[16093] in SIPB IPv6
Re: packages.debian.org unreachable via IPv6
daemon@ATHENA.MIT.EDU (Greg Troxel)
Mon Mar 23 08:11:38 2009
X-Barracuda-Envelope-From: gdt@work.lexort.com
From: Greg Troxel <gdt@work.lexort.com>
To: Quentin Smith <quentin@MIT.EDU>
Cc: sipbv6@MIT.EDU
In-Reply-To: <alpine.DEB.1.10.0903221503000.1549@vinegar-pot.mit.edu> (Quentin
Smith's message of "Sun, 22 Mar 2009 15:05:14 -0400 (EDT)")
Date: Mon, 23 Mar 2009 08:11:23 -0400
Quentin Smith <quentin@MIT.EDU> writes:
> I'm unable to reach packages.debian.org (2001:8d8:81:1520::1) from
> SIPBv6 service on 64-NET. The traceroute to the machine dies somewhere
> on or after occaid in London, but the reverse traceroute (see below)
> dies after reaching 2001:4830:2446:ee::1, which is assigned to us. It
> seems like we're probably dropping reply packets that get onto our
> network; can someone who has bits please investigate this?
At bbn I have a tunnel from sixxs, and the tunnel has been up but
routing messed up over the weekend. It got better around 0600 today
said nagios. During the weekend, packets to my bbn sixxs tunnel address
from MIT were delivered, and I have a shortcut tunnel bbn-mit so pings
worked. But pinging MIT's occaid address from BBN did not work, and
ftp.netbsd.org was also unreachable.
This morning I can reach MIT's occaid address, netbsd and
packages.debian.org from BBN.
From MIT (18.62) I can reach everything I've tried except
packages.debian.org.
So what is darkenergy?
linuxpal gdt 7 ~ > traceroute6 2001:4830:2446:ee::1
traceroute6 to 2001:4830:2446:ee::1 (2001:4830:2446:ee::1) from 2001:4830:2446:3e::10e, 64 hops max, 12 byte packets
1 2001:4830:2446:3e::1 0.328 ms 0.265 ms 0.258 ms
2 limekiller.ipv6.mit.edu 1.083 ms 0.833 ms 0.864 ms
3 darkenergy.ipv6.mit.edu 1.26 ms 1.173 ms 1.135 ms
Traceroute6 from ftp.netbsd.org to 18.62 shows
2001:4830:e1:8::2
which is apparently limekiller's end of the mit-occaid tunnel but it has
a bogus PTR record.
From netbsd I get to ee::1 via limekiller
traceroute6 to 2001:4830:2446:ee::1 (2001:4830:2446:ee::1) from 2001:4f8:4:7:230:48ff:fe31:43f2, 64 hops max, 12 byte packets
1 2001:4f8:4:7:20b:60ff:fea1:9c1b 0.855 ms 0.629 ms 0.716 ms
2 2001:4f8:0:4::3 5.488 ms 5.191 ms 4.907 ms
3 2001:4f8:4:b:2d0:b7ff:fee1:4d0f 1.485 ms 1.548 ms 1.489 ms
4 2001:4830:ff:1202::2 12.643 ms 12.846 ms 12.508 ms
5 2001:4830:ff:11ab::1 14.459 ms 13.964 ms 14.234 ms
6 2001:4830:ff:e100::1 15.076 ms 14.978 ms 15.463 ms
7 2001:4830:ff:e101::2 60.946 ms 64.892 ms 59.692 ms
8 2001:4830:ff:1100::2 109.69 ms 111.925 ms 106.623 ms
9 2001:4830:ff:f150::1 114.079 ms 113.733 ms 113.346 ms
10 2001:4830:ff:15c4::2 126.353 ms 120.225 ms 119.973 ms
11 2001:4830:e1:8::2 121.983 ms 122.218 ms 121.964 ms
12 2001:4830:2446:ee::1 120.848 ms 121.537 ms 122.667 ms
And apparently you are too.
Are you on 18.238.0.0/16 ?
Whose machine is darkenergy? Is it running ripng?
I see a route to it from sunpal7
sunpal7 gdt 3 ~ > ns6|egrep 2001:4830
2001:4830::/32 fe80::a00:20ff:feb0:93b4%gif0 UG1 0 10 - gif0
2001:4830:e1:8::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
2001:4830:100::/40 fe80::a00:20ff:feb0:93b4%gif0 UG1 0 0 - gif0
2001:4830:1600::/40 fe80::a00:20ff:feb0:93b4%gif0 UG1 0 0 - gif0
2001:4830:2441::/48 fe80::a00:20ff:feb0:93b4%gif0 UG1 0 0 - gif0
2001:4830:2446:12::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
2001:4830:2446:3e::/64 link#1 UC 36 0 - hme0
2001:4830:2446:b5::/64 fe80::a00:20ff:feb0:93b4%gif0 UG1 0 0 - gif0
2001:4830:2446:b5::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 1 31399 - gif0
2001:4830:2446:bb::/64 fe80::a00:20ff:feb0:93b4%gif0 UG1 0 0 - gif0
2001:4830:2446:d6::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
2001:4830:2446:ee::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
2001:4830:2446:f3::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
2001:4830:2446:fd00::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
2001:4830:2446:fe30::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
2001:4830:2446:fe60::/64 fe80::250:daff:fe9a:15e7%gif2 UG1 0 49 - gif2
2001:4830:2446:ff00::1 fe80::a00:20ff:feb0:93b4%gif0 UGH1 0 0 - gif0
but I am not seeing a route for the /64, just the host.
sunpal7 gdt 5 ~ > traceroute6 2001:4830:2446:ee:21b:63ff:febb:8c64
traceroute6 to 2001:4830:2446:ee:21b:63ff:febb:8c64 (2001:4830:2446:ee:21b:63ff:febb:8c64) from 2001:4830:2446:3e::6a9, 64 hops max, 12 byte packets
1 limekiller.ipv6.mit.edu 1.027 ms 0.806 ms 0.8 ms
2 darkenergy.ipv6.mit.edu 1.105 ms 1.229 ms 1.087 ms
3 darkenergy.ipv6.mit.edu 3003.29 ms !H 3006.01 ms !H 3007.98 ms !H
We are perhaps still in the middle of moving to ripng. My opinion is
that tunnels to stub subnets (those subnets that have no beyond-MIT-AS
tunnels) should be configured with just link-local addresses on both
sides, and should run ripngd.
So, I think your problem is unrelated to the global routing table mess and is about darkenergy's config.