AS42700 - Realis Informacijske tehnologijePIRFC 4890 ✓RPKI ✓ 1/1ASPA -

← back to summary

All countriesHomeState of IPv6TopologySIXAboutipv6.si ↗ Sparky

AS overview

Test target: 2001:678:1ec::1 · static prefix probe · address space: PI · prefixes announced: 1

prefix(es): 2001:678:1ec::/48

Targets & per-vantage-point probe results (1 target(s) across 3 vantage point(s))

Source codes (hover any badge for full description): CUR=curated · NS/SOA/MX=DNS records · SPF=SPF TXT · DRV=holder-derived (www, ns1, mail, gw, …) · ATL=RIPE Atlas · PDB=PeeringDB · WHOIS=RIPE whois · RDAP=RIPE RDAP · HIT=IPv6 Hitlist · RTR=in-prefix path hop (router) · PRB=static prefix probe · SYN=synthetic prefix::1 fallback

Target IP / hostnameSourceNL host (go6lab)ITA host (Karsolink)SLO host (6connect)
ping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reached
2001:678:1ec::1prb??-refusedrefused-refusedrefused-

SIX peering

Not an SIX member, but our traceroute path crosses the SIX LAN from SLO host (6connect) - reached via an SIX-resident transit operator.

RPKI & ASPA

1 of 1 prefix(es) covered by a valid ROA.

PrefixRPKI stateReasonCovering VRP(s)
2001:678:1ec::/48✓ validmatched VRP (correct origin, length within maxLength)AS42700 /48 maxLen 48 (ripe)

Random-IP probe (yarrp) into the AS' prefixes

We probed 15 arbitrary IPv6 address(es) inside AS42700's announced prefix(es). No router inside the prefix responded. The deepest visible hop was 2a02:800:e:2009::2 at hop 10 - that router answers ICMPv6 Echo. This is not in AS42700's announced prefix; operationally it's the AS-edge / peering interface (often on a SIX peering address or an upstream's /127 link). The traceroute boundary is the AS edge: ICMPv6 Time-Exceeded responses from anything inside this AS are filtered.

ICMPv6 Type 2 (Packet Too Big) acceptance - active test

Vantage points disagree about Type 2 acceptance - transit ASes on one path may be filtering Type 2 even though the destination's stack accepts it on another path:

Why they disagree - reachability mismatch: One vantage couldn't drive a flow at all to this destination (no Echo Reply or no responding TCP port), so the active test had no behavioural change to observe. The other vantage's verdict is the only meaningful one here.

Failure detail — what to grep in your logs
vantageour sourceyour targetmethodresulttested (UTC)
go6lab2a00:8642:42::752001:678:1ec::1icmp6-echohonored2026-05-30T10:30:43Z
karsolink2a12:d8c0:105a:9001::a1542001:678:1ec::1icmp6-echono_echo2026-05-30T10:31:34Z
odin2607:fae0:a000::422001:678:1ec::1icmp6-echohonored2026-05-30T10:30:41Z

Attempt log (go6lab):

  1. icmp6-echohonored (size_before=1460, size_after=None)
  2. dns-tcpno_tcp: connect failed: timed out
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (karsolink):

  1. icmp6-echono_echo: no Echo Reply to 1300-byte probe
  2. dns-tcpno_tcp: connect failed: [Errno 111] Connection refused
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (odin):

  1. icmp6-echohonored (size_before=1460, size_after=None)
  2. dns-tcpno_tcp: connect failed: [Errno 111] Connection refused
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

To match the corresponding ICMPv6 packet on your side (host firewall, AS edge, or transit tap), look for our PTBs around the timestamps above:

sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a12:d8c0:105a:9001::a154)'

If you see our PTBs arriving but the destination's TCP/Echo flow does not shrink, the drop is in the destination kernel (cause 3 below). If you don't see them at all, drop is upstream of you (cause 2). If you only see them from one of our two source IPs, the drop is path-asymmetric — one transit on the asymmetric route is filtering, the other is not.

Where the path divergence is

Per-vantage probe + verdict (headline):

Full per-method matrix (all four methods run at each vantage):

vantageicmp6-echodns-tcptlshttp
go6labhonoredno_tcpno_tcpno_tcp
karsolinkno_echono_tcpno_tcpno_tcp
odinhonoredno_tcpno_tcpno_tcp

✓ All vantages agree on method(s): icmp6-echo — the headline-method spread above is dispatcher noise, not a real Type 2 disagreement.

These vantage-level disagreements are rooted somewhere in the forward paths. Joining each per-vantage traceroute against the IP→AS lookup from our global yarrp mesh, the first hop where the paths land in different ASes is the most likely site of the offending filter / unreachable AS / Type 2 drop.

Suspect transit ASes (ranked by how often they appear at the divergence point on the path of the worse-classifying vantage): AS50673, AS56635.

Diagnosis is path-level, not packet-level: it tells you which transit AS is the prime suspect, not exactly which firewall rule is to blame. Use the tracepath6 output below (when available) for per-hop PMTU evidence on the same path.

Diagnostic interpretation

An operator-targeted diagnostic interpretation can be generated for this AS on demand. The pipeline holds the raw verdicts and the per-hop walk; an AI pass synthesises where to start looking. Click the button below to run it.

Per-hop PTB acceptance walk

From the local vantage, we walk the forward path hop-by-hop, sending each hop a 1500-byte ICMPv6 Echo, then a forged PTB (MTU=1280) sourced from us, then another 1500-byte Echo. If the second reply arrives fragmented or smaller, that hop honoured the PTB. If unchanged, it didn't. The first ✗ in an otherwise-✓ path is the most likely filter location. Cross-country aggregation: see the global PTB filter atlas for transit ASes ranked by filter rate across all measurements.

#hop IPASHolderPTB acceptance
12607:fae0:a000::2AS80386CONNECT - 6connect, Inc., US- skipped (CoPP)
2*-- (no IP)
32a03:a100:0:201:1::1AS56635XENYA - XENYA inzeniring, proizvodnja in✓ honored
42001:7f8:46::3:4779AS34779T-2✓ honored
52a01:260:1:1::93AS34779T-2-AS - T-2, d.o.o., SI? no_response
62a01:260:4042::2AS34779T-2-AS - T-2, d.o.o., SI? no_response

Tests host-mode PTB acceptance (PTBs aimed at the hop itself). A router that honours PTBs to itself can still be filtering PTBs transiting through it; this is one indicator, not proof of full PTB transparency. Hops in CoPP-rate-limit ranges are skipped to avoid false signals.

From NL host (go6lab)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 55.9ms
4/4
Echo 1500B (DF) 48.1ms
yes
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
12a00:8642:42::32.6ms0%AS203993STEFFANN-DC-AS - S.J.M. Steffann, NL
2*-0%*-
32a00:1ca8:1::1942.2ms0%AS50673Serverius-as - Serverius Holding B.V., NL
42a03:3f40::10:334.8ms0%AS50673Serverius-as - Serverius Holding B.V., NL
5t-2.interxionfra11.nlsix.net
2001:7f8:13::a503:4779:1
33.7ms0%-NA
62a01-260-1-1--95.core6.t-2.net
2a01:260:1:1::95
38.3ms0%AS34779T-2-AS - T-2, d.o.o., SI
72a01-260-4042--2.link6.t-2.net
2a01:260:4042::2
38.6ms0%AS34779T-2-AS - T-2, d.o.o., SI

tracepath -6

 1?: [LOCALHOST]                        0.030ms pmtu 1500
 1:  2a00:8642:42::3                                       3.348ms 
 1:  2a00:8642:42::3                                       1.902ms 
 2:  no reply
 3:  2a00:1ca8:1::194                                      3.160ms 
 4:  2a03:3f40::10:33                                      6.057ms 
 5:  t-2.interxionfra11.nlsix.net                         36.004ms asymm  6 
 6:  2a01-260-1-1--95.core6.t-2.net                       36.206ms asymm  7 
 7:  2a01-260-4042--2.link6.t-2.net                       38.686ms reached
     Resume: pmtu 1500 hops 7 back 8 

From ITA host (Karsolink)   open

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 29.0ms
4/4
Echo 1500B (DF) 26.7ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1*-0%*-
2*---
3*---
4*---
5*---
6*---
7decix.softnet.si
2001:7f8::239f:0:1
20.7ms--NA
8sn-lju-hu-0-1-0-0-81-slo.ntwk.softnet.si
2a02:800:1:6000::1
26.7ms-AS9119SOFTNET-AS - SOFTNET d.o.o., SI
92a02:800:e:2009::226.6ms0%AS9119SOFTNET-AS - SOFTNET d.o.o., SI

tracepath -6

 1?: [LOCALHOST]                        0.028ms pmtu 1500
 1:  karsolink-01.net.karsolink.com                        1.150ms 
 2:  no reply
 3:  2a12:d8c0:101f:6::1                                  10.292ms 
 4:  no reply
 5:  no reply
 6:  no reply
 7:  decix.softnet.si                                     21.308ms 
 8:  sn-lju-hu-0-1-0-0-81-slo.ntwk.softnet.si             27.095ms 
 9:  2a02:800:e:2009::2                                   27.472ms reached
     Resume: pmtu 1500 hops 9 back 9 

From SLO host (6connect)   openRFC 4890 ✓

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 2.2ms
4/4
Echo 1500B (DF) 2.4ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1fw1-lju.6connect.com
2607:fae0:a000::2
1.1ms0%*AS80386CONNECT - 6connect, Inc., US
2*---
32a03:a100:0:201:1::130.9ms-AS56635XENYA - XENYA inzeniring, proizvodnja in trgovina, d.o.o. Ljubljana, SI
4six.t-2.si @SIX
2001:7f8:46::3:4779
1.2ms0%AS34779T-2
52a01-260-1-1--93.core6.t-2.net
2a01:260:1:1::93
1.4ms0%AS34779T-2-AS - T-2, d.o.o., SI
62a01-260-4042--2.link6.t-2.net
2a01:260:4042::2
1.7ms0%AS34779T-2-AS - T-2, d.o.o., SI

tracepath -6

 1?: [LOCALHOST]                        0.045ms pmtu 1500
 1:  fw1-lju.6connect.com                                  0.551ms 
 1:  fw1-lju.6connect.com                                  0.392ms 
 2:  no reply
 3:  2a03:a100:0:201:1::1                                  2.383ms 
 4:  six.t-2.si                                            1.095ms 
 5:  2a02:800:e:2009::2                                    1.517ms reached
     Resume: pmtu 1500 hops 5 back 5