AS overview
Test target: 2a02:28b0:53::53 · dns1.siel.si · address space: mixed · prefixes announced: 4
prefix(es): 2a02:28b0::/32, 2a02:28b1::/32, 2a02:28b2::/32, 2a02:28b7::/32
Targets & per-vantage-point probe results (10 target(s) across 3 vantage point(s))
Source codes (hover any badge for full description): CUR=curated · NS/SOA/MX=DNS records · SPF=SPF TXT · DRV=holder-derived (www, ns1, mail, gw, …) · ATL=RIPE Atlas · PDB=PeeringDB · WHOIS=RIPE whois · RDAP=RIPE RDAP · HIT=IPv6 Hitlist · RTR=in-prefix path hop (router) · PRB=static prefix probe · SYN=synthetic prefix::1 fallback
| Target IP / hostname | Source | NL host (go6lab) | ITA host (Karsolink) | SLO host (6connect) | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ping | 1500B | :80 | :443 | reached | ||
2a02:28b0:101:1299::1 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:1299::2 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | - | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:1499::1 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:1499::2 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:1699::1 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:1699::2 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:1::1 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:247::1 | hit | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:101:800::1 | rtr | ✓ | ✓ | ? | ? | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
2a02:28b0:53::53dns1.siel.si | NS | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ | ✓ | ✓ | refused | refused | ✓ |
SIX peering
SIX member - open peering, peering member, since 2015-05-05. IPv6 LAN: 2001:7f8:46:0:0::5:1790. Locations: lj_ijs, lj_tpl.
- rs1-lan1-ipv6 →
2001:7f8:46::5:1790Established (loc: lj_ijs, since 2026-05-23) - rs1-lan1-ipv6 →
2001:7f8:46:0:1:0:5:1790Established (loc: lj_tpl, since 2026-05-13) - rs2-lan1-ipv6 →
2001:7f8:46::5:1790Established (loc: lj_ijs, since 2026-05-12) - rs2-lan1-ipv6 →
2001:7f8:46:0:1:0:5:1790Established (loc: lj_tpl, since 2026-05-12)
Announces via SIX route servers: 5 prefix(es) - 2a02:28b0::/32, 2a02:28b1::/32, 2a02:28b7::/32, 2a04:dd40::/32, 2a0e:ce40::/32
RPKI & ASPA
4 of 4 prefix(es) covered by a valid ROA.
| Prefix | RPKI state | Reason | Covering VRP(s) |
|---|---|---|---|
2a02:28b1::/32 | ✓ valid | matched VRP (correct origin, length within maxLength) | AS51790 /32 maxLen 32 (ripe) |
2a02:28b0::/32 | ✓ valid | matched VRP (correct origin, length within maxLength) | AS51790 /32 maxLen 32 (ripe) |
2a02:28b7::/32 | ✓ valid | matched VRP (correct origin, length within maxLength) | AS51790 /32 maxLen 32 (ripe) |
2a02:28b2::/32 | ✓ valid | matched VRP (correct origin, length within maxLength) | AS51790 /32 maxLen 32 (ripe) |
Random-IP probe (yarrp) into the AS' prefixes
At least one router inside AS51790's announced prefix replied during the random-target probe. Hop(s): 2a02:28b0:101:1499::1, 2a02:28b0:101:1699::2, 2a02:28b0:101:3::1, 2a02:28b0:101:800::1, 2a02:28b0:101:823::1. These are candidate targets for direct testing.
ICMPv6 Type 2 (Packet Too Big) acceptance - active test
Vantage points disagree about Type 2 acceptance - transit ASes on one path may be filtering Type 2 even though the destination's stack accepts it on another path:
- NL host (go6lab): Type 2 honored. Forged PTB accepted; next response shrunk. (ICMPv6 Echo + forged PTB)
- ITA host (Karsolink): inconclusive: no Echo Reply to 1300-byte probe. (ICMPv6 Echo + forged PTB)
- SLO host (6connect): Type 2 honored. Forged PTB accepted; next response shrunk. (ICMPv6 Echo + forged PTB)
Why they disagree - reachability mismatch: One vantage couldn't drive a flow at all to this destination (no Echo Reply or no responding TCP port), so the active test had no behavioural change to observe. The other vantage's verdict is the only meaningful one here.
Failure detail — what to grep in your logs
| vantage | our source | your target | method | result | tested (UTC) |
|---|---|---|---|---|---|
| go6lab | 2a00:8642:42::75 | 2a02:28b0:53::53 | icmp6-echo | honored | 2026-05-30T10:34:08Z |
| karsolink | 2a12:d8c0:105a:9001::a154 | 2a02:28b0:53::53 | icmp6-echo | no_echo | 2026-05-30T10:41:48Z |
| odin | 2607:fae0:a000::42 | 2a02:28b0:53::53 | icmp6-echo | honored | 2026-05-30T10:33:56Z |
Attempt log (go6lab):
icmp6-echo→ honored (size_before=1460, size_after=None)dns-tcp→ inconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrinktls→ no_tcp: TLS connect failedhttp→ no_tcp: tcp/80 not open
Attempt log (karsolink):
icmp6-echo→ no_echo: no Echo Reply to 1300-byte probedns-tcp→ inconclusive (size_before=156, size_after=None): max DNS-over-TCP segment 156B; not big enough to test PMTU shrinktls→ no_tcp: TLS connect failedhttp→ no_tcp: tcp/80 not open
Attempt log (odin):
icmp6-echo→ honored (size_before=1460, size_after=None)dns-tcp→ inconclusive (size_before=128, size_after=None): max DNS-over-TCP segment 128B; not big enough to test PMTU shrinktls→ no_tcp: TLS connect failedhttp→ no_tcp: tcp/80 not open
To match the corresponding ICMPv6 packet on your side (host firewall, AS edge, or transit tap), look for our PTBs around the timestamps above:
sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a12:d8c0:105a:9001::a154)'
If you see our PTBs arriving but the destination's TCP/Echo flow does not shrink, the drop is in the destination kernel (cause 3 below). If you don't see them at all, drop is upstream of you (cause 2). If you only see them from one of our two source IPs, the drop is path-asymmetric — one transit on the asymmetric route is filtering, the other is not.
Where the path divergence is
Per-vantage probe + verdict (headline):
- go6lab: probe
icmp6-echo→ verdicthonored - karsolink: probe
icmp6-echo→ verdictno_echo - odin: probe
icmp6-echo→ verdicthonored
Full per-method matrix (all four methods run at each vantage):
| vantage | icmp6-echo | dns-tcp | tls | http |
|---|---|---|---|---|
| go6lab | honored | inconclusive | no_tcp | no_tcp |
| karsolink | no_echo | inconclusive | no_tcp | no_tcp |
| odin | honored | inconclusive | no_tcp | no_tcp |
✓ All vantages agree on method(s): icmp6-echo — the headline-method spread above is dispatcher noise, not a real Type 2 disagreement.
These vantage-level disagreements are rooted somewhere in the forward paths. Joining each per-vantage traceroute against the IP→AS lookup from our global yarrp mesh, the first hop where the paths land in different ASes is the most likely site of the offending filter / unreachable AS / Type 2 drop.
Suspect transit ASes (ranked by how often they appear at the divergence point on the path of the worse-classifying vantage): AS6939, AS51790.
- From go6lab (open/Type-2=honored) the path enters AS6939 at hop 6; from karsolink (open/Type-2=no_echo) the same hop is in an opaque hop. Last common AS: AS51790. The disagreement is most likely rooted in one of those two transit ASes.
- From go6lab (open/Type-2=honored) the path enters AS6939 at hop 5; from odin (open/Type-2=honored) the same hop is in AS51790. Last common AS: AS51790. The disagreement is most likely rooted in one of those two transit ASes.
- From karsolink (open/Type-2=no_echo) the path enters AS6939 at hop 5; from odin (open/Type-2=honored) the same hop is in AS51790. Last common AS: AS51790. The disagreement is most likely rooted in one of those two transit ASes.
Diagnosis is path-level, not packet-level: it tells you which transit AS is the prime suspect, not exactly which firewall rule is to blame. Use the tracepath6 output below (when available) for per-hop PMTU evidence on the same path.
✨ Diagnostic interpretation
Per-hop PTB acceptance walk
From the local vantage, we walk the forward path hop-by-hop, sending each hop a 1500-byte ICMPv6 Echo, then a forged PTB (MTU=1280) sourced from us, then another 1500-byte Echo. If the second reply arrives fragmented or smaller, that hop honoured the PTB. If unchanged, it didn't. The first ✗ in an otherwise-✓ path is the most likely filter location. Cross-country aggregation: see the global PTB filter atlas for transit ASes ranked by filter rate across all measurements.
| # | hop IP | AS | Holder | PTB acceptance |
|---|---|---|---|---|
| 1 | 2607:fae0:a000::2 | AS8038 | 6CONNECT - 6connect, Inc., US | - skipped (CoPP) |
| 2 | * | - | - (no IP) | |
| 3 | * | - | - (no IP) | |
| 4 | 2001:7f8:46::5:1790 | AS51988 | ARNES-SIX - ARNES, SI | ? no_response |
| 5 | 2a02:28b0:101:824::1 | AS51790 | SIEL - SIEL, d.o.o., SI | ? no_response |
| 6 | 2a02:28b0:101:823::1 | AS51790 | SIEL - SIEL, d.o.o., SI | ? no_response |
| 7 | 2a02:28b0:101:3::1 | AS51790 | SIEL - SIEL, d.o.o., SI | ? no_response |
| 8 | 2a02:28b0:53::53 | AS51790 | SIEL - SIEL, d.o.o., SI | ? no_response |
Tests host-mode PTB acceptance (PTBs aimed at the hop itself). A router that honours PTBs to itself can still be filtering PTBs transiting through it; this is one indicator, not proof of full PTB transparency. Hops in CoPP-rate-limit ranges are skipped to avoid false signals.
From NL host (go6lab) openRFC 4890 ✓
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | 2a00:8642:42::3 | 0.8ms | 0% | AS203993 | STEFFANN-DC-AS - S.J.M. Steffann, NL |
| 2 | gw.friends.steffann.nl 2a00:8642:1000:f000::1 | 1.9ms | 0%* | AS203993 | STEFFANN-DC-AS - S.J.M. Steffann, NL |
| 3 | * | - | - | - | |
| 4 | be1.core3.ams1.he.net 2001:470:e:5e::1 | 4.4ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 5 | be2.core4.fra1.he.net 2001:470:e:38::2 | 10.9ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 6 | be3.core2.fra2.he.net 2001:470:e:5a::1 | 11.5ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 7 | e0-33.core2.muc1.he.net 2001:470:0:2ef::2 | 14.5ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 8 | 100ge0-0-0-23.core1.vie1.he.net 2001:470:0:41d::1 | 20.9ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 9 | e0-36.core1.lju1.he.net 2001:470:0:578::2 | 26.4ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 10 | 2a02:28b0:101:800::1 | 29.9ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
| 11 | 2a02:28b0:101:866::1 | 29.2ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
| 12 | 2a02:28b0:101:825::1 | 37.8ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
| 13 | dns1.siel.si 2a02:28b0:53::53 | 24.2ms | - | AS51790 | SIEL - SIEL, d.o.o., SI |
tracepath -6
1?: [LOCALHOST] 0.072ms pmtu 1500
1: 2a00:8642:42::3 1.311ms
1: 2a00:8642:42::3 1.905ms
2: gw.friends.steffann.nl 2.649ms
3: no reply
4: be1.core3.ams1.he.net 7.698ms
5: be2.core4.fra1.he.net 12.493ms
6: be3.core2.fra2.he.net 10.333ms
7: e0-33.core2.muc1.he.net 15.121ms
8: e0-36.core1.lju1.he.net 26.370ms
9: e0-36.core1.lju1.he.net 25.611ms asymm 8
10: 2a02:28b0:101:800::1 27.767ms
11: dns1.siel.si 24.914ms reached
Resume: pmtu 1500 hops 11 back 12 From ITA host (Karsolink) open
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | * | - | - | - | |
| 2 | * | - | 0%* | - | |
| 3 | * | - | - | - | |
| 4 | * | - | - | - | |
| 5 | e0-35.core1.zag2.he.net 2001:470:0:6ea::2 | 19.2ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 6 | * | - | - | - | |
| 7 | e0-35.core1.lju1.he.net 2001:470:0:577::2 | 21.7ms | 0% | AS6939 | HURRICANE - Hurricane Electric LLC, US |
| 8 | six2.siel.si @SIX 2001:7f8:46:0:1:0:5:1790 | 21.2ms | 0% | AS51988 | ARNES-SIX - ARNES, SI |
| 9 | 2a02:28b0:101:800::1 | 20.9ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
| 10 | dns1.siel.si 2a02:28b0:53::53 | 20.6ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
tracepath -6
1?: [LOCALHOST] 0.030ms pmtu 1500
1: no reply
2: 2a12:d8c0:109f:121::a1 1.142ms
3: 2a12:d8c0:101f:6::1 10.631ms
4: no reply
5: e0-35.core1.zag2.he.net 19.600ms
6: no reply
7: e0-35.core1.lju1.he.net 22.467ms
8: six2.siel.si 21.570ms
9: 2a02:28b0:101:866::1 24.275ms asymm 10
10: 2a02:28b0:101:825::1 34.755ms
11: dns1.siel.si 21.001ms reached
Resume: pmtu 1500 hops 11 back 11 From SLO host (6connect) openRFC 4890 ✓
filter likely at: (none) · min PMTU on path: 1500
Path (traceroute + mtr + PTR)
| # | IP / PTR | RTT | mtr loss | AS | AS holder |
|---|---|---|---|---|---|
| 1 | fw1-lju.6connect.com 2607:fae0:a000::2 | 0.3ms | 0%* | AS8038 | 6CONNECT - 6connect, Inc., US |
| 2 | * | - | - | - | |
| 3 | * | - | - | - | |
| 4 | 2001:7f8:46::5:1790 @SIX | 1.0ms | 0% | AS51988 | ARNES-SIX - ARNES, SI |
| 5 | 2a02:28b0:101:824::1 | 3.6ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
| 6 | 2a02:28b0:101:823::1 | 8.9ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
| 7 | 2a02:28b0:101:3::1 | 5.6ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
| 8 | dns1.siel.si 2a02:28b0:53::53 | 1.8ms | 0% | AS51790 | SIEL - SIEL, d.o.o., SI |
tracepath -6
1?: [LOCALHOST] 0.032ms pmtu 1500
1: fw1-lju.6connect.com 0.516ms
1: fw1-lju.6connect.com 0.377ms
2: no reply
3: no reply
4: 2001:7f8:46::5:1790 1.365ms asymm 5
5: 2a02:28b0:101:824::1 41.032ms asymm 6
6: 2a02:28b0:101:823::1 7.538ms asymm 7
7: 2a02:28b0:101:3::1 8.371ms asymm 6
8: dns1.siel.si 1.287ms reached
Resume: pmtu 1500 hops 8 back 7