IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV)
-
@NogBadTheBad this might be a way of getting around it... if I just assign a static DHCPv6 for the MAC address. I'll give it a try if the NDP table issue keeps happening.
This will also be a simple way for me to keep the hostnames in check and make it easier to know what is what.
Did you find that the Apple TV's actually received a DHCPv6 address when you configured it?
Where did you configure those static DHCPv6 addresses? When I go to configure one it asks for a DUID and has no specific spot for the MAC Address?
Thanks!
Best Regards,
dg6464
-
What makes you think my ATV doesn’t go to sleep?
Have you got a spare lan port on your router to try and connect it to directly dos a test.
I originally let my ATV get a random IPv6 address then fixed it using the DUID address in the status - dhcpv6 leases page.
-
@NogBadTheBad I'm not saying it doesn't go to sleep... I'm saying your switch modem may not detect CRC align errors for some reason. It was more commercial gear that seemed to detect the issue.
I've tried multiple switching ports, multiple cables... and everything works perfectly when it's awake. Only when it goes to sleep does it have the issue.
As for the DHCPv6 lease... for some reason the DUID that it assigns won't allow me to assign a reservation:
Either way... the NDP Table only has 1 entry now... the most I have seen yet is 4 entries for it now. Only time will tell.
Not that it helps at all, but the Meraki switch GUI with the CRC errors... you can see the "red" gaps.. that's where it goes to sleep:
It's asleep right now, so it negotiates at 10/100:
Meraki thread about it:
[https://community.meraki.com/t5/Switching/AppleTV-4K-Ethernet-Madness/td-p/41254](link url)
-
@dg6464 said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
if I just assign a static DHCPv6 for the MAC address.
I don't know that would do it. You'd still have the neighbour announcements. With SLAAC, you will have a link local address and at least 1 global address. With DHCPv6, you will have a link local address and 1 global address. I don't see much difference in that.
As for that huge packet capture, what happens if you wait for the dust to settle, before starting it? You should still see neighbour advertisements periodically.
-
@JKnott do you think it's worth running RA in "Managed" mode then, to force DHCPv6? Not sure if I am in a world of hurt for all of the IP's that have been assigned using SLAAC / RA already though (likely my pihole DNS servers IP, unRAID's IPv6 IP and such). Not sure if I turn off Assisted mode and move to Managed if the existing used IP's will show up as leases.
Honestly if most things are compatible with DHCPv6 now and don't require SLAAC / RA's and autoconfigure... i'd almost rather manage the DHCPv6 leases just like I manage the DHCP IPv4 leases today... one by one from the pool as a round-robin and configuring reservations when it makes sense.
I can try another packet capture as well if you'd like and just not boot up Netflix and such.
You think just a cycle from sleep to wake up to sleep again will do the trick?
I can tinker with the options if it makes sense... just thought I'd ask just in case I'm in for a world of hurt by changing from Assisted. Doesn't that basically disable auto-configure / SLAAC?
Existing Configuration for DHCPv6 and RA:
Thanks!
Best Regards,
dg6464
-
@dg6464 said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
do you think it's worth running RA in "Managed" mode then, to force DHCPv6?
I doubt it would make any difference. RAs are required, whether SLAAC, DHCPv6 or manual config. RAs are the IPv6 equivalent of ARP and without them, it won't work.
-
@johnpoz said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
Name one mainstream anything that requires I have an IPv6 address.. Just 1...
Here's one example. IIRC, the Xbox requires IPv6. It had used Teredo, but I believe that's been turned down or will be shortly.
-
I have 2 older 1080p AppleTvs On a dual stack network and haven’t seen what you are seeing. I am using them currently on WiFi but I have used them wired in the past with no issue
They work fine with my ipv6 network. I use SLAAC only (unmanaged) but they also work as “assisted”.
About the only thing I have ever had to do to them is restart them if I reconfigure my network.
I have noticed that they don’t update their network configuration unless you restart them and that includes ipv4 too. Pulling the plug doesn’t work.
I have seen multiple ipv6 addresses (>600) once on a Windows machine but that was due to a router problem.
-
@dg6464 said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
@JKnott do you think it's worth running RA in "Managed" mode then, to force DHCPv6? Not sure if I am in a world of hurt for all of the IP's that have been assigned using SLAAC / RA already though (likely my pihole DNS servers IP, unRAID's IPv6 IP and such). Not sure if I turn off Assisted mode and move to Managed if the existing used IP's will show up as leases.
Honestly if most things are compatible with DHCPv6 now and don't require SLAAC / RA's and autoconfigure... i'd almost rather manage the DHCPv6 leases just like I manage the DHCP IPv4 leases today... one by one from the pool as a round-robin and configuring reservations when it makes sense.
I find that "unmanaged" SLAAC mode works the best with most devices like these media devices and IOT type devices. DHCPv6 implementation on some of these types of devices are hit or miss, but SLAAC always seems to work.
The support for SLAAC in the RFCs are mandatory for hosts, whereas DHCPv6 host support is "optional".
-
@JKnott said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
@johnpoz said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
This is perfect example of when you just disable IPv6 for this network..
My choice would be to get rid of the Apple crap. I'm allergic to the stuff. Disabling IPv6 is short sighted, as the world has to move to IPv6, to get rid of that NAT nonsense.
Take the complaint to Apple and let them fix it. They're the ones who caused the problem.
Apple works perfectly fine with ipv6, actually, one of the best. I think the issue here is the network itself is misconfigured..
-
Personally I think the issue lies with the Meraki switch, I can't understand why the speed changes to 100 Mbps when the ATV sleeps, my screenshots occured what the ATV was asleep.
I have 1 ATV connected to ethernet & 1 connected via Wi-Fi both don't have the issue you're seeing.
I'm using switches from the Linksys Business range.
Do you have a spare port on the router that you could set up as a new test lan and connect the ATV directly to it?
-
@NogBadTheBad Thanks for the insight - I've also got the same setup... my one Apple-TV 4K, connected via LAN and the other Apple TV connected via WiFi.
The issue (as per the Meraki thread) seems to persist beyond just Meraki switches when the Apple TV sleeps... and is only an issue for wired clients.
You may be correct, however in that the Apple TV could be giving the issue because it's wired specifically, so likely it would fix the issue to just move totally to wireless, but what is the fun in that? :).
I've attached some screenshots of the NDP table as of this morning... the ATV4 is gradually grabbing more IPv6 IP's via RA / SLAAC it seems.
I can run some experiments and see if the other ATV does the same on wireless, as well as wired if need be, I can capture packets from both the pfSense box, as well as all packets on the switch ports (there's a make .pcap function on the switch... so I assume I'd also see the L2 switch negotiation messages if I get the .pcap from the switch.
There IS a DHCP lease that contains the ATV4's MAC address in it (as part of the DUID), but doesn't actually specifically show that as the MAC Address as an entry in the DHCPv6 lease table (screenshot attached). When I try to create a reservation for that DUID it gives me an error as well, not sure why... seems my DUID formatting is wrong (but it came directly from clicking the "+" and trying to add via the pfSense formatting and reserve function itself).
-
Are you trying to allocate a fixed IP that's been handed out via DHCPv6 and is in the available range, you need to hand out an IP from outside the range.
I set my range to 2a02:xxxx:xxxx:4::64 - 2a02:xxxx:xxxx:4::fe and allocate 2a02:xxxx:xxxx:4::ABCD where ABCD = the last octet of my IPv4 address converted to hex.
andy@mac-pro ~ % host livingroom-atv
livingroom-atv has address 172.16.4.12
livingroom-atv has IPv6 address 2a02:xxxx:xxxx:4:c
andy@mac-pro ~ %FYI the last few digits of the DUID contain the device MAC address.
BTW Those are different IPv6 addresses from your DHCPv6 scope that are being handed out to the same MAC address.
Think you need to do an extended packet capture on the router itself and try and figure out why the router is handing out multiple IPv6 addresses to the same MAC when it should reuse the same address thats being handed out.
https://docs.netgate.com/pfsense/en/latest/book/services/ipv6-dhcp-server-and-router-advertisements.html
Here is how my IOT subnet is setup for DHCPv6
-
@NogBadTheBad said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
Are you trying to allocate a fixed IP that's been handed out via DHCPv6 and is in the available range
Does pfSense allow that with IPv6? It certainly doesn't with IPv4.
-
@JKnott said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
@NogBadTheBad said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
Are you trying to allocate a fixed IP that's been handed out via DHCPv6 and is in the available range
Does pfSense allow that with IPv6? It certainly doesn't with IPv4.
That's why I mentioned it,
I don't think it does.it doesn't.Also the setting on his DHCPv6 server doesn't look correct.
-
@NogBadTheBad Thanks for the quick response... it may be worth diving into my overall IPv6 configuration, then... as I think it might require some tweaking.
My ISP gives me a /64 to use for my LAN from what I can tell... so that means (since I believe /64 is the minimum recommended LAN segment to use) that I only get one segment to use for IPv6?
That segment is automatically used for SLAAC since I believe clients use the local address of the RA router in addition to their DUID to make their own addresses (the IPv6 address assigned to the LAN interface by default).
That segment is ALSO used as my range for my DHCPv6 server.
I assume what you have is a /60 or something and you are able to use separate non-overlapping /64's for the different spots... one /64 on you main LAN, one for your IOT (which is used for SLAAC on both)... one /64 for your DHCPv6 subnets on each LAN as well?
Screenshots of my configuration and IP's provided.
It's likely I've got something mixed up... as my ranges are much simpler (since I only have the one block to use, I omitted the beginning of the addresses since it's assumed by the LAN interfaces leased info, I thought.
-
@NogBadTheBad You are correct, this is a misconfiguration... as for some reason I thought it was supported on IPv4 and that's what I was doing. I was incorrect.
I use 192.168.1.0 /24 as my LAN subnet and thought I had set the DHCP Pool for the whole thing, but I did not it's only 192.168.1.130 - 254.
But I am not sure there is a way to do this in IPv6 anyway with a /64 is there?
Best Regards,
dg6464
-
@dg6464 said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
@NogBadTheBad Thanks for the quick response... it may be worth diving into my overall IPv6 configuration, then... as I think it might require some tweaking.
My ISP gives me a /64 to use for my LAN from what I can tell... so that means (since I believe /64 is the minimum recommended LAN segment to use) that I only get one segment to use for IPv6?
That segment is automatically used for SLAAC since I believe clients use the local address of the RA router in addition to their DUID to make their own addresses (the IPv6 address assigned to the LAN interface by default).
That segment is ALSO used as my range for my DHCPv6 server.
I assume what you have is a /60 or something and you are able to use separate non-overlapping /64's for the different spots... one /64 on you main LAN, one for your IOT (which is used for SLAAC on both)... one /64 for your DHCPv6 subnets on each LAN as well?
Yes /64 is really the minimum for an IPv6 LAN segment.
RIPE recommend everyone gets a /48:-
https://www.ripe.net/publications/docs/ripe-690I've been allocated a /48 that I split on a /64 boundary, my ISP routes the /48 to my WAN interface.
I'd be tempted to change your settings so they look like mine, I don't have track interface set on my interfaces I have 2a02:xxxx:xxxx:1::1, 2a02:xxxx:xxxx:2::1, etc ... set as a static.
-
@NogBadTheBad I was just using the suggested pfSense settings from my ISP, Rogers:
https://communityforums.rogers.com/t5/Internet/Rogers-IPv6-Status/td-p/146117/page/33
Rogers IPv6 Settings for pFSense firewall
In WAN Interface menu:
Use IPv4 connectivity as parent interface: yes
Request only a IPv6 prefix: no
DHCPv6 Prefix Delegation Size: 64
Send IPv6 prefix hint: yesIn LAN Interface menu:
IPv6 Configuration Type: track interface
IPv6 Interface: WAN
IPv6 Prefix ID: 0
In Advanced Settings / Network menu:Allow IPv6: enabled
Thoughts? Is this Rogers just issuing a /64? Does that mean I just have to stick with SLAAC on the only /64 subnet given (I assume the IP information based on the address my LAN interface gets) and no DHCPv6?
Thanks!
Best Regards,
dg6464
-
-
@dg6464 said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
DHCPv6 Prefix Delegation Size: 64
If you're on Rogers, then you can use /56. That info in the link was posted when Rogers only offered a /64. The info was updated in a later post.
Also, select Do not allow PD/Address release. Otherwise, it won't take much for your prefix to change. I found all it took was to disconnect/reconnect the WAN cable.
-
@NogBadTheBad said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
RIPE recommend everyone gets a /48
Many people are still stuck in the IPv4 address shortage mindset and can't comprehend how many IPv6 addresses there are. There are enough /48s to give every single person on earth over 4000 of them and that's with only 1/8th of the IPv6 addresss space allocated to global unique addresses. I have a /56, which seems adequate for now.
-
@JKnott Thanks for that - I changed to /56 on Prefix Delegation and rebooted the pfSense and my Rogers modem.
On the LAN side, it appears I now have 0 - FF as an option for IPv6 Prefix ID for the LAN interface (I assume this means it worked switching to /56 on WAN).
On the WAN side, I get a /128 for the interface from a totally different subnet:
WAN Interface:
IPv6 Address: 2607:f798:xxxx:xxxx:xxxx:69e5:2207:a96d
Subnet mask IPv6: 128LAN Interface:
IPv6 Address: 2607:fea8:xxxx:xxxx:xxxx:31ff:fe0a:7e00
Subnet mask IPv6: 64I assume the /128 on the WAN is because I request an IP Address for it as well in the configuration and not just prefix delegations? (ie: I have the following option unselected on the WAN page):
"Request only an IPv6 prefixOnly request an IPv6 prefix, do not request an IPv6 address".
Do you have any particular suggestion for the best way to find the actual /56 prefix assigned to me and calculating the various /64's and subnet boundaries so that I can use the next /64 subnet (prefix 01) for the DHCPv6 Server and a second /64 (prefix 02) for the static DHCPv6 Reservations I would like to make?
Is it easiest to just going to a subnet calculator online or something and put in the IPv6 LAN IP assigned from Prefix 0 automatically and using /56 or something?
There doesn't seem to be an easy way in the pfSense GUI to figure out the actual assigned prefix(s) that I can use.
Thanks!
Best Regards,
dg6464
-
The /128 is entirely normal. It's just an address attached to the WAN interface, but it's not used for routing. With IPv6, link local addresses are often use for routing. As for which prefix you use, that's entirely up to you though, typically, the main LAN is 0. Since a /56 provides 256 /64s, I set up something similar on IPv4. My main LAN is 172.16.0.0 /24 and IPv6 prefix is 0. My VPN is prefix ff and IPv4 subnet is 172.16.255.0. Again though, it's entirely your choice. There's really no need for a subnet calculator, as there is only 1 size of subnet. The actual assigned prefix is done with IPv6 Prefix ID, on each LAN interface, including VLANs. You can choose any value between 0 - ff, though each value can only be used once.
BTW, on IPv6, subnets are referred to as prefixes.
-
@JKnott Thanks! The thing I notice though... is in DHCPv6 configuration doesn't seem to auto-fill the "subnet" spot like @NogBadTheBad ...
Any particular reason this would be?
It even shows this way when I enable the server.
I was looking at using the following:
/64 Subnet 1 (LAN Interface, for SLAAC and such):
2607:fea8:xxxx:xxx0:0:0:0:0 - 2607:fea8:xxxx:xxx0:ffff:ffff:ffff:ffff
/64 Subnet 2 (DHCPv6 Interface):
2607:fea8:xxxx:xxx1:0:0:0:0 - 2607:fea8:xxxx:xxx1:ffff:ffff:ffff:ffff
/64 Subnet 3 (DHCPv6 Static Reservations):
2607:fea8:xxxx:xxx2:0:0:0:0 - 2607:fea8:xxxx:xxx2:ffff:ffff:ffff:ffff
Let me know if you think that looks adequate, or if I have something totally wrong in my head (ie: I am not sure if I need to define a new interface for each IPv6 prefix I defined above, or if they will all work under LAN).
Thanks!
Best Regards,
dg6464
-
The prefix is provided automagically by the router advertisements. That seems OK, though why are you choosing prefixes according to DHCPv6 etc.? I have never used DHCPv6, just SLAAC.
-
@JKnott Thanks!
The goal of using DHCPv6 is to experiment with the original issue at hand for this post... the Apple TV taking tons and tons of addresses via SLAAC. It was one of the suggestions from @NogBadTheBad to try and tweak these settings as he uses a statically assigned IP for his Apple TV and it works fine. I was just having trouble assigning one based on the DUID because the DHCPv6 pool I was using overlapped with the the static assignment I was trying to make. So now hopefully that will be resolved now that I have some more /64's assigned.
First thing I want to try is to statically assign the DUID an IPv6 address and see if it still keeps taking tons of SLAAC addresses.
Secondarily... I have a local pihole DNS server that has an IPv6 address that all other IPv6 clients on the LAN use for both IPv4 and IPv6 DNS resolution. Ideally.. I would assume that should be a static IPv6 address (like it is for IPv4), which I assume I need to do via DHCPv6 reservation so that it never changes? Unless there is a way to do that via SLAAC?
-
@dg6464 said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
First thing I want to try is to statically assign the DUID an IPv6 address and see if it still keeps taking tons of SLAAC addresses.
What you may want to try is create an address based on the link local. Remove the fe80:: prefix and replace it with the prefix for that LAN.
-
@JKnott do you mean to create a DHCPv6 reservation for the link local address and DUID? I did some packet captures while it was sleeping... I don't really see anything out of the ordinary from my knowledge, but who knows.
When I look at both Apple TV's, they are constantly flapping from 1Gbps to 100Mbps when they are sleeping, which causes RSTP to move the port from "Disabled->Designated" and "Designated->Disabled". Both have the exact same behaviour:
The ATV 4K has much higher CRC Alignment Errors and Fragments (only while sleeping and negotiated to 100Mbps).
The standard ATV has less CRC errors, no fragments, but does the same STP flapping.
Cable tests performed on both cables, all pairs just fine.
The ATV 4K seems to be the only one filling up the NDP Table gradually (I woke up to 40+ entries again, which end up showing in my pihole as tons and tons of clients when I only have 40 on the LAN), the regular ATV seems to be just fine, staying with 2 entries:
So I am going to chalk it up to a weird wired underlying chipset or driver issue in the ATV4 for the tons and tons of IPv6 addresses and expected sleep behaviour for both.
Next troubleshooting steps will be trying to put some switches in front of both before the Meraki switch (I've got an unmanaged D-Link, as well as a Managed Cisco SMB switch lying around)... just to see if they also flap the port from STP/RSTP messages with the ATV's when they go into sleep mode, and I'll monitor that as well as changes to the NDP Table for IPv6.
Secondarily once done... I'll run in full wireless mode on both to see if it makes a difference. That takes the cables, chipset and drivers off of the table and would leave us with just software on the Apple side if the issue still persists.
Sorry it took me a bit to respond... I totally effed up my unRAID IPv6 configuration as part of this.
I moved it to a static DHCPv6 reservation, but then it somehow made it lose the logical br0 interface, which forced pihole to stop working. I had to completely rebuild my docker.img file and the entire docker network stack and re-import all of the docker containers from a backup, to find that IPv6 was no longer working just inside docker. From there, it took a bunch of troubleshooting to figure out that for some reason... at some point I'd set a fully static IPv6 address on the main unRAID interface using a /128 mask.
This persisted once I went back to DHCP (keeping the /128 mask).So the fix (finally, apologies), was to set back to static, specify a /64 mask... then I was able to keep it static, or use DHCPv6 again and use a /64 prefix.
Something about the main unRAID interface having a /128 mask wouldn't allow the logical br0 interface to be used for IPv6 underneath.
Anyway - problem solved, but what a PITA kind of day. Now back to looking into this one... will post my findings, but I think as discussed at the start... this thread can be considered a non-issue from a pfSense perspective and really only folks interested in the findings (and future Google Searchers with the same issue) will find it potentially useful.
Best Regards,
dg6464
-
@dg6464 said in IPv6 NDP Table - Hundreds of Entries for Single Mac Address (Apple TV):
@JKnott do you mean to create a DHCPv6 reservation for the link local address and DUID?
When you mentioned "static", I assumed you meant a manual config, if the TV supported it, though you could certainly make a static map of the address. However, I was suggesting that if you did, you might want to make the address have the same suffix as the link local address. With SLAAC and MAC based addresses, that happens automagically. However, that's only cosmetic. It wouldn't make any technical difference.
-
Tried forcing the LAN ports that the ATV connects to to 1000 Mbps ?
-
Forcing it at one end only is a bad idea. Either do both ends or leave it auto-negotiate.
-
Yup I concur thinking about it, there's no way to do the ATV end.
-
@JKnott is correct @NogBadTheBad ... the Apple TV’s don’t have the ability to force a specific speed/duplex.
I forced to 1Gbps at one end (switch) and the ATV’s both disconnected and wouldn’t reconnect.
Will continue some testing today with going pure wireless, as well as an unmanaged switch in between and report back.
Best Regards,
dg6464
-
Think I've found the culprit, Energy Efficient Ethernet:-
https://community.meraki.com/t5/Switching/Port-Speed-Changing/td-p/1913
-
@NogBadTheBad yes, this is correct. It’s also noted in the Meraki case that I sent near the start of the thread:
https://community.meraki.com/t5/Switching/AppleTV-4K-Ethernet-Madness/td-p/41254
He did quite a bit of troubleshooting already and has the case in with Meraki, who is also talking to Apple apparently.
The latest update was January 2020... so hopefully we will see a fix at some point in the next few Apple TV TVOS releases and potentially Meraki switch OS’s as well (although the issue seems to be persistent in Meraki, Cisco and Ubiquiti switches... so I doubt all vendors have done it wrong, it likely lies specifically with Apple).
Since the issue seems to persist in some Apple TV 4K’s and not others... I’d assume it has to do with the included wired chipset and associated driver.
Best Regards,
dg6464
-
So quick question @JKnott ... I ran into a major IPv6 issue last night to the point where it totally dickered my entire LAN and all IPv6 services and some IPv4 services as well because docker images stopped functioning that serve both... I’ll keep it in this thread as I was still trying to troubleshoot things for this NDP Table/Apple TV issue.
Situation: Rogers gave me a new IPv6 prefix when I rebooted.
What happened: even though I have the option in interfaces configured to “not change my prefix” (I cant remember the setting) all WAN/LAN interface IP’s and the entire LAN subnet prefix totally changed.
This caused some docker containers (ie: pihole and DNScrypt) to stop working, because the static assignment for the main unRAID interface was now wrong.
I believe this is because the definitions I used on the interfaces were static and tied to the global IPv6 prefix lease.
Should I be setting these to automatic opposed to static?
And subsequently for LAN services like DNS... set the actual DNS server IP’s (in my DHCP / DJCPv6/RA pools) as the link-local fe80: IP’s?Reason being... literally everything I configured for DNS needed to change when the IPv6 prefix changed. It legit broke everything. My pihole and DNScrypt dockers, in fact wouldn’t boot anymore because the IPv6 global address assigned to the main unRAID interface was no longer valid; so of course same goes for the IPv6 IP’s set on docker containers and in DHCPv6/RA leases.
Thoughts?
I’ve totally disabled IPv6 at this point out of frustration... as it happened at like 11pm last night :(.
Thanks!
Best Regards,
dg6464
-
I have no experience with Docker, so I can't answer any questions about it. However, my prefix stopped changing when I made that setting. Did you do anything else that might have caused it to change?
-
@JKnott only a reboot, unfortunately. That’s all I did, was reboot pfSense.
With IPv6 disabled, the option isn’t there.
Can you remind me by chance of what the option is and if you’ve got it checked or not checked?
Do you have any other services on your LAN (DNS, NTP, or anything) that serve using IPv6 addresses? If so do you use link local or their global address to advertise via DHCPv6/RA?
Thanks!
Best Regards,
dg6464
-
The option is Do not allow PD/Address release and prevents the prefix from changing. Rebooting without that setting will cause a prefix change. It has no effect on IPv4.
Yes, my entire network runs IPv6, so pfSense provides NTP & DNS. Link local addresses are used for a lot of things, including router & neighbour advertisements. Unlike IPv4, IPv6 can't function without link local addresses. They're even often used for routing.
BTW, you normally don't have to reboot pfSense, other than when updating the system.