Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ipv6 Default gw from Provider seems wrong

Hi all,

 

currently I again started testing IPv6. Last time is a couple of months (and firmwares) ago with another Internet Provider and worked quite well.

Now with a Fresh Setup and new Provider I can't get it running with the following steps:

1. Enabled IPv6->Global
2. Interfaces -> WAN interface (eth1)-> enabled IPv6 Default GW

after a few seconds I got:
a) Interfaces & Routing
-> IPv6: Native over External -> assigned IPv6 from Provider (ZZZZ)
-> IPv6: Subnet -> /64 subnet (YYYY)
-> IPv6: Delegated Prefix -> /56 subnet (XXXX)

b) Interfaces & Routing
-> Interfaces overview: WAN Shows assigned IPv6 from Provider
But the Default ipv6 Gateway is : fe80::200:ff:fe00:0

 

Is that a correct entry??? I'm not sure 'bout that.

 

Moving Forward I tried pinging e.g. ipv6.google.com from the Shell -> working

2nd part: Enabling IPv6 on an internal interface::

- from the delegated prefix I created a few subnets (for different use-cases) and assigned one of them to the WLAN1 interface

 

Tried a ping6 from the CL using IF WLAN1 gave a "Network unreachable".

I checked the Routing table (Support -> Advanced -> Routes table) and found following IPv6 related entries:


unreachable default dev lo  table unspec  proto kernel  metric 4294967295  error -101
default via fe80::200:ff:fe00:0 dev ppp0  table default  proto kernel  metric 1024 
unreachable default dev lo  table unspec  proto kernel  metric 4294967295  error -101
XXXX:X:XXXX:XXXX::/64 dev wlan1  proto kernel  metric 256 
YYYY:Y:YYYY:YYYY::/64 dev ppp0  proto kernel  metric 256  expires 14397sec
fd32:5a88:8e98:2::/64 dev tun0  proto kernel  metric 256 
fe80::/64 dev redw2  proto kernel  metric 256 
fe80::/64 dev redw0  proto kernel  metric 256 
fe80::/64 dev redw1  proto kernel  metric 256 
fe80::/64 dev redw1.101  proto kernel  metric 256 
fe80::/64 dev redw2.101  proto kernel  metric 256 
fe80::/64 dev redw0.101  proto kernel  metric 256 
fe80::/64 dev redw1.100  proto kernel  metric 256 
fe80::/64 dev redw2.100  proto kernel  metric 256 
fe80::/64 dev redw0.100  proto kernel  metric 256 
fe80::/64 dev wlan0  proto kernel  metric 256 
fe80::/64 dev eth0.100  proto kernel  metric 256 
fe80::/64 dev eth0.120  proto kernel  metric 256 
fe80::/64 dev eth0.178  proto kernel  metric 256 
fe80::/64 dev eth1  proto kernel  metric 256 
fe80::/64 dev eth1.7  proto kernel  metric 256 
fe80::/64 dev wlan1  proto kernel  metric 256 
fe80::/10 dev ppp0  metric 1 
fe80::/10 dev ppp0  proto kernel  metric 256 
default via fe80::200:ff:fe00:0 dev ppp0  proto ra  metric 1024  expires 1797sec hoplimit 64
unreachable default dev lo  table unspec  proto kernel  metric 4294967295  error -101
local ::1 dev lo  table local  proto none  metric 0 
local XXXX:X:XXXX:XXXX:: dev lo  table local  proto none  metric 0 
local XXXX:X:XXXX:XXXX::1 dev lo  table local  proto none  metric 0 
local YYYY:Y:YYYY:YYYY:: dev lo  table local  proto none  metric 0 
local ZZZZ:Z:ZZZZ:ZZZZ:ZZZZ:ZZZZ:ZZZZ:ZZZZ dev lo  table local  proto none  metric 0 
local fd32:5a88:8e98:2:: dev lo  table local  proto none  metric 0 
local fd32:5a88:8e98:2::1 dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80:: dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:5c01 dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:5c01 dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:5c01 dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:5c01 dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:d000 dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:d000 dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:d000 dev lo  table local  proto none  metric 0 
local fe80::21a:8cff:fe0a:d000 dev lo  table local  proto none  metric 0 
local fe80::30b9:4fff:feab:1664 dev lo  table local  proto none  metric 0 
local fe80::6a05:caff:fe46:143a dev lo  table local  proto none  metric 0 
local fe80::6a05:caff:fe46:143a dev lo  table local  proto none  metric 0 
local fe80::6a05:caff:fe46:269e dev lo  table local  proto none  metric 0 
local fe80::6a05:caff:fe46:269e dev lo  table local  proto none  metric 0 
local fe80::6a05:caff:fe46:269e dev lo  table local  proto none  metric 0 
local fe80::9c97:6bff:fecc:cc29 dev lo  table local  proto none  metric 0 
local fe80::b09f:2eff:fe37:5458 dev lo  table local  proto none  metric 0 
local fe80::bc45:c1fe:3e2a:5f68 dev lo  table local  proto none  metric 0 
ff00::/8 dev redw2  table local  metric 256 
ff00::/8 dev redw0  table local  metric 256 
ff00::/8 dev redw1  table local  metric 256 
ff00::/8 dev redw1.101  table local  metric 256 
ff00::/8 dev redw2.101  table local  metric 256 
ff00::/8 dev redw0.101  table local  metric 256 
ff00::/8 dev redw1.100  table local  metric 256 
ff00::/8 dev redw2.100  table local  metric 256 
ff00::/8 dev redw0.100  table local  metric 256 
ff00::/8 dev wlan0  table local  metric 256 
ff00::/8 dev eth0  table local  metric 256 
ff00::/8 dev eth0.100  table local  metric 256 
ff00::/8 dev eth0.120  table local  metric 256 
ff00::/8 dev eth0.178  table local  metric 256 
ff00::/8 dev tun0  table local  metric 256 
ff00::/8 dev eth1  table local  metric 256 
ff00::/8 dev eth1.7  table local  metric 256 
ff00::/8 dev ppp0  table local  metric 256 
ff00::/8 dev wlan1  table local  metric 256 
unreachable default dev lo  table unspec  proto kernel  metric 4294967295  error -101

 


I already tried deleting all IPv6 related configuation made and disabled ipv6 GW and IPv6 (yesterday). Today I started from the Scratch (IPv6) but got stuck at the same Point.

Further steps like prefix advertisment or DHCPv6 will get interesting as soon as the ping would work from an internal interface, Right?


Hope s/o can Point me to the solution for this.

Kind regards,
LoD


This thread was automatically locked due to age.
  • Hi  

    Is the default IPv6 gateway fe80::200:ff:fe00:0 is provided from your ISP? I believe that's invalid IPv6. Please check with your ISP for that.

    Regards

    Jaydeep

  • Hi @ll,

    Hi Jaydeep,

    [First of: Could a mod move this to General discussion or Network and Routing, please? Guess it's not really Web Filter related. Sry ]

     

    it took some time testing Things. Had a long call with Telekom. They checked the protocol and told me on their side everything's fine. Unfortunately I'm still stuck with that problem. I -again- deleted everything I found concerning IPv6 and started from the Scratch:

     

    0. following IPv6 Networks are in use: 2002:1b:177f:b3bf:dfe:78bb:bb6a:ddfa/64 (WAN IPv6 assigned by Telekom) 2002:001b:1733:bf00:0000:0000:0000:0000/56 (Customer's LAN)

    2002:1b:1733:bf01::/64 (for use on LAN (eth0))
    2002:1b:1733:bfaf::/64 (for use on Guest-WLAN (wlan1))

    1. Enabling IPv6 (no Default IPv6 Gateway on WAN)
    -> getting an /64 IPv6 2002:1b:177f:b3bf:dfe:78bb:bb6a:ddfa/64 (-> Matches WAN ok)

    At this time IPv6 still Shows "None" connectivity ('cause IPv6 Default Gateway isn't checked yet ?)
    I Chose ipv6test.com to check. Pinging from UTM Shell from interface ppp0 is ok, all other interfaces not. (because of the missing Gateway again, I asume).

    Output of 'ip -6 route':

    2002:1b:1733:bf01::/64 dev eth0  proto kernel  metric 256
    2002:1b:1733:bf01::/64 dev ppp0  proto kernel  metric 256  expires 2590777sec
    2002:1b:1733:bfaf::/64 dev wlan1  proto kernel  metric 256
    2002:1b:177f:b3bf::/64 dev ppp0  proto kernel  metric 256  expires 14352sec
    fd32:5a88:8e98:2::/64 dev tun0  proto kernel  metric 256
    fe80::/64 dev redw2  proto kernel  metric 256
    fe80::/64 dev redw0  proto kernel  metric 256
    fe80::/64 dev redw1  proto kernel  metric 256
    fe80::/64 dev redw1.101  proto kernel  metric 256
    fe80::/64 dev redw2.101  proto kernel  metric 256
    fe80::/64 dev redw0.101  proto kernel  metric 256
    fe80::/64 dev redw1.100  proto kernel  metric 256
    fe80::/64 dev redw2.100  proto kernel  metric 256
    fe80::/64 dev redw0.100  proto kernel  metric 256
    fe80::/64 dev wlan0  proto kernel  metric 256
    fe80::/64 dev eth1  proto kernel  metric 256
    fe80::/64 dev eth1.7  proto kernel  metric 256
    fe80::/64 dev eth0.100  proto kernel  metric 256
    fe80::/64 dev eth0.120  proto kernel  metric 256
    fe80::/64 dev eth0.178  proto kernel  metric 256
    fe80::/64 dev wlan1  proto kernel  metric 256
    fe80::/10 dev ppp0  metric 1
    fe80::/10 dev ppp0  proto kernel  metric 256
    default via fe80::200:ff:fe00:0 dev ppp0  proto ra  metric 1024  expires 1150sec hoplimit 64

    At this Point the 'assumed-to-be-wrong' Default Gateway (fe80::200...) is already mentioned and I don't know where this is coming from and wether or not it's ok ?

    2. Enabled IPv6 Default Gateway on WAN
    WAN-Interface Shows the Default Gateway from above for IPv6
    IPv6 Status Show
        Native over External (WAN): 2002:1b:177f:b3bf:dfe:78bb:bb6a:ddfa
        Subnet: 2002:1b:177f:b3bf::/64
        Delegated Prefix: 2002:1b:1733:bf00::/56

    No changes on 'ip -6 route' though. Is that assumed to be correct?

    If I configure e.g. LAN interface with the 2002:1b:1733:bf01::1 I can ping6 from the Internet and vice versa. DHCPv6 and Stateless Server Integration don't work. I even don't see any request for IPv6. Maybe because of that Gateway?

    If needed I'll post additional Information/logs (didn't find a way to Quote or spoiler).

     

    Any help is really appreciated. Next step could be a test with the Telekom Speedlink router to see if it really is an issue with UTM.

     

     

    Greetinx

    LoD

  • Hi @ all.

     

    After testing and trying really a lot of things it turned out that the source of the issue were the Netgear switches. By default they have 'broadcast filtering' and 'IGMP filtering' turned on by default.

    Disabling those and IPv6 address assigning works now.

     

    The part with the fe80:: gateway does not have any negative influence on IPv6. Created some subnets for different VLANs and also this is working fine.

    By default IPv6 does NOT have a default gateway (found some info stating IPv6 clients get their default gateway from RA. But also with 'traditional' DHCPv6 no option for the default GW is offered).

     

    May be it helps another frustrated user with Netgear :-)

     

    Greetinx

    LoD