Set SRv6 Tunnel Sources and HMAC Keys with ip sr
You will finish with a controlled way to inspect and configure the IPv6 Segment Routing (SRv6) internal parameters managed by ip sr: the tunnel source address and the HMAC key mapping. The examples match the installed iproute2 package, version 6.1.0-1ubuntu6.4, whose ip utility reports version 6.1.0.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes, plus time to confirm the address and key details with whoever operates the rest of the SRv6 network. You need an IPv6-enabled Linux host with iproute2. Read-only inspection may require elevated privilege on your host. Setting either parameter changes kernel networking state, so use a maintenance window and record the previous values before you change anything.
1. Confirm the installed command
Start with an ordinary local version check. This does not change networking state:
$ command -v ip
/usr/sbin/ip
$ ip -V
ip utility, iproute2-6.1.0, libbpf 1.3.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4
The manpage calls the command group ip sr. Its supported operations are deliberately small: hmac show, hmac set, tunsrc show, and tunsrc set. Do not add flags copied from another ip object unless the installed help or manpage documents them for this group.
2. Inspect the current tunnel source
Read the current source before planning a change:
$ sudo ip sr tunsrc show
On the machine used for this guide, the same command without privilege returned RTNETLINK answers: Operation not permitted. That is a host-specific permission result, not evidence that the setting is absent. Retry with the privilege required by your system's network administration policy. If the command still fails, stop and investigate the kernel, SRv6 support and the privilege boundary before changing anything.
The default tunnel source is ::. With that value, the egress interface's address is selected for encapsulated packets. The manpage warns that this selection may hinder performance and recommends a non-default source. A non-default address must be valid for the host and appropriate for the route and interface that will carry the encapsulated traffic.
Checkpoint
Record the exact value printed by tunsrc show. You need it for recovery if the new source causes a routing or reachability problem.
3. Set a deliberate tunnel source
Replacing 2001:db8::1 below with a real, approved local IPv6 address changes the source used for SRv6 encapsulation:
$ sudo ip sr tunsrc set 2001:db8::1
$ sudo ip sr tunsrc show
Use the second command as the verification step. The output format is supplied by the installed utility, so compare the displayed address with the value you requested rather than relying on an assumed heading or punctuation.
This operation is not a per-route setting. It changes the internal SRv6 tunnel source used by the host. Check the address on the intended interface first, and check the routing design before applying it to a production node. A source address that is not usable on the relevant path can make encapsulated traffic fail or become difficult to return.
To undo this example and return to the documented default, set the source to the unspecified address:
$ sudo ip sr tunsrc set ::
$ sudo ip sr tunsrc show
That restores automatic selection from the egress interface. It also restores the performance trade-off described by the manpage, so treat it as a rollback, not automatically as the best final configuration.
4. Inspect the HMAC mapping
SRv6 HMAC configuration maps a numeric key ID to a supported hashing algorithm and a secret. Inspect the existing mapping before adding or replacing one:
$ sudo ip sr hmac show
Keep the output private. It describes security-sensitive configuration, and the corresponding secret must not be pasted into a terminal transcript, ticket or shell history. If an unprivileged run is denied, use the same carefully controlled privilege escalation as for tunsrc show.
The supported algorithms documented on this installation are sha1 and sha256. The command does not take the secret as a command-line argument. That is useful because command arguments can be exposed through process inspection and logging.
5. Add or replace one HMAC mapping
Security warning
This step changes kernel security configuration and prompts for a secret. Obtain the key ID, algorithm and passphrase through your approved key-management process. Do not use the example ID or a real secret copied into a script:
$ sudo ip sr hmac set 42 sha256
Password:
The prompt is for the HMAC passphrase, not necessarily the account password. Type it interactively, then verify the mapping with:
$ sudo ip sr hmac show
Use a key ID that does not collide with a mapping used by the peer configuration. The command supports only the two algorithms named above on this installation. If the operation reports an unsupported algorithm, correct the algorithm choice instead of guessing another spelling.
A blank passphrase removes the mapping for that key ID. That is the documented undo action, but it is still a security-sensitive change. Before using it, confirm the ID and understand whether active traffic or another process depends on the mapping:
$ sudo ip sr hmac set 42 sha256
Password: [press Enter at the passphrase prompt]
$ sudo ip sr hmac show
Do not put a passphrase in a shell command, environment variable or configuration file merely to automate this interaction. If unattended key rotation is required, design it around the platform's documented interface and secret-handling controls rather than exposing the value to ordinary process or file inspection.
6. Separate verification from troubleshooting
Run both show commands after a planned change:
$ sudo ip sr tunsrc show
$ sudo ip sr hmac show
If either command fails, capture its exit status immediately and keep the original error text:
$ sudo ip sr tunsrc show
$ status=$?
$ printf 'tunsrc show exit status: %s\n' "$status"
Do not treat an empty-looking result, a permission error and a missing SRv6 capability as the same condition. Check the command's status, the kernel and the privileges available to the network administrator. Review ip-route(8) as the next local reference for the route and encapsulation side of SRv6; ip-sr(8) only covers these internal parameters.
Done means
- You confirmed the installed
iproute2version and theip srcommand shape. - You recorded the previous tunnel source before changing it.
- You set and re-read a deliberate source address, or restored
::as the rollback. - You treated HMAC IDs, algorithms and passphrases as security-sensitive configuration.
- You verified the HMAC mapping without putting its secret on the command line.
- You know that a blank HMAC passphrase removes the mapping and that source
::restores automatic address selection.