0

Anycast 45.90.28.0/24 and 45.90.30.0/24 unreachable from Verizon Fios Washington DC, zepto-xrs PoP not answering anycast

Since before 11:55 EDT on 28 Sep 2026, plain DNS to 45.90.28.162 and 45.90.30.162 times out on UDP 53, TCP 53 and TCP 443 from Verizon Fios in Washington DC. 1.1.1.1 and 8.8.8.8 answer normally from the same hosts, and your ultra low latency servers are reachable (zepto-xrs 4 ms, anexia-mnz 7 ms). The Setup tab on my.nextdns.io also shows "Error while checking the current status". The diag tool was run at 12:47 EDT and the report was sent, but the window closed before the link could be copied; full output is below. Traceroute to 45.90.30.0 ends at 199.119.65.14 inside the zepto-xrs site, and test.nextdns.io (199.119.65.94) also times out, so that PoP appears to announce anycast it is not answering. Traceroute to 45.90.28.0 ends after 128.241.8.171 in NTT. Two Windows DNS servers forwarding to the profile addresses fail for the whole network.

Diag output:
Welcome to NextDNS network diagnostic tool. Testing IPv6 connectivity available: false Fetching https://test.nextdns.io Fetch error: Get "https://dat9i0h02hc9mc8tfo70.test.nextdns.io/": dial tcp 199.119.65.94:443: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond. Fetching PoP name for ultra low latency primary IPv4 (ipv4.dns1.nextdns.io) zepto-xrs: 4.279ms Fetching PoP name for ultra low latency secondary IPv4 (ipv4.dns2.nextdns.io) anexia-mnz: 7.5ms Fetching PoP name for anycast primary IPv4 (45.90.28.0) Fetch error: Get "https://dns.nextdns.io/info": dial tcp 45.90.28.0:443: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond. Fetching PoP name for anycast secondary IPv4 (45.90.30.0) Fetch error: Get "https://dns.nextdns.io/info": dial tcp 45.90.30.0:443: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond. Pinging PoPs zepto-xrs: 7.715ms hetzner-iad: 7.774ms anexia-mnz: 7.765ms vultr-ewr: 11.618ms anexia-ewr: 11.667ms tier-clt: 15.469ms smarthost-bos: 19.377ms teraswitch-pit: 23.241ms cloudzy-pit: 38.142ms Traceroute for ultra low latency primary IPv4 (170.39.224.134) 1 192.168.10.1 3ms 3ms 3ms 2 71.120.27.1 2ms 6ms 6ms 3 100.41.22.144 10ms 6ms 6ms 4 * * * 5 129.250.9.25 4ms 8ms 6ms 6 129.250.3.254 6ms 6ms 6ms 7 129.250.3.251 8ms 6ms 3ms 8 157.238.229.130 6ms 3ms 6ms 9 84.17.33.31 6ms 6ms 3ms 10 199.119.64.237 6ms 6ms 3ms 11 199.119.65.17 6ms 6ms 6ms 12 170.39.224.134 6ms 6ms 6ms Traceroute for ultra low latency secondary IPv4 (213.227.173.235) 1 192.168.10.1 2ms 3ms 3ms 2 71.120.27.1 3ms 3ms 6ms 3 100.41.22.142 3ms 6ms 3ms 4 * * * 5 80.239.135.178 6ms * * 6 62.115.141.51 7ms * 5ms 7 62.115.143.100 6ms 6ms 6ms 8 62.115.143.103 6ms 6ms 6ms 9 62.115.159.51 15ms 7ms 6ms 10 213.227.173.235 7ms 7ms 7ms Traceroute for anycast primary IPv4 (45.90.28.0) 1 192.168.10.1 1ms 3ms 3ms 2 71.120.27.1 6ms 7ms 7ms 3 100.41.22.144 6ms 6ms 6ms 4 * * * 5 129.250.9.25 110ms 2ms 6 129.250.5.6 8ms 6ms 7 129.250.4.189 22ms 21ms 8 129.250.6.37 19ms 15ms 9 128.241.8.171 21ms 25ms 10 * * 11 to 20 * * error: context deadline exceeded Traceroute for anycast secondary IPv4 (45.90.30.0) 1 192.168.10.1 3ms 3ms 3ms 2 71.120.27.1 3ms 6ms 6ms 3 100.41.22.144 25ms 6ms 25ms 4 * * * 5 129.250.8.209 7ms 4ms 6ms 6 129.250.3.254 2ms 6ms 6ms 7 129.250.3.251 12ms 5ms 6ms 8 157.238.229.130 2ms 6ms 6ms 9 84.17.33.31 6ms 6ms 6ms 10 199.119.64.237 6ms 6ms 6ms 11 199.119.65.14 6ms 6ms 6ms 12 to 20 * * * error: context deadline exceeded

1 reply

null
    • Joseph_Lonergan
    • 7 days ago
    • Reported - view

    3 Days latter the issue is still occurring. 

    Pro plan, five profiles on linked IP 108.39.2.153 (Verizon Fios, Washington DC). Our resolvers are Windows DNS servers that forward plain DNS to the per profile anycast addresses, so we depend on the two anycast blocks.

    **What is happening**

    - Since Sept 30 at 18:46 EDT every address in 45.90.28.0/24 times out from our network on UDP 53, TCP 53 and TCP 443. 45.90.30.0/24 answers for a few minutes about once an hour, then times out again. Still ongoing at 14:00 EDT on Oct 1, about 19 hours.

    - The same thing happened on Sept 28 from about 11:30 to 16:30 EDT and cleared on its own. A diag report was sent that day as well.

    - Nothing changed on our side between the good and bad periods. Public IP has been 108.39.2.153 throughout. 1.1.1.1 and 8.8.8.8 answer normally the whole time.

     

    **What the diag tool shows** (report: https://nextdns.io/diag/e5b3f530-bdc1-11f1-80dd-17f9a9310b3b)

    -Every PoP answers by its direct address: zepto-xrs 7 ms, hetzner-iad 8 ms, anexia-mnz 8 ms, vultr-ewr 12 ms and the rest.

    - Traceroute to 45.90.30.0 reaches 199.119.65.14 inside the zepto-xrs site and dies there. The direct address of that same site, 170.39.224.134, answers one hop away through 199.119.65.17.

    - Traceroute to 45.90.28.0 dies after NTT at 128.241.8.171.

    - From a phone on T Mobile both anycast blocks answer, so the service is up. It is the anycast path from Verizon through NTT into zepto-xrs that is broken.

     

    **Questions**

    1. Is the anycast announcement at zepto-xrs known to be broken or partial right now?

    2. Is there anything we can do on our side with the linked IP setup? Plain DNS forwarders cannot use the direct PoP addresses.

Content aside

  • 7 hrs agoLast active
  • 1Replies
  • 20Views
  • 1 Following