doc:appunti:net:ipv6_on_ppp
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| doc:appunti:net:ipv6_on_ppp [2026/09/27 06:58] – [Commands] niccolo | doc:appunti:net:ipv6_on_ppp [2026/09/27 09:37] (current) – [Commands] niccolo | ||
|---|---|---|---|
| Line 565: | Line 565: | ||
| That IPv6 address is guaranteed to be static and assigned to the firewall, so you can use it for incoming connections and you can register it as an AAAA record in the DNS. But outgoiung IPv6 connections originating from the firewall itself use the ppp0 address, which may be dynamic. | That IPv6 address is guaranteed to be static and assigned to the firewall, so you can use it for incoming connections and you can register it as an AAAA record in the DNS. But outgoiung IPv6 connections originating from the firewall itself use the ppp0 address, which may be dynamic. | ||
| + | Therefore, we need a script that **sets the source IPv6 address** to the static address assigned to the **br0** interface, rather than the one dynamically assigned to the **ppp0** interface. This setting must be applied every time the ppp0 interface is activated, but only after the subnet delegation negotiation has completed. | ||
| - | FIXME | + | Here is the sample script |
| - | ===== Commands | + | <code bash> |
| + | #!/bin/sh | ||
| + | # / | ||
| + | |||
| + | # Execute first the default Debian script (DNS, etc.), if it exists. | ||
| + | # We do not need this because the DNS is configured locally, not via DHCPv6. | ||
| + | #[ -x / | ||
| + | |||
| + | get_src() { | ||
| + | # Global address of br0, excluding those in DAD or deprecated. | ||
| + | ip -6 addr show dev br0 scope global -tentative -deprecated \ | ||
| + | | awk '/ | ||
| + | } | ||
| + | |||
| + | # It waits up to ~5 s for DAD to complete (a " | ||
| + | # not accepted as the source address, and the command would fail). | ||
| + | i=0 | ||
| + | SRC=$(get_src) | ||
| + | while [ -z " | ||
| + | sleep 0.5 | ||
| + | i=$((i+1)) | ||
| + | SRC=$(get_src) | ||
| + | done | ||
| + | |||
| + | [ -n " | ||
| + | |||
| + | # Replaces (or adds, if it does not already exist) the default route with a metric of 100. | ||
| + | ip -6 route replace default dev ppp0 metric 100 src " | ||
| + | && logger -t dhcp6c-src " | ||
| + | exit 0 | ||
| + | </ | ||
| + | |||
| + | To hook this script to the moment the IPv6 configuration is received, modify the **/ | ||
| + | |||
| + | < | ||
| + | interface ppp0 { | ||
| + | # Send an option for " | ||
| + | send ia-pd 0; | ||
| + | # Script executed when the daemon receives a reply message. | ||
| + | script "/ | ||
| + | }; | ||
| + | </ | ||
| + | |||
| + | If you need to call the default Debian hook script **/ | ||
| + | |||
| + | You can see all the times that the script is executed (because the DHCPv6 lease renews) using the command: | ||
| + | |||
| + | < | ||
| + | journalctl --boot -t dhcp6c-src | ||
| + | </ | ||
| + | |||
| + | ===== Useful commands | ||
| Mostra la **rotta predefinita** per IPv6: | Mostra la **rotta predefinita** per IPv6: | ||
| Line 579: | Line 631: | ||
| default via fe80:: | default via fe80:: | ||
| </ | </ | ||
| + | |||
| + | La prima riga indica una rotta predefinita verso l' | ||
| + | |||
| + | La seconda riga viene istanziata durante la negoziazione del Router Advertisement (abbiamo '' | ||
| Visualizza l' | Visualizza l' | ||
doc/appunti/net/ipv6_on_ppp.1790485110.txt.gz · Last modified: by niccolo
