IPv6 problem from Gravelines VM (GRA3)

Hi
Everything was working fine until today, impossible to do a git pull on gitlab.com from a VM in Gravelines (GRA3), so I checked the IPv6 to google.com and bam, same thing, packets get blocked starting at AS16276 :weary_face:

$ sudo traceroute6 -n ``gitlab.com
traceroute to ``gitlab.com`` (2606:4700:90:0:f22e:fbec:5bed:a9b9), 30 hops max, 80 byte packets
1 2001:41d0:302:1100::1 1.295 ms 1.206 ms 1.156 ms
2 fd00::ffe 1.674 ms 1.623 ms 1.574 ms
3 2001:41d0:0:1:3::aabf 2.577 ms 2.524 ms 2.478 ms
4 2001:41d0:0:1:3::aac0 2.427 ms 2.381 ms 2001:41d0:0:1:3::a73e 2.332 ms
5 * * *

$ sudo traceroute6 -n ``ipv6.google.com
traceroute to ``ipv6.google.com`` (2a00:1450:4007:809::200e), 30 hops max, 80 byte packets
1 2001:41d0:302:1100::1 0.480 ms 0.422 ms 0.384 ms
2 fd00::ffe 0.353 ms 1.099 ms 1.060 ms
3 2001:41d0:0:1:3::aabf 1.030 ms 0.999 ms 0.969 ms
4 2001:41d0:0:1:3::aac0 0.938 ms 0.898 ms 2001:41d0:0:1:3::a73e 0.856 ms
5 2001:41d0:0:1:3::a13e 1.350 ms * *
6 * * *

ps: sorry for the “vps” tag but there isn’t much choice and it’s mandatory :frowning:

the joys of IPv6 at OVH... Or I don’t know if it’s OVH, or if it’s just IPv6 that’s a problematic nightmare...

No problems encountered at Hetzner and Scaleway ... The cause is probably not IPv6.

Hi @Cyrille37

I have a feeling this is an internal OVH issue. I'd suggest they look at the TCAM exceptions on the Gravelines routers. When the TCAM gets saturated or enters an exception state, the router hardware can't correctly process IPv6 routes, causing packets to be lost in its own backbone.

Maybe I'm wrong… :smirking_face:

Also check https://network.status-ovhcloud.com/

Cheers,
Sergio Turpín

It makes me laugh, it looks like some kind of giant maze at OVH with packets wandering everywhere for two days while the security guy runs after them. Fortunately, the problem seems to have been resolved since 14:45 UTC.

I still have the problem with a VPS in gra4 :confused:

Indeed, it’s happening again on other instances. IPv6 is down.

Also affected in GRA, was down yesterday too.

Start: 2026-07-08T21:17:29+0000
HOST: lil1.lg.ovh.net                                         Loss%   Snt   Last   Avg  Best  Wrst StDev
  1. AS16276  vss-9a-6k.fr.eu (2001:41d0:8:caff:ff:ff:ff:fe)   0.0%     3    0.9   0.9   0.7   1.0   0.2
  2. AS16276  2001:41d0:0:50::1:511a                           0.0%     3    1.0   0.9   0.8   1.0   0.1
  3. AS???    fdff:f000::3                                     0.0%     3    0.9   0.8   0.8   0.9   0.0
  4. AS???    fdff:f003:8::44                                  0.0%     3    4.9   4.1   3.1   4.9   0.9
  5. AS16276  2001:41d0:20a:600::1b                            0.0%     3    1.0   0.9   0.8   1.0   0.1
  6. AS16276  2001:41d0::189                                   0.0%     3    2.5   2.5   2.4   2.5   0.1
  7. AS16276  2001:41d0:20a:600::1e                            0.0%     3    3.7   3.9   3.7   4.1   0.2
  8. AS???    fdff:f000:8::                                    0.0%     3    2.6   2.5   2.4   2.6   0.1
  9. AS???    ???                                             100.0     3    0.0   0.0   0.0   0.0   0.0
xxx -> gra.proof.ovh.net (2001:41d0:303:fa91::)  2026-07-08T21:30:46+0000
                                              Packets               Pings
 Host                                       Loss%   Snt   Last   Avg  Best  Wrst StDev
 1. _gateway                                 0.0%   152    0.2   0.3   0.1   1.9   0.2
 2. fd00::ffe                                0.0%   152    0.3   0.3   0.2   0.6   0.1
 3. 2001:41d0:302:c14:ffff:ffff:ffff:ffff    0.0%   152    0.5   0.5   0.4   1.0   0.1
 4. po138.gra-z1g1-a75.fr.eu                 0.0%   152    0.4   0.5   0.3   0.9   0.1
 5. 2001:41d0:0:1:3:0:1:90f0                86.1%   152    1.1   1.0   0.8   1.2   0.1
 6. (waiting for reply)
 7. (waiting for reply)
 8. 2001:41d0:0:50::4:5109                  99.3%   152    1.5   1.5   1.5   1.5   0.0
 9. 2001:41d0:0:50::a:fa49                  99.3%   152    1.4   1.4   1.4   1.4   0.0
10. (waiting for reply)
11. (waiting for reply)
12. (waiting for reply)
13. 2001:41d0:303:fa91::                    98.7%   151    1.1   1.0   0.8   1.1   0.2

And now IPv4 is broken. Is VPS not considered a priority at OVH?

                                                 Packets               Pings
 Host                                          Loss%   Snt   Last   Avg  Best  Wrst StDev
 1. 10.78.100.1                                 0.0%    82    0.1   0.2   0.1   0.3   0.0
 2. xxxxxxxx.static.ziggozakelijk.nl            0.0%    82    1.5   2.1   1.3  43.5   4.7
 3. (waiting for reply)
 4. asd-tr0021-cr101-be64.core.as9143.net       0.0%    82    1.8   1.8   1.7   2.3   0.1
 5. nl-ams04a-ri3-ae51-0.core.as9143.net       85.0%    81    2.0   2.0   1.9   2.4   0.1
 6. 213-46-183-46.aorta.net                     0.0%    81    5.4   4.6   3.0   7.6   0.8
 7. (waiting for reply)
 8. (waiting for reply)
 9. be102.ams-gsa1-sbb2-nc5.nl.eu               0.0%    81    2.9   2.7   2.4   3.1   0.1
10. be103.lil2-gra1-sbb2-nc5.fr.eu              0.0%    81   11.8  12.1  11.7  14.2   0.4
11. 37.59.16.28                                 0.0%    81   13.6  13.7  12.0  15.2   0.7
12. (waiting for reply)
13. (waiting for reply)
14. (waiting for reply)
15. (waiting for reply)
16. 51.255.253.19                              84.0%    81   10.9  10.9  10.8  11.0   0.1
17. 51.255.253.62                              98.8%    81   11.0  11.0  11.0  11.0   0.0
18. 51.255.253.19                              98.8%    81   10.9  10.9  10.9  10.9   0.0
19. 51.255.253.62                              98.8%    81   11.1  11.1  11.1  11.1   0.0
20. 51.255.253.19                              98.8%    81   10.9  10.9  10.9  10.9   0.0
21. 51.255.253.62                              98.8%    81   11.1  11.1  11.1  11.1   0.0
22. 51.255.253.19                              97.4%    78   10.9  10.9  10.9  11.0   0.0
23. 51.255.253.62                              92.3%    14   11.1  11.1  11.1  11.1   0.0
24. 51.255.253.19                              92.3%    14   11.0  11.0  11.0  11.0   0.0
25. 51.255.253.62                              92.3%    14   11.3  11.3  11.3  11.3   0.0
26. 51.255.253.19                              92.3%    14   11.0  11.0  11.0  11.0   0.0
27. (waiting for reply)

Both IPv4 and IPv6 are back to working again now. Hopefully it's fixed properly this time!

It seems there was emergency maintenance on a host, my VPS went into maintenance but otherwise it seems to be returning to normal.

I took the opportunity to adjust the filter for my alerts.

The problem is that there’s nothing on the OVH status page, we’re not aware of anything and a technician told me that some people went on vacation on Saturday.

Personally I'm still getting alerts on a VPS in UK2, with the monitoring based in GRA8. And on IPv4.
With Nagios which reports: connect to address … and port 25: No route to host

Do you have vRack on that VPS?

No, no, the two VPS are standard VPS offers...
I got alerts on several VPS last night, a few in the early hours.
But this one on uk2 keeps popping up from time to time...

Same tonight, several reboots of hosts hosting some of my VPS.
Downtime of 5–10 minutes each time.
Well, you have to update kernels from time to time, no problem (we’d like to be notified, though).
However, what’s disappointing is that the VMs get shut down abruptly, even though the host could gracefully stop the VMs before reboot.

I was talking about a VM (Public Cloud), not a VPS, and I don’t know if it’s the same network. In any case, support pointed me to this ticket regarding the IPv6 issue: https://network.status-ovhcloud.com/incidents/cfjg549ghh2y

Well, the network behind it stays the same.

Yes, I think it was urgent because I saw a security vulnerability that allows, from a VM (VPS, Public Cloud Instance), to intrude on the host: https://www.it-connect.fr/januscape-faille-kvm-evasion-vm-hote/

rofl, seriously, again... it never ends...

The security context is really complicated right now… I’ve never done so many reboots.
On Debian 13 – kernel 6.12-95-1 it’s already fixed.
However on Debian 12 I haven’t really found the info (I no longer have KVM on Debian 12 :slight_smile: )