09-20-2024 04:18 AM
hi guys
I'm having an issue tuning my IPv6 outbound flows on the ASR1001-X (1Gen) and my struggle is that MTR is now showing the IP address of the router itself or showing the packet loss on the level of 90%. All other hops are fine and at the end my traces reaches the dst. at 3.9ms so all good (10G BTNET FIbre).
The point is that my ACL's are fine, happy to show them if required.
Port-Channel 1 is configured without Service instance just L2 Po1 and then L3 Po1.vlanid.
What am I doing wrong that my IPv6 traffic works perfectly fine just the trace (mtr) ALWAYS shows the GAP (???) iwth 90% PL.
what should I look for? what params should be in (on the Po or L3 Po1.xxx ? or of ACL's plays the role here based on the QFP ?
please advise.
ps. sh ipv6 traff ....
ASRx#sh ipv6 traffic | i encap
4094456 encapsulation failed, 0 no route, 0 too big
09-20-2024 05:15 AM
Can you post show version , configuration of PO1 that including sub inteface (removing any IP and confidential information)
ASRx#sh ipv6 traffic | i encap (post interface full put where this errors on interface ?)
what is other side connected to this ports or port-channle ( do you see other side same errors ?)
09-20-2024 05:40 AM
Thanks for your reply, I will provide all you require just below, please have a look:
ASRx#sh run int Po1
Building configuration...
Current configuration : 105 bytes
!
interface Port-channel1
description L2-LACP
mtu 9216
no ip address
lacp fast-switchover
end
---
interface Port-channel1.xxx
description L3-LACP
encapsulation dot1Q xxx
vrf forwarding XXX
ip address a.b.c.d 255.255.255.0
ip access-group 100 in
ip access-group 100 out
ipv6 address FE80::1 link-local
ipv6 address a.b.c::d/64
ipv6 nd router-preference High
ipv6 verify unicast source reachable-via any
ipv6 traffic-filter IPv6-XX-IN in
ipv6 traffic-filter IPv6-XX-OUT out
ip virtual-reassembly
end
--
ASRx#sh ipv6 traffic
IPv6 statistics:
Rcvd: 303818874 total, 84215465507 total_bytes, 992855 local destination
0 source-routed, 0 truncated, 0 no route
0 format errors, 9068 hop count exceeded
0 bad header, 0 unknown option, 0 bad source
0 unknown protocol, 0 not a router
0 fragments, 0 total reassembled
0 reassembly timeouts, 0 reassembly failures
Sent: 598411259 total, 167380152863 total_bytes
1200915 generated, 597462498 forwarded
0 fragmented into 0 fragments, 0 failed
4094456 encapsulation failed, 0 no route, 0 too big
5 RPF drops, 1487702 RPF suppressed drops
Mcast: 26151 received, 2493904 received bytes
66212 sent, 4767304 sent bytes
ICMP statistics:
Rcvd: 484052 input, 0 checksum errors, 0 too short
0 unknown info type, 0 unknown error type
unreach: 0 routing, 0 admin, 0 neighbor, 0 address, 0 port
0 sa policy, 0 reject route
parameter: 0 error, 0 header, 0 option
0 hopcount expired, 0 reassembly timeout,0 too big
0 bad embedded ipv6
14 echo request, 15 echo reply
0 group query, 0 group report, 0 group reduce
3997 router solicit, 21092 router advert, 0 redirects
192491 neighbor solicit, 266425 neighbor advert
Sent: 267805378 output, 267108794 rate-limited
unreach: 0 routing, 1 admin, 0 neighbor, 1920 address, 0 port
0 sa policy, 0 reject route
parameter: 0 error, 0 header, 0 option
2237 hopcount expired, 0 reassembly timeout,0 too big
25 echo request, 14 echo reply
0 group query, 0 group report, 0 group reduce
0 router solicit, 21105 router advert, 0 redirects
479643 neighbor solicit, 191619 neighbor advert
UDP statistics:
Rcvd: 494892 input, 0 checksum errors, 0 length errors
0 no port, 0 dropped
Sent: 494898 output
TCP statistics:
Rcvd: 13929 input, 0 checksum errors
Sent: 11671 output, 25 retransmitted
---
ASRx#sh ver
Cisco IOS XE Software, Version 17.09.04a
Cisco IOS Software [Cupertino], ASR1000 Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 17.9.4a, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2023 by Cisco Systems, Inc.
Compiled Fri 20-Oct-23 10:56 by mcpre
License Type: Smart License is permanent
License Level: adventerprise
Next reload license Level: adventerprise
The current throughput level is 10000000 kbps
Smart Licensing Status: Smart Licensing Using Policy
cisco ASR1001-X (1NG) processor (revision 1NG) with 3700437K/6147K bytes of memory.
Processor board ID ............................
Router operating mode: Autonomous
6 Gigabit Ethernet interfaces
2 Ten Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
8388608K bytes of physical memory.
6594559K bytes of eUSB flash at bootflash:.
---
hope it is all you asked for, if not - do let me know please
09-20-2024 05:54 AM
one more detail, the 20G LACP link to that ASR Po1 is the Aggregation Interface terminated on Juniper QFX and stats from that interface looks as following (current snap):
Physical interface: ae0, Enabled, Physical link is Up
Interface index: 640, SNMP ifIndex: 613
Description: ---20G---ASRx.Po1.........*
Link-level type: Ethernet, MTU: 9216, Speed: 20Gbps, BPDU Error: None, Ethernet-Switching Error: None, MAC-REWRITE Error: None, Loopback: Disabled, Source filtering: Disabled, Flow control: Enabled,
Minimum links needed: 1, Minimum bandwidth needed: 1bps
Device flags : Present Running
Interface flags: SNMP-Traps Internal: 0x4000
Current address: c0:03:................, Hardware address: c0:03:...............
Last flapped : 2024-08-08 18:39:05 BST (6w0d 19:12 ago)
Input rate : 50112 bps (46 pps)
Output rate : 47064 bps (42 pps)
Logical interface ae0.0 (Index 547) (SNMP ifIndex 614)
Flags: Up SNMP-Traps 0x24024000 Encapsulation: Ethernet-Bridge
Statistics Packets pps Bytes bps
Bundle:
Input : 0 0 0 0
Output: 0 0 0 0
Adaptive Statistics:
Adaptive Adjusts: 0
Adaptive Scans : 0
Adaptive Updates: 0
Protocol eth-switch, MTU: 9216
Flags: Is-Primary, Trunk-Mode
09-20-2024 06:40 AM
no errors on aggregation lacp on QFX (2x10G from ASR). no issues at all but
ASR has on Po1 mtu 9216
ISP ISR 4431 has mtu 1514 but
QFX (core switch) has a port for both, ASR and ISR and
whilst ASR on LACP 2x10G has mtu 9216
ISR (ISP rtr C4431) have no mtu set (fixed) but I believe BT is giving to customer mtu 1514 or 1500 - depending on mux etc. so,
whilst my core QFX has both devices connected and working (ASR and ISR) - having ASR on 20G and ISR on 1G I wonder how should I set it on MTU's - imho it should NOT MATTER but might be wrong.
my lacp between CORE and ASR has 9216 on 2x10G fibre
my single Gig to ISP ISR have no mtu set as it is fibre 1G SFP to SFP link.
any thoughts guys?
09-21-2024 02:03 AM
One more hint whoever is willing to help:
If you guys could please have a look at all this otherwise I have no choice other than rising a TAC case as my IPv4 via the very same device works fab but IPv6 flow is severally interrupted by that ASR which despite utilisation on very basic level dropping more than 70% of the icmpv6 traffic, TCP/UDP works pefectly fine but icmpv6 is massively dropped by the ASR.
Thanks for all your hints/helps in advance.
09-24-2024 12:18 AM
seems not many of you cares here, that's my last reply though. sorry folks but I don't have much time to spare updating that post over and over again and have just one reply from BB so vague it's quite hard to say how useful this forum become.
I know there are some people who'd care more about ASR issues with IPv6 but since 75% ccie's worldwide don't give a monkey frankly about the ipv6 in general here is the result. Nobody cares as not many uses ipv6 na/nd anymore especially when it comes to "just" asr1001-x ...
thanks so many of you for at least reading that post and I hope you won't mind my critisizm here. it's just sad that despite paid consultancy these days you simply cannot share your issues within the community because help may or may not come eventually in a matter of month or two but not really quick enough for those affected.
cheers!
09-24-2024 07:18 AM
all sorted. found the reasons of RPF supressed drops.
I was having a missing line on the Po1.vlan interface. now the interface works perfectly fine and its config looks as following:
interface Port-channel1.xxx
description ISP-L3-LACP
encapsulation dot1Q xxx
vrf forwarding XXX
ip address 1.2.3.4 255.255.255.240
no ip redirects
ip verify unicast reverse-path
ip access-group xxx in
ip access-group xxx out
ipv6 address ABCD::1/64
ipv6 nd other-config-flag
ipv6 nd router-preference High
no ipv6 redirects
ipv6 verify unicast reverse-path
ipv6 traffic-filter IPv6-IN in
ipv6 traffic-filter IPv6-OUT out
ip virtual-reassembly
***
thanks for your brilliant help and loads of useful hints and support. as always the best community on internet ! LOL
09-24-2024 01:35 PM
Glad to know all good.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide