OPNsense High Availability Behind AT&T BGW320
Preserving IPv6 Prefix Delegation (PD) and Dual‑Stack LAN Continuity
This document describes a working, tested method for running OPNsense 26.7.2 in a high-availability (HA) configuration behind an AT&T BGW320 gateway in passthrough mode, while maintaining:
• A stable IPv6 delegated prefix (IA-PD) across failover
• Consistent IPv6 SLAAC behavior
• Correct Router Advertisements (RA)
• dnsmasq SLAAC-glean AAAA/PTR synthesis
• Unbound recursion and local zones
• Dual-stack LAN continuity
• Seamless CARP failover and failback
The solution uses a single CARP syshook (30-wan-identity) to manage WAN identity, fencing, DHCPv6 behavior, radvd state, and IPv6 interface configuration.
----------------------------------------------------------------------
AT&T IPv6 PD Structure (Anonymized Example)
----------------------------------------------------------------------
AT&T assigns a /60:
2600:1700:ffff:fff0::/60
Within this block:
• ...fff0::/64 — BGW LAN
• ...fff1::/64 through ...fff7::/64 — reserved
• ...fff8::/64 through ...ffff::/64 — delegated (highest handed out first)
With one IA_PD request, the delegated prefix is always:
2600:1700:ffff:ffff::/64
This prefix is preserved across failover by ensuring only one firewall presents the WAN identity at any time.
----------------------------------------------------------------------
WAN Identity Model
----------------------------------------------------------------------
Both firewalls share:
• A virtual MAC (vMAC)
• A virtual DHCPv6 DUID (vDUID)
Only the CARP MASTER presents these values.
The BACKUP removes them and disables WAN IPv6 entirely.
This ensures AT&T always assigns the PD to the active MASTER.
----------------------------------------------------------------------
LAN IPv6 Model
----------------------------------------------------------------------
LAN IPv6 is provided via CARP VIPs:
• IPv6 link-local VIP (RA source)
• IPv6 GUA VIP (RDNSS + DNS AAAA)
dnsmasq provides:
• DHCPv4
• SLAAC gleaning (AAAA + PTR) (requires 'empty' DHCPv6 Range Configuration to enable gleaning)
• Local forward/reverse zones
radvd provides:
• Router Advertisements
• Prefix
• Gateway
• RDNSS
unbound provides:
• Recursion
• Local zones
• Reverse zones
dnsmasq RA lifetime is set to 0 to disable dnsmasq RA while preserving SLAAC gleaning.
----------------------------------------------------------------------
Failover Logic (Role-Accurate)
----------------------------------------------------------------------
MASTER → BACKUP
Box becoming BACKUP:
• Stops dhcp6c
• Clears vMAC
• Disables WAN IPv6
• Deletes vDUID
• Disables radvd
• Loses PD
• Becomes passive
Box becoming MASTER:
• Stops any lingering dhcp6c
• Performs fencing
• Restores vMAC
• Restores vDUID
• Enables WAN IPv6 (DHCPv6)
• Starts dhcp6c
• Enables radvd
• Gains PD
• Becomes active
AT&T assigns the PD to the box that becomes MASTER.
BACKUP → MASTER
Box becoming MASTER:
• Stops any lingering dhcp6c
• Performs fencing
• Restores vMAC
• Restores vDUID
• Enables WAN IPv6 (DHCPv6)
• Starts dhcp6c
• Enables radvd
• Gains PD
• Becomes active
Box becoming BACKUP:
• Stops dhcp6c
• Clears vMAC
• Disables WAN IPv6
• Deletes vDUID
• Disables radvd
• Loses PD
• Becomes passive
LAN IPv6 continuity is preserved throughout.
----------------------------------------------------------------------
The Syshook
----------------------------------------------------------------------
A single CARP syshook (30-wan-identity) handles:
• CARP role detection
• Fencing (passive + active)
• DHCPv6 teardown/restore
• vMAC/vDUID management
• WAN IPv6 enable/disable
• radvd model-level control
• Retry logic
This script is the core of the HA IPv6 solution.
----------------------------------------------------------------------
Notes
----------------------------------------------------------------------
• No DHCPv6 is used on LAN (pure SLAAC, IPv6 Mode - None)
• No authoritative unbound zones are used
• Only one syshook is required
• Potential to extend to multiple internal interfaces/vLANs (not tested here)
ymmv