Keep IPv6 router announcements working with forwarding on
With net.ipv6.conf.all.forwarding=1, Linux ignores router announcements unless accept_ra is 2, so a server that gets its IPv6 route by SLAAC (e.g. a Raspberry Pi at home) lost IPv6 once the route expired. The sysctl file now also sets accept_ra=2 for the default and for every network card and the IPv6 default-route interface, except where accept_ra is 0. "update" rewrites the file, which fixes existing installs. A new health check warns while the uplink still has accept_ra=1.
This commit is contained in:
+14
-9
@@ -3,13 +3,13 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"cmp"
|
||||
"errors"
|
||||
"fmt"
|
||||
"net"
|
||||
"net/netip"
|
||||
"os"
|
||||
"slices"
|
||||
"strings"
|
||||
|
||||
"github.com/vishvananda/netlink"
|
||||
"golang.zx2c4.com/wireguard/wgctrl"
|
||||
@@ -318,14 +318,6 @@ func publicAddr(uplink string, v6 bool) (bool, string) {
|
||||
return false, "no address on " + uplink
|
||||
}
|
||||
|
||||
func readSysctl(path string) string {
|
||||
b, err := os.ReadFile(path)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return strings.TrimSpace(string(b))
|
||||
}
|
||||
|
||||
func (k *linuxKernel) Checks(c *Config) []Check {
|
||||
var out []Check
|
||||
link, err := netlink.LinkByName(c.Server.Interface)
|
||||
@@ -341,6 +333,19 @@ func (k *linuxKernel) Checks(c *Config) []Check {
|
||||
v := readSysctl("/proc/sys/net/ipv6/conf/all/forwarding")
|
||||
out = append(out, Check{"IPv6 forwarding", v == "1", "net.ipv6.conf.all.forwarding=" + v})
|
||||
}
|
||||
// With IPv6 forwarding on, accept_ra 1 means router announcements are
|
||||
// ignored: an IPv6 route learned from them expires (see sysctlConf).
|
||||
if readSysctl("/proc/sys/net/ipv6/conf/all/forwarding") == "1" {
|
||||
up := cmp.Or(k.Uplink(c, true), k.Uplink(c, false))
|
||||
if ra := readSysctl("/proc/sys/net/ipv6/conf/" + up + "/accept_ra"); up != "" && ra != "" {
|
||||
ok := ra != "1"
|
||||
detail := "net.ipv6.conf." + up + ".accept_ra=" + ra
|
||||
if !ok {
|
||||
detail += ": IPv6 from router announcements stops working; run " + appName + " update"
|
||||
}
|
||||
out = append(out, Check{"IPv6 router announcements", ok, detail})
|
||||
}
|
||||
}
|
||||
ok, detail := firewallPresent()
|
||||
out = append(out, Check{"nftables rules", ok, detail})
|
||||
up4 := k.Uplink(c, false)
|
||||
|
||||
Reference in New Issue
Block a user