Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Three Entries in NDP for Some Devices? [ANSWERED]

    IPv6
    3
    4
    698
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • beremonavabiB
      beremonavabi
      last edited by beremonavabi

      In pfSense 2.4.4_1, looking at Diagnostics > NDP Table, most of my devices have two entries: one with its IPv6 address and another with its link local address. Some of them (currently two Windows 10 computers and one Android phone), though, have an additional entry. Its IPv6 address starts with the first four hextets of the device's IPv6 address (at least what's showing in the DHCPv6 Server), but the last four hextets are different. Can anyone tell me why? PfSense is the only thing handing out IP addresses on my network and I have no DMZ's, guest networks, or any other active interfaces besides WAN and LAN. It's a basic, simple, mostly Windows 10 workgroup-based home network.

      Unfortunately, I don't even have a name for what I'm seeing so I can't look it up.

      SG-4860, pfSense 2.4.5-RELEASE-p1 (amd64)

      sigiS 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott
        last edited by

        @beremonavabi said in Three Entries in NDP for Some Devices?:

        Some of them (currently two Windows 10 computers and one Android phone), though, have an additional entry. Its IPv6 address starts with the first four hextets of the device's IPv6 address (at least what's showing in the DHCPv6 Server), but the last four hextets are different. Can anyone tell me why?

        Those are likely random privacy addresses. The idea is that by having an address tied to the hardware could cause privacy issues. So, these privacy addresses change daily and remain for a week, before being discarded. For incoming connections, to a server for example, you'd use the consistent address, which is often based on the MAC address, but could also be a random number.

        BTW, with SLAAC, pfSense does not hand out addresses. It only provides the prefix, with the device generating the lower 64 bits of the address.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 1
        • beremonavabiB
          beremonavabi
          last edited by

          That sounds like it's it. Thanks.

          SG-4860, pfSense 2.4.5-RELEASE-p1 (amd64)

          1 Reply Last reply Reply Quote 0
          • sigiS
            sigi @beremonavabi
            last edited by

            @beremonavabi said in Three Entries in NDP for Some Devices? [ANSWERED]:

            Unfortunately, I don't even have a name for what I'm seeing so I can't look it up.

            https://en.wikipedia.org/wiki/IPv6#SLAAC_privacy_extensions

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.