Quote from: stanthewizzard on January 19, 2026, 07:44:48 PMISC DHCPv6 gives wan routable ipv6 from my ISP [...] to other devices
Quote from: Patrick M. Hausen on January 18, 2026, 11:35:58 PMI have only ever seen these:ahcicho 0: Timeout on slot 7 port 0
CAM Status: Command Timeout
Retrying command, 2 more tries remain
with dying devices. If I saw that in a new unit I would never put that into production before I had successfully eliminated the cause. Timeouts in the CAM subsystem must not happen. If they do, something is broken. Never ignore them.
What do you mean by "vanilla" and "backwards compatible"? Save the configuration from your current unit, fix the hardware, install the very same version, restore configuration ...
Quote from: franco on January 19, 2026, 04:05:14 AMThe firmware health audit can probably confirm?Not sure if there is one, I already ordered a replacement so will replace and see how it goes. Hopefully the reboot will be instant compared to the current one where it takes quite a while to reboot.
Quote from: meyergru on January 19, 2026, 07:25:10 PMQuote from: stanthewizzard on January 19, 2026, 07:13:54 PMevery server inside the lan (homelab) has a statiq IP fddd:31e8:3076:XX:YY
DHCPv6 with prefix and RA managed on carpv6 (also updated with IPv6 changes) and RA advertises fddd:31e8:3076:XX:YY
Do not send any DNS configuration to clients
fddd:31e8:3076:: is an ULA prefix that is not routed outside of your LAN, unless you use NAT66 or you still have the assigned GUA prefix IPv6s on top for outside access. If you use those ULA IPs for server access, fine.
But then, why / how do you rely on ISC DHCPv6?
I can see only two things it could provide: routeable IPv6 addresses, which can be handed out via SLAAC as well and leases and/or reservations which allow to use internal DNS names (which you say you do not use).
Frankly, I do not get what you are missing.
Quote from: uneu on January 19, 2026, 06:14:50 PMHast du ein WAN-GW (IP-Adresse der Fritzbox) eingetragen?Wie konnte das denn passieren. Man sollte das nicht mal eben so nebenbei versuchen.
Quote from: meyergru on January 19, 2026, 07:15:10 PMUnd ja, das WAN-Gateway (wahrscheinlich 192.168.178.1) fehlt. Das wäre alles korrekt, wenn Du auf dem WAN nicht Static IP, sondern DHCPv4 eingestellt hättest.
Vielleicht liest Du mal dies: https://forum.opnsense.org/index.php?topic=39556
Quote from: stanthewizzard on January 19, 2026, 07:13:54 PMevery server inside the lan (homelab) has a statiq IP fddd:31e8:3076:XX:YY
DHCPv6 with prefix and RA managed on carpv6 (also updated with IPv6 changes) and RA advertises fddd:31e8:3076:XX:YY
Do not send any DNS configuration to clients
Quote from: Monviech (Cedrik) on January 19, 2026, 10:17:50 AMIf you have a changing prefix use dnsmasq for dhcpv6, it can construct from a partial prefix:
https://docs.opnsense.org/manual/dnsmasq.html#dhcpv6-and-router-advertisements
Quote from: meyergru on January 19, 2026, 10:19:58 AMThere is a problem with your approach with ISC DHCPv6 as well: The prefix change will potentially go unnoticed for as long as your lease time, because your clients will use the old prefix for as long.
With dynamic IPv6 prefixes, you basically have two choices:
a. Use SLAAC in "assisted" mode, where DHCPv6 only supplies the DNS server (besides RDNSS) - if at all, because DNSv4 is sufficient to supply both IPv4 and IPv6 resolution. This is the safest/easiest approach and shown here. Any local traffic is done via IPv4, such that you do not need DHCPv6 to supply specific IPv6 to your devices in order to adress those in DNS.
b. If you need to have fixed IPv6, you will need to use some adresses on top of GUA that you can use for internal DNS purposes. Keep in mind that LUA will probably not work, because it is prioritized lower than even IPv4. Still, you can use any unused IPv6 prefix.