Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
Incomplete CARP IPv6 neighbour discovery from client side
« previous
next »
Print
Pages: [
1
]
Author
Topic: Incomplete CARP IPv6 neighbour discovery from client side (Read 1173 times)
Hypocrisy7186
Newbie
Posts: 11
Karma: 0
Incomplete CARP IPv6 neighbour discovery from client side
«
on:
June 01, 2023, 09:46:02 am »
When attempting to ping a CARP IPv6 address on the same VLAN from a client machine I get "Destination unreachable: Address unreachable". The output of "ip -6 neigh show" show the following "x:x:x:5::1 dev br0 INCOMPLETE". Packet capture on the OPNsense instance that hosts the CARP IPv6 address shows "ICMP6, neighbor solicitation" but no ICMP6 responses. I've attached my network diagram to this post.
If I add a static entry with "sudo ip -6 neigh add x:x:x:5::1 lladdr 00:e2:69:63:f7:00 nud permanent dev br0" The ping completes until I remove the static entry. Not sure what else to try to resolve this issue?
Logged
Hypocrisy7186
Newbie
Posts: 11
Karma: 0
Re: Incomplete CARP IPv6 neighbour discovery from client side
«
Reply #1 on:
June 02, 2023, 08:33:06 am »
Just to added to the above the IPv4 CARP address is pingable on the same VLAN. This just effect IPv6 CARP address
Logged
franco
Administrator
Hero Member
Posts: 17668
Karma: 1611
Re: Incomplete CARP IPv6 neighbour discovery from client side
«
Reply #2 on:
June 02, 2023, 10:29:06 am »
Maybe going down a rabbit hole here, but what is your CARP IPv6 address? It doesn't look like a link-local being anonymised so I think there's one problem right there.
Cheers,
Franco
Logged
Hypocrisy7186
Newbie
Posts: 11
Karma: 0
Re: Incomplete CARP IPv6 neighbour discovery from client side
«
Reply #3 on:
June 03, 2023, 11:52:42 am »
The Carp addresses are as below. The "x" is to hide the start of my ipv6 address
Ipv6 x:x:x:5::1/64
Ipv6 ll: fe80::5/64
Logged
franco
Administrator
Hero Member
Posts: 17668
Karma: 1611
Re: Incomplete CARP IPv6 neighbour discovery from client side
«
Reply #4 on:
June 03, 2023, 01:45:31 pm »
Ping to link-local CARP from client works but not to ULA? Does the client have an ULA from the correct prefix?
Cheers,
Franco
Logged
Hypocrisy7186
Newbie
Posts: 11
Karma: 0
Re: Incomplete CARP IPv6 neighbour discovery from client side
«
Reply #5 on:
June 03, 2023, 04:06:44 pm »
Sorry to have troubled you but its now working despite 0 changes on the firewall, switches or the client networking. Now that its working I've got no ways to try and trace why it was not working previously
Logged
franco
Administrator
Hero Member
Posts: 17668
Karma: 1611
Re: Incomplete CARP IPv6 neighbour discovery from client side
«
Reply #6 on:
June 03, 2023, 09:36:54 pm »
No worries... if it works it works
Cheers,
Franco
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
Incomplete CARP IPv6 neighbour discovery from client side