Skip to content

Conversation

@AndyChiang888
Copy link

Some ISPs may use a GUA or other non-LLA as the source addr for the DHCPv6 response, but the destination addr is always LLA (fe80::/10).
Therefore, adding a dest addr restriction improves security.
See https://forum.mikrotik.com/t/xfinity-comcast-dhcpv6-configuration-change/156031/10

Some ISPs may use a GUA or other non-LLA as the source addr for the DHCPv6 response, but the destination addr is always LLA (fe80::/10).
Therefore, adding a dest addr restriction improves security.
See https://forum.mikrotik.com/t/xfinity-comcast-dhcpv6-configuration-change/156031/10

Signed-off-by: Andy Chiang <AndyChiang_git@outlook.com>
@brada4
Copy link

brada4 commented Oct 27, 2025

Just cross-referncing with other restriction bc changing same lines. #62

@AndyChiang888
Copy link
Author

For DHCPv6, just limiting the dest addr to a LLA is sufficient to ensure security and compatibility.

@brada4
Copy link

brada4 commented Oct 27, 2025

Mine is read directly from RFC, but yours indeed is more precise.

@brada4
Copy link

brada4 commented Oct 27, 2025

dhcp clients discard otherbsource ports leaving dangling ct unreplied state for them, so both complement eachother

@AndyChiang888
Copy link
Author

firewall3 is complete (openwrt/openwrt@4ad22d0)
now only firewall4 needs to be merged.

@AndyChiang888
Copy link
Author

@jow- @nbd168 PTAL

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants