IPV6 flows not showing up in bridge mode after router changes IPV6 prefix
I have
5G Home Internet Gateway (router) -->Firewalla (bridge mode) --> rest of LAN
Steps to reproduce:
1. Power up everything from cold
2. Wait for traffic to flow. Run IPV6 testing from some LAN clients. It works.
3. Check firewalla App flow history. IPV6 addresses in flows are visible.
4. Reboot the 5G home internet gateway to force it to get a new WAN IPV4 and a new IPV6 /64 prefix. This box does not serve DHCPv6 to the LAN, only stateless prefix delegation with RA packets.
5. Run IPV6 tests in some LAN clients. Sometimes they need to wait a little while to find and device to start using the new IPV6 prefix. (RA packets come from the router every 30 seconds by looks of it). Mac desktops are slow at this, phones pick it up quickly. The IPV6 tests all work fine. Also test ping6 to say google, it works fine.
6. Wait some time, maybe 15 minutes to be safe, for things to show up in firewalla flow log. Only IPV4 flows show up.
7. ssh to firewalla and confirm it has IPV6 address, it does, with the correct new prefix. Firewalla also shows the latest IPV6 addresses for clients in the device details from the device listing.
8. Reboot firewalla. Chęćk flow logs again. Flows recorded after the reboot time now readily include IPV6 flows.
I am suspecting firewalla flow recording fails to record IPV6 flows if the IPV6 prefix in the packets no longer matches what it was last time firewalla started, in the absence of DHCPv6 being served.
Please sign in to leave a comment.
Comments
1 comment