XB6 Blocking 6in4 IPv6 Tunnel

samedwards2020
Grasshopper

I recently upgraded from a Hitron CGNM-2250 to an XB6. Specifically, I received the Technicolor CGM4140COM, and have placed it bridge mode, where it is connected to a Ubiquiti ER-X SFP.

With the Hitron, I had an IPv6 tunnel with Hurricane Electric (https://tunnelbroker.net) working for years without issue. With the XB6, no such luck. While I appreciate that the XB6 is finally allowing native IPv6 connectivity (and I am making using of it via DHCPv6 PD), I would still like the Hurricane Electric tunnel as it provides a know stable IPv6 address vs the Shaw delegated prefix which makes no such guarantees.

After extensive testing and packet capture, it appears that the tunnel works in the outbound direction, with a ping reaching the target host, and is then returned, but that never makes it back to the tunnelled IPv6 address. As best as I can tell, these 6in4 protocol 41 packets are blocked somewhere by the XB6, or within whichever cloud stack that it's dealing with.

I'm seeing Comcast users with a CGA4131 (which uses the same Broadcom BCM3390 chipset as Shaw's CGM4140) seeing this same issue develop between a 3.x and 4.x firmware version (my CGM4140 is currently running CGM4140COM_4.4p8s1_PROD_sey) (https://forums.businesshelp.comcast.com/t5/Connectivity/IPv6-over-IPv4-6in4-seems-to-be-blocked/td-p...), but Comcast employees there seem to have been less than helpful.

I'm hoping that I can get confirmation that another Shaw customer is seeing this issue too, and hopefully some helpful comments from a Shaw employee, probably @corbin if he's still around.

Labels (2)
7 Replies

this is generally outside our scope of support. However,...

shaw-tony
Moderator
Moderator

@samedwards2020 this is generally outside our scope of support. However, I had our engineers check this and it is indeed blocked on the XB6. An escalation ticket is being created to find a resolution for this matter. Your feedback and patience are appreciated!

Reply
Loading...

Hi Tony, Thanks for taking the time to look in to this an...

samedwards2020
Grasshopper

Hi Tony,

Thanks for taking the time to look in to this and confirm it. I hope the escalation to the vendor can resolve this, but I also understand that it will probably be months until we could see a potential fix rolled out in a new firmware version. I'll keep an eye on firmware update, and I'm happy to beta-test any new releases as well to confirm resolution.

Reply
Loading...

no worries, glad to help! Thank you for your enthusiasm t...

shaw-tony
Moderator
Moderator

@samedwards2020 no worries, glad to help! Thank you for your enthusiasm to help work on a resolution. Fyi, we are tracking this issue under INC0898505.

0 Kudos
Reply
Loading...

Just upgraded my service and my modem from Hitron to XB7...

dennis369
Grasshopper

Just upgraded my service and my modem from Hitron to XB7 and both my IPv6 tunnels via Hurricane Electric's tunnelbroker have also stopped working.

The tunnels themselves are established and I can ping the IPv4 tunnel endpoints, however I can not ping the IPv6 tunnel endpoint. There is no response whatsoever and no IPv6 network traffic appears to flow beyond that hop. It definitely appears to be blocked.

I too relied on the IPV6 connectivity and prefix delegations those tunnels provided.

0 Kudos
Reply
Loading...

Update:

dennis369
Grasshopper

Without any configuration changes, reverting back to my previous hitron modem immediately resolved this issue...

and an additional issue:  https://support.shaw.ca/t5/internet-discussions/network-communication-on-bridged-xb7-modem-s-lan-por... 

I'll revisit Fibre+ and the XB7 modem later on when presumably the firmware bugs are eventually ironed out.

Reply
Loading...

Did that escalation ticket resolve anything? I'm hitting...

gehrehmee
Grasshopper

Did that escalation ticket resolve anything? I'm hitting the same problem since setting up an XB6 today.

0 Kudos
Reply
Loading...

The prefix I'm getting from Shaw has been stable so far,...

samedwards2020
Grasshopper

The prefix I'm getting from Shaw has been stable so far, so I haven't bothered to check back to see if 6in4 traffic is flowing properly with any of the firmware updates this year (and there seem to have been 4 or 5).

0 Kudos
Reply
Loading...
TALK TO US
We're here to help