hops 12 back 12 From SLO host (6connect) openRFC 4890 ✓
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | fw1-lju.6connect.com 2607:fae0:a000::2 | 0.3ms | 0%* | AS8038 | 6CONNECT - 6connect, Inc., US |
| 2 | * | - | - | - | |
| 3 | * | - | 70% | - | |
| 4 | 2a00:ee0:1:10::2 | 1.1ms | 0% | AS5603 | SIOL-NET - Telekom Slovenije, d.d., SI |
| 5 | de-cix.r60.inx.fra.de.nextlayer.net 2001:7f8::6e4:0:1 | 15.5ms | 0% | - | NA |
| 6 | ip6-ae1-0-r01.fern.vie.nextlayer.net 2a01:190:1764:5c::2 | 15.9ms | 0% | AS1764 | NEXTLAYER-AS - Next Layer Telekommunikationsdienstleistungs- und Beratungs GmbH, AT |
| 7 | 2a01:190:15ff:5f::2 | 16.1ms | 0% | AS1764 | NEXTLAYER-AS - Next Layer Telekommunikationsdienstleistungs- und Beratungs GmbH, AT |
| 8 | 2a03:e600:100:2::6 | 16.8ms | 0% | AS208323 | APPLIEDPRIVACY-AS - Foundation for Applied Privacy, AT |
Rate-limited ICMPv6: hop 3 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).
tracepath -6
1?: [LOCALHOST] 0.025ms pmtu 9000
1: fw1-lju.6connect.com 0.644ms
1: fw1-lju.6connect.com 0.479ms
2: no reply
3: 2a00:ee1:800:9::1 2.414ms
4: 2a00:ee0:1:15::2 1.404ms asymm 3
5: 2a00:ee0:1:10::2 1.506ms pmtu 1500
5: de-cix.r60.inx.fra.de.nextlayer.net 15.915ms asymm 6
6: ip6-ae1-0-r01.fern.vie.nextlayer.net 16.629ms asymm 11
7: 2a01:190:15ff:5f::2 17.095ms asymm 10
8: 2a03:e600:100:2::6 16.826ms reached
Resume: pmtu 1500 hops 8 back 12 From SLO host (T-2) openRFC 4890 ✓
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | * | - | 0%* | - | |
| 2 | 2a01:260:1::225 | 2.8ms | 0%* | AS34779 | T-2-AS - T-2, d.o.o., SI |
| 3 | 2a01-260-1-1--9c.core6.t-2.net 2a01:260:1:1::9c | 2.2ms | 0%* | AS34779 | T-2-AS - T-2, d.o.o., SI |
| 4 | 2a01-260-1-1--38.core6.t-2.net 2a01:260:1:1::38 | 2.1ms | 0%* | AS34779 | T-2-AS - T-2, d.o.o., SI |
| 5 | vix-ip6-et-0-1-2-0-r60.esh.vie.at.nextlayer.net @VIX / AAIX / SAIX / TIROL-IX / ERA-IX 2001:7f8:30:0:1:1:0:1764 | 9.3ms | 0% | - | NA |
| 6 | vix-ip6-et-0-1-2-0-r60.esh.vie.at.nextlayer.net @VIX / AAIX / SAIX / TIROL-IX / ERA-IX 2001:7f8:30:0:1:1:0:1764 | 11.7ms | 0% | - | NA |
| 7 | 2a01:190:15ff:5f::2 | 10.4ms | 0% | AS1764 | NEXTLAYER-AS - Next Layer Telekommunikationsdienstleistungs- und Beratungs GmbH, AT |
| 8 | 2a03:e600:100:2::6 | 18.5ms | 0% | AS208323 | APPLIEDPRIVACY-AS - Foundation for Applied Privacy, AT |
tracepath -6
1?: [LOCALHOST] 0.022ms pmtu 1500
1: no reply
2: 2a01:260:1::225 3.510ms
3: 2a01-260-1-1--9a.core6.t-2.net 2.692ms
4: 2a01-260-1-1--38.core6.t-2.net 2.074ms asymm 3
5: vix-ip6-et-0-1-2-0-r60.esh.vie.at.nextlayer.net 8.725ms
6: vix-ip6-et-0-1-2-0-r60.esh.vie.at.nextlayer.net 8.615ms asymm 5
7: 2a01:190:15ff:5f::2 10.182ms
8: 2a01:190:15ff:5f::2 13.957ms asymm 7
9: 2a03:e600:100:2::6 23.335ms reached
Resume: pmtu 1500 hops 9 back 8