[j-nsp] PFE-forwarded IPv6

Truman Boyes truman at suspicious.org
Tue Dec 22 21:25:23 EST 2009


Hi,

Have you enabled the tunnel-services statement at the [ edit chassis fpc slot-number pic pic-number] stanza?

Otherwise the ipip.0 tunnel is only from the RE, which can't forward transit traffic. 

Truman


On 23/12/2009, at 8:47 AM, Jonathan Lassoff wrote:

> Excerpts from Truman Boyes's message of Tue Dec 22 04:17:22 -0800 2009:
>> Can you post the relevant configuration from the box? I expect that the host is
>> directly connect to the MX-960; and the interface that is facing the host is
>> running RA; furthermore if you look at the routing table on the host, you will
>> see a default route to the MX's link-local address?
> 
> Actually, I was testing with a Cisco Cat6k/Sup720 box downstream to test
> the interoperability of the two routers, and also IPv6 on the Cat6k.
> 
> As a test to better understand what's going on, I attached a host
> downstream from the MX960. I can ping and reach the MX's inet6 interface
> just fine. I'm also setting my default route to go through the inet6
> interface on the MX.  Pinging out to 2001:500:2f::f (f.root-servers.net)
> through this interface causes the MX to return an ICMPv6 Unreachable
> (Address unreachable) message.
> 
> However, there's a route on the MX to that destination:
> 
> --------------------------------------------------------------------------
> jof at mx1.sfo2-re0> show route 2001:500:2f::f 
> 
> inet6.0: 2299 destinations, 2302 routes (2299 active, 0 holddown, 0 hidden)
> + = Active Route, - = Last Active, * = Both
> 
> 2001:500:2f::/48   *[BGP/170] 1w3d 20:24:53, localpref 100
>                      AS path: xxxx xxxxx 3557 I
>> to xxxx:xxx:xxxx:xx::1 via ipip.0
> --------------------------------------------------------------------------
> 
> Here's the relevant configuration of interface "ipip":
> --------------------------------------------------------------------------
> jof at mx1.sfo2-re0> show configuration interfaces ipip 
> unit 0 {
>    tunnel {
>        source xxx.xxx.xxx.xxx;
>        destination xxx.xxx.xxx.xxx;
>    }
>    family inet6 {
>        address 2001:xxx:xxxx:xx::2/64;
>    }
> }
> --------------------------------------------------------------------------
> 
> Thanks for any help or insight you can provide.
> 
> Cheers,
> jonathan
> 



More information about the juniper-nsp mailing list