Page MenuHomeVyOS Platform

neighbor-proxy: nd (IPv6) doesn't work - proxy_ndp not enabled
Closed, ResolvedPublicBUG

Description

Configuring protocols static neighbor-proxy nd <ipv6> interface <if> is supposed to make the router answer IPv6 neighbor discovery for that address.
VyOS installs the kernel proxy entry but doesn't enable net.ipv6.conf.<if>.proxy_ndp - which the Linux kernel requires (default 0). The IPv4 arp variant works, only the IPv6 nd side doesn't.

Minimal config (router r1, eth1 on the LAN):

set interfaces ethernet eth1 address 'fd00::1/64'
set protocols static neighbor-proxy nd fd00::99 interface eth1
commit

r1 after commit — proxy entry installed, but the required sysctl is off:

vyos@r1$ ip -6 neigh show proxy
 fd00::99 dev eth1 proxy
vyos@r1$ cat /proc/sys/net/ipv6/conf/eth1/proxy_ndp
 0

Host on the same segment (r2, fd00::2/64) - router doesn't answer:

vyos@r2$ ping6 -c2 fd00::99
 2 packets transmitted, 0 received, 100% packet loss
vyos@r2$ ip -6 neigh show fd00::99
 fd00::99 FAILED

Enable it by hand on r1:

vyos@r1$ sudo sysctl -w net.ipv6.conf.eth1.proxy_ndp=1
 net.ipv6.conf.eth1.proxy_ndp = 1

Re-probe from r2 (echo still lost as nothing hosts .99 but this re-triggers ND):

vyos@r2:~$ ping6 -c2 fd00::99
 2 packets transmitted, 0 received, 100% packet loss

vyos@r2$ ip -6 neigh show fd00::99
 fd00::99 lladdr 52:54:00:01:01:00 REACHABLE   # r1's eth1 MAC - proxy answers

Details

Version
1.5, 1.4
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)