User Tools

Site Tools


doc:appunti:net:ipv6_on_ppp

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
doc:appunti:net:ipv6_on_ppp [2026/09/25 16:56] – [Using a static addresses] niccolodoc:appunti:net:ipv6_on_ppp [2026/09/27 09:37] (current) – [Commands] niccolo
Line 561: Line 561:
 As stated above, the address autoamtically assigned to the **ppp0** interface may be **dynamic**, so we must use one of the addresses from the **delegated /56 prefix**. As stated above, the address autoamtically assigned to the **ppp0** interface may be **dynamic**, so we must use one of the addresses from the **delegated /56 prefix**.
  
-FIXME+In the configuration file **/etc/wide-dhcpv6/dhcp6c.conf** shown above we already defined the site-level aggregator ID 3 (**sla-id**) to be appended to the /56 prefix and the interface ID 1 (**ifid**) to obtain the full IPv6 address **2a02:2427:513:1c03::1** that is assigned to the **br0** interface. 
 + 
 +That IPv6 address is guaranteed to be static and assigned to the firewall, so you can use it for incoming connections and you can register it as an AAAA record in the DNS. But outgoiung IPv6 connections originating from the firewall itself use the ppp0 address, which may be dynamic. 
 + 
 +Therefore, we need a script that **sets the source IPv6 address** to the static address assigned to the **br0** interface, rather than the one dynamically assigned to the **ppp0** interface. This setting must be applied every time the ppp0 interface is activated, but only after the subnet delegation negotiation has completed. 
 + 
 +Here is the sample script  **/etc/wide-dhcpv6/dhcp6c-src-route**: 
 + 
 +<code bash> 
 +#!/bin/sh 
 +# /etc/wide-dhcpv6/dhcp6c-src-route   (chmod 755) 
 + 
 +# Execute first the default Debian script (DNS, etc.), if it exists. 
 +# We do not need this because the DNS is configured locally, not via DHCPv6. 
 +#[ -x /etc/wide-dhcpv6/dhcp6c-script ] && /etc/wide-dhcpv6/dhcp6c-script 
 + 
 +get_src() { 
 +    # Global address of br0, excluding those in DAD or deprecated. 
 +    ip -6 addr show dev br0 scope global -tentative -deprecated \ 
 +        | awk '/inet6/ {sub("/.*","",$2); print $2; exit}' 
 +} 
 + 
 +# It waits up to ~5 s for DAD to complete (a "tentative" address is 
 +# not accepted as the source address, and the command would fail). 
 +i=0 
 +SRC=$(get_src) 
 +while [ -z "$SRC" ] && [ $i -lt 10 ]; do 
 +    sleep 0.5 
 +    i=$((i+1)) 
 +    SRC=$(get_src) 
 +done 
 + 
 +[ -n "$SRC" ] || { logger -t dhcp6c-src "No valid IPv6 address on br0"; exit 0; } 
 + 
 +# Replaces (or adds, if it does not already exist) the default route with a metric of 100. 
 +ip -6 route replace default dev ppp0 metric 100 src "$SRC" \ 
 +    && logger -t dhcp6c-src "Default route via ppp0 with src $SRC" 
 +exit 0 
 +</code> 
 + 
 +To hook this script to the moment the IPv6 configuration is received, modify the **/etc/wide-dhcpv6/dhcp6c.conf** configuration file by replacing the default value of //script// in the //interface ppp0// section: 
 + 
 +<file> 
 +interface ppp0 { 
 +    # Send an option for "Identity Association for Prefix Delegation" with ID=0. 
 +    send ia-pd 0; 
 +    # Script executed when the daemon receives a reply message. 
 +    script "/etc/wide-dhcpv6/dhcp6c-src-route"; 
 +}; 
 +</file> 
 + 
 +If you need to call the default Debian hook script **/etc/wide-dhcpv6/dhcp6c-script** (used mainly to set the DNS nameserver on DHCPv6) you need to uncomment the relevant line in the scrtip above. 
 + 
 +You can see all the times that the script is executed (because the DHCPv6 lease renews) using the command: 
 + 
 +<code> 
 +journalctl --boot -t dhcp6c-src 
 +</code> 
 + 
 +===== Useful commands ===== 
 + 
 +Mostra la **rotta predefinita** per IPv6: 
 + 
 +<code> 
 +ip -6 route show default 
 +</code> 
 +<code> 
 +default dev ppp0 metric 1024 pref medium 
 +default via fe80::be26:c7ff:fe0d:8bc0 dev ppp0 proto ra metric 1024 expires 1775sec hoplimit 64 pref medium 
 +</code> 
 + 
 +La prima riga indica una rotta predefinita verso l'interfaccia ppp0 senza specificare un gateway (non serve per una interfaccia punto-punto). È stata creata insieme all'interfaccia ppp0 grazie al parametro ''defaultroute6'' di pppd. Non scade. 
 + 
 +La seconda riga viene istanziata durante la negoziazione del Router Advertisement (abbiamo ''accept_ra = 2'' su ppp0), è stata impostata sull'indirizzo IPv6 del gateway e viene rinegoziata periodicamente. Se la rinegoziazione dovesse fallire, la rotta sparisce. 
 + 
 +Visualizza l'**indirizzo IPv6 globale** per l'interfaccia br0: 
 + 
 +<code> 
 +ip -6 addr show dev br0 scope global 
 +</code> 
 +<code> 
 +5: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000 
 +    inet6 2a02:2420:503:1c03::1/64 scope global  
 +       valid_lft forever preferred_lft forever 
 +</code> 
 + 
 +Mostra la **rotta selezionata** e **indirizzo sorgente** per un indirizzo IPv6 remoto: 
 + 
 +<code> 
 +ip -6 route get 2a01:4f8:1c17:7636::1 
 +</code> 
 +<code> 
 +2a01:4f8:1c17:7636::1 from :: dev ppp0 src 2a02:2420:105:61::1 metric 1024 pref medium 
 +</code> 
 + 
 +**Imposta la rotta predefinita** IPv6 indicando l'indirizzo origine e una metrica bassa (il valore 100 viene preferito a quello delle rotte predefinite 1024): 
 + 
 +<code> 
 +ip -6 route add default dev ppp0 metric 100 src 2a02:2420:503:1c03::1 
 +</code> 
 +<code> 
 +2a01:4f8:1c17:7636::1 from :: dev ppp0 src 2a02:2420:105:61::1 metric 1024 pref medium 
 +</code>
  
 ===== MRU and MTU for PPPoE ===== ===== MRU and MTU for PPPoE =====
doc/appunti/net/ipv6_on_ppp.1790348218.txt.gz · Last modified: by niccolo