New pTLA /32 and prefix-list

Nicolas DEFFAYET nicolas.deffayet-extml@ndsoftwaregroup.com
Fri, 5 Apr 2002 19:30:36 +0200


Hello all,

I remind you: new pTLA are now /32 in 3ffe:4000::/18 (check mailing-list
archives for more informations about this).

Many peoples have forgot the creation of this new pTLA format (/32) for
all new pTLA request and don't have updated the prefix-list of their
routers because new pTLAs (TELEPAC and ANSNET for the moment) aren't
annonced and/or accessible on a lot of of network...

TELEPAC don't annonce their pTLA but ASNET annonce it in good conditions
from external.
I have do all my tests with ANSNET's pTLA (3ffe:4001::/32)

parcr2.fr.fastnetxp.net> traceroute6 3ffe:4001::
traceroute6 to 3ffe:4001:: (3ffe:4001::) from 3ffe:8271:201:2100::2, 30
hops max, 12 byte packets
 1  tun100-0-parcr1  81.213 ms  70.85 ms  76.991 ms
 2  lavanet-gw-parcr1  351.365 ms  400.334 ms  327.774 ms
 3  * * *
 4  * * *
parcr2.fr.fastnetxp.net> show ipv6 3ffe:4001::/32

<cut other neighbors of this second router>

  6435 9264
    3ffe:8271:201:2100::1 from 3ffe:8271:201:2100::1 (213.91.4.3)
    (fe80::d55b:403)
      Origin IGP, localpref 100, valid, internal, best
      Last update: Thu Apr  4 23:46:00 2002
parcr2.fr.fastnetxp.net> 

I have try many public traceroute6 gateway and looking-glass, a lot of
people have the same problem.
Don't forget to update your access-list if you filter bgp routes !!!

You can use this prefix-list for accept only valid pTLA, subTLA and
6to4:

!
ipv6 prefix-list peering-full-in permit 3ffe::/18 ge 24 le 24
ipv6 prefix-list peering-full-in permit 3ffe:4000::/18 ge 32 le 32
ipv6 prefix-list peering-full-in permit 3ffe:8000::/17 ge 28 le 28
ipv6 prefix-list peering-full-in permit 2001::/16 ge 35 le 35
ipv6 prefix-list peering-full-in permit 2002::/16
ipv6 prefix-list peering-full-in deny 0::/0
!

Personnal stats:

On 26 full bgp peering on parcr1.fr.fastnetxp.net:
14 peers (50%) annonces me the new (/32) pTLA !
26 peers (100%) annonces me the old (/24 and /28) pTLA
And a annonces can be good but a router after can filter...

I wait your comments....

Think to new pTLA !


Best Regards,

Nicolas DEFFAYET