Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #1194 > unrolled thread
| Started by | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| First post | 2012-03-23 10:53 +0100 |
| Last post | 2012-03-26 06:55 +0200 |
| Articles | 10 — 3 participants |
Back to article view | Back to comp.os.linux.networking
IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-03-23 10:53 +0100
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-24 11:25 +0100
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-03-24 13:43 +0000
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-24 20:41 +0100
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-03-24 21:49 +0000
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-04-02 22:10 +0200
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-04-02 22:08 +0200
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-04-02 22:07 +0200
Re: IPv6 SLAAC-Adresse herunterpriorisieren? Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-03-26 06:50 +0200
Reduce priority of an IPv6 SLAAC adderss (was: IPv6 SLAAC-Adresse herunterpriorisieren?) Marc Haber <mh+usenetspam1118@zugschl.us> - 2012-03-26 06:55 +0200
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2012-03-23 10:53 +0100 |
| Subject | IPv6 SLAAC-Adresse herunterpriorisieren? |
| Message-ID | <jkhh6u$udm$1@news1.tnib.de> |
Hallo, ich habe hier einen Host, der mit IPv6 angebunden ist. Eine statische IP-Adresse ist lokal konfiguriert, zusätzlich lernt das Gerät einen Prefix und sein Defaultgateway per SLAAC: |2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 | link/ether 52:54:00:fa:de:7d brd ff:ff:ff:ff:ff:ff | inet 192.168.146.11/24 scope global eth0 | inet6 2001:db8:40b7:9102::200:100/64 scope global | valid_lft forever preferred_lft forever | inet6 2001:db8:40b7:9102:5054:ff:fefa:de7d/64 scope global dynamic | valid_lft 86338sec preferred_lft 14338sec | inet6 fe80::5054:ff:fefa:de7d/64 scope link | valid_lft forever preferred_lft forever Kann ich irgendwie durch lokale Konfiguration oder durch Konfiguration des radvd auf dem Router dafür sorgen, dass die SLAAC-Adresse gleich als "deprecated" gelernt wird, so dass er für ausgehende Verbindungen die statisch konfiguriert Adresse nimmt? Dummerweise kann nagios' check_ssh plugin die Source-Adresse nicht festlegen. Grüße Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | http://www.zugschlus.de/ Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-03-24 11:25 +0100 |
| Message-ID | <jkk7ea$30on$1@saria.nerim.net> |
| In reply to | #1194 |
Hello, Marc Haber a écrit : (automatic translation from german as I do not speak the language) > > I've got a host that is connected with IPv6. a static > IP address is configured locally, in addition the device gets a > Prefix and its default gateway via SLAAC: > > | 2: eth0: mtu 1500 qdisc <BROADCAST,MULTICAST,UP,LOWER_UP> pfifo_fast state UP qlen 1000 > | Link / ether 52:54:00: fa: de: 7d brd ff: ff: ff: ff: ff: ff > | Inet 192.168.146.11/24 scope global eth0 > | Inet6 2001: db8: 40b7: 9102 :: 200:100 / 64 scope global > | Valid_lft preferred_lft forever forever > | Inet6 2001: db8: 40b7: 9102:5054: ff: fefa: de7d/64 scope global dynamic > | Valid_lft 86338sec preferred_lft 14338sec > | Inet6 fe80 :: 5054: ff: fefa: de7d/64 scope link > | Valid_lft preferred_lft forever forever > > Can I somehow through local configuration or configuration > ensure the radvd on the router that the same address SLAAC > is taught as "deprecated", making it suitable for outgoing connections > the statically configured address does? Unfortunately, can nagios' > check_ssh plugin not set the source address. IME, IPv6 static addresses are preferred over autoconfigured addresses. On the local host, you can disable autoconfiguration on the interface (sysctl net.ipv6.conf.eth0.autoconf=0). The host will still learn the prefix and default router information from RA, but not create an autoconfigured address. In radvd configuration, you can try to disable the "Autonomous" flag (AdvAutonomous off) for the prefix, or set AdvPreferredLifetime to 0 but this will affect all hosts which use the RA's. I haven't tested either of these.
[toc] | [prev] | [next] | [standalone]
| From | Jorgen Grahn <grahn+nntp@snipabacken.se> |
|---|---|
| Date | 2012-03-24 13:43 +0000 |
| Message-ID | <slrnjmrjsi.1ls.grahn+nntp@frailea.sa.invalid> |
| In reply to | #1198 |
On Sat, 2012-03-24, Pascal Hambourg wrote: > Hello, > > Marc Haber a écrit : > (automatic translation from german as I do not speak the language) Thanks! >> I've got a host that is connected with IPv6. a static >> IP address is configured locally, in addition the device gets a >> Prefix and its default gateway via SLAAC: SLAAC = Stateless address autoconfiguration. I'm quite familiar with the concept, but not the abbreviation. >> |2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 >> | link/ether 52:54:00:fa:de:7d brd ff:ff:ff:ff:ff:ff >> | inet 192.168.146.11/24 scope global eth0 >> | inet6 2001:db8:40b7:9102::200:100/64 scope global >> | valid_lft forever preferred_lft forever >> | inet6 2001:db8:40b7:9102:5054:ff:fefa:de7d/64 scope global dynamic >> | valid_lft 86338sec preferred_lft 14338sec >> | inet6 fe80::5054:ff:fefa:de7d/64 scope link >> | valid_lft forever preferred_lft forever >> Can I somehow through local configuration or configuration >> ensure the radvd on the router that the same address SLAAC >> is taught as "deprecated", making it suitable for outgoing connections >> the statically configured address does? Unfortunately, can nagios' >> check_ssh plugin not set the source address. Unfortunately, it still doesn't make sense to me. > IME, IPv6 static addresses are preferred over autoconfigured addresses. Why? I set it up with radvd here some time ago, and I found it rather elegant. The only drawback I can see is long addresses (e.g. 2001:470:28:4cf:211:d8ff:fe82 when it could have been 2001:470:28:4cf::7). > On the local host, you can disable autoconfiguration on the interface > (sysctl net.ipv6.conf.eth0.autoconf=0). The host will still learn the > prefix and default router information from RA, but not create an > autoconfigured address. > > In radvd configuration, you can try to disable the "Autonomous" flag > (AdvAutonomous off) for the prefix, or set AdvPreferredLifetime to 0 but > this will affect all hosts which use the RA's. I haven't tested either > of these. /Jorgen -- // Jorgen Grahn <grahn@ Oo o. . . \X/ snipabacken.se> O o .
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-03-24 20:41 +0100 |
| Message-ID | <jkl815$b2c$1@saria.nerim.net> |
| In reply to | #1199 |
Jorgen Grahn a écrit : > On Sat, 2012-03-24, Pascal Hambourg wrote: >> Hello, >> >> Marc Haber a écrit : >> (automatic translation from german as I do not speak the language) > > Thanks! > >>> Can I somehow through local configuration or configuration >>> ensure the radvd on the router that the same address SLAAC >>> is taught as "deprecated", making it suitable for outgoing connections >>> the statically configured address does? Unfortunately, can nagios' >>> check_ssh plugin not set the source address. > > Unfortunately, it still doesn't make sense to me. Sure, some words are out of order, but it makes sense to me. What about this : "Can I somehow, through local configuration or configuration of radvd on the router, ensure that the SLAAC address is taught as "deprecated", making the statically configured address suitable for outgoing connections ? Unfortunately, nagios check_ssh plugin cannot set the source address." >> IME, IPv6 static addresses are preferred over autoconfigured addresses. > > Why? I set it up with radvd here some time ago, and I found it rather > elegant. The only drawback I can see is long addresses Maybe there is a misunderstanding in the meaning of "preferred". I did not mean it as "recommended practice". I just mean that in my experience, when a Linux host has both statically assigned and autoconfigured IPv6 addresses in the same prefix, the IPv6 stack always select the statically assigned address by default. This makes sense to me, because through static assignment the administrator wants the host to use that specific address.
[toc] | [prev] | [next] | [standalone]
| From | Jorgen Grahn <grahn+nntp@snipabacken.se> |
|---|---|
| Date | 2012-03-24 21:49 +0000 |
| Message-ID | <slrnjmsgal.1ls.grahn+nntp@frailea.sa.invalid> |
| In reply to | #1203 |
On Sat, 2012-03-24, Pascal Hambourg wrote: > Jorgen Grahn a écrit : >> On Sat, 2012-03-24, Pascal Hambourg wrote: >>> Hello, >>> >>> Marc Haber a écrit : >>> (automatic translation from german as I do not speak the language) >> >> Thanks! >> >>>> Can I somehow through local configuration or configuration >>>> ensure the radvd on the router that the same address SLAAC >>>> is taught as "deprecated", making it suitable for outgoing connections >>>> the statically configured address does? Unfortunately, can nagios' >>>> check_ssh plugin not set the source address. >> >> Unfortunately, it still doesn't make sense to me. > > Sure, some words are out of order, but it makes sense to me. > What about this : > "Can I somehow, through local configuration or configuration of > radvd on the router, ensure that the SLAAC address > is taught as "deprecated", making the statically configured address > suitable for outgoing connections ? Unfortunately, nagios check_ssh > plugin cannot set the source address." Thanks again. I suspect then that "deprecated" has an official meaning in IPv6 autoconfig, and that it would make sense if I knew about that aspect. >>> IME, IPv6 static addresses are preferred over autoconfigured addresses. >> >> Why? I set it up with radvd here some time ago, and I found it rather >> elegant. The only drawback I can see is long addresses > > Maybe there is a misunderstanding in the meaning of "preferred". I did > not mean it as "recommended practice". I just mean that in my > experience, when a Linux host has both statically assigned and > autoconfigured IPv6 addresses in the same prefix, the IPv6 stack always > select the statically assigned address by default. This makes sense to > me, because through static assignment the administrator wants the host > to use that specific address. Yes, I misunderstood, in the way you suspected. /Jorgen -- // Jorgen Grahn <grahn@ Oo o. . . \X/ snipabacken.se> O o .
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2012-04-02 22:10 +0200 |
| Message-ID | <jld13n$cea$1@news1.tnib.de> |
| In reply to | #1204 |
Jorgen Grahn <grahn+nntp@snipabacken.se> wrote: >Thanks again. I suspect then that "deprecated" has an official meaning >in IPv6 autoconfig, It has. A "deprecated" address is one that is kept online to allow existing connections to survive, but it is never used as address for outgoing connections, and, IIRC, a deprecated address doesn't accept new connections as well. An address with preferred lifetime of zero is deprecated. Greetings Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | http://www.zugschlus.de/ Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2012-04-02 22:08 +0200 |
| Message-ID | <jld10p$c41$1@news1.tnib.de> |
| In reply to | #1199 |
Jorgen Grahn <grahn+nntp@snipabacken.se> wrote: >On Sat, 2012-03-24, Pascal Hambourg wrote: >> IME, IPv6 static addresses are preferred over autoconfigured addresses. > >Why? IP address based access lists that you want to hold after changing the host's hardware. Static DNS entries that should survive changing the host's hardware. Greetings Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | http://www.zugschlus.de/ Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2012-04-02 22:07 +0200 |
| Message-ID | <jld0un$c3r$1@news1.tnib.de> |
| In reply to | #1198 |
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote: >Marc Haber a écrit : >(automatic translation from german as I do not speak the language) >> Can I somehow through local configuration or configuration >> ensure the radvd on the router that the same address SLAAC >> is taught as "deprecated", making it suitable for outgoing connections >> the statically configured address does? Unfortunately, can nagios' >> check_ssh plugin not set the source address. > >IME, IPv6 static addresses are preferred over autoconfigured addresses. unfortunately, not. >On the local host, you can disable autoconfiguration on the interface >(sysctl net.ipv6.conf.eth0.autoconf=0). The host will still learn the >prefix and default router information from RA, but not create an >autoconfigured address. I haven't yet been able to find the correct place to set this. You need to set it after the ipv6 module is loaded, but before the prefix is learned. Setting this sysctl after the SLAAC address was learned doesn't remove the address. >In radvd configuration, you can try to disable the "Autonomous" flag >(AdvAutonomous off) for the prefix, or set AdvPreferredLifetime to 0 but >this will affect all hosts which use the RA's. I'd rather have a host specific setting. Greetings Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | http://www.zugschlus.de/ Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2012-03-26 06:50 +0200 |
| Message-ID | <jkosih$p3p$1@news1.tnib.de> |
| In reply to | #1194 |
Marc Haber <mh+usenetspam1118@zugschl.us> wrote: >ich habe hier einen Host, der mit IPv6 angebunden ist ... and obviously hit the wrong news group. I apologize for the German post. Greetings Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | http://www.zugschlus.de/ Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2012-03-26 06:55 +0200 |
| Subject | Reduce priority of an IPv6 SLAAC adderss (was: IPv6 SLAAC-Adresse herunterpriorisieren?) |
| Message-ID | <jkosrj$pij$1@news1.tnib.de> |
| In reply to | #1194 |
My translation: Marc Haber <mh+usenetspam1118@zugschl.us> wrote: >ich habe hier einen Host, der mit IPv6 angebunden ist. Eine statische >IP-Adresse ist lokal konfiguriert, zusätzlich lernt das Gerät einen >Prefix und sein Defaultgateway per SLAAC: One of my hosts has IPv6 connectivity. It has a static IPv6 address configured locally, but learns one Prefix/IP address and its default gateway via SLAAC. >|2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 >| link/ether 52:54:00:fa:de:7d brd ff:ff:ff:ff:ff:ff >| inet 192.168.146.11/24 scope global eth0 >| inet6 2001:db8:40b7:9102::200:100/64 scope global >| valid_lft forever preferred_lft forever >| inet6 2001:db8:40b7:9102:5054:ff:fefa:de7d/64 scope global dynamic >| valid_lft 86338sec preferred_lft 14338sec >| inet6 fe80::5054:ff:fefa:de7d/64 scope link >| valid_lft forever preferred_lft forever > >Kann ich irgendwie durch lokale Konfiguration oder durch Konfiguration >des radvd auf dem Router dafür sorgen, dass die SLAAC-Adresse gleich >als "deprecated" gelernt wird, so dass er für ausgehende Verbindungen >die statisch konfiguriert Adresse nimmt? Dummerweise kann nagios' >check_ssh plugin die Source-Adresse nicht festlegen. Unfortunately, it takes the SLAAC-Address for outgoing connections, which causes some issues with Nagios' check_ssh, since the hosts that I check have access lists which allow the static address, but not the dynamic SLAAC address. Is it possible to configure radvd (or the local host, as a fall back solution) to announce the SLAAC address in a way that it is learned (to make the host accessible in case of connectivity problems), but not used for outgoing connections? The other way around would work by configuring the IP address with a preferred lifetime of 0, which causes the host to immediately consider it deprecated. Greetings Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | http://www.zugschlus.de/ Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.networking
csiph-web