Page MenuHomeVyOS Platform

Add persistent IPv6 neighbor (NDP) binding logging for SLAAC address tracking
Open, Requires assessmentPublicFEATURE REQUEST

Description

Summary

Add a native, configurable service that records IPv6 address to MAC address bindings observed on selected interfaces and sends them to syslog.

When SLAAC is used, the router does not assign addresses, so there is no lease log comparable to DHCPv4/DHCPv6. There is currently no native way in VyOS to answer "which device (MAC) used this IPv6 address at time X". Users have to rely on custom scripts polling ip -6 neigh via the task-scheduler, which live outside the configuration tree.

Use case

  • Traceability / incident response: map an IPv6 address found in firewall, flow or upstream abuse logs back to a specific device on the LAN.
  • Networks where DHCPv6 is not an option (e.g. Android clients do not support DHCPv6 address assignment), so SLAAC must be used.
  • Privacy extensions (RFC 8981) rotate temporary addresses frequently, which makes a historical binding log especially important.
  • Forwarding these events to a central log system (syslog, Loki, VictoriaLogs, etc.) using the existing system syslog remote configuration.

Similar functionality exists in other products, e.g. "NDP Monitoring" on Palo Alto PAN-OS, and arpwatch-style tools such as addrwatch or ndpmon.

Additional information

Proposed CLI (example only, open to discussion):

set service neighbor-log interface <interface>
set service neighbor-log address-family <ipv4|ipv6> (default: ipv6)
set service neighbor-log exclude-link-local (skip fe80::/10)
set service neighbor-log syslog facility <facility> (default: local5)
set service neighbor-log hold-time <seconds> (suppress duplicate events; default 86400)

Example log lines:

neighbor-log: event=new ip=2001:db8:1::1234 mac=aa:bb:cc:dd:ee:ff dev=eth1
neighbor-log: event=changed ip=2001:db8:1::1234 mac=11:22:33:44:55:66 old_mac=aa:bb:cc:dd:ee:ff dev=eth1

Optional op-mode command:

show neighbor-log [interface <interface>] [address <address>] [mac <mac>]

Implementation ideas:

  • Listen to netlink RTM_NEWNEIGH / RTM_DELNEIGH events (equivalent to ip monitor neigh) instead of polling, so short-lived temporary addresses are not missed.
  • Alternatively, package an existing tool such as addrwatch (available in Debian), which also captures DAD/NS/NA packets and records addresses even if the host never talks to the router.
  • Only emit an event when a binding is first seen or the MAC changes, to keep log volume low.

Related: T2706 added an op-mode NDP monitor command, which is useful for live troubleshooting but does not provide a persistent, config-driven binding log.

Details

Version
VyOS 2026.03
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)

Related Objects