Hurricane Electric's IPv6 Tunnel Broker Forums

General IPv6 Topics => IPv6 on Windows => Topic started by: AndrejaKo on February 25, 2011, 08:00:16 AM

Title: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 08:00:16 AM
I'm having really bad luck with IPv6!

I finally managed to get a router which can run OpenWRT and then I spent several days setting up IPv6 connection to SixXs using AICCU, because it looked easier than HE.net. After I set everything up nicely, my PoP started acting up and going down all the time. Fine. I then spent several days researching and experimenting with HE and managed to have my router set up a tunnel and have it hand out addresses using radvd.

After that I noticed that only web-site that works is ipv6.google.com! I can ping sixxs, he, kame and others fine, and I can get traceroutes to them but when I type the URL into firefox, it doesn't load. It's just in loading state.

Here's for example my tracert for ipv6.he.net:

Tracing route to ipv6.he.net [2001:470:0:64::2]
over a maximum of 30 hops:

 1    <1 ms     1 ms     1 ms  2001:470:1f0b:de5::1
 2    62 ms    63 ms    62 ms  andrejako-1.tunnel.tserv6.fra1.ipv6.he.net [2001:470:1f0a:de5::1]
 3    60 ms    60 ms    63 ms  gige-g2-4.core1.fra1.he.net [2001:470:0:69::1]
 4    63 ms    68 ms    68 ms  10gigabitethernet1-4.core1.ams1.he.net [2001:470:0:47::1]
 5    84 ms    74 ms    76 ms  10gigabitethernet1-4.core1.lon1.he.net [2001:470:0:3f::1]
 6   146 ms   147 ms   151 ms  10gigabitethernet4-4.core1.nyc4.he.net [2001:470:0:128::1]
 7   200 ms   198 ms   202 ms  10gigabitethernet5-3.core1.lax1.he.net [2001:470:0:10e::1]
 8   219 ms     *      210 ms  10gigabitethernet2-2.core1.fmt2.he.net [2001:470:0:18d::1]
 9   221 ms   338 ms   209 ms  gige-g4-18.core1.fmt1.he.net [2001:470:0:2d::1]
10   206 ms   210 ms   207 ms  ipv6.he.net [2001:470:0:64::2]

Trace complete.


Also, I don't know if this is the right forum, because the issue could be related to the router too. My computers are using Windows 7 64bit SP1.

So what should I do?

UPDATE: I can browse IPv6 sites fine from the router,
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: cholzhauer on February 25, 2011, 08:08:20 AM
Did you assign an IPv6 address to your local area connection? If not, assign one out of your routed /64  (check your tunnel page for it)
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 08:18:46 AM
Yes, I did assign IP address to LAN interface of the router. 
It's  2001:470:1f0b:de5::1/64.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: cholzhauer on February 25, 2011, 08:22:18 AM
What are you using for a DNS server?  If you entered HE's DNS server, this is the behavior I would expect.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: kriteknetworks on February 25, 2011, 08:24:27 AM
Quote from: AndrejaKo on February 25, 2011, 08:18:46 AM
Yes, I did assign IP address to LAN interface of the router. 
It's  2001:470:1f0b:de5::1/64.

The same adress you're using for your tunnel endpoint?


  1    <1 ms     1 ms     1 ms  2001:470:1f0b:de5::1
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 08:42:22 AM
@cholzhauer
I'm using my ISP's DNS servers and Google's 8.8.8.8 I never had problems resolving AAAA with them and they worked fine with SixXs. Shouls I be using different DNS servers?

@kriteknetworks
Well, under my tunnel settings it says:
Client IPv6 address: 2001:470:1f0a:de5::2/64


Shouldn't that be the endpoint of my tunnel at my side?

Anyway, I'll try with a different address just in case that's the problem.
It didn't help.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: cholzhauer on February 25, 2011, 08:49:25 AM
That's fine...I was just wondering if you were using HE's DNS for everything.

The 2001:470:1f0a:de5::2/64 should only appear on your tunnel adapter...you have a routed /64 network listed on your tunnel detail page that is one character different.

From your trace route though, it looks like that's correct.  Your first hop is 2001:470:1f0b:de5::1  and your second hop is 2001:470:1f0a:de5::1.  I assume the first hop is the "inside interface" of your router and the 2001:470:1f0a:de5::1 is the IP address of the HE side of your tunnel.

It's strange that everything is working from your tunnel server and not anything behind it.  You mentioned that you're doing RA...what happens if you set up the addresses by hand?
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 09:04:50 AM
Manual settings didn't help either. I can still access only Google form the computers. On router using elinks, everything seems to be fine and sixxs is reporting that I'm using IPv6.


As for IP addresses, as far as I can see, it's the way you described. Here's my ifconfig output:

6in4-hene Link encap:IPv6-in-IPv4
          inet6 addr: 2001:470:1f0a:de5::2/64 Scope:Global
          inet6 addr: fe80::4d69:288c/128 Scope:Link
          UP POINTOPOINT RUNNING NOARP  MTU:1280  Metric:1
          RX packets:89 errors:0 dropped:0 overruns:0 frame:0
          TX packets:131 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:26960 (26.3 KiB)  TX bytes:26383 (25.7 KiB)

br-lan    Link encap:Ethernet  HWaddr 74:EA:3A:E4:DF:48
          inet addr:192.168.1.1  Bcast:192.168.1.255  Mask:255.255.255.0
          inet6 addr: 2001:470:1f0b:de5::1/64 Scope:Global
          inet6 addr: fe80::5085:feff:fe5a:489c/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:38625 errors:0 dropped:0 overruns:0 frame:0
          TX packets:68321 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:2938427 (2.8 MiB)  TX bytes:85277918 (81.3 MiB)

eth0      Link encap:Ethernet  HWaddr 74:EA:3A:E4:DF:48
          inet6 addr: fe80::76ea:3aff:fee4:df48/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:70989 errors:0 dropped:0 overruns:0 frame:0
          TX packets:40926 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:86623353 (82.6 MiB)  TX bytes:5126791 (4.8 MiB)
          Interrupt:4

eth0.1    Link encap:Ethernet  HWaddr 74:EA:3A:E4:DF:48
          inet6 addr: fe80::76ea:3aff:fee4:df48/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:2618 errors:0 dropped:0 overruns:0 frame:0
          TX packets:3649 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:1008364 (984.7 KiB)  TX bytes:1825232 (1.7 MiB)

eth0.2    Link encap:Ethernet  HWaddr 74:EA:3A:E4:DF:48
          inet addr:77.105.40.140  Bcast:77.105.40.255  Mask:255.255.255.0
          inet6 addr: fe80::76ea:3aff:fee4:df48/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:68228 errors:0 dropped:0 overruns:0 frame:0
          TX packets:37266 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:84585557 (80.6 MiB)  TX bytes:3299682 (3.1 MiB)

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:8 errors:0 dropped:0 overruns:0 frame:0
          TX packets:8 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:577 (577.0 B)  TX bytes:577 (577.0 B)

mon.wlan0 Link encap:UNSPEC  HWaddr 74-EA-3A-E4-DF-48-00-00-00-00-00-00-00-00-00-00
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:470 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:84371 (82.3 KiB)  TX bytes:0 (0.0 B)

wlan0     Link encap:Ethernet  HWaddr 74:EA:3A:E4:DF:48
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:42694 errors:0 dropped:0 overruns:0 frame:0
          TX packets:73691 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:5609868 (5.3 MiB)  TX bytes:88684085 (84.5 MiB)

Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: cholzhauer on February 25, 2011, 09:07:03 AM
Strange.  OK, so your tunnel is up, I can verify by pinging your side of the tunnel.

Let's see a copy of the routing tables and ipconfig/ifconfig from one of your hosts that isn't working

Are you running any firewall on your router that might be interfering?
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 09:27:18 AM
Please correct me if I'm wrong, since I'm not too sure I get the show routing and firewall tables.


root@OpenWrt:/# ip route show
77.105.40.0/24 dev eth0.2  proto kernel  scope link  src 77.105.40.140
192.168.1.0/24 dev br-lan  proto kernel  scope link  src 192.168.1.1
default via 77.105.40.141 dev eth0.2


I'm not too good with iptables, so I can't interpret the output.  I added  henet to wan zone as per instructions shown here: =hurricane&s[]=electric#dynamic.ipv6-in-ipv4.tunnel.he.net.only]http://wiki.openwrt.org/doc/uci/network?s[]=hurricane&s[]=electric#dynamic.ipv6-in-ipv4.tunnel.he.net.only (http://wiki.openwrt.org/doc/uci/network?s[)

root@OpenWrt:/# iptables -L -n
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
syn_flood  tcp  --  0.0.0.0/0            0.0.0.0/0           tcp flags:0x17/0x02
input_rule  all  --  0.0.0.0/0            0.0.0.0/0
input      all  --  0.0.0.0/0            0.0.0.0/0

Chain FORWARD (policy DROP)
target     prot opt source               destination
zone_wan_MSSFIX  all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED
forwarding_rule  all  --  0.0.0.0/0            0.0.0.0/0
forward    all  --  0.0.0.0/0            0.0.0.0/0
reject     all  --  0.0.0.0/0            0.0.0.0/0

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
output_rule  all  --  0.0.0.0/0            0.0.0.0/0
output     all  --  0.0.0.0/0            0.0.0.0/0

Chain forward (1 references)
target     prot opt source               destination
zone_lan_forward  all  --  0.0.0.0/0            0.0.0.0/0
zone_wan_forward  all  --  0.0.0.0/0            0.0.0.0/0
zone_wan_forward  all  --  0.0.0.0/0            0.0.0.0/0

Chain forwarding_lan (1 references)
target     prot opt source               destination

Chain forwarding_rule (1 references)
target     prot opt source               destination
nat_reflection_fwd  all  --  0.0.0.0/0            0.0.0.0/0

Chain forwarding_wan (1 references)
target     prot opt source               destination

Chain input (1 references)
target     prot opt source               destination
zone_lan   all  --  0.0.0.0/0            0.0.0.0/0
zone_wan   all  --  0.0.0.0/0            0.0.0.0/0
zone_wan   all  --  0.0.0.0/0            0.0.0.0/0

Chain input_lan (1 references)
target     prot opt source               destination

Chain input_rule (1 references)
target     prot opt source               destination

Chain input_wan (1 references)
target     prot opt source               destination

Chain nat_reflection_fwd (1 references)
target     prot opt source               destination
ACCEPT     tcp  --  192.168.1.0/24       192.168.1.2         tcp dpt:80

Chain output (1 references)
target     prot opt source               destination
zone_lan_ACCEPT  all  --  0.0.0.0/0            0.0.0.0/0
zone_wan_ACCEPT  all  --  0.0.0.0/0            0.0.0.0/0

Chain output_rule (1 references)
target     prot opt source               destination

Chain reject (7 references)
target     prot opt source               destination
REJECT     tcp  --  0.0.0.0/0            0.0.0.0/0           reject-with tcp-reset
REJECT     all  --  0.0.0.0/0            0.0.0.0/0           reject-with icmp-port-unreachable

Chain syn_flood (1 references)
target     prot opt source               destination
RETURN     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp flags:0x17/0x02 limit: avg 25/sec burst 50
DROP       all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_lan (1 references)
target     prot opt source               destination
input_lan  all  --  0.0.0.0/0            0.0.0.0/0
zone_lan_ACCEPT  all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_lan_ACCEPT (2 references)
target     prot opt source               destination
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_lan_DROP (0 references)
target     prot opt source               destination
DROP       all  --  0.0.0.0/0            0.0.0.0/0
DROP       all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_lan_MSSFIX (0 references)
target     prot opt source               destination
TCPMSS     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 TCPMSS clamp to PMTU

Chain zone_lan_REJECT (1 references)
target     prot opt source               destination
reject     all  --  0.0.0.0/0            0.0.0.0/0
reject     all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_lan_forward (1 references)
target     prot opt source               destination
zone_wan_ACCEPT  all  --  0.0.0.0/0            0.0.0.0/0
forwarding_lan  all  --  0.0.0.0/0            0.0.0.0/0
zone_lan_REJECT  all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_wan (2 references)
target     prot opt source               destination
ACCEPT     udp  --  0.0.0.0/0            0.0.0.0/0           udp dpt:68
ACCEPT     icmp --  0.0.0.0/0            0.0.0.0/0           icmp type 8
ACCEPT     41   --  0.0.0.0/0            0.0.0.0/0
input_wan  all  --  0.0.0.0/0            0.0.0.0/0
zone_wan_REJECT  all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_wan_ACCEPT (2 references)
target     prot opt source               destination
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_wan_DROP (0 references)
target     prot opt source               destination
DROP       all  --  0.0.0.0/0            0.0.0.0/0
DROP       all  --  0.0.0.0/0            0.0.0.0/0
DROP       all  --  0.0.0.0/0            0.0.0.0/0
DROP       all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_wan_MSSFIX (1 references)
target     prot opt source               destination
TCPMSS     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 TCPMSS clamp to PMTU
TCPMSS     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 TCPMSS clamp to PMTU

Chain zone_wan_REJECT (2 references)
target     prot opt source               destination
reject     all  --  0.0.0.0/0            0.0.0.0/0
reject     all  --  0.0.0.0/0            0.0.0.0/0
reject     all  --  0.0.0.0/0            0.0.0.0/0
reject     all  --  0.0.0.0/0            0.0.0.0/0

Chain zone_wan_forward (2 references)
target     prot opt source               destination
ACCEPT     tcp  --  0.0.0.0/0            192.168.1.2
forwarding_wan  all  --  0.0.0.0/0            0.0.0.0/0
zone_wan_REJECT  all  --  0.0.0.0/0            0.0.0.0/0


Here's the ipconfig on a computer when radvd is enabled:


Windows IP Configuration


Ethernet adapter tun0:

  Media State . . . . . . . . . . . : Media disconnected
  Connection-specific DNS Suffix  . :

Ethernet adapter Lokalna veza:

  Media State . . . . . . . . . . . : Media disconnected
  Connection-specific DNS Suffix  . :

Ethernet adapter Bluetooth Network Connection:

  Media State . . . . . . . . . . . : Media disconnected
  Connection-specific DNS Suffix  . :

Ethernet adapter Local Area Connection:

  Connection-specific DNS Suffix  . :
  IPv6 Address. . . . . . . . . . . : 2001:470:1f0b:de5:21b:38ff:fedd:7e0f
  Temporary IPv6 Address. . . . . . : 2001:470:1f0b:de5:78a1:3119:a794:5c1b
  Link-local IPv6 Address . . . . . : fe80::21b:38ff:fedd:7e0f%12
  IPv4 Address. . . . . . . . . . . : 192.168.1.2
  Subnet Mask . . . . . . . . . . . : 255.255.255.0
  Default Gateway . . . . . . . . . : fe80::5085:feff:fe5a:489c%12
                                      192.168.1.1

Wireless LAN adapter Wireless Network Connection:

  Connection-specific DNS Suffix  . : lan
  Link-local IPv6 Address . . . . . : fe80::21d:e0ff:feab:1d95%11
  IPv4 Address. . . . . . . . . . . : 192.168.1.143
  Subnet Mask . . . . . . . . . . . : 255.255.255.0
  Default Gateway . . . . . . . . . : 192.168.1.1


WLAN adapter isn't getting its IPv6 address automagically, but that's a problem which I had before and it only seems to be affecting this one particular computer on the network.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: cholzhauer on February 25, 2011, 09:31:38 AM
I can't do IPTables either...why not just shut it off and see what happens?

You should be able to do a "netstat -nr" to get your routing tables
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 09:36:13 AM
Here's netstat -nr
root@OpenWrt:/# netstat -nr
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
77.105.40.0     0.0.0.0         255.255.255.0   U         0 0          0 eth0.2
192.168.1.0     0.0.0.0         255.255.255.0   U         0 0          0 br-lan
0.0.0.0         77.105.40.141   0.0.0.0         UG        0 0          0 eth0.2
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: cholzhauer on February 25, 2011, 09:36:54 AM
Well the interesting thing is there isn't any mention of IPv6 routes there.

What OS?
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 09:42:44 AM
Os on the router is OpenWRT Linux distribution.
Here's uname -a

Linux OpenWrt 2.6.32.25 #1 Fri Nov 19 20:27:50 PST 2010 mips GNU/Linux



There's some information on IPv6 routing on its wiki here: http://wiki.openwrt.org/doc/howto/ipv6?s[#enable.routing (http://wiki.openwrt.org/doc/howto/ipv6?s%5B#enable.routing)
According to that, my routing is correctly set up. When I run  cat /proc/sys/net/ipv6/conf/all/forwarding, I get 1.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: cholzhauer on February 25, 2011, 09:47:58 AM
Did you add any routes to it manually?

# Add default routes
ip route add default via ${HETUNNELIP} dev ${INTERFACE} metric 1
ip route add 2000::/3 via ${HETUNNELIP} dev ${INTERFACE} metric 1

(That's in DDWRT, but I assume it'll work for openwrt)

I'm not aware of a separate command to list the IPv6 routing table...someone please correct me if i'm wrong
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 10:13:04 AM
It doesn't work on OpenWRT. I get No such process when I try to use server ipv4 address and I get an inet address is expected when I try to use IPv6 address.


Also, if I have problem with routes, why would Google and ping work fine?


Also, I think I forgot to mention,  stopping firewall service doesn't help.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: Mierdin on February 25, 2011, 12:02:08 PM
Here's the linux version - windows makes this all nice by showing both tables with a netstat -rn but it needs some arguments on the linux side

[root@localhost ~]# ip -f inet6 route
2001:470:FFFF:FFFF::/64 dev eth0  proto kernel  metric 256  expires 214710sec mtu 1500 advmss 1440 hoplimit 64
fe80::/64 dev eth0  metric 256  expires 2099218sec mtu 1500 advmss 1440 hoplimit 64
ff00::/8 dev eth0  metric 256  expires 2099218sec mtu 1500 advmss 1440 hoplimit 1
default via fe80::2aa:aaff:feaa:aaaa dev eth0  proto kernel  metric 1024  expires 175sec mtu 1500 advmss 1440 hoplimit 64
unreachable default dev lo  proto none  metric -1  error -101 hoplimit 255
[root@localhost ~]#


I don't run OpenWRT so I'm only assuming you can run that

Also - yours will hopefully look a bit different - this device isn't configured for IPv6 in any intelligent way

Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: Mierdin on February 25, 2011, 12:16:28 PM
In addition:
I would ping henet's DNS server for example (2001:470:20::2) from your windows client. If the problem is DNS related, you might have basic IP connectivity, and this will prove that. Would also rule out routing problems.

Also - how are you distributing DNS info to your clients? To rule it out, I'd statically set your DNS server to HE.NET's DNS server on your windows clients (assuming you could get to that server successfully in the first test) for resolution.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 25, 2011, 01:37:22 PM
Here:

root@OpenWrt:/# ip -f inet6 route
2001:470:1f0a:de5::/64 via :: dev 6in4-henet  proto kernel  metric 256  mtu 1280 advmss 1220 hoplimit 0
2001:470:1f0b:de5::/64 dev br-lan  proto kernel  metric 256  mtu 1500 advmss 1440 hoplimit 0
fe80::/64 dev eth0  proto kernel  metric 256  mtu 1500 advmss 1440 hoplimit 0
fe80::/64 dev br-lan  proto kernel  metric 256  mtu 1500 advmss 1440 hoplimit 0
fe80::/64 dev eth0.1  proto kernel  metric 256  mtu 1500 advmss 1440 hoplimit 0
fe80::/64 dev eth0.2  proto kernel  metric 256  mtu 1500 advmss 1440 hoplimit 0
fe80::/64 via :: dev 6in4-henet  proto kernel  metric 256  mtu 1280 advmss 1220 hoplimit 0
default dev 6in4-henet  metric 1024  mtu 1280 advmss 1220 hoplimit 0


I can ping the DNS server fine from windows. Setting DNS server by hand didn't help.

As for DNS info, right now I have the RDNSS field in RADVD empty and rely on DNS servers which computers get from IPv4 DHCP. I'm using servers form my local ISP and Google's 8.8.8.8 and I didn't have any problems with name resolution so far. Name resolution seems to be working fine with HE's servers too.
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: Mierdin on February 26, 2011, 03:04:22 AM
Its not a routing issue, you have the correct entry for a default route to your tunnel IF. As you said, pings all work fine for any valid address (correct?)

So ipv6.google.com loads in FF but no other page does? What about whatismyipv6.com?

If that's true, my vote's for gremlins.  ::) Usually my first instinct is "shut off firewall, work from there" but reading back it looks like that didn't work.
Does this behavior manifest on other PCs on your network?
Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 26, 2011, 06:09:34 AM
I just tried with two other PCs and same problems happen to them too. I also tried with openSUSE 11.3 and it too doesn't work, so this could still be a router issue. Maybe I'm having firewall problems? But if that was the case, everything would be working fine with firewall off.

whatismyipv6 only works over IPv4.

Here are some pings and tracerts:

Pinging whatismyipv6.com [2001:4870:a24f:2::90] with 32 bytes of data:
Reply from 2001:4870:a24f:2::90: time=222ms
Reply from 2001:4870:a24f:2::90: time=217ms
Reply from 2001:4870:a24f:2::90: time=221ms
Reply from 2001:4870:a24f:2::90: time=219ms

Ping statistics for 2001:4870:a24f:2::90:
   Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
   Minimum = 217ms, Maximum = 222ms, Average = 219ms



Tracing route to whatismyipv6.com [2001:4870:a24f:2::90]
over a maximum of 30 hops:

 1     7 ms     1 ms     1 ms  2001:470:1f0b:de5::1
 2    69 ms    70 ms    63 ms  AndrejaKo-1.tunnel.tserv6.fra1.ipv6.he.net [2001:470:1f0a:de5::1]
 3    57 ms    65 ms    58 ms  gige-g2-4.core1.fra1.he.net [2001:470:0:69::1]
 4    73 ms    74 ms    75 ms  10gigabitethernet1-4.core1.ams1.he.net [2001:470:0:47::1]
 5    71 ms    74 ms    76 ms  10gigabitethernet1-4.core1.lon1.he.net [2001:470:0:3f::1]
 6   141 ms   149 ms   148 ms  10gigabitethernet2-3.core1.nyc4.he.net [2001:470:0:3e::1]
 7   141 ms   147 ms   143 ms  10gigabitethernet1-2.core1.nyc1.he.net [2001:470:0:37::2]
 8   144 ms   145 ms   142 ms  2001:504:1::a500:4323:1
 9   226 ms   225 ms   218 ms  2001:4870:a240::2
10   220 ms   224 ms   219 ms  2001:4870:a240::2
11   219 ms   218 ms   220 ms  2001:4870:a24f::2
12   221 ms   222 ms   220 ms  www.whatismyipv6.com [2001:4870:a24f:2::90]

Trace complete.



Tracing route to ipv6.l.google.com [2a00:1450:8004::68]
over a maximum of 30 hops:

 1     1 ms     1 ms     1 ms  2001:470:1f0b:de5::1
 2    67 ms    63 ms    64 ms  AndrejaKo-1.tunnel.tserv6.fra1.ipv6.he.net [2001:470:1f0a:de5::1]
 3    58 ms    57 ms    60 ms  gige-g2-4.core1.fra1.he.net [2001:470:0:69::1]
 4    61 ms    88 ms    60 ms  de-cix20.net.google.com [2001:7f8::3b41:0:2]
 5    61 ms    64 ms    60 ms  2001:4860::1:0:11
 6    74 ms    71 ms    70 ms  2001:4860::1:0:fdd
 7    78 ms    74 ms    74 ms  2001:4860::1:0:60d
 8    73 ms   245 ms    78 ms  2001:4860::2:0:612
 9    75 ms     *       76 ms  2001:4860:0:1::9d
10    76 ms    74 ms    73 ms  2a00:1450:8004::68

Trace complete.



Tracing route to orange.kame.net [2001:200:dff:fff1:216:3eff:feb1:44d7]
over a maximum of 30 hops:

 1     4 ms     1 ms     1 ms  2001:470:1f0b:de5::1
 2    65 ms    68 ms    64 ms  AndrejaKo-1.tunnel.tserv6.fra1.ipv6.he.net [2001:470:1f0a:de5::1]
 3    60 ms    65 ms    56 ms  gige-g2-4.core1.fra1.he.net [2001:470:0:69::1]
 4    60 ms    58 ms    58 ms  xe-0.de-cix.frnkge03.de.bb.gin.ntt.net [2001:7f8::b62:0:1]
 5    62 ms    62 ms    64 ms  ae-0.r21.frnkge04.de.bb.gin.ntt.net [2001:728:0:2000::2]
 6    64 ms    69 ms    67 ms  as-1.r23.amstnl02.nl.bb.gin.ntt.net [2001:728:0:2000::13d]
 7    71 ms    65 ms    63 ms  as-0.r22.amstnl02.nl.bb.gin.ntt.net [2001:728:0:2000::11]
 8   375 ms   384 ms   373 ms  as-0.r25.tokyjp01.jp.bb.gin.ntt.net [2001:418:0:2000::16]
 9   449 ms   372 ms   418 ms  ae-9.r20.tokyjp01.jp.bb.gin.ntt.net [2001:218:0:2000::1c5]
10   377 ms   379 ms   378 ms  po-1.a15.tokyjp01.jp.ra.gin.ntt.net [2001:218:0:6000::10e]
11   333 ms   329 ms   334 ms  ge-8-2.a15.tokyjp01.jp.ra.gin.ntt.net [2001:218:2000:5000::82]
12   331 ms   341 ms   332 ms  ve44.foundry6.otemachi.wide.ad.jp [2001:200:0:10::141]
13   333 ms   333 ms   331 ms  ve42.foundry4.nezu.wide.ad.jp [2001:200:0:11::66]
14   331 ms   329 ms   331 ms  cloud-net1.wide.ad.jp [2001:200:0:1c0a:218:8bff:fe43:d1d0]
15   331 ms   334 ms   330 ms  2001:200:dff:fff1:216:3eff:feb1:44d7

Trace complete.



Tracing route to orange.kame.net [2001:200:dff:fff1:216:3eff:feb1:44d7]
over a maximum of 30 hops:

 1     4 ms     1 ms     1 ms  2001:470:1f0b:de5::1
 2    65 ms    68 ms    64 ms  AndrejaKo-1.tunnel.tserv6.fra1.ipv6.he.net [2001:470:1f0a:de5::1]
 3    60 ms    65 ms    56 ms  gige-g2-4.core1.fra1.he.net [2001:470:0:69::1]
 4    60 ms    58 ms    58 ms  xe-0.de-cix.frnkge03.de.bb.gin.ntt.net [2001:7f8::b62:0:1]
 5    62 ms    62 ms    64 ms  ae-0.r21.frnkge04.de.bb.gin.ntt.net [2001:728:0:2000::2]
 6    64 ms    69 ms    67 ms  as-1.r23.amstnl02.nl.bb.gin.ntt.net [2001:728:0:2000::13d]
 7    71 ms    65 ms    63 ms  as-0.r22.amstnl02.nl.bb.gin.ntt.net [2001:728:0:2000::11]
 8   375 ms   384 ms   373 ms  as-0.r25.tokyjp01.jp.bb.gin.ntt.net [2001:418:0:2000::16]
 9   449 ms   372 ms   418 ms  ae-9.r20.tokyjp01.jp.bb.gin.ntt.net [2001:218:0:2000::1c5]
10   377 ms   379 ms   378 ms  po-1.a15.tokyjp01.jp.ra.gin.ntt.net [2001:218:0:6000::10e]
11   333 ms   329 ms   334 ms  ge-8-2.a15.tokyjp01.jp.ra.gin.ntt.net [2001:218:2000:5000::82]
12   331 ms   341 ms   332 ms  ve44.foundry6.otemachi.wide.ad.jp [2001:200:0:10::141]
13   333 ms   333 ms   331 ms  ve42.foundry4.nezu.wide.ad.jp [2001:200:0:11::66]
14   331 ms   329 ms   331 ms  cloud-net1.wide.ad.jp [2001:200:0:1c0a:218:8bff:fe43:d1d0]
15   331 ms   334 ms   330 ms  2001:200:dff:fff1:216:3eff:feb1:44d7

Trace complete.



Title: Re: Set up tunnel and now only ipv6.google.com works, but other sites ping fine.
Post by: AndrejaKo on February 26, 2011, 02:05:25 PM
People at OpenWRT forums solved the issue. I set up MTU advertised over radvd to 1280 and everything is working fine now.