Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Flood DHCP V6 on esxi

    Scheduled Pinned Locked Moved DHCP and DNS
    23 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      Here did a tcpdump on pfsense so can see mac on the ip6 traffic…

      See source link, and dest link address there 00:08:a2 is my pfsense interface on lan... And that 18:03:73 is my PC..

      tcpdumpip6.png
      tcpdumpip6.png_thumb

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • D
        demonium
        last edited by

        So if i understand you have ipv6 request with icmp to discover the network ? So it's normal ?

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          But he is saying that ANY ipv6 traffic and wherever this server is located gets blocked, like it shuts down the switch port for all traffic or something..

          Never ever ever heard of such a thing..  Seems nuts to me..  But from sniff I did if pfsense has no IPv6 set on its interface its not going to be sending out any sort of NDP or other noise on ipv6..

          His sniffs didn't show the MAC of the ipv6 traffic so not sure where its coming from.

          You ever here of DC or colo or anywhere shutting you down if you send out an IPv6 packet?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott
            last edited by

            @demonium:

            So if i understand you have ipv6 request with icmp to discover the network ? So it's normal ?

            Normally, with IPv6, you'd use DHCPv6-PD to get your WAN IP and LAN prefix.  On the LAN side, the router will announce the prefix, with router advertisements and then the device adds the least significant 64 bits.  DHCPv6 (without PD) can also be used to assign the device address.  Router advertisements are carried via ICMP6.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • D
              demonium
              last edited by

              Hi,
              You can find below my pcap file

              ipv6.pcap

              1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott
                last edited by

                Most of that capture is RARP with 00:0c:29:c0:91:db asking who is 00:0c:29:c0:91:db.

                I have no idea why it's doing that, as RARP is obsolete.

                https://en.wikipedia.org/wiki/Reverse_Address_Resolution_Protocol

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  The reverse arps are not IPv6  The IPv6 traffic is coming from

                  Source: Vmware_d6:37:24 (00:0c:29:d6:37:24)

                  You got something messed up with pfsense… I do not see any ipv6 coming off my pfsense once you set ipv6 to none..

                  I sure and the hell do not recall ever seeing a rarp from pfsense..

                  You sure that is your pfsense.. lets see iconfig from the pfsense VM..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott
                    last edited by

                    I sure and the hell do not recall ever seeing a rarp from pfsense..

                    I don't think I've ever seen it.  As I mentioned it's obsolete and has been for years, replaced by bootp & dhcp.
                    What's it doing on a modern network?

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • D
                      demonium
                      last edited by

                      Hi All,
                      First of all, thanks for your help.
                      I think I have an issue with my esxi server I have started a VM with SUSE and the lan card xas blocked I don't know why…
                      I have made a new installation of pfsense and I observed the same ICMPv6 request on my lan but I didn't configure any IPV6 service.
                      Is it normal ?

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Is what normal - yes esxi has ipv6 support.. But it wouldn't be coming from the mac of your VM virtual nic..

                        Yes suse most likely out of the box would try and configure IPv6.. Did you tell SUSE not to do ipv6?

                        Pretty much every single current OS on the planet willl use IPv6 - unless you specifically and sometimes quite difficult turn it off..  Windows for example you can even disable it with reg key… But its still there in the core, just doesn't do anything with it..  But if you look you will still see ipv6 loopback, etc.

                        Same with linux to rip it out of the kernel you would have to compile your own, etc.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.