UFW block dhclient for ipv6
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{ margin-bottom:0;
}
I have setup ufw and now I'm tring to setup IPv6 using dhclient:
interface "eth0" {
send dhcp6.client-id DUID;
}
When ufw is enabled it blocks dchp for ipv6, when i disable ufw, all is OK and dhcp starts fine.
ufw allow from any port 547 to any port 546 proto udp that help, but is that corect decision?
16.04 networking server ufw
add a comment |
I have setup ufw and now I'm tring to setup IPv6 using dhclient:
interface "eth0" {
send dhcp6.client-id DUID;
}
When ufw is enabled it blocks dchp for ipv6, when i disable ufw, all is OK and dhcp starts fine.
ufw allow from any port 547 to any port 546 proto udp that help, but is that corect decision?
16.04 networking server ufw
Hello and welcome to AskUbuntu! Can you share yourufwconfiguration? The question as is it's too broad/vague?
– Mr Shunz
Feb 12 at 9:34
ufw allow from any port 547 to any port 546 proto udpthat helps. or that isn't correct ?
– Beliaf
Feb 12 at 10:30
add a comment |
I have setup ufw and now I'm tring to setup IPv6 using dhclient:
interface "eth0" {
send dhcp6.client-id DUID;
}
When ufw is enabled it blocks dchp for ipv6, when i disable ufw, all is OK and dhcp starts fine.
ufw allow from any port 547 to any port 546 proto udp that help, but is that corect decision?
16.04 networking server ufw
I have setup ufw and now I'm tring to setup IPv6 using dhclient:
interface "eth0" {
send dhcp6.client-id DUID;
}
When ufw is enabled it blocks dchp for ipv6, when i disable ufw, all is OK and dhcp starts fine.
ufw allow from any port 547 to any port 546 proto udp that help, but is that corect decision?
16.04 networking server ufw
16.04 networking server ufw
edited Feb 12 at 10:41
Beliaf
asked Feb 12 at 7:41
BeliafBeliaf
32
32
Hello and welcome to AskUbuntu! Can you share yourufwconfiguration? The question as is it's too broad/vague?
– Mr Shunz
Feb 12 at 9:34
ufw allow from any port 547 to any port 546 proto udpthat helps. or that isn't correct ?
– Beliaf
Feb 12 at 10:30
add a comment |
Hello and welcome to AskUbuntu! Can you share yourufwconfiguration? The question as is it's too broad/vague?
– Mr Shunz
Feb 12 at 9:34
ufw allow from any port 547 to any port 546 proto udpthat helps. or that isn't correct ?
– Beliaf
Feb 12 at 10:30
Hello and welcome to AskUbuntu! Can you share your
ufw configuration? The question as is it's too broad/vague?– Mr Shunz
Feb 12 at 9:34
Hello and welcome to AskUbuntu! Can you share your
ufw configuration? The question as is it's too broad/vague?– Mr Shunz
Feb 12 at 9:34
ufw allow from any port 547 to any port 546 proto udp that helps. or that isn't correct ?– Beliaf
Feb 12 at 10:30
ufw allow from any port 547 to any port 546 proto udp that helps. or that isn't correct ?– Beliaf
Feb 12 at 10:30
add a comment |
1 Answer
1
active
oldest
votes
You have your ports swapped. If ufw is running on the dhcpv6 server, you should allow from port 546 to port 547:
sudo ufw allow from any port 546 to any port 547 proto udp
Your rule is valid for a dhcpv6 client. Please check that IPv6=yes is in /etc/default/ufw, too. I can't remember if it's enabled by default.
Also, I suggest you configure explicit multicast IPv6 adresses (fe00::/7) instead of any:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
If your server is itself a DHCPv6 client (i.e. it gets its prefix delegation from a router), you should keep the original rule, too:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546 proto udp
Remember, a DHCPv6 Client initiate the connection from port 546 to port 547 via a multicast address in the range fe00::/7.
/etc/default/ufwIPv6=yesbut inuf.confthere isn't such configuration
– Beliaf
Feb 12 at 10:52
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpi allowed 547 to 546, need vice versa?
– Beliaf
Feb 12 at 10:52
@Beliaf exactly. Server uses port 547 and client 546, i.e. Client initiate the request from port 546 to port 547.
– Mr Shunz
Feb 12 at 10:54
ah ok, so i need add 2 rulsesudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpandsudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpcorrect?
– Beliaf
Feb 12 at 10:56
cause if i removesudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpdhcp don't start and i have errorPRC: Depreference scheduled in 1836 seconds. PRC: Expiration scheduled in 37836 seconds.
– Beliaf
Feb 12 at 10:57
|
show 1 more comment
Your Answer
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "89"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1117589%2fufw-block-dhclient-for-ipv6%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
You have your ports swapped. If ufw is running on the dhcpv6 server, you should allow from port 546 to port 547:
sudo ufw allow from any port 546 to any port 547 proto udp
Your rule is valid for a dhcpv6 client. Please check that IPv6=yes is in /etc/default/ufw, too. I can't remember if it's enabled by default.
Also, I suggest you configure explicit multicast IPv6 adresses (fe00::/7) instead of any:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
If your server is itself a DHCPv6 client (i.e. it gets its prefix delegation from a router), you should keep the original rule, too:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546 proto udp
Remember, a DHCPv6 Client initiate the connection from port 546 to port 547 via a multicast address in the range fe00::/7.
/etc/default/ufwIPv6=yesbut inuf.confthere isn't such configuration
– Beliaf
Feb 12 at 10:52
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpi allowed 547 to 546, need vice versa?
– Beliaf
Feb 12 at 10:52
@Beliaf exactly. Server uses port 547 and client 546, i.e. Client initiate the request from port 546 to port 547.
– Mr Shunz
Feb 12 at 10:54
ah ok, so i need add 2 rulsesudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpandsudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpcorrect?
– Beliaf
Feb 12 at 10:56
cause if i removesudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpdhcp don't start and i have errorPRC: Depreference scheduled in 1836 seconds. PRC: Expiration scheduled in 37836 seconds.
– Beliaf
Feb 12 at 10:57
|
show 1 more comment
You have your ports swapped. If ufw is running on the dhcpv6 server, you should allow from port 546 to port 547:
sudo ufw allow from any port 546 to any port 547 proto udp
Your rule is valid for a dhcpv6 client. Please check that IPv6=yes is in /etc/default/ufw, too. I can't remember if it's enabled by default.
Also, I suggest you configure explicit multicast IPv6 adresses (fe00::/7) instead of any:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
If your server is itself a DHCPv6 client (i.e. it gets its prefix delegation from a router), you should keep the original rule, too:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546 proto udp
Remember, a DHCPv6 Client initiate the connection from port 546 to port 547 via a multicast address in the range fe00::/7.
/etc/default/ufwIPv6=yesbut inuf.confthere isn't such configuration
– Beliaf
Feb 12 at 10:52
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpi allowed 547 to 546, need vice versa?
– Beliaf
Feb 12 at 10:52
@Beliaf exactly. Server uses port 547 and client 546, i.e. Client initiate the request from port 546 to port 547.
– Mr Shunz
Feb 12 at 10:54
ah ok, so i need add 2 rulsesudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpandsudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpcorrect?
– Beliaf
Feb 12 at 10:56
cause if i removesudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpdhcp don't start and i have errorPRC: Depreference scheduled in 1836 seconds. PRC: Expiration scheduled in 37836 seconds.
– Beliaf
Feb 12 at 10:57
|
show 1 more comment
You have your ports swapped. If ufw is running on the dhcpv6 server, you should allow from port 546 to port 547:
sudo ufw allow from any port 546 to any port 547 proto udp
Your rule is valid for a dhcpv6 client. Please check that IPv6=yes is in /etc/default/ufw, too. I can't remember if it's enabled by default.
Also, I suggest you configure explicit multicast IPv6 adresses (fe00::/7) instead of any:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
If your server is itself a DHCPv6 client (i.e. it gets its prefix delegation from a router), you should keep the original rule, too:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546 proto udp
Remember, a DHCPv6 Client initiate the connection from port 546 to port 547 via a multicast address in the range fe00::/7.
You have your ports swapped. If ufw is running on the dhcpv6 server, you should allow from port 546 to port 547:
sudo ufw allow from any port 546 to any port 547 proto udp
Your rule is valid for a dhcpv6 client. Please check that IPv6=yes is in /etc/default/ufw, too. I can't remember if it's enabled by default.
Also, I suggest you configure explicit multicast IPv6 adresses (fe00::/7) instead of any:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
If your server is itself a DHCPv6 client (i.e. it gets its prefix delegation from a router), you should keep the original rule, too:
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp
sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546 proto udp
Remember, a DHCPv6 Client initiate the connection from port 546 to port 547 via a multicast address in the range fe00::/7.
edited Feb 12 at 11:03
answered Feb 12 at 10:43
Mr ShunzMr Shunz
2,49131922
2,49131922
/etc/default/ufwIPv6=yesbut inuf.confthere isn't such configuration
– Beliaf
Feb 12 at 10:52
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpi allowed 547 to 546, need vice versa?
– Beliaf
Feb 12 at 10:52
@Beliaf exactly. Server uses port 547 and client 546, i.e. Client initiate the request from port 546 to port 547.
– Mr Shunz
Feb 12 at 10:54
ah ok, so i need add 2 rulsesudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpandsudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpcorrect?
– Beliaf
Feb 12 at 10:56
cause if i removesudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpdhcp don't start and i have errorPRC: Depreference scheduled in 1836 seconds. PRC: Expiration scheduled in 37836 seconds.
– Beliaf
Feb 12 at 10:57
|
show 1 more comment
/etc/default/ufwIPv6=yesbut inuf.confthere isn't such configuration
– Beliaf
Feb 12 at 10:52
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpi allowed 547 to 546, need vice versa?
– Beliaf
Feb 12 at 10:52
@Beliaf exactly. Server uses port 547 and client 546, i.e. Client initiate the request from port 546 to port 547.
– Mr Shunz
Feb 12 at 10:54
ah ok, so i need add 2 rulsesudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udpandsudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpcorrect?
– Beliaf
Feb 12 at 10:56
cause if i removesudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udpdhcp don't start and i have errorPRC: Depreference scheduled in 1836 seconds. PRC: Expiration scheduled in 37836 seconds.
– Beliaf
Feb 12 at 10:57
/etc/default/ufw IPv6=yes but in uf.conf there isn't such configuration– Beliaf
Feb 12 at 10:52
/etc/default/ufw IPv6=yes but in uf.conf there isn't such configuration– Beliaf
Feb 12 at 10:52
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp i allowed 547 to 546, need vice versa?– Beliaf
Feb 12 at 10:52
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp i allowed 547 to 546, need vice versa?– Beliaf
Feb 12 at 10:52
@Beliaf exactly. Server uses port 547 and client 546, i.e. Client initiate the request from port 546 to port 547.
– Mr Shunz
Feb 12 at 10:54
@Beliaf exactly. Server uses port 547 and client 546, i.e. Client initiate the request from port 546 to port 547.
– Mr Shunz
Feb 12 at 10:54
ah ok, so i need add 2 rulse
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp and sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udp correct?– Beliaf
Feb 12 at 10:56
ah ok, so i need add 2 rulse
sudo ufw allow from fe00::/7 port 546 to fe00::/7 port 547 proto udp and sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udp correct?– Beliaf
Feb 12 at 10:56
cause if i remove
sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udp dhcp don't start and i have error PRC: Depreference scheduled in 1836 seconds. PRC: Expiration scheduled in 37836 seconds.– Beliaf
Feb 12 at 10:57
cause if i remove
sudo ufw allow from fe00::/7 port 547 to fe00::/7 port 546proto udp dhcp don't start and i have error PRC: Depreference scheduled in 1836 seconds. PRC: Expiration scheduled in 37836 seconds.– Beliaf
Feb 12 at 10:57
|
show 1 more comment
Thanks for contributing an answer to Ask Ubuntu!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1117589%2fufw-block-dhclient-for-ipv6%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Hello and welcome to AskUbuntu! Can you share your
ufwconfiguration? The question as is it's too broad/vague?– Mr Shunz
Feb 12 at 9:34
ufw allow from any port 547 to any port 546 proto udpthat helps. or that isn't correct ?– Beliaf
Feb 12 at 10:30