- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Custom IPv6 link-local address on Gaia interface
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Custom IPv6 link-local address on Gaia interface
Hello,
we are building R80.10 vSEC firewall with dual-stack enabled and we have 2 subnets inside DMZ, which will have Global unicast IPv6 subnet together with IPv4 subnet. However, this subnet is not directly connected to Check Point Gaia and we need to route to this subnet via another router. As we would prefer not to assign Global unicast IPv6 subnet on point-to-point connections between firewall and router, we decided to route to this global subnet using link-local addresses. However, I can't find a way to set up custom link-local address on Gaia Interface, such as fe80::5.
I though this would be possible as is on Cisco routers, where you just use:
ipv6 address FE80::AB8 link-local
but Gaia seems to refuse this. I can see link-local address derived from MAC address using EUI-64, we can probably use this, however will this IP be stable and won't change with some privacy extensions after restart or on other occasion? Or would it be better to just assign Global IPv6 subnets on whole path to DMZ?
Thanks for answers.
- Tags:
- ipv6
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Lukas,
I experienced the same behavior. You could configure VRRPv3 (should work with a single gateway too) which allows you to define a custom link local IP which you can use as a next hop gateway.
Matthias
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"Address has link local prefix" error when creating a manual Link local IPv6 address
But you can do it with VRRPv3, as Matthias said.
