Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1194 > unrolled thread

IPv6 SLAAC-Adresse herunterpriorisieren?

Started byMarc Haber <mh+usenetspam1118@zugschl.us>
First post2012-03-23 10:53 +0100
Last post2012-03-26 06:55 +0200
Articles 10 — 3 participants

Back to article view | Back to comp.os.linux.networking


Contents

  IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-03-23 10:53 +0100
    Re: IPv6 SLAAC-Adresse herunterpriorisieren? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-24 11:25 +0100
      Re: IPv6 SLAAC-Adresse herunterpriorisieren? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-03-24 13:43 +0000
        Re: IPv6 SLAAC-Adresse herunterpriorisieren? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-24 20:41 +0100
          Re: IPv6 SLAAC-Adresse herunterpriorisieren? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-03-24 21:49 +0000
            Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-04-02 22:10 +0200
        Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-04-02 22:08 +0200
      Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-04-02 22:07 +0200
    Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-03-26 06:50 +0200
    Reduce priority of an IPv6 SLAAC adderss (was: IPv6 SLAAC-Adresse herunterpriorisieren?) Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-03-26 06:55 +0200

#1194 — IPv6 SLAAC-Adresse herunterpriorisieren?

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2012-03-23 10:53 +0100
SubjectIPv6 SLAAC-Adresse herunterpriorisieren?
Message-ID<jkhh6u$udm$1@news1.tnib.de>
Hallo,

ich habe hier einen Host, der mit IPv6 angebunden ist. Eine statische
IP-Adresse ist lokal konfiguriert, zusätzlich lernt das Gerät einen
Prefix und sein Defaultgateway per SLAAC:

|2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
|    link/ether 52:54:00:fa:de:7d brd ff:ff:ff:ff:ff:ff
|    inet 192.168.146.11/24 scope global eth0
|    inet6 2001:db8:40b7:9102::200:100/64 scope global 
|       valid_lft forever preferred_lft forever
|    inet6 2001:db8:40b7:9102:5054:ff:fefa:de7d/64 scope global dynamic 
|       valid_lft 86338sec preferred_lft 14338sec
|    inet6 fe80::5054:ff:fefa:de7d/64 scope link 
|       valid_lft forever preferred_lft forever

Kann ich irgendwie durch lokale Konfiguration oder durch Konfiguration
des radvd auf dem Router dafür sorgen, dass die SLAAC-Adresse gleich
als "deprecated" gelernt wird, so dass er für ausgehende Verbindungen
die statisch konfiguriert Adresse nimmt? Dummerweise kann nagios'
check_ssh plugin die Source-Adresse nicht festlegen.

Grüße
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | http://www.zugschlus.de/
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834

[toc] | [next] | [standalone]


#1198

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-03-24 11:25 +0100
Message-ID<jkk7ea$30on$1@saria.nerim.net>
In reply to#1194
Hello,

Marc Haber a écrit :
(automatic translation from german as I do not speak the language)
>
> I've got a host that is connected with IPv6. a static
> IP address is configured locally, in addition the device gets a
> Prefix and its default gateway via SLAAC:
> 
> | 2: eth0: mtu 1500 qdisc <BROADCAST,MULTICAST,UP,LOWER_UP> pfifo_fast state UP qlen 1000
> | Link / ether 52:54:00: fa: de: 7d brd ff: ff: ff: ff: ff: ff
> | Inet 192.168.146.11/24 scope global eth0
> | Inet6 2001: db8: 40b7: 9102 :: 200:100 / 64 scope global
> | Valid_lft preferred_lft forever forever
> | Inet6 2001: db8: 40b7: 9102:5054: ff: fefa: de7d/64 scope global dynamic
> | Valid_lft 86338sec preferred_lft 14338sec
> | Inet6 fe80 :: 5054: ff: fefa: de7d/64 scope link
> | Valid_lft preferred_lft forever forever
> 
> Can I somehow through local configuration or configuration
> ensure the radvd on the router that the same address SLAAC
> is taught as "deprecated", making it suitable for outgoing connections
> the statically configured address does? Unfortunately, can nagios'
> check_ssh plugin not set the source address.

IME, IPv6 static addresses are preferred over autoconfigured addresses.

On the local host, you can disable autoconfiguration on the interface
(sysctl net.ipv6.conf.eth0.autoconf=0). The host will still learn the
prefix and default router information from RA, but not create an
autoconfigured address.

In radvd configuration, you can try to disable the "Autonomous" flag
(AdvAutonomous off) for the prefix, or set AdvPreferredLifetime to 0 but
this will affect all hosts which use the RA's. I haven't tested either
of these.

[toc] | [prev] | [next] | [standalone]


#1199

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2012-03-24 13:43 +0000
Message-ID<slrnjmrjsi.1ls.grahn+nntp@frailea.sa.invalid>
In reply to#1198
On Sat, 2012-03-24, Pascal Hambourg wrote:
> Hello,
>
> Marc Haber a écrit :
> (automatic translation from german as I do not speak the language)

Thanks!

>> I've got a host that is connected with IPv6. a static
>> IP address is configured locally, in addition the device gets a
>> Prefix and its default gateway via SLAAC:

SLAAC = Stateless address autoconfiguration. I'm quite familiar with
the concept, but not the abbreviation.

>> |2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
>> |    link/ether 52:54:00:fa:de:7d brd ff:ff:ff:ff:ff:ff
>> |    inet 192.168.146.11/24 scope global eth0
>> |    inet6 2001:db8:40b7:9102::200:100/64 scope global
>> |       valid_lft forever preferred_lft forever
>> |    inet6 2001:db8:40b7:9102:5054:ff:fefa:de7d/64 scope global dynamic
>> |       valid_lft 86338sec preferred_lft 14338sec
>> |    inet6 fe80::5054:ff:fefa:de7d/64 scope link
>> |       valid_lft forever preferred_lft forever

>> Can I somehow through local configuration or configuration
>> ensure the radvd on the router that the same address SLAAC
>> is taught as "deprecated", making it suitable for outgoing connections
>> the statically configured address does? Unfortunately, can nagios'
>> check_ssh plugin not set the source address.

Unfortunately, it still doesn't make sense to me.

> IME, IPv6 static addresses are preferred over autoconfigured addresses.

Why? I set it up with radvd here some time ago, and I found it rather
elegant. The only drawback I can see is long addresses (e.g.
2001:470:28:4cf:211:d8ff:fe82 when it could have been
2001:470:28:4cf::7).

> On the local host, you can disable autoconfiguration on the interface
> (sysctl net.ipv6.conf.eth0.autoconf=0). The host will still learn the
> prefix and default router information from RA, but not create an
> autoconfigured address.
>
> In radvd configuration, you can try to disable the "Autonomous" flag
> (AdvAutonomous off) for the prefix, or set AdvPreferredLifetime to 0 but
> this will affect all hosts which use the RA's. I haven't tested either
> of these.

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [next] | [standalone]


#1203

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-03-24 20:41 +0100
Message-ID<jkl815$b2c$1@saria.nerim.net>
In reply to#1199
Jorgen Grahn a écrit :
> On Sat, 2012-03-24, Pascal Hambourg wrote:
>> Hello,
>>
>> Marc Haber a écrit :
>> (automatic translation from german as I do not speak the language)
> 
> Thanks!
> 
>>> Can I somehow through local configuration or configuration
>>> ensure the radvd on the router that the same address SLAAC
>>> is taught as "deprecated", making it suitable for outgoing connections
>>> the statically configured address does? Unfortunately, can nagios'
>>> check_ssh plugin not set the source address.
> 
> Unfortunately, it still doesn't make sense to me.

Sure, some words are out of order, but it makes sense to me.
What about this :
"Can I somehow, through local configuration or configuration of
radvd on the router, ensure that the SLAAC address
is taught as "deprecated", making the statically configured address
suitable for outgoing connections ? Unfortunately, nagios check_ssh
plugin cannot set the source address."

>> IME, IPv6 static addresses are preferred over autoconfigured addresses.
> 
> Why? I set it up with radvd here some time ago, and I found it rather
> elegant. The only drawback I can see is long addresses

Maybe there is a misunderstanding in the meaning of "preferred". I did
not mean it as "recommended practice". I just mean that in my
experience, when a Linux host has both statically assigned and
autoconfigured IPv6 addresses in the same prefix, the IPv6 stack always
select the statically assigned address by default. This makes sense to
me, because through static assignment the administrator wants the host
to use that specific address.

[toc] | [prev] | [next] | [standalone]


#1204

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2012-03-24 21:49 +0000
Message-ID<slrnjmsgal.1ls.grahn+nntp@frailea.sa.invalid>
In reply to#1203
On Sat, 2012-03-24, Pascal Hambourg wrote:
> Jorgen Grahn a écrit :
>> On Sat, 2012-03-24, Pascal Hambourg wrote:
>>> Hello,
>>>
>>> Marc Haber a écrit :
>>> (automatic translation from german as I do not speak the language)
>> 
>> Thanks!
>> 
>>>> Can I somehow through local configuration or configuration
>>>> ensure the radvd on the router that the same address SLAAC
>>>> is taught as "deprecated", making it suitable for outgoing connections
>>>> the statically configured address does? Unfortunately, can nagios'
>>>> check_ssh plugin not set the source address.
>> 
>> Unfortunately, it still doesn't make sense to me.
>
> Sure, some words are out of order, but it makes sense to me.
> What about this :
> "Can I somehow, through local configuration or configuration of
> radvd on the router, ensure that the SLAAC address
> is taught as "deprecated", making the statically configured address
> suitable for outgoing connections ? Unfortunately, nagios check_ssh
> plugin cannot set the source address."

Thanks again. I suspect then that "deprecated" has an official meaning
in IPv6 autoconfig, and that it would make sense if I knew about that
aspect.

>>> IME, IPv6 static addresses are preferred over autoconfigured addresses.
>> 
>> Why? I set it up with radvd here some time ago, and I found it rather
>> elegant. The only drawback I can see is long addresses
>
> Maybe there is a misunderstanding in the meaning of "preferred". I did
> not mean it as "recommended practice". I just mean that in my
> experience, when a Linux host has both statically assigned and
> autoconfigured IPv6 addresses in the same prefix, the IPv6 stack always
> select the statically assigned address by default. This makes sense to
> me, because through static assignment the administrator wants the host
> to use that specific address.

Yes, I misunderstood, in the way you suspected.

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [next] | [standalone]


#1229

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2012-04-02 22:10 +0200
Message-ID<jld13n$cea$1@news1.tnib.de>
In reply to#1204
Jorgen Grahn <grahn+nntp@snipabacken.se> wrote:
>Thanks again. I suspect then that "deprecated" has an official meaning
>in IPv6 autoconfig,

It has. A "deprecated" address is one that is kept online to allow
existing connections to survive, but it is never used as address for
outgoing connections, and, IIRC, a deprecated address doesn't accept
new connections as well.

An address with preferred lifetime of zero is deprecated.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | http://www.zugschlus.de/
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834

[toc] | [prev] | [next] | [standalone]


#1228

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2012-04-02 22:08 +0200
Message-ID<jld10p$c41$1@news1.tnib.de>
In reply to#1199
Jorgen Grahn <grahn+nntp@snipabacken.se> wrote:
>On Sat, 2012-03-24, Pascal Hambourg wrote:
>> IME, IPv6 static addresses are preferred over autoconfigured addresses.
>
>Why?

IP address based access lists that you want to hold after changing the
host's hardware.

Static DNS entries that should survive changing the host's hardware.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | http://www.zugschlus.de/
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834

[toc] | [prev] | [next] | [standalone]


#1227

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2012-04-02 22:07 +0200
Message-ID<jld0un$c3r$1@news1.tnib.de>
In reply to#1198
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote:
>Marc Haber a écrit :
>(automatic translation from german as I do not speak the language)
>> Can I somehow through local configuration or configuration
>> ensure the radvd on the router that the same address SLAAC
>> is taught as "deprecated", making it suitable for outgoing connections
>> the statically configured address does? Unfortunately, can nagios'
>> check_ssh plugin not set the source address.
>
>IME, IPv6 static addresses are preferred over autoconfigured addresses.

unfortunately, not.

>On the local host, you can disable autoconfiguration on the interface
>(sysctl net.ipv6.conf.eth0.autoconf=0). The host will still learn the
>prefix and default router information from RA, but not create an
>autoconfigured address.

I haven't yet been able to find the correct place to set this. You
need to set it after the ipv6 module is loaded, but before the prefix
is learned. Setting this sysctl after the SLAAC address was learned
doesn't remove the address.

>In radvd configuration, you can try to disable the "Autonomous" flag
>(AdvAutonomous off) for the prefix, or set AdvPreferredLifetime to 0 but
>this will affect all hosts which use the RA's.

I'd rather have a host specific setting.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | http://www.zugschlus.de/
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834

[toc] | [prev] | [next] | [standalone]


#1216

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2012-03-26 06:50 +0200
Message-ID<jkosih$p3p$1@news1.tnib.de>
In reply to#1194
Marc Haber <mh+usenetspam1118@zugschl.us> wrote:
>ich habe hier einen Host, der mit IPv6 angebunden ist

... and obviously hit the wrong news group. I apologize for the German
post.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | http://www.zugschlus.de/
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834

[toc] | [prev] | [next] | [standalone]


#1217 — Reduce priority of an IPv6 SLAAC adderss (was: IPv6 SLAAC-Adresse herunterpriorisieren?)

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2012-03-26 06:55 +0200
SubjectReduce priority of an IPv6 SLAAC adderss (was: IPv6 SLAAC-Adresse herunterpriorisieren?)
Message-ID<jkosrj$pij$1@news1.tnib.de>
In reply to#1194
My translation:

Marc Haber <mh+usenetspam1118@zugschl.us> wrote:
>ich habe hier einen Host, der mit IPv6 angebunden ist. Eine statische
>IP-Adresse ist lokal konfiguriert, zusätzlich lernt das Gerät einen
>Prefix und sein Defaultgateway per SLAAC:

One of my hosts has IPv6 connectivity. It has a static IPv6 address
configured locally, but learns one Prefix/IP address and its default
gateway via SLAAC.

>|2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
>|    link/ether 52:54:00:fa:de:7d brd ff:ff:ff:ff:ff:ff
>|    inet 192.168.146.11/24 scope global eth0
>|    inet6 2001:db8:40b7:9102::200:100/64 scope global 
>|       valid_lft forever preferred_lft forever
>|    inet6 2001:db8:40b7:9102:5054:ff:fefa:de7d/64 scope global dynamic 
>|       valid_lft 86338sec preferred_lft 14338sec
>|    inet6 fe80::5054:ff:fefa:de7d/64 scope link 
>|       valid_lft forever preferred_lft forever
>
>Kann ich irgendwie durch lokale Konfiguration oder durch Konfiguration
>des radvd auf dem Router dafür sorgen, dass die SLAAC-Adresse gleich
>als "deprecated" gelernt wird, so dass er für ausgehende Verbindungen
>die statisch konfiguriert Adresse nimmt? Dummerweise kann nagios'
>check_ssh plugin die Source-Adresse nicht festlegen.

Unfortunately, it takes the SLAAC-Address for outgoing connections,
which causes some issues with Nagios' check_ssh, since the hosts that
I check have access lists which allow the static address, but not the
dynamic SLAAC address. Is it possible to configure radvd (or the local
host, as a fall back solution) to announce the SLAAC address in a way
that it is learned (to make the host accessible in case of
connectivity problems), but not used for outgoing connections? The
other way around would work by configuring the IP address with a
preferred lifetime of 0, which causes the host to immediately consider
it deprecated.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | http://www.zugschlus.de/
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web