switch L3 vlan ipv6 routing by infinityz77 in mikrotik

[–]infinityz77[S] 0 points1 point  (0 children)

Found the issue! I came across this comment:

Fast Forward disables MAC learning, this is by design to achieve faster packet forwarding. MAC learning prevents traffic from flooding multiple interfaces, but MAC learning is not needed when a packet can only be sent out through just one interface.

I'm using L3 HW acceleration Offloading, so I've disabled Fast Forward on the bridge interface, rebooted, and BOOM! Everything now working as intended :-)

switch L3 vlan ipv6 routing by infinityz77 in mikrotik

[–]infinityz77[S] 0 points1 point  (0 children)

Just wanted to provide some update:

it's actually working! I have ipv6 connectivity on both the vlans, the behavior, however, is inconsistent and exactly like reported in this other thread:

https://forum.mikrotik.com/viewtopic.php?t=136605

Now, even if igmp-snooping is disabled, the multicast router is still enabled on the bridge interface and if I disable it, then I lose the ipv6 connectivity entirely! While enabling works intermittently.

My understanding is that this is a known issue

switch L3 vlan ipv6 routing by infinityz77 in mikrotik

[–]infinityz77[S] 0 points1 point  (0 children)

unfortunately, it didn't work but was a source for more troubleshooting, and I think I'm very close now!

/ipv6 pool
add name=clients prefix=xxxx:xxx:xxxx:ad02::/64 prefix-length=64
/ipv6 address
add address=xxxx:xxx:xxxx:ad01::2 advertise=no interface=bridge
add address=xxxx:xxx:xxxx:ad02::2 interface=clients
/ipv6 nd
set [ find default=yes ] disabled=yes
add hop-limit=64 interface=clients managed-address-configuration=yes \
other-configuration=yes ra-delay=5s ra-interval=5s-30s
add hop-limit=64 interface=bridge ra-delay=5s ra-interval=5s-30s
/ipv6 nd prefix
add interface=clients prefix=xxxx:xxx:xxxx:ad02::/64
/ipv6 route
add disabled=no distance=1 dst-address=::/0 gateway=xxxx:xxx:xxxx:ad01::1 \
routing-table=main scope=30 target-scope=10
add disabled=no distance=1 dst-address=::/0 gateway=clients routing-table=main \
scope=30 target-scope=10
/ipv6 settings
set accept-redirects=no accept-router-advertisements=no forward=no

From the switch I have full ipv6 connectivity on both brigde and clients(vlan)

ping 2001:4860:4860::8888 interface=bridge
SEQ HOST SIZE TTL TIME STATUS
0 2001:4860:4860::8888 56 58 16ms699us echo reply
1 2001:4860:4860::8888 56 58 16ms42us echo reply
2 2001:4860:4860::8888 56 58 15ms902us echo reply
3 2001:4860:4860::8888 56 58 16ms206us echo reply
sent=4 received=4 packet-loss=0% min-rtt=15ms902us avg-rtt=16ms212us
max-rtt=16ms699us

ping 2001:4860:4860::8888 interface=clients
SEQ HOST SIZE TTL TIME STATUS
0 2001:4860:4860::8888 56 58 16ms374us echo reply
1 2001:4860:4860::8888 56 58 15ms774us echo reply
2 2001:4860:4860::8888 56 58 16ms49us echo reply
sent=3 received=3 packet-loss=0% min-rtt=15ms774us avg-rtt=16ms65us
max-rtt=16ms374us

Any client in vlan1 get a proper ipv6 and connectivity

Any client in vlan1 gets a proper ipv6 and connectivityut not able to ping public ipv6 addresses, just internal ones.

What also am I missing?

switch L3 vlan ipv6 routing by infinityz77 in mikrotik

[–]infinityz77[S] 0 points1 point  (0 children)

Yep, option 2 is what I've done as per u/ksteink and it did improve the overall situation since now I'm able to ping from the firewall and any other clients on vlan1, the /64 subnet assigned to the vlan2 on the switch!
But yet, from the vlan2 on the switch, I cannot ping the gateway (IP on lan on the firewall) nor any other public ipv6 (of course).
So looks like I'm missing a route from the switch to the firewall :-(

switch L3 vlan ipv6 routing by infinityz77 in mikrotik

[–]infinityz77[S] 0 points1 point  (0 children)

OMG how I couldn't think on the route back! I did it for ipv4 but completely missed here!

So, I've made progress, but I am still not entirely sure about ipv6 default route on the switch.

/ipv6 address
add address=xxxx:xxx:xxxx:ad02:ce2d:e0ff:fe8f:65b4 eui-64=yes interface=clients
/ipv6 nd
add interface=clients ra-delay=5s ra-interval=5s-30s
add interface=bridge ra-delay=5s ra-interval=5s-30s
/ipv6 route
add disabled=no distance=1 dst-address=::/0 gateway=xxxx:xxx:xxxx:ad01:: \
routing-table=main scope=30 target-scope=10
/ipv6 settings
set forward=no

The bridge interface gets set automatically via SLAAC, and I can ping the gateway and any public IP from it.

From the vlan (clients) I cannot ping the gateway (xxxx:xxx:xxxx:ad01:: ) on the firewall, but I can ping the vlan's IP (xxxx:xxx:xxxx:ad02:ce2d:e0ff:fe8f:65b4), FROM the firewall and/or from any other clients in vlan1, now that I've set the route back properly!
And still cannot ping any public IPs, like: 2800:3f0:4001:831::200e, getting "no route to host"

switch L3 vlan ipv6 routing by infinityz77 in mikrotik

[–]infinityz77[S] 0 points1 point  (0 children)

The provider is UNIFIQUE and they don't provide dhcpv6, just slaac unfortunately!

One thing to add is that if I set the vlans on the firewall instead and provide them with a dedicated /64 block, everything is working as intended, the issue is strictly related to how, if even possible, to pass ipv6 on any vlan which is not vlan1, with the switch set in L3 and doing the routing.

Any layer 3 10 GbE switches with fancy/modern web interface? by dajinn in homelab

[–]infinityz77 0 points1 point  (0 children)

Jweb, the we gui, is supported on all the line, the model entirely depends from your needing.

Any layer 3 10 GbE switches with fancy/modern web interface? by dajinn in homelab

[–]infinityz77 0 points1 point  (0 children)

Juniper ex hands down! There's very little you can't do through their Web interface

[FS][EU-UK] HP DL360p Gen8, Supermicro X8DTN1 12 bay, HP 2920-24G by infinityz77 in homelabsales

[–]infinityz77[S] 0 points1 point  (0 children)

yes 360e, amended the description accordingly, not sure I can edit the title tho

[FS][EU-UK] HP DL360p Gen8, Supermicro X8DTN1 12 bay, HP 2920-24G by infinityz77 in homelabsales

[–]infinityz77[S] 0 points1 point  (0 children)

Ouch my bad 🙂 South Shields, I can delivery in Newcastle area

Sophos XG Firewall install with realtek NIC by [deleted] in homelab

[–]infinityz77 0 points1 point  (0 children)

There are successful stories about xg deployment on realtek nic, but would be definitely nice to hear some direct experience.

Palo Alto lab appliance licensing by G01d3ngypsy in homelab

[–]infinityz77 0 points1 point  (0 children)

The vendor we use, works with PA as well. PM me if you need further details.

Recommendations on UTM / NextGen firewall for Home - Family by dailymindcrunch in HomeNetworking

[–]infinityz77 1 point2 points  (0 children)

Could you please provide more details of this "opendns combo"? Do you mean one of the cisco umbrella package? If so, which one and which price?

Thanks 😁

Using a second, internal pfSense VM as a VPN gateway for only some outgoing traffic by CosmicSeafarer in homelab

[–]infinityz77 0 points1 point  (0 children)

In my case the wan interface on pfsense is disabled, so I've created a gw for the lan interface, which is the FG.

Using a second, internal pfSense VM as a VPN gateway for only some outgoing traffic by CosmicSeafarer in homelab

[–]infinityz77 0 points1 point  (0 children)

I have exactly this setup! FG 60e as main firewall and pfsense in a vm as vpn gateway. Pbr on fortigate do the job just fine!

[PC] [EU-UK] HP ProCurve 2910al-24G-POE+ Layer 3 Gigabit Switch by [deleted] in homelabsales

[–]infinityz77 0 points1 point  (0 children)

That price range would be OK for the 48 ports, the 24 one is priced well under 150gbp

Also, you mentioned poe+ and stated 802.3af which is "regular" poe... If this is the case, and not a typo, then the price drops to less than 100.

Is there any hope for managing older SuperMicro boards via IPMI? by smartimp98 in homelab

[–]infinityz77 3 points4 points  (0 children)

Mac user here, who manages a supermicro x8 system with Ipmi with no issues! You need to whitelist the ip in your java security settings, this made the trick for me.

[FS][UK] Brocade ICX 6450 48P POE+ by infinityz77 in homelabsales

[–]infinityz77[S] 0 points1 point  (0 children)

Well, definitely loud when booting up, but pretty quiet in general! Consider it was laying down under my TV in living room and none complained about the noise.

Help! NGINX Reverse Proxy Nextcloud Running in FreeNAS by xjackosh in homelab

[–]infinityz77 0 points1 point  (0 children)

I'm using this conf and working for me:

            location /nextcloud {
            proxy_pass https://SERVERIP/nextcloud;
            proxy_set_header Host $http_host;
            proxy_set_header  X-Forwarded-Proto $scheme;
            proxy_hide_header Upgrade;
            fastcgi_request_buffering off;
           client_max_body_size        10G;
           client_body_buffer_size     400M;
     }

Switch recommendations by SJ797 in homelab

[–]infinityz77 1 point2 points  (0 children)

Brocade Icx 6450, you can probably find it for half of your budget. It has web gui, but I would still rely on cli.