Anycast 45.90.28.0/24 and 45.90.30.0/24 unreachable from Verizon Fios in Washington DC, second long outage in four days
Pro plan, five profiles on linked IP 108.39.2.153 (Verizon Fios, Washington DC). Our resolvers are Windows DNS servers that forward plain DNS to the per profile anycast addresses, so we depend on the two anycast blocks.
**What is happening**
- Since Sept 30 at 18:46 EDT every address in 45.90.28.0/24 times out from our network on UDP 53, TCP 53 and TCP 443. 45.90.30.0/24 answers for a few minutes about once an hour, then times out again. Still ongoing at 14:00 EDT on Oct 1, about 19 hours.
- The same thing happened on Sept 28 from about 11:30 to 16:30 EDT and cleared on its own. A diag report was sent that day as well.
- Nothing changed on our side between the good and bad periods. Public IP has been 108.39.2.153 throughout. 1.1.1.1 and 8.8.8.8 answer normally the whole time.
**What the diag tool shows** (report: https://nextdns.io/diag/e5b3f530-bdc1-11f1-80dd-17f9a9310b3b)
-Every PoP answers by its direct address: zepto-xrs 7 ms, hetzner-iad 8 ms, anexia-mnz 8 ms, vultr-ewr 12 ms and the rest.
- Traceroute to 45.90.30.0 reaches 199.119.65.14 inside the zepto-xrs site and dies there. The direct address of that same site, 170.39.224.134, answers one hop away through 199.119.65.17.
- Traceroute to 45.90.28.0 dies after NTT at 128.241.8.171.
- From a phone on T Mobile both anycast blocks answer, so the service is up. It is the anycast path from Verizon through NTT into zepto-xrs that is broken.
**Questions**
1. Is the anycast announcement at zepto-xrs known to be broken or partial right now?
2. Is there anything we can do on our side with the linked IP setup? Plain DNS forwarders cannot use the direct PoP addresses.
Reply
Content aside
- 7 hrs agoLast active
- 4Views
-
1
Following
