AS21309 - CASAWEB-AS HERABITPARFC 4890 ✓RPKI ✓ 1/1ASPA -

← back to summary

All countriesHomeState of IPv6TopologyIXPsAboutipv6.si ↗ Sparky

AS overview

Test target: 2a03:c380:4010:0:213:174:160:2 · ns3.acantho.net · address space: PA · prefixes announced: 1

prefix(es): 2a03:c380::/32

Targets & per-vantage-point probe results (1 target(s) across 3 vantage point(s))

Source codes (hover any badge for full description): CUR=curated · NS/SOA/MX=DNS records · SPF=SPF TXT · DRV=holder-derived (www, ns1, mail, gw, …) · ATL=RIPE Atlas · PDB=PeeringDB · WHOIS=RIPE whois · RDAP=RIPE RDAP · HIT=IPv6 Hitlist · RTR=in-prefix path hop (router) · PRB=static prefix probe · SYN=synthetic prefix::1 fallback

Target IP / hostnameSourceNL host (go6lab)ITA host (Karsolink)SLO host (6connect)
ping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reached
2a03:c380:4010:0:213:174:160:2
ns3.acantho.net
NS??-??-??-

MIX-IT / NAMEX / MINAP / TOP-IX / VSIX / EQUINIX-MILAN / BGPX-ROME / NAMEX-BARI / PCIX / DECIX-PALERMO peering

MIX-IT / NAMEX / MINAP / TOP-IX / VSIX / EQUINIX-MILAN / BGPX-ROME / NAMEX-BARI / PCIX / DECIX-PALERMO member - Open peering, peering member, since 2013-05-20. IPv6 LAN: 2001:7f8:b:100:1d1:a5d2:1309:84. Locations: -.

RPKI & ASPA

1 of 1 prefix(es) covered by a valid ROA.

PrefixRPKI stateReasonCovering VRP(s)
2a03:c380::/32✓ validmatched VRP (correct origin, length within maxLength)AS21309 /32 maxLen 32 (ripe)

Random-IP probe (yarrp) into the AS' prefixes

We probed 14 arbitrary IPv6 address(es) inside AS21309's announced prefix(es). No router inside the prefix responded. The deepest visible hop was 2a02:2d8:4:180f:232a::1 at hop 13 - that router answers ICMPv6 Echo. This is not in AS21309's announced prefix; operationally it's the AS-edge / peering interface (often on an IXP peering address or an upstream's /127 link). The traceroute boundary is the AS edge: ICMPv6 Time-Exceeded responses from anything inside this AS are filtered.

ICMPv6 Type 2 (Packet Too Big) acceptance - active test

Vantage points disagree about Type 2 acceptance - transit ASes on one path may be filtering Type 2 even though the destination's stack accepts it on another path:

Why they disagree - reachability mismatch: One vantage couldn't drive a flow at all to this destination (no Echo Reply or no responding TCP port), so the active test had no behavioural change to observe. The other vantage's verdict is the only meaningful one here.

Failure detail — what to grep in your logs
vantageour sourceyour targetmethodresulttested (UTC)
go6lab2a00:8642:42::752a03:c380:4010:0:213:174:160:2icmp6-echohonored2026-05-30T12:44:59Z
karsolink2a12:d8c0:105a:9001::a1542a03:c380:4010:0:213:174:160:2icmp6-echono_echo2026-05-30T12:52:40Z
odin2607:fae0:a000::422a03:c380:4010:0:213:174:160:2icmp6-echohonored2026-05-30T12:44:44Z

Attempt log (go6lab):

  1. icmp6-echohonored (size_before=1460, size_after=None)
  2. dns-tcpinconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (karsolink):

  1. icmp6-echono_echo: no Echo Reply to 1300-byte probe
  2. dns-tcpinconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (odin):

  1. icmp6-echohonored (size_before=1460, size_after=None)
  2. dns-tcpinconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

To match the corresponding ICMPv6 packet on your side (host firewall, AS edge, or transit tap), look for our PTBs around the timestamps above:

sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a12:d8c0:105a:9001::a154)'

If you see our PTBs arriving but the destination's TCP/Echo flow does not shrink, the drop is in the destination kernel (cause 3 below). If you don't see them at all, drop is upstream of you (cause 2). If you only see them from one of our two source IPs, the drop is path-asymmetric — one transit on the asymmetric route is filtering, the other is not.

From NL host (go6lab)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 32.2ms
4/4
Echo 1500B (DF) 32.4ms
no
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
12a00:8642:42::31.2ms0%AS203993STEFFANN-DC-AS - S.J.M. Steffann, NL
2*-0%*-
32a00:1ca8:1::1942.5ms0%AS50673Serverius-as - Serverius Holding B.V., NL
42a03:3f40::10:411.9ms0%AS50673Serverius-as - Serverius Holding B.V., NL
5*-90%-
6*-80%-
7be3343.ccr41.fra05.atlas.cogentco.com
2001:550:0:1000::9a36:3e8d
11.9ms0%AS174COGENT-174 - Cogent Communications, LLC, US
8*---
9port-channel5891.ccr91.mil02.atlas.cogentco.com
2001:550:0:1000::9a36:3db5
26.7ms0%AS174COGENT-174 - Cogent Communications, LLC, US
10be2155.rcr71.vce01.atlas.cogentco.com
2001:550:0:1000::9a36:2612
30.0ms0%AS174COGENT-174 - Cogent Communications, LLC, US
11be9705.rcr61.blq01.atlas.cogentco.com
2001:550:0:1000::9a36:38ba
31.5ms0%AS174COGENT-174 - Cogent Communications, LLC, US
122001:978:2:51::230.2ms0%AS174COGENT-174 - Cogent Communications, LLC, US
13GW-AS21309.retn.net
2a02:2d8:4:180f:232a::1
33.6ms0%AS9002RETN-AS - RETN Limited, GB
14*---
15*---
16*---
17*---
18*---
19*-0%-
20*---
21*---
22*---
23*---
24*---

Rate-limited ICMPv6: hop 5, hop 6 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.045ms pmtu 1500
 1:  2a00:8642:42::3                                       2.427ms 
 1:  2a00:8642:42::3                                       1.953ms 
 2:  gw.friends.steffann.nl                                3.225ms 
 3:  2a00:1ca8:1::194                                      3.250ms 
 4:  2a03:3f40::10:41                                      3.464ms 
 5:  no reply
 6:  no reply
 7:  be3343.ccr41.fra05.atlas.cogentco.com                11.941ms 
 8:  no reply
 9:  port-channel5892.ccr92.mil02.atlas.cogentco.com      25.686ms 
10:  be2434.rcr71.vce01.atlas.cogentco.com                30.301ms 
11:  be9705.rcr61.blq01.atlas.cogentco.com                31.417ms 
12:  2001:978:2:51::2                                     29.930ms asymm  8 
13:  GW-AS21309.retn.net                                  34.506ms asymm  7 
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500 

From ITA host (Karsolink)   open

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 17.0ms
4/4
Echo 1500B (DF) 17.0ms
no
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1*---
2*-0%*-
3*-70%-
4acantho-v6.mix-it.net @MIX-IT / NAMEX / MINAP / TOP-IX / VSIX / EQUINIX-MILAN / BGPX-ROME / NAMEX-BARI / PCIX / DECIX-PALERMO
2001:7f8:b:100:1d1:a5d2:1309:84
13.2ms0%-NA
5*---
6*---
7*---
8*---
9*---
10*-0%-
11*---
12*---
13*---
14*---
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

Rate-limited ICMPv6: hop 3 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.065ms pmtu 1500
 1:  karsolink-01.net.karsolink.com                        0.977ms 
 2:  2a12:d8c0:109f:121::a1                                0.964ms 
 3:  2a12:d8c0:101f:103::1                                 9.002ms 
 4:  acantho-v6.mix-it.net                                14.054ms 
 5:  no reply
 6:  no reply
 7:  no reply
 8:  no reply
 9:  no reply
10:  no reply
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500 

From SLO host (6connect)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 18.9ms
4/4
Echo 1500B (DF) 18.8ms
no
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1fw1-lju.6connect.com
2607:fae0:a000::2
0.2ms0%*AS80386CONNECT - 6connect, Inc., US
2*---
3*---
4*-90%-
5*---
6port-channel1.core1.zag2.he.net
2001:470:0:2ea::2
3.7ms60%AS6939HURRICANE - Hurricane Electric LLC, US
7*---
8*---
9*---
10*---
11*---
12*---
13*---
14*-0%-
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

Rate-limited ICMPv6: hop 4, hop 6 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.051ms pmtu 1500
 1:  fw1-lju.6connect.com                                  1.248ms 
 1:  fw1-lju.6connect.com                                  0.656ms 
 2:  no reply
 3:  no reply
 4:  e0-1.core1.lju1.he.net                                4.142ms 
 5:  no reply
 6:  port-channel1.core1.zag2.he.net                       5.288ms 
 7:  no reply
 8:  no reply
 9:  no reply
10:  no reply
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500