Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    23.01 DUID question - I can't spoof my way to a new prefix

    Scheduled Pinned Locked Moved IPv6
    3 Posts 2 Posters 536 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mfld LAYER 8
      last edited by

      I wanted to test forcing a new prefix by deleting dhcp6c_duid /var/db/ and changing

      DUID generation method
      

      in System - Advanced - Network - DHCP6 DUID.

      I tried all options there generating UUIDs or random MAC addresses, unchecking

      Do not allow PD/Address release
      

      and rebooting.

      My observation is that the sha256sum of /var/db/dhcp6c_duid does indeed change, but the ISP still assigns the same prefix. Note the service package here assigns one dynamic /64 (no /56 or /60 PD.. ugh).

      The prefix they assign resolves to the WAN interface's MAC address which is why I wanted to play around with this.

      Why does dhcpv6 over pppoe not get a different dynamic /64 when the contents of /var/db/dhcp6c_duid have clearly changed and I am rebooting ?

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @mfld
        last edited by

        @mfld

        This is the opposite problem of what some others have. What happens if you uncheck Do not allow PD/Address release?

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        M 1 Reply Last reply Reply Quote 0
        • M
          mfld LAYER 8 @JKnott
          last edited by

          @jknott said in 23.01 DUID question - I can't spoof my way to a new prefix:

          @mfld

          This is the opposite problem of what some others have.

          That's the story of my life, brother 😆

          I specialize in bizarre tickets.

          The reason I want a new prefix is that this one directly resolves to the actual MAC address of the CPE and the OUI on this one is very specific. I'd rather obfuscate. Just out of habit.

          I did uncheck that option (meaning yes absolutely release the PD on restart) but they still send the same prefix.

          It may need to be offline for a bit. Maybe they tie it to the pppoe credential for a period of time and a reboot is too short.

          I called them to ask if their policy changed and the prefixes are static now but they assured me that it's still a /64 only and it's definitely dynamic.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.