OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • DHCPv6 ports open but no service configured
« previous next »
  • Print
Pages: [1]

Author Topic: DHCPv6 ports open but no service configured  (Read 4367 times)

opnsenuser

  • Newbie
  • *
  • Posts: 27
  • Karma: 2
    • View Profile
DHCPv6 ports open but no service configured
« on: March 04, 2019, 10:57:18 am »
Hi everyone,
I'm running the latest release 19.1.2...
In the pfinfo, Tab: Rules I have some rules that have the following comment @ the end "allow access to DHCPv6 on LAN", but there is no DHCPv6 server active. Is this a Bug??

greetings
opnsenuser
Logged

marjohn56

  • Hero Member
  • *****
  • Posts: 1701
  • Karma: 179
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #1 on: March 04, 2019, 07:26:28 pm »
I would imagine that by default it will always allow access to its own dhcp servers on the LAN, even if you do not have it running.
Logged
OPNsense 24.7 - Qotom Q355G4 - ISP - Squirrel 1Gbps.

Team Rebellion Member - If we've helped you remember to applaud

opnsenuser

  • Newbie
  • *
  • Posts: 27
  • Karma: 2
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #2 on: March 05, 2019, 10:41:36 am »
Hi,

Quote from: marjohn56 on March 04, 2019, 07:26:28 pm
I would imagine that by default it will always allow access to its own dhcp servers on the LAN, even if you do not have it running.

Why is there a need for open port, if no service is running?
Firewallports should only be open if they are required.

Looking in the github repo for the cause... but so far no findings :(

greetings
opnsenuser
Logged

marjohn56

  • Hero Member
  • *****
  • Posts: 1701
  • Karma: 179
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #3 on: March 05, 2019, 01:23:05 pm »
It's on the LAN side so not an issue and nothing is listening there anyway. If you feel strongly about it put a rule in to close it, just don't forget you've put it there if ever you need to run a dhcp server.
Logged
OPNsense 24.7 - Qotom Q355G4 - ISP - Squirrel 1Gbps.

Team Rebellion Member - If we've helped you remember to applaud

opnsenuser

  • Newbie
  • *
  • Posts: 27
  • Karma: 2
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #4 on: March 05, 2019, 06:45:11 pm »
Hi,
then the text below the interfaces is wrong "... Everything that isn't explicitly passed is blocked by default."
That should be valid on every interface even the LAN. Only if a service on the firewalls interface is active, the required ports should be open.
Or am I wrong??

greetings
opnsenuser
Logged

marjohn56

  • Hero Member
  • *****
  • Posts: 1701
  • Karma: 179
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #5 on: March 05, 2019, 06:52:48 pm »
If you feel its an issue then please raise an issue on Github.


https://github.com/opnsense/core/issues
Logged
OPNsense 24.7 - Qotom Q355G4 - ISP - Squirrel 1Gbps.

Team Rebellion Member - If we've helped you remember to applaud

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17704
  • Karma: 1617
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #6 on: March 05, 2019, 07:11:35 pm »
https://github.com/opnsense/core/issues/1306
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #7 on: March 05, 2019, 07:45:05 pm »
This IPv6 cluster f**k is a REAL pain. How to stop this completely? Same with built-in firewall in opensuse distributions: OOTB there is a port open for IPv6 DHCP, although everything (literally, at 3 different places in the configs) related to IPv6 is DISABLED.

Is this an NSA/GCHQ requirement, to have that in each and every software/device running? I don't want protocols I can't control with devices assigning themselves half a dozen of addresses and spamming the network with broadcast of all kind until you kill each and every instance on each and every machine. And 3 updates later the same trash is active OOTB again.

Sorry, but...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17704
  • Karma: 1617
    • View Profile
Re: DHCPv6 ports open but no service configured
« Reply #8 on: March 05, 2019, 07:51:23 pm »
(:
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • DHCPv6 ports open but no service configured
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2