Summary
Add a native, configurable service that records IPv6 address to MAC address bindings observed on selected interfaces and sends them to syslog.
When SLAAC is used, the router does not assign addresses, so there is no lease log comparable to DHCPv4/DHCPv6. There is currently no native way in VyOS to answer "which device (MAC) used this IPv6 address at time X". Users have to rely on custom scripts polling ip -6 neigh via the task-scheduler, which live outside the configuration tree.
Use case
- Traceability / incident response: map an IPv6 address found in firewall, flow or upstream abuse logs back to a specific device on the LAN.
- Networks where DHCPv6 is not an option (e.g. Android clients do not support DHCPv6 address assignment), so SLAAC must be used.
- Privacy extensions (RFC 8981) rotate temporary addresses frequently, which makes a historical binding log especially important.
- Forwarding these events to a central log system (syslog, Loki, VictoriaLogs, etc.) using the existing system syslog remote configuration.
Similar functionality exists in other products, e.g. "NDP Monitoring" on Palo Alto PAN-OS, and arpwatch-style tools such as addrwatch or ndpmon.
Additional information
Proposed CLI (example only, open to discussion):
set service neighbor-log interface <interface> set service neighbor-log address-family <ipv4|ipv6> (default: ipv6) set service neighbor-log exclude-link-local (skip fe80::/10) set service neighbor-log syslog facility <facility> (default: local5) set service neighbor-log hold-time <seconds> (suppress duplicate events; default 86400)
Example log lines:
neighbor-log: event=new ip=2001:db8:1::1234 mac=aa:bb:cc:dd:ee:ff dev=eth1 neighbor-log: event=changed ip=2001:db8:1::1234 mac=11:22:33:44:55:66 old_mac=aa:bb:cc:dd:ee:ff dev=eth1
Optional op-mode command:
show neighbor-log [interface <interface>] [address <address>] [mac <mac>]
Implementation ideas:
- Listen to netlink RTM_NEWNEIGH / RTM_DELNEIGH events (equivalent to ip monitor neigh) instead of polling, so short-lived temporary addresses are not missed.
- Alternatively, package an existing tool such as addrwatch (available in Debian), which also captures DAD/NS/NA packets and records addresses even if the host never talks to the router.
- Only emit an event when a binding is first seen or the MAC changes, to keep log volume low.
Related: T2706 added an op-mode NDP monitor command, which is useful for live troubleshooting but does not provide a persistent, config-driven binding log.