Looking Glass¶
Looking Glass lets you run commands on Internet2 routers.
Usage¶
- Select one or more nodes in the node list
- Type your query and press enter
- Select a node in the node list to view its output
Supported commands¶
Commands must be typed exactly as they appear in the Supported Commands sidebar; the shortened versions (i.e. desc instead of description) will not work.
Tip
The list of supported commands (along with their platforms) is available under Supported Commands in the right sidebar.
Supported operators¶
|- the pipe modifier passes a command's output through a built-in filter such asincludeorexcludeso you only see the lines you asked for instead of the full output.
VRF names¶
| VRF name | Description |
|---|---|
I2PX |
Internet2 Peering Exchange — Internet2's Layer 3 service giving members access to commercial peers (e.g. Google, Zoom, Netflix) and commodity internet; also carries Internet2's paid upstream transit routes for authorized services. |
RE |
Research & Education — Internet2's private Layer 3 network enabling connectivity among members of the R&E community, including connectors, participants, and national/international R&E network peers (e.g. GÉANT, ESnet, regional networks). |
BLENDED |
A combined view of the R&E and I2PX routing tables plus full transit routes, letting connectors reach both worlds over a single connection and BGP session. |
LHCONE |
Large Hadron Collider Open Network Environment — a dedicated overlay for LHC experiment data movement between participating sites, peering with ESnet, GÉANT, CANARIE, and other R&E networks at Internet2's exchange points. |
SCRUBBING |
DDoS Volumetric Mitigation Service (AS396450) — prefixes under attack are diverted into this VRF and routed through Radware's scrubbing centers, which return clean traffic to the subscriber. |
Virtual Network Routers each get their own VRF, named VNROUTER-{Router ID}. Retrieve the Router ID from the Insight Console Virtual Network Router information.
Examples¶
| Command | Description |
|---|---|
ping |
Ping from the router to a supplied destination, using the global routing table |
ping {IP address} |
Ping destination IP address |
ping vrf {VRF name} {IP address} |
Ping destination IP address from specified VRF |
ping vrf I2PX |
Ping a supplied destination from the I2PX VRF |
ping vrf RE |
Ping a supplied destination from the RE VRF |
show bfd |
Bidirectional Forwarding Detection session state, used for fast detection of link failures |
show bgp |
BGP table for the global routing table |
show bgp vrf {VRF name} summary |
Show BGP summary for specified VRF |
show bgp vrf {VRF name} neighbors |
Show BGP neighbors for specified VRF |
show bgp vrf {VRF name} {address family} neighbor {neighbor IP} received routes |
Routes received from a neighbor, before inbound route policy. Address family is ipv4 unicast or ipv6 unicast |
show bgp vrf {VRF name} {address family} neighbor {neighbor IP} routes |
Routes accepted from a neighbor, after inbound route policy |
show bgp vrf {VRF name} {address family} neighbor {neighbor IP} advertised-routes |
Routes advertised to a neighbor, after outbound route policy |
show bgp vrf I2PX summary |
BGP neighbor state and prefix counts for the I2PX VRF |
show bgp vrf I2PX neighbors |
Detailed BGP neighbor information for the I2PX VRF, including accepted and denied prefixes |
show bgp vrf I2PX |
BGP table for the I2PX VRF |
show bgp vrf RE summary |
BGP neighbor state and prefix counts for the RE VRF |
show bgp vrf RE neighbors |
Detailed BGP neighbor information for the RE VRF, including accepted and denied prefixes |
show bgp vrf RE |
BGP table for the RE VRF |
show cef |
Cisco Express Forwarding table — the forwarding entries used to switch packets (IOS XR only) |
show controllers |
Controller statistics for physical interfaces, including optics and link-layer errors (IOS XR only) |
show interfaces |
Interface status, addressing, and traffic and error counters |
show lacp |
LACP state for the members of each link bundle |
show lldp neighbors |
Directly connected neighbors discovered via LLDP, and the ports connecting them |
show l2vpn xconnect |
Point-to-point Layer 2 circuits (cross-connects) and their state (IOS XR only) |
show l2vpn bridge-domain group {Group ID} |
Retrieve the Group ID from the Insight Console Virtual Network Switch information |
show policy-map interface {interface} |
QoS service policy applied to the specified interface |
show qos interface {interface} {direction} |
QoS interface-level configuration for the specified interface, on IOS XR. Direction is input or output |
show qos interface {interface} |
QoS interface-level configuration for the specified interface, on Arista EOS |
show route |
IP routing table for the global routing table |
show route vrf {VRF name} |
IP routing table for specified VRF |
show route vrf {VRF name} afi-all |
IP routing table for specified VRF, both IPv4 and IPv6 |
show route vrf I2PX |
IP routing table for the I2PX VRF |
show route vrf RE |
IP routing table for the RE VRF |
show version |
Router platform, firmware version, and uptime |
show vrf all |
Every VRF configured on the router, with its route distinguisher and route targets |
traceroute |
Traceroute from the router to a supplied destination, using the global routing table |
traceroute {IP address} |
Traceroute from router to destination IP address |
traceroute vrf {VRF name} {IP address} |
Traceroute from router to destination IP address from specified VRF |
traceroute vrf I2PX |
Traceroute to a supplied destination from the I2PX VRF |
traceroute vrf RE |
Traceroute to a supplied destination from the RE VRF |
Note
Commands run without a vrf argument use the global routing table, which primarily carries backbone and Loopback0 interfaces rather than production traffic — for most troubleshooting, specify a VRF. ping and traceroute are executed with read-only privileges, so options such as source, count, size, and df-bit are not available.
Note
show qos interface takes a different argument on each platform — IOS XR requires a direction, while EOS rejects one.
| Platform | Accepted | Rejected |
|---|---|---|
| IOS XR | show qos interface Gi0/0/0/0 input |
show qos interface Gi0/0/0/0 — % Incomplete command. |
| EOS | show qos interface ethernet 1/1 |
show qos interface ethernet 1/1 input — % Invalid input |
A query sends the same arguments to every selected node, so select one platform at a time when running show qos interface — in a mixed selection, the nodes on the other platform reject the command.
Throttling¶
The execution of Looking Glass commands is throttled in order to maximize the performance of the network.
Switching from Junos OS to IOS XR¶
Translating between Juniper and Cisco commands.
- Cisco IOS command's equivalent in JUNOS
- Cisco IOS Commands vs Juniper Junos Commands
- Configuration Commands for Cisco, Juniper, Nokia and Huawei
MCP server¶
An MCP server for Looking Glass is available at https://periscope.ns.internet2.edu/mcp. Add the MCP server to your AI agent to ask questions about the Internet2 network. The MCP server is capable of:
- Listing devices
- Listing valid commands, filters, and parameters
- Executing commands
Using the MCP server¶
Refer to the documentation for your particular agent. Here are a few pointers:
- Claude Desktop - Get started with custom connectors using remote MCP
- Claude Code - Connect to MCP servers
- ChatGPT - Connect from ChatGPT
- Gemini CLI - MCP servers with Gemini CLI
Troubleshooting Virtual Networks route policy¶
A route policy on a peering (a Layer 3 Virtual Network Connection) is an inbound or outbound BGP policy on that peering's neighbor, inside the Virtual Network Router's VRF. To check whether a policy is doing what you intended, look at the routes on each side of it.
| Address family | Shows | Command |
|---|---|---|
| Both | Routing table, before outbound policy is applied | show route vrf {VRF name} afi-all |
| IPv4 | Routes received, before inbound policy is applied | show bgp vrf {VRF name} ipv4 unicast neighbor {neighbor IP} received routes |
| IPv4 | Routes accepted, after inbound policy is applied | show bgp vrf {VRF name} ipv4 unicast neighbor {neighbor IP} routes |
| IPv4 | Routes sent, after outbound policy is applied | show bgp vrf {VRF name} ipv4 unicast neighbor {neighbor IP} advertised-routes |
| IPv6 | Routes received, before inbound policy is applied | show bgp vrf {VRF name} ipv6 unicast neighbor {neighbor IP} received routes |
| IPv6 | Routes accepted, after inbound policy is applied | show bgp vrf {VRF name} ipv6 unicast neighbor {neighbor IP} routes |
| IPv6 | Routes sent, after outbound policy is applied | show bgp vrf {VRF name} ipv6 unicast neighbor {neighbor IP} advertised-routes |
Comparing two of these tells you which policy acted on a prefix:
- A prefix in Routes received but not in Routes accepted was dropped by your inbound policy.
- A prefix in the routing table but not in Routes sent was dropped by your outbound policy.
Note
Omit ipv4 unicast or ipv6 unicast and the command defaults to IPv4 unicast. Name the address family explicitly — it's required to see IPv6, and it keeps the output unambiguous.
Example¶
You have a peering with a cloud provider on Virtual Network Router 10431, and the provider says they aren't receiving one of your prefixes.
First, find the peering's neighbor address and confirm the session is up:
Neighbor Spk AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down St/PfxRcd
192.0.2.2 0 64500 1548382 1506876 6636412228 0 0 1y22w 1
Then check what you are actually advertising to that neighbor:
Network Next Hop From AS Path
198.51.100.0/24 192.0.2.1 163.253.0.43 64496i
203.0.113.0/24 192.0.2.1 163.253.0.43 64496i
If the prefix is in show route vrf VNROUTER-10431 afi-all but missing here, your outbound policy is dropping it — review the policy assigned to the peering in Insight Console.
To check the other direction, compare what the peer sent against what you accepted:
show bgp vrf VNROUTER-10431 ipv4 unicast neighbor 192.0.2.2 received routes
show bgp vrf VNROUTER-10431 ipv4 unicast neighbor 192.0.2.2 routes
For the IPv6 side of the same peering, swap in ipv6 unicast and the peer's IPv6 address — find it with show bgp vrf VNROUTER-10431 ipv6 unicast summary.
Tip
Pipe any of these through a filter to focus on a single prefix, e.g. show bgp vrf VNROUTER-10431 ipv4 unicast neighbor 192.0.2.2 advertised-routes | include 203.0.113.