AS212405 - Kristjan KomlosiRFC 4890 ✓RPKI -ASPA -

← back to summary

All countriesHomeState of IPv6TopologySIXAboutipv6.si ↗ Sparky

AS overview

Test target: 2a07:22c1:31::4 · via IPv6 Hitlist (responsive) · address space: unknown · prefixes announced: 1

prefix(es): 2a07:22c1:31::/48

Targets & per-vantage-point probe results (2 target(s) across 3 vantage point(s))

Source codes (hover any badge for full description): CUR=curated · NS/SOA/MX=DNS records · SPF=SPF TXT · DRV=holder-derived (www, ns1, mail, gw, …) · ATL=RIPE Atlas · PDB=PeeringDB · WHOIS=RIPE whois · RDAP=RIPE RDAP · HIT=IPv6 Hitlist · RTR=in-prefix path hop (router) · PRB=static prefix probe · SYN=synthetic prefix::1 fallback

Target IP / hostnameSourceNL host (go6lab)ITA host (Karsolink)SLO host (6connect)
ping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reached
2a07:22c1:31::1prb??-??-??-
2a07:22c1:31::4hit??-??-??-

RPKI & ASPA

0 of 1 prefix(es) covered by a valid ROA, 1 not-found.

PrefixRPKI stateReasonCovering VRP(s)
2a07:22c1:31::/48- not-foundno covering VRP

Random-IP probe (yarrp) into the AS' prefixes

We probed 15 arbitrary IPv6 address(es) inside AS212405's announced prefix(es). No router inside the prefix responded. The deepest visible hop was 2a0c:9a40:1030::326 at hop 25 - that router answers ICMPv6 Echo. This is not in AS212405's announced prefix; operationally it's the AS-edge / peering interface (often on a SIX peering address or an upstream's /127 link). The traceroute boundary is the AS edge: ICMPv6 Time-Exceeded responses from anything inside this AS are filtered.

ICMPv6 Type 2 (Packet Too Big) acceptance - active test

Vantage points disagree about Type 2 acceptance - transit ASes on one path may be filtering Type 2 even though the destination's stack accepts it on another path:

Why they disagree - measurement artifact: One vantage's probe didn't generate enough data to detect segment shrinkage (natural reply too small, or no second response). The other vantage's verdict is the meaningful one.

Failure detail — what to grep in your logs
vantageour sourceyour targetmethodresulttested (UTC)
go6lab2a00:8642:42::752a07:22c1:31::4icmp6-echohonored2026-05-30T10:35:33Z
karsolink2a12:d8c0:105a:9001::a1542a07:22c1:31::4icmp6-echoinconclusive2026-05-30T10:45:06Z
odin2607:fae0:a000::422a07:22c1:31::4icmp6-echohonored2026-05-30T10:35:09Z

Attempt log (go6lab):

  1. icmp6-echohonored (size_before=1460, size_after=None)
  2. dns-tcpno_tcp: connect failed: timed out
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (karsolink):

  1. icmp6-echoinconclusive (size_before=1460, size_after=None): no Echo Reply after PTB (probe 1500B)
  2. dns-tcpno_tcp: connect failed: timed out
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (odin):

  1. icmp6-echohonored (size_before=1460, size_after=None): natural Echo Reply at 1500B was already split into IPv6 fragments without our PTB intervention -- the destination's stack has a cached path MTU below 1500B from a previously-honored ICMPv6 Type 2, which is itself evidence that this destination honors PTB on this path.
  2. dns-tcpno_tcp: connect failed: timed out
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

To match the corresponding ICMPv6 packet on your side (host firewall, AS edge, or transit tap), look for our PTBs around the timestamps above:

sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a12:d8c0:105a:9001::a154)'

If you see our PTBs arriving but the destination's TCP/Echo flow does not shrink, the drop is in the destination kernel (cause 3 below). If you don't see them at all, drop is upstream of you (cause 2). If you only see them from one of our two source IPs, the drop is path-asymmetric — one transit on the asymmetric route is filtering, the other is not.

Where the path divergence is

Per-vantage probe + verdict (headline):

Full per-method matrix (all four methods run at each vantage):

vantageicmp6-echodns-tcptlshttp
go6labhonoredno_tcpno_tcpno_tcp
karsolinkinconclusiveno_tcpno_tcpno_tcp
odinhonoredno_tcpno_tcpno_tcp

✓ All vantages agree on method(s): icmp6-echo — the headline-method spread above is dispatcher noise, not a real Type 2 disagreement.

These vantage-level disagreements are rooted somewhere in the forward paths. Joining each per-vantage traceroute against the IP→AS lookup from our global yarrp mesh, the first hop where the paths land in different ASes is the most likely site of the offending filter / unreachable AS / Type 2 drop.

Suspect transit ASes (ranked by how often they appear at the divergence point on the path of the worse-classifying vantage): AS34927, AS5603.

Diagnosis is path-level, not packet-level: it tells you which transit AS is the prime suspect, not exactly which firewall rule is to blame. Use the tracepath6 output below (when available) for per-hop PMTU evidence on the same path.

Diagnostic interpretation

An operator-targeted diagnostic interpretation can be generated for this AS on demand. The pipeline holds the raw verdicts and the per-hop walk; an AI pass synthesises where to start looking. Click the button below to run it.

Per-hop PTB acceptance walk

From the local vantage, we walk the forward path hop-by-hop, sending each hop a 1500-byte ICMPv6 Echo, then a forged PTB (MTU=1280) sourced from us, then another 1500-byte Echo. If the second reply arrives fragmented or smaller, that hop honoured the PTB. If unchanged, it didn't. The first ✗ in an otherwise-✓ path is the most likely filter location. Cross-country aggregation: see the global PTB filter atlas for transit ASes ranked by filter rate across all measurements.

First break at hop 3: AS5603 (SIOL-NET - Telekom Slovenije, d.d., SI) -- this is the most likely site of the offending PTB filter. Hop IP: 2a00:ee1:800:9::1.

#hop IPASHolderPTB acceptance
12607:fae0:a000::2AS80386CONNECT - 6connect, Inc., US- skipped (CoPP)
2*-- (no IP)
32a00:ee1:800:9::1AS5603SIOL-NET - Telekom Slovenije, d.d., SI✗ not_honored
42a00:ee0:1:15::2AS5603SIOL-NET - Telekom Slovenije, d.d., SI✗ not_honored
52a0c:9a40:1001::1AS34927iFog-GmbH - iFog GmbH, CH✓ honored
6*-- (no IP)
7*-- (no IP)
8*-- (no IP)
9*-- (no IP)
10*-- (no IP)
11*-- (no IP)
12*-- (no IP)
13*-- (no IP)
14*-- (no IP)
15*-- (no IP)
16*-- (no IP)
17*-- (no IP)
18*-- (no IP)
19*-- (no IP)
20*-- (no IP)
21*-- (no IP)
22*-- (no IP)
23*-- (no IP)
24*-- (no IP)

Tests host-mode PTB acceptance (PTBs aimed at the hop itself). A router that honours PTBs to itself can still be filtering PTBs transiting through it; this is one indicator, not proof of full PTB transparency. Hops in CoPP-rate-limit ranges are skipped to avoid false signals.

From NL host (go6lab)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 10.7ms
4/4
Echo 1500B (DF) 10.9ms
no
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
12a00:8642:42::31.0ms0%AS203993STEFFANN-DC-AS - S.J.M. Steffann, NL
2gw.friends.steffann.nl
2a00:8642:1000:f000::1
2.6ms-AS203993STEFFANN-DC-AS - S.J.M. Steffann, NL
32a0c:9a40:1071::13.6ms0%AS34927iFog-GmbH - iFog GmbH, CH
42a0c:9a40:1001::110.9ms0%AS34927iFog-GmbH - iFog GmbH, CH
5*-0%-
6*---
7*---
8*---
9*---
10*---
11*---
12*---
13*---
14*---
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

tracepath -6

 1?: [LOCALHOST]                        0.033ms pmtu 1500
 1:  2a00:8642:42::3                                       1.520ms 
 1:  2a00:8642:42::3                                       1.087ms 
 2:  gw.friends.steffann.nl                                1.731ms 
 3:  2a0c:9a40:1071::1                                     2.930ms 
 4:  2a0c:9a40:1001::1                                    10.763ms asymm  5 
 5:  no reply
 6:  no reply
 7:  no reply
 8:  no reply
 9:  no reply
10:  no reply
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500 

From ITA host (Karsolink)   open

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 19.1ms
4/4
Echo 1500B (DF) 19.1ms
no
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1karsolink-01.net.karsolink.com
2a12:d8c0:105a:9001::1
0.3ms0%*AS204471KARSOLINK - 2S Computers SRL, IT
2*-0%*-
32a12:d8c0:101f:103::18.5ms0%AS204471KARSOLINK - 2S Computers SRL, IT
4interlink-AS5405.mix-it.net
2001:7f8:b:100:1d1:a5d0:5405:221
8.5ms0%-NA
5r1-zrh1-ch.as5405.net
2a11:4140::25
18.6ms0%AS5405INTERDOTLINK - Inter.link GmbH, DE
6r3-fra1-de.as5405.net
2a11:4140::6
18.4ms0%AS5405INTERDOTLINK - Inter.link GmbH, DE
7r7-fra1-de.as5405.net
2a11:4140::4c
18.4ms0%AS5405INTERDOTLINK - Inter.link GmbH, DE
8r4-fra2-de.as5405.net
2a11:4140::b
18.3ms0%AS5405INTERDOTLINK - Inter.link GmbH, DE
9r2-fra2-de.as5405.net
2a11:4140::9
18.2ms0%AS5405INTERDOTLINK - Inter.link GmbH, DE
102a0c:9a40:1001::118.8ms0%AS34927iFog-GmbH - iFog GmbH, CH
11*-0%-
12*---
13*---
14*---
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

tracepath -6

 1?: [LOCALHOST]                        0.031ms pmtu 1500
 1:  karsolink-01.net.karsolink.com                        0.984ms 
 2:  no reply
 3:  2a12:d8c0:101f:103::1                                 9.018ms 
 4:  interlink-AS5405.mix-it.net                           9.072ms asymm  5 
 5:  r1-zrh1-ch.as5405.net                                19.166ms asymm 14 
 6:  r3-fra1-de.as5405.net                                18.818ms asymm 13 
 7:  r7-fra1-de.as5405.net                                24.175ms asymm 12 
 8:  r4-fra2-de.as5405.net                                18.909ms asymm 11 
 9:  r2-fra2-de.as5405.net                                18.946ms asymm 10 
10:  2a0c:9a40:1001::1                                    19.493ms asymm  6 
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500 

From SLO host (6connect)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 37.4ms
4/4
Echo 1500B (DF) 35.9ms
no
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1fw1-lju.6connect.com
2607:fae0:a000::2
0.3ms0%*AS80386CONNECT - 6connect, Inc., US
2*---
32a00:ee1:800:9::12.1ms40%AS5603SIOL-NET - Telekom Slovenije, d.d., SI
42a00:ee0:1:15::21.0ms0%AS5603SIOL-NET - Telekom Slovenije, d.d., SI
52a0c:9a40:1001::134.0ms10%AS34927iFog-GmbH - iFog GmbH, CH
6*-10%-
7*---
8*---
9*---
10*---
11*---
12*---
13*---
14*---
15*---
16*---
17*---
18*---
19*---
20*---
21*---
22*---
23*---
24*---

Rate-limited ICMPv6: hop 3, hop 5, hop 6 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.026ms pmtu 1500
 1:  fw1-lju.6connect.com                                  0.542ms 
 1:  fw1-lju.6connect.com                                  0.635ms 
 2:  no reply
 3:  2a00:ee1:800:9::1                                     2.578ms 
 4:  2a00:ee0:1:15::2                                      1.481ms asymm  3 
 5:  2a0c:9a40:1001::1                                    34.371ms asymm  9 
 6:  no reply
 7:  no reply
 8:  no reply
 9:  no reply
10:  no reply
11:  no reply
12:  no reply
13:  no reply
14:  no reply
15:  no reply
16:  no reply
17:  no reply
18:  no reply
19:  no reply
20:  no reply
21:  no reply
22:  no reply
23:  no reply
24:  no reply
     Too many hops: pmtu 1500
     Resume: pmtu 1500