Skip to content

Looking Glass

Looking Glass lets you run commands on Internet2 routers.

Usage

  1. Select one or more nodes in the node list
  2. Type your query and press enter
  3. Select a node in the node list to view its output

Supported commands

Commands must be typed exactly as they appear in the Supported Commands sidebar; the shortened versions (i.e. desc instead of description) will not work.

Tip

The list of supported commands (along with their platforms) is available under Supported Commands in the right sidebar.

Supported operators

  • | - the pipe modifier passes a command's output through a built-in filter such as include or exclude so you only see the lines you asked for instead of the full output.

VRF names

VRF name Description
I2PX Internet2 Peering Exchange — Internet2's Layer 3 service giving members access to commercial peers (e.g. Google, Zoom, Netflix) and commodity internet; also carries Internet2's paid upstream transit routes for authorized services.
RE Research & Education — Internet2's private Layer 3 network enabling connectivity among members of the R&E community, including connectors, participants, and national/international R&E network peers (e.g. GÉANT, ESnet, regional networks).
BLENDED A combined view of the R&E and I2PX routing tables plus full transit routes, letting connectors reach both worlds over a single connection and BGP session.
LHCONE Large Hadron Collider Open Network Environment — a dedicated overlay for LHC experiment data movement between participating sites, peering with ESnet, GÉANT, CANARIE, and other R&E networks at Internet2's exchange points.
SCRUBBING DDoS Volumetric Mitigation Service (AS396450) — prefixes under attack are diverted into this VRF and routed through Radware's scrubbing centers, which return clean traffic to the subscriber.

Virtual Network Routers each get their own VRF, named VNROUTER-{Router ID}. Retrieve the Router ID from the Insight Console Virtual Network Router information.

Examples

Command Description
ping Ping from the router to a supplied destination, using the global routing table
ping {IP address} Ping destination IP address
ping vrf {VRF name} {IP address} Ping destination IP address from specified VRF
ping vrf I2PX Ping a supplied destination from the I2PX VRF
ping vrf RE Ping a supplied destination from the RE VRF
show bfd Bidirectional Forwarding Detection session state, used for fast detection of link failures
show bgp BGP table for the global routing table
show bgp vrf {VRF name} summary Show BGP summary for specified VRF
show bgp vrf {VRF name} neighbors Show BGP neighbors for specified VRF
show bgp vrf {VRF name} {address family} neighbor {neighbor IP} received routes Routes received from a neighbor, before inbound route policy. Address family is ipv4 unicast or ipv6 unicast
show bgp vrf {VRF name} {address family} neighbor {neighbor IP} routes Routes accepted from a neighbor, after inbound route policy
show bgp vrf {VRF name} {address family} neighbor {neighbor IP} advertised-routes Routes advertised to a neighbor, after outbound route policy
show bgp vrf I2PX summary BGP neighbor state and prefix counts for the I2PX VRF
show bgp vrf I2PX neighbors Detailed BGP neighbor information for the I2PX VRF, including accepted and denied prefixes
show bgp vrf I2PX BGP table for the I2PX VRF
show bgp vrf RE summary BGP neighbor state and prefix counts for the RE VRF
show bgp vrf RE neighbors Detailed BGP neighbor information for the RE VRF, including accepted and denied prefixes
show bgp vrf RE BGP table for the RE VRF
show cef Cisco Express Forwarding table — the forwarding entries used to switch packets (IOS XR only)
show controllers Controller statistics for physical interfaces, including optics and link-layer errors (IOS XR only)
show interfaces Interface status, addressing, and traffic and error counters
show lacp LACP state for the members of each link bundle
show lldp neighbors Directly connected neighbors discovered via LLDP, and the ports connecting them
show l2vpn xconnect Point-to-point Layer 2 circuits (cross-connects) and their state (IOS XR only)
show l2vpn bridge-domain group {Group ID} Retrieve the Group ID from the Insight Console Virtual Network Switch information
show policy-map interface {interface} QoS service policy applied to the specified interface
show qos interface {interface} {direction} QoS interface-level configuration for the specified interface, on IOS XR. Direction is input or output
show qos interface {interface} QoS interface-level configuration for the specified interface, on Arista EOS
show route IP routing table for the global routing table
show route vrf {VRF name} IP routing table for specified VRF
show route vrf {VRF name} afi-all IP routing table for specified VRF, both IPv4 and IPv6
show route vrf I2PX IP routing table for the I2PX VRF
show route vrf RE IP routing table for the RE VRF
show version Router platform, firmware version, and uptime
show vrf all Every VRF configured on the router, with its route distinguisher and route targets
traceroute Traceroute from the router to a supplied destination, using the global routing table
traceroute {IP address} Traceroute from router to destination IP address
traceroute vrf {VRF name} {IP address} Traceroute from router to destination IP address from specified VRF
traceroute vrf I2PX Traceroute to a supplied destination from the I2PX VRF
traceroute vrf RE Traceroute to a supplied destination from the RE VRF

Note

Commands run without a vrf argument use the global routing table, which primarily carries backbone and Loopback0 interfaces rather than production traffic — for most troubleshooting, specify a VRF. ping and traceroute are executed with read-only privileges, so options such as source, count, size, and df-bit are not available.

Note

show qos interface takes a different argument on each platform — IOS XR requires a direction, while EOS rejects one.

Platform Accepted Rejected
IOS XR show qos interface Gi0/0/0/0 input show qos interface Gi0/0/0/0 — % Incomplete command.
EOS show qos interface ethernet 1/1 show qos interface ethernet 1/1 input — % Invalid input

A query sends the same arguments to every selected node, so select one platform at a time when running show qos interface — in a mixed selection, the nodes on the other platform reject the command.

Throttling

The execution of Looking Glass commands is throttled in order to maximize the performance of the network.

Switching from Junos OS to IOS XR

Translating between Juniper and Cisco commands.

MCP server

An MCP server for Looking Glass is available at https://periscope.ns.internet2.edu/mcp. Add the MCP server to your AI agent to ask questions about the Internet2 network. The MCP server is capable of:

  • Listing devices
  • Listing valid commands, filters, and parameters
  • Executing commands

Using the MCP server

Refer to the documentation for your particular agent. Here are a few pointers:

Troubleshooting Virtual Networks route policy

A route policy on a peering (a Layer 3 Virtual Network Connection) is an inbound or outbound BGP policy on that peering's neighbor, inside the Virtual Network Router's VRF. To check whether a policy is doing what you intended, look at the routes on each side of it.

Address family Shows Command
Both Routing table, before outbound policy is applied show route vrf {VRF name} afi-all
IPv4 Routes received, before inbound policy is applied show bgp vrf {VRF name} ipv4 unicast neighbor {neighbor IP} received routes
IPv4 Routes accepted, after inbound policy is applied show bgp vrf {VRF name} ipv4 unicast neighbor {neighbor IP} routes
IPv4 Routes sent, after outbound policy is applied show bgp vrf {VRF name} ipv4 unicast neighbor {neighbor IP} advertised-routes
IPv6 Routes received, before inbound policy is applied show bgp vrf {VRF name} ipv6 unicast neighbor {neighbor IP} received routes
IPv6 Routes accepted, after inbound policy is applied show bgp vrf {VRF name} ipv6 unicast neighbor {neighbor IP} routes
IPv6 Routes sent, after outbound policy is applied show bgp vrf {VRF name} ipv6 unicast neighbor {neighbor IP} advertised-routes

Comparing two of these tells you which policy acted on a prefix:

  • A prefix in Routes received but not in Routes accepted was dropped by your inbound policy.
  • A prefix in the routing table but not in Routes sent was dropped by your outbound policy.

Note

Omit ipv4 unicast or ipv6 unicast and the command defaults to IPv4 unicast. Name the address family explicitly — it's required to see IPv6, and it keeps the output unambiguous.

Example

You have a peering with a cloud provider on Virtual Network Router 10431, and the provider says they aren't receiving one of your prefixes.

First, find the peering's neighbor address and confirm the session is up:

show bgp vrf VNROUTER-10431 ipv4 unicast summary
Neighbor        Spk    AS MsgRcvd MsgSent       TblVer  InQ OutQ  Up/Down  St/PfxRcd
192.0.2.2         0 64500  1548382 1506876   6636412228    0    0    1y22w          1

Then check what you are actually advertising to that neighbor:

show bgp vrf VNROUTER-10431 ipv4 unicast neighbor 192.0.2.2 advertised-routes
Network            Next Hop        From            AS Path
198.51.100.0/24    192.0.2.1       163.253.0.43    64496i
203.0.113.0/24     192.0.2.1       163.253.0.43    64496i

If the prefix is in show route vrf VNROUTER-10431 afi-all but missing here, your outbound policy is dropping it — review the policy assigned to the peering in Insight Console.

To check the other direction, compare what the peer sent against what you accepted:

show bgp vrf VNROUTER-10431 ipv4 unicast neighbor 192.0.2.2 received routes
show bgp vrf VNROUTER-10431 ipv4 unicast neighbor 192.0.2.2 routes

For the IPv6 side of the same peering, swap in ipv6 unicast and the peer's IPv6 address — find it with show bgp vrf VNROUTER-10431 ipv6 unicast summary.

Tip

Pipe any of these through a filter to focus on a single prefix, e.g. show bgp vrf VNROUTER-10431 ipv4 unicast neighbor 192.0.2.2 advertised-routes | include 203.0.113.