Strange IPv6 problem : RA packets are forwarded on all SSID

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Strange IPv6 problem : RA packets are forwarded on all SSID

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Strange IPv6 problem : RA packets are forwarded on all SSID
Strange IPv6 problem : RA packets are forwarded on all SSID
2023-01-08 19:43:54
Model: EAP245  
Hardware Version: V1
Firmware Version: 1.4.0 Build 20180323 Rel. 32551

Hello everyone,

 

I bought for a couple of euros TP Link EAP245 access points and they are great.

But my oldest son started complaining about bad wifi and I spent some time digging around with him.

It turns out, I have 3 SSID linked to 3 VLAN (LAN, id 1, Work id 50 and IOT, id 51), each VLAN is getting a different /64 IPv6 subnet (my ISP gives me a /56 subnet so I can do that).

When I am connected on a give VLAN with a wired connection, I only get IPv6 address that belong to this VLAN.

 

When I am connected to the SSID linked to this VLAN, I get IPv6 address from the 3 /64 subnets.

It turns out, on windows, linux, Mac OS and whatever you want, that's not a problem.

On Android, IPv6 simply doesn't work. I simply disabled IPv6 on 2 interfaces it isn't really needed and left it as this for the rest of the week. Now that my kids are back to their mother house, I activated IPv6 on one VLAN/SSID (the IOT one) and I did a wireshark capture on my Linux laptop. The capture shows that the laptop receives RA packets from the IOT interface (as stated by the MAC address it comes from, and the prefix the IPv6 belongs to)

 

I'm very surprised by this situation, so if anyone here encounters anything like this, please let me know :)

  0      
  0      
#1
Options
5 Reply
Re:Strange IPv6 problem : RA packets are forwarded on all SSID
2023-01-09 08:53:23

 Dear @Oupsman 

 

To better assist you, I've created a support ticket via your registered email address, and escalated it to our support engineer to look into the issue. 

The ticket ID is TKID230115648, please check your email box and ensure the support email is well received. Thanks!

 

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#2
Options
Re:Strange IPv6 problem : RA packets are forwarded on all SSID
2023-01-09 09:06:05

  @Hank21 I've received the escalation notice, thanks.

  0  
  0  
#3
Options
Re:Strange IPv6 problem : RA packets are forwarded on all SSID
2023-05-12 16:24:18

Hi @Oupsman, were you able to resolve the issue? I'm using the EAP670 with FW1.0.0. Because of a problem with IPv6 (udp) traffic not being forwarded using FW 1.06 (latest available as of now), the support recommended to downgrade / use version 1.0.0. It fixed the issue, but created a new problem, the one you mentioned. RAs from different vlans are broadcasted to all clients, no matter on which SSID or vlan they are on. In my case, I'm only using a single SSID setup, with mac-based vlan assignment using an external radius server. I've checked my lan setup, everything is fine, it's the AP behaving wrong.

  0  
  0  
#4
Options
Re:Strange IPv6 problem : RA packets are forwarded on all SSID
2023-05-12 18:20:10

  @osc 

 

No, I did not found a solution to this issue, and support wasn't able either. The only way I found to circumvent it was to disable IPv6 on my other vlans and just activate it on my main VLAN.

 

Maybe if it's a firmware issue, and your AP are supported (mine are not), the labs will provide an updated firmware for this issue.

  0  
  0  
#5
Options
Re:Strange IPv6 problem : RA packets are forwarded on all SSID
2023-05-14 13:15:01

  @Oupsman 

thanks for your reply.

I've tried literally everything to fix the issue, but failed.

 

I can't stop IPv6 multicast frames from leaking between clients connected to different vlans and I consider this a major security issue. It basically makes using IPv6 impossible on EAPs, and I don't think it's limited to the two devices mentioned here, but a security flaw in the current firmware in general.

 

I'm at a point where I'll just return my EAP670 and buy a device from another vendor. The lack of support and firmware updates from TP-Link is unacceptable.

  1  
  1  
#6
Options