Probe 61817 currently shows as connected from the 2600:4800::/28 network, and it shows the IPv6 network as ASN 6128.
While the probe was briefly connecting through that it’s connected via 2600:4000::/24 (ASN 701) for the past ~2 days (and most of the time before).
The “IPv6 Current Configuration” also properly shows an address in 2600:4000::/24 and nothing in 2600:4800::/28.
IP echo address and local IP are again using the correct address.
The IP4 address is currently correctly shown from ASN 701, but I noticed a few days back that is was showing a wrong address from that ASN that had changed a few days earlier.
So something seems to be off with the IP reporting on the status pages.
Hello, is there some kind of v6 NAT in place? Seemingly the UI shows the probe’s local IP there. The connection history indeed has entries showing flaps between the two networks.
Note: I believe the upcoming new (beta) user interface shows the IP what you describe as the correct one, please check it out.
(I apologise for not posting a direct link here, I don’t want the link to be on permanent record since it’s supposed to be temporary I’ll send you mail instead.)
No, there is no v6 NAT involved. The new status page shows the exact same information as the old one for me (i.e., connection via ASN 6128). They both correctly show the ASN 701 address as the IP echo service address.
For context: I have a HA setup with two routers to two different ISPs, so that is why the probe will occasionally connect via ASN 6128. The last time there was a failover was Tue Feb 11 07:22:05 PM EST 2025, but that was brief and I think did not show up as a disconnect for the probe (i.e., I think it fell into the gap between two status updates by the probe). But that means the probe might still have the ASN 6128 address within the valid lifetime (but not as preferred).
I have confirmed via tcpdump on the external interfaces that there is no relevant traffic via the router connected to ASN 6128. All traffic (probes and the ssh over port 443 based status updates) go out via ASN 701.
The only thing I do see on the ASN 6128 connection are incoming syncs on various ports from a “shadowserver.org” server, but they are dropped by the firewall.