Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 RA breaks through VLAN's

    Scheduled Pinned Locked Moved IPv6
    12 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mphilippi @JKnott
      last edited by mphilippi

      @JKnott
      Thanks for your response. It's a Mikrotik CRS354.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @mphilippi
        last edited by

        @mphilippi

        I haven't used Mikrtik gear. However, that is the exact problem I had with a TP-Link AP. My guest WiFi is on VLAN 3 and until I replaced my access point with one from Ubiquiti I couldn't use IPv6 on it.

        You mention the VLAN is not configured on the PC. Does the port it's connected to have VLAN 10 on it?

        BTW, a line or two from Wireshark is pretty much useless. You should post the capture file here.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        M 1 Reply Last reply Reply Quote 0
        • M
          mphilippi @JKnott
          last edited by mphilippi

          @JKnott

          With the Mikrotik, I can use IPv6 without issues. The problem seems to be related when you use a hybrid port setup with a tagged and untagged VLAN.

          After some research, I found out it's not a router nor a switch problem: Windows listens to RA's coming in on tagged VLAN's and strips VLAN tags, even when it's not configured to do so.
          Testing the same port on a Linux box, it will disregard tagged VLAN's and the setup works as intended. So it seems to be a Windows problem only.

          1
          2
          3

          In our network, some ports have a phone connected and a computer connected to the phone, others have the computer directly connected to the ports.
          For generalization, I liked the idea to have only hybrid ports and be able to plug every combination into every port.

          It looks like I have to go back to access ports without any VLAN's being tagged and have the VLAN's stripped on the phones if a computer is connected to it.

          johnpozJ JKnottJ 2 Replies Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @mphilippi
            last edited by

            @mphilippi so I am curious about this - I don't recall ever seeing such an issue in the wild.. But should be easy enough to test..

            So if what reading is valid, or still valid on current versions of windows. My IPv4 is untagged native to my windows port, your saying if I enable IPv6 on this interface, but don't have IPv6 on the native untagged network, but also have a tagged vlan on this port with IPv6 on it pfsense will use this on its untagged interface?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            NogBadTheBadN M 2 Replies Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @johnpoz
              last edited by

              What happens if you don't run Wireshark in promiscuous mode ?

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              M 1 Reply Last reply Reply Quote 0
              • M
                mphilippi @johnpoz
                last edited by mphilippi

                @johnpoz

                The client receives IPv6 addressing from the tagged VLAN but obviously won't be able to communicate with it through the untagged VLAN. It seems to be an issue with Windows.
                Could you re-create the scenario?

                1 Reply Last reply Reply Quote 0
                • M
                  mphilippi @NogBadTheBad
                  last edited by

                  @NogBadTheBad
                  It has nothing to do with Wireshark. I used the packet capture feature of pfSense only after I found out about the issue to get more data

                  NogBadTheBadN 1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott @mphilippi
                    last edited by JKnott

                    @mphilippi said in IPv6 RA breaks through VLAN's:

                    So it seems to be a Windows problem only.

                    Yeah, another Windows "feature". Normally, with VoIP on a VLAN, you connect the computer through the phone, which will remove the tag, before passing packets on to the computer.

                    MS has a very long history of breaking things, because they don't follow standards and practices.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @mphilippi
                      last edited by

                      @mphilippi Both Wireshark and a packet capture from pfSense defaults to promiscuous mode, that was why I asked.

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      JKnottJ 1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @NogBadTheBad
                        last edited by

                        @NogBadTheBad

                        I always do packet capture in promiscuous mode, as these days switches keep most of the other traffic away. Back when I first started using it, then known as Ethereal, hubs were still in use, so you'd see everything on the network, including passwords.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.