Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Neighbor Solicitation is lost via NPt

    Routing and Multi WAN
    2
    3
    71
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      ebsense last edited by

      So, I've got an NPt going to route IPv6 ULA to /64 block available on WAN from ISP gateway. Using packet capture I see that outbound traffic correctly gets translated from private to public scope, but no ping replies get back. Instead I see that ISP gateway is attempting to Solicit a neighbor information for the public IPv6 from which the ping request has came in, but solicitation does not itself get translated back to LAN's ULA scope or show up on the packet capture of the LAN interface.

      How can I handle neighbor solicitations with NPt?

      Alas I cannot route the entire / dedicated /64 block to the pfsense, nor does Protocol 41 (IPv6 over v4) gets back to the DMZ host (pfsense). Gateway does not come with an option of a bridge mode, so NPt is my current, best, hope.

      1 Reply Last reply Reply Quote 0
      • E
        ebsense last edited by

        I now realize that the solicitations may also be missing because they are sent with Hop limit of 255, meaning that the router drops them? Not quite sure if I understood this correctly or the best way to rebroadcast them on the lan.

        1 Reply Last reply Reply Quote 0
        • jimp
          jimp Rebel Alliance Developer Netgate last edited by jimp

          You appear to be trying to configure an unsupported role. The /64 for NPt must be routed to pfSense. If the upstream expects it to respond to NDP on the WAN segment, that cannot work. pfSense does not support the concept of proxying NDP requests.

          If you have a handful of static addresses on the inside, you could setup IP alias VIPs on the WAN for those, but automatic assignment wouldn't be possible.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 1
          • First post
            Last post