General Discussion
  >> Fibre Broadband


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | (show all)   Print Thread
Standard User jpm
(committed) Fri 23-Jul-21 15:31:37
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: JESC77] [link to this post]
 
Have Daisy said what they are expecting the next-hop address to be for your /56 from the perspective of their router? Usually how I'd expect to see this configured is (ignoring VRRP to keep things simple):

ISP interface configured to 2300::1/64
Your firewall configured to 2300::2/64

The ISP then has a route in their network that the next-hop for 2300::/56 is 2300::2/64 so that traffic can actually get back to you.

If they've just stuck a /64 on an interface and given you a 'usable range' as if it's IPv4 networking then that won't work. I've had this discussion with ISPs a fair amount so it can get frustrating but normally someone who works there knows what you're after.
Standard User JESC77
(newbie) Fri 23-Jul-21 16:42:45
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: jpm] [link to this post]
 
No Daisy hasn't said anything about the next hop, their support ended with "We have provided you with the IPv6 solution as per your request, of which you have tested locally via a laptop and confirmed to be working."

Isn't the fact that it does work with my laptop connected to the Cisco proof that it's configured correctly on Daisys network? If your answer is no, I'll go back to them, what should I ask?

Thanks
Standard User pluralist
(committed) Fri 23-Jul-21 17:01:07
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: E300] [link to this post]
 
In reply to a post by E300:
Daisy did say they have routed all of the /56 as well.
Exactly! Not all the /56s within the /64. That's my whole point.

They have specified /56 2300. Not /23ff.

Edit: To repeat:
Gateway IP: 2001:xxx:xxx:2300::1/64

Usable IP's: 2001:xxx:xxx:2300::2 - 2001:xxx:xxx:2300:ffff:ffff:ffff:ffff


Connections: OnePlus 8 Pro, 4G+ (LTE) max 165Mbps down, 24Mbps up on Three Mobile, and B311 4G+ router, tbb tests normally 35-45Mpbs down, 65Mbps off-peak, 9-24 up.

Edited by pluralist (Fri 23-Jul-21 17:12:58)


Register (or login) on our website and you will not see this ad.

Standard User jpm
(committed) Fri 23-Jul-21 17:31:11
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: JESC77] [link to this post]
 
When you set your laptop up you're sat in the subnet that your firewall goes in, that's why you can ping your UDM and the UDM can ping IPv6 targets. The Daisy network doesn't know where to send traffic to all the other hosts in the /56 because it doesn't sound like a route has been added.

You need to ask Daisy to add a route so you can use the IPv6 allocation, and the next-hop address needs to be whatever your UDM IPv6 address is on the WAN port.

Run a traceroute from an internet location to an address in the /56 allocation - you'll probably find it fails before the address on your UDM.

Here's me doing a (redacted) traceroute to an address in an unconfigured prefix on my LAN:

Tracing route to 2a01:xxxx:129:3::1 over a maximum of 30 hops

1 1 ms 1 ms 1 ms 2a00:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:1bb2
2 6 ms 5 ms 5 ms 2a00:xxxx::xxxx:xxxx
3 7 ms 7 ms 7 ms 2a00:xxxx::xxxx:xxxx:xxxx
4 8 ms 8 ms 8 ms 2a00:xxxx::xxxx:xxxx:xxxx
5 * * * Request timed out.
6 10 ms 10 ms 11 ms peer7-et0-1-6.telehouse.ukcore.bt.net [2a00:2380:13::a7]
7 10 ms 8 ms 10 ms 2001:7f8:4::b972:1
8 16 ms 14 ms 7 ms 2a01:xxxx:xxxx:xxxx::
9 13 ms 9 ms 8 ms 2a01:xxxx:xxxx:xxxx::1
10 10 ms 7 ms 8 ms 2a01:xxxx:129::2
11 * * * Request timed out.
12 * * * Request timed out.
13 * * * Request timed out.
14 * ^C


Hop 10 is the interface on the firewall, which then starts dropping the traffic hence the timeout messages. If you do the same thing and get a "no route to host" error instead of seeing your UDM WAN interface IP then Daisy need to add a route.

Edited by jpm (Fri 23-Jul-21 17:38:41)

Standard User pluralist
(committed) Fri 23-Jul-21 17:53:01
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: E300] [link to this post]
 
In reply to a post by E300:
I think those details appear correct, if the OP is configuring their LAN side, which those settings appear to be, you would specify usually a /64.

They have been allocated a /56, this means they have 256 subnets available and can pick anything in the range of 2001:xxxx:xxxx:2300 to 2001:xxxx:xxxx:23ff for use on their LAN. The configuration looks okay for the LAN side, I think the issue may be how they have configured the WAN side.
Ah, we were both right and both wrong, with me being the cause. I have struck out the offending part of the post. My brain was half-asleep at the time, by the look of things.

The fact remains that OP in his first picture link to is using 2301 in the first of his links, (https://drive.google.com/file/d/1e3GFOK0L95OTcLcphY9IS69ZxAR8Kc9q/view), which is what I objected to. That is the final quartet of a /64, and he hasn't been allocated it.

I accept it does look as if he can use the whole of his allocated /64 as he wishes blush.

Connections: OnePlus 8 Pro, 4G+ (LTE) max 165Mbps down, 24Mbps up on Three Mobile, and B311 4G+ router, tbb tests normally 35-45Mpbs down, 65Mbps off-peak, 9-24 up.
Standard User JESC77
(newbie) Fri 23-Jul-21 18:15:50
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: pluralist] [link to this post]
 
I have to say that this is an excellent forum, I've tried to receive support on the Ubiquiti forum but that just sucks in comparison, so thank you everyone for taking the time to help.

So if 2301 on my LAN is no good what should I use?
Standard User pluralist
(committed) Fri 23-Jul-21 19:44:25
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: JESC77] [link to this post]
 
Not all of it perfect from me frown! My apologies. However, I can can still get some things right smile.

Another minor point is that on your lan you should no longer see fe80 addresses. These are now "deprecated", meaning they are being phased out and shouldn't be used. The correct equivalent is fc00.

Then we come to your specific setup
a Virgin tail, with an Adva OS6250-8M and Cisco C1111-8P managed router connected to my UDM Pro. It's been up and running fine for nearly two years using IPv4, but I need to use IPv6 for some Terragraph kit. I've had the static IPv6 configured by Daisy and can use this successfully with my laptop connected directly to the Cisco, however I can't make it work properly on the UDMP, it can ping6 out fine with SSH on the UDMP and my clients receive an IPv6 address but have no IPv6 connectivity.
I wouldn't have a clue where to start with that particular kit combination. Modems, modems feeding routers, modem/routers bridging to routers I can often handle, but you have two high-end routers and a fancy switch there. One of the routers presumably containing the modem.

What I expect you should have on your LAN is roughly what I previously described. Each device should receive its own public IPv6 address on your 2001:xxx:xxx:2300::/56. IIRC from the past, your 2301 config picture is fine except for the 2301 should be 2300 and I'm unsure now about the final /56 or the /64 you had there. (I ditched my dual IPv4 and IPv6 AAISP connection at the end of November 2018 so can't easily looked up how I configured my /64s. Not /56s as I previously said when I did have 2 for a while inside the full /48 they provide).

Although in E300's first reply to me he says you could use anything including your 2301 on your LAN, I believe those would be sent via the net (and possibly fail), rather than through your LAN where your should have fc00 addresses just like you get 192.168.n.n ones on IPv4.

I of course, given my track record today, stand to be corrected on that! (Dammit smile!)

Your router controlling your LAN's connection to the net I would expect use its DHCP to provide the fc00 addresses and the 2300 ones. With two 2300 ones per device per device as I explained previously.

Useful stuff:
AAISP IPv6 knowledgebase, which although it describes how they handle it also contains a lot of explanation. Also related pages linked from there.

RIPE, which includes
A single network at a customer site will be a /64. At present, RIR policies permit assignment of a /48 per site, so the possible options when choosing a prefix size to delegate are /48, /52, /56, /60 and /64. However, /64 is not sustainable, it doesn't allow customer subnetting, and it doesn't follow IETF recommendations of “at least” multiple /64s per customer. Moreover, future work within the IETF and recommendations from RFC 7934 (section 6) allow the assignment of a /64 to a single interface (https://tools.ietf.org/html/draft-ietf-v6ops-unique-ipv6-prefix-per-host-07).

The following sections explain why /48 and /56 are the recommended prefix assignment sizes for end customers.
That quote comes from Section 4.2. I suggest you read on to the end of 4.2.3 smile.

Connections: OnePlus 8 Pro, 4G+ (LTE) max 165Mbps down, 24Mbps up on Three Mobile, and B311 4G+ router, tbb tests normally 35-45Mpbs down, 65Mbps off-peak, 9-24 up.
Standard User tdw42
(member) Sat 24-Jul-21 12:27:04
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: pluralist] [link to this post]
 
In reply to a post by pluralist:
Another minor point is that on your lan you should no longer see fe80 addresses. These are now "deprecated", meaning they are being phased out and shouldn't be used. The correct equivalent is fc00.


Completely incorrect. There will always be an fe80::/10 address (so in the range fe80:: - fe80::ffff:ffff:ffff:ffff) present on an interface, regardless of any other addresses, it is required for some IPv6 mechanisms such as NDP (Neighbour Discovery Protocol) and DHCPv6. The closest IPv4 equivalent are the RFC3927 addresses (169.254.1.0 - 169.254.254.255).

The fc00::/7 ULA (Unique Local Address) range is split into two equal-sized blocks. The use of fc00::/8 is currently undefined, and fd00::/8 (so in the range fd00:: - fdff:ffff:ffff:ffff:ffff:ffff:ffff:ffff) is for private addressing within an administrative domain encompassing a site or organisation, the IPv4 equivalent are the RFC1918 addresses (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).

You may be thinking of the fec0::/10 site-local address range which was deprecated in 2004 as what comprised a "site" was open to interpretation causing confusion. These should not be used.
Standard User JESC77
(newbie) Sat 24-Jul-21 13:09:05
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: jpm] [link to this post]
 
Hi, I hope this is useful.

Traceroute from https://network-tools.webwiz.net/traceroute.htm to Cisco
1 0 ms 2a00:85c0:1::2
2 6 ms 2001:1900:5:2:2:0:8:7d75
3 5 ms 2001:1900:2::3:159
4 5 ms 2001:1900:5:2:2::2a5e
5 8 ms 2001:xxx:1:1::ff3e:b0
6 12 ms 2001:xxx:xxx:2300::1

Traceroute from https://network-tools.webwiz.net/traceroute.htm to UDMP
1 0 ms 2a00:85c0:1::2
2 5 ms 2001:1900:5:2:2:0:8:7d75
3 5 ms 2001:1900:2::3:159
4 6 ms 2001:1900:5:2:2::2a5e
5 7 ms 2001:xxx:1:1::ff3e:b0
6 12 ms 2001:xxx:xxx:101::35:2
7 Timeout Unknown Host did not respond to ping

From UDMP SSH
traceroute to ipv6.google.com (2a00:1450:4009:815::200e), 30 hops max, 72 byte packets
1 2001:xxx:xxx:2300::1 0.722 ms 0.592 ms 0.461 ms
2 2001:xxx:300:101::35:1 5.748 ms 6.417 ms 6.109 ms
3 2001:xxx:1:1::ff40:dc 5.805 ms 5.860 ms 5.962 ms
4 2001:xxx:1:40:1525:3b41:1:2 6.587 ms 6.645 ms 6.561 ms
5 2a00:1450:8125::1 5.877 ms * *
6 * 2001:4860:0:1::5378 5.954 ms 2001:4860:0:1::248e 5.874 ms
7 * 2001:4860:0:1100::f 7.301 ms 2001:4860:0:1100::10 6.801 ms
8 lhr35s11-in-x0e.1e100.net (2a00:1450:4009:815::200e) 6.390 ms 5.881 ms *

I get no route from the LAN.

Thanks.
Standard User pluralist
(committed) Sat 24-Jul-21 13:26:01
Print Post

Re: Leased Line IPv6 problem with Unifi UDM Pro


[re: tdw42] [link to this post]
 
In reply to a post by tdw42:
In reply to a post by pluralist:
Another minor point is that on your lan you should no longer see fe80 addresses. These are now "deprecated", meaning they are being phased out and shouldn't be used. The correct equivalent is fc00.


Completely incorrect.
...
You may be thinking of the fec0::/10 site-local address range which was deprecated in 2004 as what comprised a "site" was open to interpretation causing confusion. These should not be used.
smile
You are right, except I wasn't thinking about fec0::/10. don't recall ever seeing that. I may have simply mis(speed)read something where fe80 v fc00 was being discussed. In particular wrt the 192.168.n.n of IPv4.

Thanks for pointing it out. The OP does need to get the right information.

Connections: OnePlus 8 Pro, 4G+ (LTE) max 165Mbps down, 24Mbps up on Three Mobile, and B311 4G+ router, tbb tests normally 35-45Mpbs down, 65Mbps off-peak, 9-24 up.
Pages in this thread: 1 | [2] | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | (show all)   Print Thread

Jump to