<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1010 IPv6 DHCP on outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410252#M1081130</link>
    <description>&lt;P&gt;Thanks for checking!&lt;/P&gt;&lt;P&gt;I tried setting those DHCP for IPv6 options, however the device doesn't seem to pick up an IPv6 address:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;outside is up, line protocol is up&lt;BR /&gt;IPv6 is enabled, link-local address is fe80::a2b4:39ff:fe3a:76c8&lt;BR /&gt;No global unicast address is configured&lt;BR /&gt;Joined group address(es):&lt;BR /&gt;ff02::1:ff00:0&lt;BR /&gt;ff02::2&lt;BR /&gt;ff02::1:ff3a:76c8&lt;BR /&gt;ff02::1&lt;BR /&gt;ICMP error messages limited to one every 100 milliseconds&lt;BR /&gt;ICMP redirects are enabled&lt;BR /&gt;ND DAD is enabled, number of DAD attempts: 1&lt;BR /&gt;ND reachable time is 30000 milliseconds&lt;BR /&gt;Hosts use DHCP to obtain routable addresses.&lt;BR /&gt;Hosts use DHCP to obtain other configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can enter the /48 prefix i got from my ISP, but then i won't receive any routes, and i'm not aware of a gateway address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I'm a bit new to IPv6, but this would help me learn more about it)&lt;/P&gt;</description>
    <pubDate>Fri, 28 May 2021 17:17:50 GMT</pubDate>
    <dc:creator>Squared</dc:creator>
    <dc:date>2021-05-28T17:17:50Z</dc:date>
    <item>
      <title>Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410221#M1081125</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Firepower 1010 with currently version 7.0.0 FTD image installed (also tried with 6.6 and 6.7), but i am unable to get IPv6 working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ISP provides me with IPv4 address through PPPoE, and a /48 IPv6 prefix through normal DHCP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPv4 is working, but i cannot find the right settings to get an IP address on my outside interface.&lt;/P&gt;&lt;P&gt;I tried different settings for the IPv6 interface, but it is not clear how to get an IPv6 address (and route) through DHCP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any tips on how to set this up?&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 16:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410221#M1081125</guid>
      <dc:creator>Squared</dc:creator>
      <dc:date>2021-05-28T16:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410239#M1081129</link>
      <description>&lt;P&gt;New as of 7.0:&lt;/P&gt;
&lt;P&gt;"By default, the IP address is obtained using IPv4 DHCP&lt;SPAN class="ph"&gt; and IPv6 autoconfiguration&lt;/SPAN&gt;, but you can set a static address during initial configuration."&lt;/P&gt;
&lt;P&gt;Looking in the online help ("Step 5" copied below), it &lt;STRONG&gt;at first&lt;/STRONG&gt; appears it only support stateless autoconfig or static IPv6 addressing. i.e., NOT IPv6 DHCP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, look under the Advanced tab ("Step 8") - there is an option there for IPv6 DHCP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="stepTable" border="0"&gt;
&lt;TBODY&gt;
&lt;TR id="task_D0C0FB15621B4F49B29CB010F7D6C2D1__step_5AF70D50F7DB40289F3583B717A5EAED" class="li step"&gt;
&lt;TD align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;8&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;Modify the &lt;SPAN class="ph uicontrol"&gt;IPv6 Configuration&lt;/SPAN&gt; settings.&lt;/P&gt;
&lt;UL class="ul choices"&gt;
&lt;LI id="task_D0C0FB15621B4F49B29CB010F7D6C2D1__choice_18F1A859E8454EE5AEFC6AFF0749E08F" class="li choice"&gt;&lt;SPAN class="ph uicontrol"&gt; Enable DHCP for IPv6 address configuration&lt;/SPAN&gt;—Whether to set the Managed Address Configuration flag in the IPv6 router advertisement packet. This flag informs IPv6 autoconfiguration clients that they should use DHCPv6 to obtain addresses, in addition to the derived stateless autoconfiguration address.&lt;/LI&gt;
&lt;LI id="task_D0C0FB15621B4F49B29CB010F7D6C2D1__choice_239BDDF3797E4507ACDCAF9881910CB1" class="li choice"&gt;&lt;SPAN class="ph uicontrol"&gt; Enable DHCP for IPv6 non-address configuration&lt;/SPAN&gt;—Whether to set the Other Address Configuration flag in the IPv6 router advertisement packet. This flag informs IPv6 autoconfiguration clients that they should use DHCPv6 to obtain additional information from DHCPv6, such as the DNS server address.&lt;/LI&gt;
&lt;LI id="task_D0C0FB15621B4F49B29CB010F7D6C2D1__choice_3F9FAEEA476C47F9A9C784BC22F0C51D" class="li choice"&gt;&lt;SPAN class="ph uicontrol"&gt;DAD Attempts&lt;/SPAN&gt;—How often the interface performs Duplicate Address Detection (DAD), from 0 - 600. The default is 1. During the stateless autoconfiguration process, DAD verifies the uniqueness of new unicast IPv6 addresses before the addresses are assigned to interfaces. If the duplicate address is the link-local address of the interface, the processing of IPv6 packets is disabled on the interface. If the duplicate address is a global address, the address is not used. The interface uses neighbor solicitation messages to perform Duplicate Address Detection. Set the value to 0 to disable duplicate address detection (DAD) processing.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="stepTable" border="0"&gt;
&lt;TBODY&gt;
&lt;TR id="task_50361D0BE07D430DA09BD60C7EF92864__step_0BE06319610E4E70AA9D2832F656CA8F" class="li step"&gt;
&lt;TD align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;5&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;(Optional.) Click the &lt;SPAN class="ph uicontrol"&gt;IPv6 Address&lt;/SPAN&gt; tab and configure the IPv6 address.&lt;/P&gt;
&lt;DIV class="itemgroup info"&gt;
&lt;UL class="ul"&gt;
&lt;LI id="task_50361D0BE07D430DA09BD60C7EF92864__d64e206" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;State&lt;/SPAN&gt;—To enable IPv6 processing and to automatically configure the link-local address when you do not configure the global address, select &lt;SPAN class="ph uicontrol"&gt;Enabled&lt;/SPAN&gt;. The link local address is generated based on the interface MAC addresses (&lt;EM class="ph i"&gt;Modified&lt;/EM&gt; EUI-64 format).&lt;/P&gt;
&lt;TABLE class="note olh_note note--note note--compact" role="note"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="td_faq"&gt;
&lt;DIV&gt;Note&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="td_faq"&gt;
&lt;DIV class="note__content"&gt;
&lt;P class="p"&gt;Disabling IPv6 does not disable IPv6 processing on an interface that is configured with an explicit IPv6 address or that is enabled for autoconfiguration.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/LI&gt;
&lt;LI id="task_50361D0BE07D430DA09BD60C7EF92864__d64e225" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;Address Auto Configuration&lt;/SPAN&gt;—Select this option to have the address automatically configured. IPv6 stateless autoconfiguration will generate a global IPv6 address only if the link on which the device resides has a router configured to provide IPv6 services, including the advertisement of an IPv6 global prefix for use on the link. If IPv6 routing services are not available on the link, you will get a link-local IPv6 address only, which you cannot access outside of the device's immediate network link. The link local address is based on the Modified EUI-64 interface ID.&lt;/P&gt;
&lt;P class="p"&gt;Although RFC 4862 specifies that hosts configured for stateless autoconfiguration do not send Router Advertisement messages, the &lt;SPAN class="ph"&gt;FTD&lt;/SPAN&gt; device does send Router Advertisement messages in this case. Select &lt;SPAN class="ph uicontrol"&gt;Suppress RA&lt;/SPAN&gt; to suppress messages and conform to the RFC.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="task_50361D0BE07D430DA09BD60C7EF92864__d64e241" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;Static Address/Prefix&lt;/SPAN&gt;—If you do not use stateless autoconfiguration, enter the full static global IPv6 address and network prefix. For example, 2001:0DB8::BA98:0:3210/48. For more information on IPv6 addressing, see &lt;A class="xref" href="https://172.31.4.3/help/fdm/en-us/help.html?url=help/fdm/en-us/t_configure_a_physical_interface.html#!c_ipv6_addressing.html#concept_7E49AD839DF94B9396576B7FE6F87DF8" target="_blank" rel="noopener"&gt;IPv6 Addressing&lt;/A&gt;.&lt;/P&gt;
&lt;P class="p"&gt;If you want to use the address as link local only, select the &lt;SPAN class="ph uicontrol"&gt;Link - Local&lt;/SPAN&gt; option. Link local addresses are not accessible outside the local network. You cannot configure a link-local address on a bridge group interface.&lt;/P&gt;
&lt;TABLE class="note olh_note note--note note--compact" role="note"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="td_faq"&gt;
&lt;DIV&gt;Note&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="td_faq"&gt;
&lt;DIV class="note__content"&gt;
&lt;P class="p"&gt;A link-local address should start with FE8, FE9, FEA, or FEB, for example fe80::20d:88ff:feee:6a82. Note that we recommend automatically assigning the link-local address based on the Modified EUI-64 format. For example, if other devices enforce the use of the Modified EUI-64 format, then a manually-assigned link-local address may cause packets to be dropped.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/LI&gt;
&lt;LI id="task_50361D0BE07D430DA09BD60C7EF92864__d64e262" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;Standby IP Address&lt;/SPAN&gt;—If you configure high availability, and you are monitoring this interface for HA, also configure a standby IPv6 address on the same subnet. The standby address is used by this interface on the standby device. If you do not set the standby IP address, the active unit cannot monitor the standby interface using network tests; it can only track the link state.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="task_50361D0BE07D430DA09BD60C7EF92864__d64e269" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;Suppress RA&lt;/SPAN&gt;—Whether to suppress router advertisements. The &lt;SPAN class="ph"&gt;Firepower Threat Defense device&lt;/SPAN&gt; can participate in router advertisements so that neighboring devices can dynamically learn a default router address. By default, router advertisement messages (ICMPv6 Type 134) are periodically sent out each IPv6 configured interface.&lt;/P&gt;
&lt;P class="p"&gt;Router advertisements are also sent in response to router solicitation messages (ICMPv6 Type 133). Router solicitation messages are sent by hosts at system startup so that the host can immediately autoconfigure without needing to wait for the next scheduled router advertisement message.&lt;/P&gt;
&lt;P class="p"&gt;You might want to suppress these messages on any interface for which you do not want the &lt;SPAN class="ph"&gt;FTD&lt;/SPAN&gt; device to supply the IPv6 prefix (for example, the outside interface).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 28 May 2021 17:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410239#M1081129</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-28T17:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410252#M1081130</link>
      <description>&lt;P&gt;Thanks for checking!&lt;/P&gt;&lt;P&gt;I tried setting those DHCP for IPv6 options, however the device doesn't seem to pick up an IPv6 address:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;outside is up, line protocol is up&lt;BR /&gt;IPv6 is enabled, link-local address is fe80::a2b4:39ff:fe3a:76c8&lt;BR /&gt;No global unicast address is configured&lt;BR /&gt;Joined group address(es):&lt;BR /&gt;ff02::1:ff00:0&lt;BR /&gt;ff02::2&lt;BR /&gt;ff02::1:ff3a:76c8&lt;BR /&gt;ff02::1&lt;BR /&gt;ICMP error messages limited to one every 100 milliseconds&lt;BR /&gt;ICMP redirects are enabled&lt;BR /&gt;ND DAD is enabled, number of DAD attempts: 1&lt;BR /&gt;ND reachable time is 30000 milliseconds&lt;BR /&gt;Hosts use DHCP to obtain routable addresses.&lt;BR /&gt;Hosts use DHCP to obtain other configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can enter the /48 prefix i got from my ISP, but then i won't receive any routes, and i'm not aware of a gateway address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I'm a bit new to IPv6, but this would help me learn more about it)&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 17:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410252#M1081130</guid>
      <dc:creator>Squared</dc:creator>
      <dc:date>2021-05-28T17:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410579#M1081151</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;try to isolate if this is an ISP issue. directly connect your laptop (or a router) to the ISP cable/handoff and see if you get an IPv6 address.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 03:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4410579#M1081151</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2021-05-30T03:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4411030#M1081184</link>
      <description>&lt;P&gt;Thanks for the replies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I pushed my laptop into the ISP-VLAN, but didn't get an IPv6 address by DHCP.&lt;/P&gt;&lt;P&gt;Will need to do an extra check; maybe i need my laptop to setup the IPv4 PPPoE aswel to be able to get an IPv6 address though.&lt;/P&gt;&lt;P&gt;I will probably check that tonight.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 15:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4411030#M1081184</guid>
      <dc:creator>Squared</dc:creator>
      <dc:date>2021-05-31T15:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4411284#M1081195</link>
      <description>&lt;P&gt;I'm a bit further with information from my ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It turns out that they use IPv6 prefix delegation, so i should setup the Firepower interface to use that.&lt;BR /&gt;I cannot find how to set up prefix delegation, but i found a bit of asa code to set an interface to ipv6 prefix delegation:&lt;/P&gt;&lt;P&gt;ipv6 dhcp client pd Outside-Prefix&lt;BR /&gt;ipv6 dhcp client pd hint 2001:DB8:ABCD:1230::/60&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, these commands are blocked by Flexconfig &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; (Block list CLI error)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there another way to configure prefix delegation on a Firepower 1010 with on the box management?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 08:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4411284#M1081195</guid>
      <dc:creator>Squared</dc:creator>
      <dc:date>2021-06-01T08:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4411990#M1081235</link>
      <description>&lt;P&gt;I opened a TAC case for this, looks like prefix delegation isn't possible without Firepower Management Center.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TAC pointed me to &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24561," target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24561,&lt;/A&gt; so i'll keep an eye on that.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 14:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4411990#M1081235</guid>
      <dc:creator>Squared</dc:creator>
      <dc:date>2021-06-02T14:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 IPv6 DHCP on outside interface</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4412042#M1081236</link>
      <description>&lt;P&gt;Good to know - another thing that's not supported in FDM.&lt;/P&gt;
&lt;P&gt;That's why the FMC 7.0 config guide is 3202 pages (vs. 856 pages for FDM). &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-ipv6-dhcp-on-outside-interface/m-p/4412042#M1081236</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-02T15:33:17Z</dc:date>
    </item>
  </channel>
</rss>

