AS56911 - ASN-WARIAN Warian S.R.LRFC 4890 ✓RPKI ✓ 13/13ASPA -

← back to summary

All countriesHomeState of IPv6TopologyIXPsAboutipv6.si ↗ Sparky

AS overview

Test target: 2a01:a620:2:a::a0 · ns11.warian.net · address space: unknown · prefixes announced: 13

prefix(es): 2a01:a620:4::/48, 2a01:a620:5::/48, 2a0a:7300:3000::/36, 2a0a:7300:1000::/36, 2a06:5bc0::/32, 2a01:a620:3::/48, 2a01:a620:2::/48, 2a07:b2c0::/32 (+5 more)

Targets & per-vantage-point probe results (3 target(s) across 3 vantage point(s))

Source codes (hover any badge for full description): CUR=curated · NS/SOA/MX=DNS records · SPF=SPF TXT · DRV=holder-derived (www, ns1, mail, gw, …) · ATL=RIPE Atlas · PDB=PeeringDB · WHOIS=RIPE whois · RDAP=RIPE RDAP · HIT=IPv6 Hitlist · RTR=in-prefix path hop (router) · PRB=static prefix probe · SYN=synthetic prefix::1 fallback

Target IP / hostnameSourceNL host (go6lab)ITA host (Karsolink)SLO host (6connect)
ping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reached
2a01:a620:2:a::a0
ns11.warian.net
NSopenopen-openopen-openopen-
2a01:a620:2:a::a2
ns12.warian.net
NSopenopen-openopen-openopen-
2a01:a620:3:b::ff
ns3.warian.net
NS??????

MIX-IT / NAMEX / MINAP / TOP-IX / VSIX / EQUINIX-MILAN / BGPX-ROME / NAMEX-BARI / PCIX / DECIX-PALERMO peering

MIX-IT / NAMEX / MINAP / TOP-IX / VSIX / EQUINIX-MILAN / BGPX-ROME / NAMEX-BARI / PCIX / DECIX-PALERMO member - Open peering, peering member, since 2018-02-20. IPv6 LAN: 2001:7f8:b:100:1d1:a5d5:6911:226. Locations: -.

RPKI & ASPA

13 of 13 prefix(es) covered by a valid ROA.

PrefixRPKI stateReasonCovering VRP(s)
2a01:a620:4::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)
2a01:a620:5::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)
2a0a:7300:3000::/36✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 36 (ripe)
2a0a:7300:1000::/36✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 36 (ripe)
2a06:5bc0::/32✓ validmatched VRP (correct origin, length within maxLength)AS56911 /29 maxLen 34 (ripe); AS215830 /29 maxLen 48 (ripe)
2a01:a620:3::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)
2a01:a620:2::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)
2a07:b2c0::/32✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 32 (ripe)
2a01:a620:6::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)
2a0a:7300:2000::/36✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 36 (ripe)
2a01:a620:9::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)
2a01:a620:7::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)
2a01:a620:1::/48✓ validmatched VRP (correct origin, length within maxLength)AS56911 /32 maxLen 48 (ripe)

Random-IP probe (yarrp) into the AS' prefixes

At least one router inside AS56911's announced prefix replied during the random-target probe. Hop(s): 2a01:a620:4:1::. These are candidate targets for direct testing.

ICMPv6 Type 2 (Packet Too Big) acceptance - active test

Vantage points disagree about Type 2 acceptance - transit ASes on one path may be filtering Type 2 even though the destination's stack accepts it on another path:

Why they disagree - different probe methods: These vantages picked different probe methods, so their verdicts are not directly comparable. The active test tries methods in order (icmp6-echodns-tcptlshttp) and stops at the first that produces a definitive verdict; if the chosen method differs, the underlying evidence differs too. Most often this is because the path PMTU on one vantage is below 1500 B, so the natural Echo Reply is already fragmented and the icmp6-echo method falls through to a TCP-based one. This is largely a measurement artifact, not a destination-behaviour difference.

Failure detail — what to grep in your logs
vantageour sourceyour targetmethodresulttested (UTC)
go6lab2a00:8642:42::752a01:a620:2:a::a0icmp6-echohonored2026-05-30T12:43:30Z
karsolink2a12:d8c0:105a:9001::a1542a01:a620:2:a::a0tlspartial2026-05-30T12:48:16Z
odin2607:fae0:a000::422a01:a620:2:a::a0icmp6-echohonored2026-05-30T12:43:20Z

Attempt log (go6lab):

  1. icmp6-echohonored (size_before=1460, size_after=None)
  2. dns-tcpinconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrink
  3. tlsnot_honored (size_before=3159, size_after=3159)
  4. httpinconclusive (size_before=295, size_after=None): natural max segment 295B already <= 1220B; nothing to shrink

Attempt log (karsolink):

  1. icmp6-echono_echo: no Echo Reply to 1300-byte probe
  2. dns-tcpinconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrink
  3. tlspartial (size_before=3159, size_after=1428)
  4. httpinconclusive (size_before=295, size_after=None): natural max segment 295B already <= 1220B; nothing to shrink

Attempt log (odin):

  1. icmp6-echohonored (size_before=1460, size_after=None)
  2. dns-tcpinconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrink
  3. tlspartial (size_before=2856, size_after=1731)
  4. httpinconclusive (size_before=295, size_after=None): natural max segment 295B already <= 1220B; nothing to shrink

To match the corresponding ICMPv6 packet on your side (host firewall, AS edge, or transit tap), look for our PTBs around the timestamps above:

sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a12:d8c0:105a:9001::a154)'

If you see our PTBs arriving but the destination's TCP/Echo flow does not shrink, the drop is in the destination kernel (cause 3 below). If you don't see them at all, drop is upstream of you (cause 2). If you only see them from one of our two source IPs, the drop is path-asymmetric — one transit on the asymmetric route is filtering, the other is not.

Where the path divergence is

Mixed disagreement. At least one pair of vantages used the same probe method and disagreed (real Type 2 asymmetry); other pairs used different methods (probe-availability noise). The path-divergence summary below covers all pairs; the AI interpretation focuses on the real cases.

Per-vantage probe + verdict (headline):

Full per-method matrix (all four methods run at each vantage):

vantageicmp6-echodns-tcptlshttp
go6labhonoredinconclusivenot_honoredinconclusive
karsolinkno_echoinconclusivepartialinconclusive
odinhonoredinconclusivepartialinconclusive

✓ All vantages agree on method(s): icmp6-echo — the headline-method spread above is dispatcher noise, not a real Type 2 disagreement.

These vantage-level disagreements are rooted somewhere in the forward paths. Joining each per-vantage traceroute against the IP→AS lookup from our global yarrp mesh, the first hop where the paths land in different ASes is the most likely site of the offending filter / unreachable AS / Type 2 drop.

Suspect transit ASes (ranked by how often they appear at the divergence point on the path of the worse-classifying vantage): AS56911, AS6939.

Diagnosis is path-level, not packet-level: it tells you which transit AS is the prime suspect, not exactly which firewall rule is to blame. Use the tracepath6 output below (when available) for per-hop PMTU evidence on the same path.

Diagnostic interpretation

An operator-targeted diagnostic interpretation can be generated for this AS on demand. The pipeline holds the raw verdicts and the per-hop walk; an AI pass synthesises where to start looking. Click the button below to run it.

Per-hop PTB acceptance walk

From the local vantage, we walk the forward path hop-by-hop, sending each hop a 1500-byte ICMPv6 Echo, then a forged PTB (MTU=1280) sourced from us, then another 1500-byte Echo. If the second reply arrives fragmented or smaller, that hop honoured the PTB. If unchanged, it didn't. The first ✗ in an otherwise-✓ path is the most likely filter location. Cross-country aggregation: see the global PTB filter atlas for transit ASes ranked by filter rate across all measurements.

#hop IPASHolderPTB acceptance
12607:fae0:a000::2AS80386CONNECT - 6connect, Inc., US- skipped (CoPP)
22607:fae0:a000:2::2AS80386CONNECT - 6connect, Inc., US- skipped (CoPP)
32a03:a100:0:201:1::1AS56635XENYA - XENYA inzeniring, proizvodnja in✓ honored
42001:470:1:5be::1AS6939HURRICANE - Hurricane Electric LLC, US? no_response
5*-- (no IP)
62001:470:0:2ea::2AS6939HURRICANE - Hurricane Electric LLC, US? no_response
7*-- (no IP)
82001:7f8:c0::5:6911:1-NA? no_response
92a01:a620:2:1-- (invalid IP)
102a01:a620:2:1::221AS56911ASN-WARIAN - Warian S.R.L., IT? no_response
11*-- (no IP)
12*-- (no IP)
13*-- (no IP)
14*-- (no IP)
15*-- (no IP)
16*-- (no IP)
17*-- (no IP)
18*-- (no IP)
19*-- (no IP)
20*-- (no IP)
21*-- (no IP)
22*-- (no IP)
23*-- (no IP)
24*-- (no IP)

Tests host-mode PTB acceptance (PTBs aimed at the hop itself). A router that honours PTBs to itself can still be filtering PTBs transiting through it; this is one indicator, not proof of full PTB transparency. Hops in CoPP-rate-limit ranges are skipped to avoid false signals.

tracepath6 per-hop PMTU drilldown

For each target where Type 2 verdicts disagreed across vantages, tracepath -6 ran from every vantage to capture per-hop PMTU evolution along that vantage's actual forward path. A pmtu change entry on a hop means that hop's router generated a PTB and we observed the shrink; absence of any change combined with a not_honored verdict suggests a router somewhere downstream is silently dropping >MTU packets (an RFC 4890 violation) rather than sending a PTB.

Target 2a01:a620:2:a::a2

go6lab — verdict honored

verdict = honored; final pmtu = 1500

#hop IPpmtu change
1<span class='muted'>no reply</span>
22a00:8642:1000:f000::1
3<span class='muted'>no reply</span>
42a01:a620:2:1::
52a01:a620:2:1::221
6<span class='muted'>no reply</span>
7<span class='muted'>no reply</span>
8<span class='muted'>no reply</span>
9<span class='muted'>no reply</span>
10<span class='muted'>no reply</span>
11<span class='muted'>no reply</span>
12<span class='muted'>no reply</span>
13<span class='muted'>no reply</span>
14<span class='muted'>no reply</span>
15<span class='muted'>no reply</span>
16<span class='muted'>no reply</span>
17<span class='muted'>no reply</span>
18<span class='muted'>no reply</span>
19<span class='muted'>no reply</span>
20<span class='muted'>no reply</span>
21<span class='muted'>no reply</span>
22<span class='muted'>no reply</span>
23<span class='muted'>no reply</span>
24<span class='muted'>no reply</span>
karsolink — verdict not_honored

verdict = not_honored; final pmtu = 1500

#hop IPpmtu change
1<span class='muted'>no reply</span>
22a12:d8c0:109f:121::a1
32a12:d8c0:101f:6::1
42001:7f8:c5::a505:6911:1
52a01:a620:2:1::
62a01:a620:2:1::221
7<span class='muted'>no reply</span>
8<span class='muted'>no reply</span>
9<span class='muted'>no reply</span>
10<span class='muted'>no reply</span>
11<span class='muted'>no reply</span>
12<span class='muted'>no reply</span>
13<span class='muted'>no reply</span>
14<span class='muted'>no reply</span>
15<span class='muted'>no reply</span>
16<span class='muted'>no reply</span>
17<span class='muted'>no reply</span>
18<span class='muted'>no reply</span>
19<span class='muted'>no reply</span>
20<span class='muted'>no reply</span>
21<span class='muted'>no reply</span>
22<span class='muted'>no reply</span>
23<span class='muted'>no reply</span>
24<span class='muted'>no reply</span>
odin — verdict honored

verdict = honored; final pmtu = 1500

#hop IPpmtu change
1<span class='muted'>no reply</span>
22607:fae0:a000:2::2
32a03:a100:0:201:1::1
42001:470:1:5be::1
5<span class='muted'>no reply</span>
62001:470:0:2ea::2
7<span class='muted'>no reply</span>
82001:7f8:b:100:1d1:a5d5:6911:226
92a01:a620:2:1::
102a01:a620:2:1::221
11<span class='muted'>no reply</span>
12<span class='muted'>no reply</span>
13<span class='muted'>no reply</span>
14<span class='muted'>no reply</span>
15<span class='muted'>no reply</span>
16<span class='muted'>no reply</span>
17<span class='muted'>no reply</span>
18<span class='muted'>no reply</span>
19<span class='muted'>no reply</span>
20<span class='muted'>no reply</span>
21<span class='muted'>no reply</span>
22<span class='muted'>no reply</span>
23<span class='muted'>no reply</span>
24<span class='muted'>no reply</span>

From NL host (go6lab)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 32.8ms
4/4
Echo 1500B (DF) 32.9ms
no
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
12a00:8642:42::31.7ms0%AS203993STEFFANN-DC-AS - S.J.M. Steffann, NL
2*-0%*-
3*---
42a01:a620:2:129.7ms0%-
52a01:a620:2:1::22141.1ms0%AS56911ASN-WARIAN - Warian S.R.L., IT
6*-0%-
7*---
8*---
9*---
10*---
11*---
12*---
13*---
14*---
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

tracepath -6

 1?: [LOCALHOST]                        0.056ms pmtu 1500
 1:  2a00:8642:42::3                                       1.376ms 
 1:  2a00:8642:42::3                                       1.360ms 
 2:  gw.friends.steffann.nl                                2.849ms 
 3:  no reply
 4:  2a01:a620:2:1::                                      30.477ms asymm 15 
 5:  2a01:a620:2:1::221                                   41.665ms asymm 16 
 6:  no reply
 7:  no reply
 8:  no reply
 9:  no reply
10:  no reply
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500 

From ITA host (Karsolink)   open

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 18.0ms
4/4
Echo 1500B (DF) 17.9ms
no
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1*-0%*-
22a12:d8c0:109f:121::a10.4ms0%*AS204471KARSOLINK - 2S Computers SRL, IT
32a12:d8c0:101f:6::19.9ms20%AS204471KARSOLINK - 2S Computers SRL, IT
4warian.minap.it
2001:7f8:c5::a505:6911:1
9.2ms0%AS56911Warian s.r.l.
52a01:a620:2:120.0ms0%-
62a01:a620:2:1::22117.7ms0%AS56911ASN-WARIAN - Warian S.R.L., IT
7*-0%-
8*---
9*---
10*---
11*---
12*---
13*---
14*---
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

Rate-limited ICMPv6: hop 3 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.029ms pmtu 1500
 1:  karsolink-01.net.karsolink.com                        0.812ms 
 2:  2a12:d8c0:109f:121::a1                                0.910ms 
 3:  2a12:d8c0:101f:6::1                                  10.511ms 
 4:  warian.minap.it                                       9.885ms asymm  6 
 5:  2a01:a620:2:1::                                      18.486ms asymm  7 
 6:  2a01:a620:2:1::221                                   18.252ms asymm  8 
 7:  no reply
 8:  no reply
 9:  no reply
10:  no reply
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500 

From SLO host (6connect)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 20.9ms
4/4
Echo 1500B (DF) 20.9ms
no
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1fw1-lju.6connect.com
2607:fae0:a000::2
0.3ms0%*AS80386CONNECT - 6connect, Inc., US
2ccr-to-fw-ccr1-gw-lju.6connect.com
2607:fae0:a000:2::2
0.5ms0%*AS80386CONNECT - 6connect, Inc., US
32a03:a100:0:201:1::10.7ms50%AS56635XENYA - XENYA inzeniring, proizvodnja in trgovina, d.o.o. Ljubljana, SI
4e0-1.core1.lju1.he.net
2001:470:1:5be::1
1.8ms10%AS6939HURRICANE - Hurricane Electric LLC, US
5*---
6port-channel1.core1.zag2.he.net
2001:470:0:2ea::2
3.9ms0%AS6939HURRICANE - Hurricane Electric LLC, US
7*---
82001:7f8:c0::5:6911:112.1ms0%-NA
92a01:a620:2:120.9ms0%-
102a01:a620:2:1::22120.7ms0%AS56911ASN-WARIAN - Warian S.R.L., IT
11*-0%-
12*---
13*---
14*---
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

Rate-limited ICMPv6: hop 3, hop 4 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.037ms pmtu 1500
 1:  fw1-lju.6connect.com                                  1.064ms 
 1:  fw1-lju.6connect.com                                  0.416ms 
 2:  no reply
 3:  2a03:a100:0:201:1::1                                  0.843ms 
 4:  e0-1.core1.lju1.he.net                                1.732ms 
 5:  no reply
 6:  port-channel1.core1.zag2.he.net                       3.966ms 
 7:  no reply
 8:  warian-v6.mix-it.net                                 12.266ms 
 9:  2a01:a620:2:1::                                      21.117ms 
10:  2a01:a620:2:1::221                                   21.064ms 
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500