System and setup: m0n0wall 1.33 running on ALIX
Physical Interfaces:vr1: WAN (IPv6 mode AICCU)
vr0: LAN (IPv6 mode static)
IPv6 Address: 2001:16d8:dd35:1::/64
Enabled: Send IPv6 router advertisements & Other stateful configuration
Virtual Interfaces:vlan0 (DMZ): vr0 tagged with ID10 (IPv6 mode static)
IPv6 Address: 2001:16d8:dd35:babe::/64
Enabled: Send IPv6 router advertisements & Other stateful configuration
vlan1 (DMZ2): vr0 tagged with ID20 (IPv6 mode disabled)
Problem:The router advertizements that are received by the clients on LAN contains information about the adresses in DMZ.
A view from the client:
Ethernet adapter Wireless Network Connection:
Connection-specific DNS Suffix . : local
IP Address. . . . . . . . . . . . : 10.0.1.192
Subnet Mask . . . . . . . . . . . : 255.255.255.0
IP Address. . . . . . . . . . . . : 2001:16d8:dd35:1:cdd8:f690:35c9:eec1
IP Address. . . . . . . . . . . . : 2001:16d8:dd35:1:221:5cff:fe5f:d897
IP Address. . . . . . . . . . . . : 2001:16d8:dd35:babe:cdd8:f690:35c9:eec1
IP Address. . . . . . . . . . . . : 2001:16d8:dd35:babe:221:5cff:fe5f:d897
IP Address. . . . . . . . . . . . : fe80::221:5cff:fe5f:d897%10
Default Gateway . . . . . . . . . : 10.0.1.254
fe80::20d:b9ff:fe15:6450%10
This causes the client to bind to addresses in two different subnets and depending on the priority of the IP's, the client will loose all IPv6 connectivity (trying to send packets with a source IP from a different subnet, and hence not allowed through the FW)..
The same doesn't happen on the DMZ interface. It only receives advertizements for its own interface:
eth0 Link encap:Ethernet HWaddr 00:0c:29:20:73:23
inet addr:10.0.10.50 Bcast:10.0.10.255 Mask:255.255.255.0
inet6 addr: 2001:16d8:dd35:babe:20c:29ff:fe20:7323/64 Scope:Global
inet6 addr: fe80::20c:29ff:fe20:7323/64 Scope:Link
If I disable RA's on DMZ, the incorrect advertizement on LAN immidiatly stops..
I haven't tested if this is only VLAN related or if the same will happen if I enable IPv6+RA on physical interface vr2..