Skip to content

Conversation

@RickLiuM2A1T90MQ-9
Copy link

Some ISPs may use a GUA or other non-LLA as the source addr for the DHCPv6 response, but the destination addr is always LLA (fe80::/10).
Therefore, adding a dest addr restriction improves security.
See https://forum.mikrotik.com/t/xfinity-comcast-dhcpv6-configuration-change/156031/10

Some ISPs may use a GUA or other non-LLA as the source addr for the DHCPv6 response, but the destination addr is always LLA (fe80::/10).
Therefore, adding a dest addr restriction improves security.
See https://forum.mikrotik.com/t/xfinity-comcast-dhcpv6-configuration-change/156031/10

Signed-off-by: Andy Chiang <AndyChiang_git@outlook.com>
@brada4
Copy link

brada4 commented Oct 27, 2025

Just cross-referncing with other restriction bc changing same lines. #62

@RickLiuM2A1T90MQ-9
Copy link
Author

For DHCPv6, just limiting the dest addr to a LLA is sufficient to ensure security and compatibility.

@brada4
Copy link

brada4 commented Oct 27, 2025

Mine is read directly from RFC, but yours indeed is more precise.

@brada4
Copy link

brada4 commented Oct 27, 2025

dhcp clients discard otherbsource ports leaving dangling ct unreplied state for them, so both complement eachother

@RickLiuM2A1T90MQ-9
Copy link
Author

firewall3 is complete (openwrt/openwrt@4ad22d0)
now only firewall4 needs to be merged.

@RickLiuM2A1T90MQ-9
Copy link
Author

@jow- @nbd168 PTAL

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants