OPNsense Forum

English Forums => High availability => Topic started by: Wynbr00k on August 25, 2026, 07:47:50 PM

Title: OPNsense HA w/ IPv6 PD & Dual-Stack LAN Continuity Behind AT&T BGW320
Post by: Wynbr00k on August 25, 2026, 07:47:50 PM
OPNsense High Availability Behind AT&T BGW320
Preserving IPv6 Prefix Delegation (PD) and Dual‑Stack LAN Continuity

This document describes a working, tested method for running OPNsense 26.7.2 in a high-availability (HA) configuration behind an AT&T BGW320 gateway in passthrough mode, while maintaining:

• A stable IPv6 delegated prefix (IA-PD) across failover
• Consistent IPv6 SLAAC behavior
• Correct Router Advertisements (RA)
• dnsmasq SLAAC-glean AAAA/PTR synthesis
• Unbound recursion and local zones
• Dual-stack LAN continuity
• Seamless CARP failover and failback

The solution uses a single CARP syshook (30-wan-identity) to manage WAN identity, fencing, DHCPv6 behavior, radvd state, and IPv6 interface configuration.

----------------------------------------------------------------------
AT&T IPv6 PD Structure (Anonymized Example)
----------------------------------------------------------------------

AT&T assigns a /60:

    2600:1700:ffff:fff0::/60

Within this block:

• ...fff0::/64 — BGW LAN
• ...fff1::/64 through ...fff7::/64 — reserved
• ...fff8::/64 through ...ffff::/64 — delegated (highest handed out first)

With one IA_PD request, the delegated prefix is always:

    2600:1700:ffff:ffff::/64

This prefix is preserved across failover by ensuring only one firewall presents the WAN identity at any time.

----------------------------------------------------------------------
WAN Identity Model
----------------------------------------------------------------------

Both firewalls share:

• A virtual MAC (vMAC)
• A virtual DHCPv6 DUID (vDUID)

Only the CARP MASTER presents these values.
The BACKUP removes them and disables WAN IPv6 entirely.

This ensures AT&T always assigns the PD to the active MASTER.

----------------------------------------------------------------------
LAN IPv6 Model
----------------------------------------------------------------------

LAN IPv6 is provided via CARP VIPs:

• IPv6 link-local VIP (RA source)
• IPv6 GUA VIP (RDNSS + DNS AAAA)

dnsmasq provides:
• DHCPv4
• SLAAC gleaning (AAAA + PTR) (requires 'empty' DHCPv6 Range Configuration to enable gleaning)
• Local forward/reverse zones

radvd provides:
• Router Advertisements
• Prefix
• Gateway
• RDNSS

unbound provides:
• Recursion
• Local zones
• Reverse zones

dnsmasq RA lifetime is set to 0 to disable dnsmasq RA while preserving SLAAC gleaning.

----------------------------------------------------------------------
Failover Logic (Role-Accurate)
----------------------------------------------------------------------

MASTER → BACKUP

Box becoming BACKUP:
• Stops dhcp6c
• Clears vMAC
• Disables WAN IPv6
• Deletes vDUID
• Disables radvd
• Loses PD
• Becomes passive

Box becoming MASTER:
• Stops any lingering dhcp6c
• Performs fencing
• Restores vMAC
• Restores vDUID
• Enables WAN IPv6 (DHCPv6)
• Starts dhcp6c
• Enables radvd
• Gains PD
• Becomes active

AT&T assigns the PD to the box that becomes MASTER.

BACKUP → MASTER

Box becoming MASTER:
• Stops any lingering dhcp6c
• Performs fencing
• Restores vMAC
• Restores vDUID
• Enables WAN IPv6 (DHCPv6)
• Starts dhcp6c
• Enables radvd
• Gains PD
• Becomes active

Box becoming BACKUP:
• Stops dhcp6c
• Clears vMAC
• Disables WAN IPv6
• Deletes vDUID
• Disables radvd
• Loses PD
• Becomes passive

LAN IPv6 continuity is preserved throughout.

----------------------------------------------------------------------
The Syshook
----------------------------------------------------------------------

A single CARP syshook (30-wan-identity) handles:

• CARP role detection
• Fencing (passive + active)
• DHCPv6 teardown/restore
• vMAC/vDUID management
• WAN IPv6 enable/disable
• radvd model-level control
• Retry logic

This script is the core of the HA IPv6 solution.

----------------------------------------------------------------------
Notes
----------------------------------------------------------------------

• No DHCPv6 is used on LAN (pure SLAAC, IPv6 Mode - None)
• No authoritative unbound zones are used
• Only one syshook is required
• Potential to extend to multiple internal interfaces/vLANs (not tested here)

ymmv