User Tools

Site Tools


doc:appunti:net:ipv6_on_ppp

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
doc:appunti:net:ipv6_on_ppp [2026/09/27 06:58] – [Commands] niccolodoc:appunti:net:ipv6_on_ppp [2026/09/27 09:37] (current) – [Commands] niccolo
Line 565: Line 565:
 That IPv6 address is guaranteed to be static and assigned to the firewall, so you can use it for incoming connections and you can register it as an AAAA record in the DNS. But outgoiung IPv6 connections originating from the firewall itself use the ppp0 address, which may be dynamic. That IPv6 address is guaranteed to be static and assigned to the firewall, so you can use it for incoming connections and you can register it as an AAAA record in the DNS. But outgoiung IPv6 connections originating from the firewall itself use the ppp0 address, which may be dynamic.
  
 +Therefore, we need a script that **sets the source IPv6 address** to the static address assigned to the **br0** interface, rather than the one dynamically assigned to the **ppp0** interface. This setting must be applied every time the ppp0 interface is activated, but only after the subnet delegation negotiation has completed.
  
-FIXME+Here is the sample script  **/etc/wide-dhcpv6/dhcp6c-src-route**:
  
-===== Commands =====+<code bash> 
 +#!/bin/sh 
 +# /etc/wide-dhcpv6/dhcp6c-src-route   (chmod 755) 
 + 
 +# Execute first the default Debian script (DNS, etc.), if it exists. 
 +# We do not need this because the DNS is configured locally, not via DHCPv6. 
 +#[ -x /etc/wide-dhcpv6/dhcp6c-script ] && /etc/wide-dhcpv6/dhcp6c-script 
 + 
 +get_src() { 
 +    # Global address of br0, excluding those in DAD or deprecated. 
 +    ip -6 addr show dev br0 scope global -tentative -deprecated \ 
 +        | awk '/inet6/ {sub("/.*","",$2); print $2; exit}' 
 +} 
 + 
 +# It waits up to ~5 s for DAD to complete (a "tentative" address is 
 +# not accepted as the source address, and the command would fail). 
 +i=0 
 +SRC=$(get_src) 
 +while [ -z "$SRC" ] && [ $i -lt 10 ]; do 
 +    sleep 0.5 
 +    i=$((i+1)) 
 +    SRC=$(get_src) 
 +done 
 + 
 +[ -n "$SRC" ] || { logger -t dhcp6c-src "No valid IPv6 address on br0"; exit 0; } 
 + 
 +# Replaces (or adds, if it does not already exist) the default route with a metric of 100. 
 +ip -6 route replace default dev ppp0 metric 100 src "$SRC" \ 
 +    && logger -t dhcp6c-src "Default route via ppp0 with src $SRC" 
 +exit 0 
 +</code> 
 + 
 +To hook this script to the moment the IPv6 configuration is received, modify the **/etc/wide-dhcpv6/dhcp6c.conf** configuration file by replacing the default value of //script// in the //interface ppp0// section: 
 + 
 +<file> 
 +interface ppp0 { 
 +    # Send an option for "Identity Association for Prefix Delegation" with ID=0. 
 +    send ia-pd 0; 
 +    # Script executed when the daemon receives a reply message. 
 +    script "/etc/wide-dhcpv6/dhcp6c-src-route"; 
 +}; 
 +</file> 
 + 
 +If you need to call the default Debian hook script **/etc/wide-dhcpv6/dhcp6c-script** (used mainly to set the DNS nameserver on DHCPv6) you need to uncomment the relevant line in the scrtip above. 
 + 
 +You can see all the times that the script is executed (because the DHCPv6 lease renews) using the command: 
 + 
 +<code> 
 +journalctl --boot -t dhcp6c-src 
 +</code> 
 + 
 +===== Useful commands =====
  
 Mostra la **rotta predefinita** per IPv6: Mostra la **rotta predefinita** per IPv6:
Line 579: Line 631:
 default via fe80::be26:c7ff:fe0d:8bc0 dev ppp0 proto ra metric 1024 expires 1775sec hoplimit 64 pref medium default via fe80::be26:c7ff:fe0d:8bc0 dev ppp0 proto ra metric 1024 expires 1775sec hoplimit 64 pref medium
 </code> </code>
 +
 +La prima riga indica una rotta predefinita verso l'interfaccia ppp0 senza specificare un gateway (non serve per una interfaccia punto-punto). È stata creata insieme all'interfaccia ppp0 grazie al parametro ''defaultroute6'' di pppd. Non scade.
 +
 +La seconda riga viene istanziata durante la negoziazione del Router Advertisement (abbiamo ''accept_ra = 2'' su ppp0), è stata impostata sull'indirizzo IPv6 del gateway e viene rinegoziata periodicamente. Se la rinegoziazione dovesse fallire, la rotta sparisce.
  
 Visualizza l'**indirizzo IPv6 globale** per l'interfaccia br0: Visualizza l'**indirizzo IPv6 globale** per l'interfaccia br0:
doc/appunti/net/ipv6_on_ppp.1790485110.txt.gz · Last modified: by niccolo