05-28-2021 09:09 AM
Hi,
I have a Firepower 1010 with currently version 7.0.0 FTD image installed (also tried with 6.6 and 6.7), but i am unable to get IPv6 working.
My ISP provides me with IPv4 address through PPPoE, and a /48 IPv6 prefix through normal DHCP.
IPv4 is working, but i cannot find the right settings to get an IP address on my outside interface.
I tried different settings for the IPv6 interface, but it is not clear how to get an IPv6 address (and route) through DHCP.
Any tips on how to set this up?
05-28-2021 09:58 AM - edited 05-28-2021 10:04 AM
New as of 7.0:
"By default, the IP address is obtained using IPv4 DHCP and IPv6 autoconfiguration, but you can set a static address during initial configuration."
Looking in the online help ("Step 5" copied below), it at first appears it only support stateless autoconfig or static IPv6 addressing. i.e., NOT IPv6 DHCP.
However, look under the Advanced tab ("Step 8") - there is an option there for IPv6 DHCP.
Step 8 |
Modify the IPv6 Configuration settings.
|
Step 5 |
(Optional.) Click the IPv6 Address tab and configure the IPv6 address.
|
05-28-2021 10:17 AM
Thanks for checking!
I tried setting those DHCP for IPv6 options, however the device doesn't seem to pick up an IPv6 address:
outside is up, line protocol is up
IPv6 is enabled, link-local address is fe80::a2b4:39ff:fe3a:76c8
No global unicast address is configured
Joined group address(es):
ff02::1:ff00:0
ff02::2
ff02::1:ff3a:76c8
ff02::1
ICMP error messages limited to one every 100 milliseconds
ICMP redirects are enabled
ND DAD is enabled, number of DAD attempts: 1
ND reachable time is 30000 milliseconds
Hosts use DHCP to obtain routable addresses.
Hosts use DHCP to obtain other configuration.
I can enter the /48 prefix i got from my ISP, but then i won't receive any routes, and i'm not aware of a gateway address.
(I'm a bit new to IPv6, but this would help me learn more about it)
05-29-2021 08:03 PM
hi,
try to isolate if this is an ISP issue. directly connect your laptop (or a router) to the ISP cable/handoff and see if you get an IPv6 address.
05-31-2021 08:15 AM
Thanks for the replies.
I pushed my laptop into the ISP-VLAN, but didn't get an IPv6 address by DHCP.
Will need to do an extra check; maybe i need my laptop to setup the IPv4 PPPoE aswel to be able to get an IPv6 address though.
I will probably check that tonight.
06-01-2021 01:22 AM
I'm a bit further with information from my ISP.
It turns out that they use IPv6 prefix delegation, so i should setup the Firepower interface to use that.
I cannot find how to set up prefix delegation, but i found a bit of asa code to set an interface to ipv6 prefix delegation:
ipv6 dhcp client pd Outside-Prefix
ipv6 dhcp client pd hint 2001:DB8:ABCD:1230::/60
However, these commands are blocked by Flexconfig
Is there another way to configure prefix delegation on a Firepower 1010 with on the box management?
06-02-2021 07:06 AM
I opened a TAC case for this, looks like prefix delegation isn't possible without Firepower Management Center.
TAC pointed me to https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24561, so i'll keep an eye on that.
06-02-2021 08:33 AM
Good to know - another thing that's not supported in FDM.
That's why the FMC 7.0 config guide is 3202 pages (vs. 856 pages for FDM).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide