• Welcome to Hurricane Electric's IPv6 Tunnel Broker Forums.

News:

Welcome to Hurricane Electric's Tunnelbroker.net forums!

Main Menu

Recent posts

#1
Questions & Answers / Need help with SMTP unblock
Last post by mitkait - July 14, 2026, 06:49:35 PM
Hello,

I have been trying to request the removal of the outbound SMTP (port 25) filtering on my tunnel for over a week, but I haven't received any response.

Account name: mitkait 
Tunnel ID: 1032386 
Certification level: Sage (attained on 2026-07-08)

I received an automated reply after emailing ipv6@he.net, but there has been no follow-up since then.

Could an administrator please assist me in enabling SMTP functionality for my tunnel?

Thank you!
#2
Questions & Answers / Re: The IP address under AS413...
Last post by agehall - July 02, 2026, 02:11:23 AM
I'm getting the same error message when attempting to create a new tunnel. My old tunnel expired and was deleted as I had to have it down for an extended period of time but now I'm ready to re-create a new tunnel.
#3
General Questions & Suggestions / Re: subdomain for my own bind9...
Last post by rakogels - June 26, 2026, 07:55:04 AM
Thanks Snarked. By removing sub.example.com from he.net it started to work.
sub.example.com is now served by my bind dns server while example.com is served by he.net as required.

I guess I got confused with the assumption that you need to add a subdomain to he.net first and in that subdomain you need to put the details for your own DNS server.
#4
General Questions & Suggestions / Re: subdomain for my own bind9...
Last post by snarked - June 26, 2026, 01:20:39 AM
Step 3 doesn't make sense.  Action 3 you took implies that HE's servers are primary for the zone.  However, actions 1 & 2 plus your opening statement implies that your private server is primary and HE's servers are secondary.  Please restate your question if this is wrong.

One does not add any RRs in HE's web interface for secondary zones; only name server addresses (names get resolved to addresses) and a TSIG key (if used).

If HE asked you to add a TXT record, that goes into the zone file, not the server configuration file.
#5
General Questions & Suggestions / subdomain for my own bind9 ser...
Last post by rakogels - June 25, 2026, 01:27:57 AM
Hi all,

I am having issues setting up DNS for my subdomain, using my own bind9 server.
It seems that the delegation part is not working.

This is what I have done:
1. In parent zone (example.com) I added a NS records for the subdomain delegation:

Name: sub.example.com
Type: NS
Value: ns1.sub.example.com

2. Added glue record in parent zone (example.com):
Name: ns1.sub.example.com
Type: A, Value: MY_SERVER_PUBLIC_IP

3. Added sub.example.com via he.net webportal to my main domain (example.com)
Note that the webportal tells me to add a TXT record with name dnshenet-key and value they provided.
I added this record to my bind config for this subdomain.

Any suggestions why this is not working?

Thanks.

#6
Questions & Answers / The IP address under AS4134 di...
Last post by HerobrineWhite - June 10, 2026, 11:07:56 AM
Hi, engineers from the TunnelBroker team.

A friend of mine created an IP tunnel years ago and has been using it ever since.
His upstream router does not support IPv6 distribution, and he has recently found that he is unable to update the "Client IPv4 Address" using the website API. When he browses or uses "cURL" to access the Update URL, he receives an abuse warning message.
I'd like to ask what happened. Is it still possible to restore the AS4134 dynamic update for "Client IPv4 Address"?
#7
Questions & Answers / /48 ?
Last post by pronetla - June 09, 2026, 11:07:51 AM
Yesterday I signed up with Hurricane Electric to practice using IPv6 on my network, but they only assigned me a /64. Do I have to wait a while, or do I need to do something else to get a /48? Or do they no longer do that?
#8
General Questions & Suggestions / Re: DNSSEC support?
Last post by jostreff - June 09, 2026, 10:54:13 AM
I am experiencing the exact same issue with my slave zones transferred from a PowerDNS master.
The zone transfers (AXFR) complete successfully, and the SOA serial numbers match perfectly across all nsX.he.net nodes. However, any external DNSSEC validation tool (like DNSViz) throws an ECONNREFUSED error specifically when querying the Hurricane Electric Anycast IPs (e.g., 216.66.1.2) for DNSKEY records.
My zones are signed using Algorithm 13 (ECDSA Curve P-256 with SHA-256), which is the current modern standard. It seems that the HE Anycast edge servers either drop/refuse requests for these crypto keys or fail to parse the DNSSEC records properly if the algorithm isn't explicitly supported by the underlying legacy software version running on the nodes.
It's 2026, and it's quite disappointing that we still cannot properly host a modern DNSSEC-signed slave zone on HE's Free DNS platform without down-grading to obsolete algorithms like RSASHA1. Any chance the backend software will be updated to support current PowerDNS/BIND DNSSEC deployments?
Best regards,
Jordan
#9
Questions & Answers / Re: Japan tunnel server with h...
Last post by snarked - May 31, 2026, 12:55:47 PM
Routing.  Someone probably in Japan thinks the best route to HE in Japan is via the U.S. instead of a peering in country.  There may have been a Japan peering with HE which is currently not working.

Using the BGP interface here, HE peers at 2 cities in Japan:  Osaka and Tokyo.  Your trace route hop 3 has a hostname indicating Tokyo routing, but hop 4's latency implies a trans-Pacific crossing.  Although the hostname is truncated, it probably refers to Tata Communications at Equinix Tokyo.  HE and Tata are both present there, but maybe they're not talking to each other.  Tata is presenting only an IPv4 interface at Equinix Tokyo at present, so maybe that has some effect on the peering situation.
#10
Questions & Answers / Japan tunnel server with high ...
Last post by 98118 - May 29, 2026, 07:40:10 PM
Hi HE.net team,

I am running a Oracle VPS intance in Japan datacenter, which has been connected to HE tunnel server for a long time.
But in recent days, I find that the latency between them is increasing a lot, from <10ms to >200ms.
I execute a mtr from VPS to tunnerl server, seeing that the route path is Japan -> US -> Japan.
What causes the issue? Thank you

$ mtr 74.82.46.6 -r
Start: 2026-05-30T10:26:02+0800
HOST: intance2                    Loss%   Snt   Last   Avg  Best  Wrst StDev
  1.|-- 140.91.206.106             0.0%    10    0.3   0.3   0.3   0.4   0.0
  2.|-- 180.87.180.138             0.0%    10    1.2   1.1   1.0   1.3   0.1
  3.|-- ix-be-35.ecore1.tv2-tokyo 30.0%    10    1.6   1.6   1.6   1.7   0.0
  4.|-- 209.58.55.73              90.0%    10  101.3 101.3 101.3 101.3   0.0
  5.|-- ???                       100.0    10    0.0   0.0   0.0   0.0   0.0
  6.|-- 64.86.26.38               50.0%    10  102.2 102.2 101.9 102.4   0.2
  7.|-- 64.86.26.37               80.0%    10  101.6 101.6 101.6 101.6   0.0
  8.|-- if-bundle-2-2.qcore2.sqn- 80.0%    10  101.1 101.3 101.1 101.4   0.2
  9.|-- port-channel22.core3.sjc2  0.0%    10  101.2 101.2 100.9 102.2   0.4
 10.|-- be47.core1.sjc2.he.net     0.0%    10  101.5 103.5 101.5 104.9   1.1
 11.|-- be1.core3.lax1.he.net     10.0%    10  115.5 114.5 112.9 115.5   0.8
 12.|-- be48.core1.lax2.he.net     0.0%    10  114.2 114.1 113.0 115.5   0.8
 13.|-- 100ge0-77.core3.tyo1.he.n 80.0%    10  211.5 211.4 211.2 211.5   0.2
 14.|-- port-channel9.core2.tyo1.  0.0%    10  211.6 211.8 211.4 213.0   0.5
 15.|-- tserv1.tyo1.he.net         0.0%    10  210.7 211.3 210.7 215.8   1.6