Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

IPv6 - Two addresses being issued by XG Firewall DHCPv6 server?

I've been looking at a strange issue on my devices regarding IPv6 addressing (at least an issue I think is strange).  I am not using SLAAC.  I have a Sophos XG acting as a DHCPv6 server issuing a private IPv6 prefix, let's call it AAAA:AAAA:AAAA:AAAA:.  All of my devices have that address, but they also have another address with a completely different prefix, let's call it  fdc9:BBBB:BBBB:BBBB:.  The fdc9:BBBB:BBBB:BBBB: prefix is not a link-local address.  It is listed as a separate second IPv6 address that is the same across all my devices in addition to the link-local address.  I've gone through all the firewall settings and there is no reference to this second IPv6 prefix anywhere.

Could there be a "hidden" configuration file on the XG that is sending out this prefix?  It is not part of my router advertisement where I also have the "autonomous" flag cleared (unchecked).

A new Windows vNext server install also has this fdc9:BBBB:BBBB:BBBB: prefix, so it doesn't seem to be a legacy item on the devices/computers.

Since the prefix is the same for all the devices, it seems to me that the Sophos XG DHCPv6 server is issuing it unless I am missing something obvious.

Thanks.



Added TAGs
[edited by: Erick Jan at 1:03 AM (GMT -7) on 8 Apr 2024]
Parents
  • Ok, figured this out.

    I did a tcpdump command from my iMac terminal and found two IPv6 link-local addresses sending router advertisements.  I looked through the arp table on Sophos, but didn't not find the link-local addresses listed.

    I then used netsh command on my windows server to list its arp table.  It had the link-local addresses with MAC addresses.  One address was the Sophos XG, the other one of my AppleTVs.  I have a few AppleTVs and the other ones don't do this.  I have no idea why this one wants to send clutter.

    Now the task of disabling/blocking the router advertisements from the AppleTV.

Reply
  • Ok, figured this out.

    I did a tcpdump command from my iMac terminal and found two IPv6 link-local addresses sending router advertisements.  I looked through the arp table on Sophos, but didn't not find the link-local addresses listed.

    I then used netsh command on my windows server to list its arp table.  It had the link-local addresses with MAC addresses.  One address was the Sophos XG, the other one of my AppleTVs.  I have a few AppleTVs and the other ones don't do this.  I have no idea why this one wants to send clutter.

    Now the task of disabling/blocking the router advertisements from the AppleTV.

Children
  • Assuming you are using v20 GA then you will get two real IPv6 addresses assigned when using DHCP. If you move to static addressing from the DHCP server you only get one address assigned. My Apple TV causes me some grief after I enabled wifi for testing. 

    Ian

    XG115W - v20.0.1 MR-1 - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.