This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM behind another UTM: DHCPv6 broken?

My UTM is configured for IPv6 and hands out addresses via DHCPv6 (Stateful Address Configuration) out of a /64 subnet.

Internal IPv6 enabled clients successfully get an address from the master UTM.

Now I have another UTM for testing purposes. It has only 1 interface in the master's Internal network. When I enable IPv6 on the client UTM and configure its interface for "Dynamic IP" it only gets an IPv4 address but no IPv6.

When I change the master UTM to hand out addresses stateless (disable DHCPv6 and enable "Stateless integrated server" at the Prefix Advertisement for Internal Network) the client UTM can successfully configure for an IPv6 address.

DHCP-Server log from master UTM:

2015:11:09-14:32:47 vpn-1 dhcpd6: Solicit message from <link local IPv6 address of client UTM> port 546, transaction ID 0xEF6EB600
2015:11:09-14:32:47 vpn-1 dhcpd6: Reply NA: address <DHCPv6 address for client UTM> to client with duid <Client UTM DUID> iaid = 1565592081 valid for 86400 seconds
2015:11:09-14:32:47 vpn-1 dhcpd6: Unable to pick client prefix: no IPv6 pools on this shared network
2015:11:09-14:32:47 vpn-1 dhcpd6: Sending Reply to <link local IPv6 address of client UTM> port 546

System Log from client UTM:

2015:11:09-14:49:32 utm-test dhclient6: XMT: Solicit on eth1, interval 116590ms.
2015:11:09-14:49:32 utm-test dhclient6: RCV: Reply message on eth1 from <link local IPv6 address of master UTM>.
2015:11:09-14:49:32 utm-test dhclient6: IA_PD status code NoPrefixAvail: "No prefixes available for this interface."

Seems like the client UTM is requesting an own prefix which the master cannot hand out.

How do I convince the master UTM to hand out an IPv6 address to the client UTM?



This thread was automatically locked due to age.
  • Just trying to get some attention on this thread again... :-)

    Any cc actions or config file magic I can do?

    ----------
    Sophos user, admin and reseller.
    Private Setup:

    • XG: HPE DL20 Gen9 (Core i3-7300, 8GB RAM, 120GB SSD) | XG 18.0 (Home License) with: Web Protection, Site-to-Site-VPN (IPSec, RED-Tunnel), Remote Access (SSL, HTML5)
    • UTM: 2 vCPUs, 2GB RAM, 50GB vHDD, 2 vNICs on vServer (KVM) | UTM 9.7 (Home License) with: Email Protection, Webserver Protection, RED-Tunnel (server)