Project

General

Profile

Actions

Bug #16572

closed

IPv6 Link Local address does not respond to Neighbor Solicitation from non-LL addresses by default

Added by Jamie Cooper 5 days ago. Updated 2 days ago.

Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
Interfaces
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.8.1
Affected Architecture:

Description

ISPs using Juniper Layer 2 liveness detection use ND packets sent to the link local address to check the host is live. By default, the pfSense box does not respond to this. After the timer expires on the ISP end (300 seconds), the Juniper device removes the mapping.
As per RFC4861, these should be responded to.

Workaround

Add the following system tuneable: net.inet6.icmp6.nd6_onlink_ns_rfc4861 as value 1.

Fix

By default, this tunable should be enabled. I don't see a reason why NDs should be ignored.

Actions

Also available in: Atom PDF