Hi Guys,
I have Cisco 3900 with IPv6 configure and fully routable.
Behind we have Fortigate 200a in Transparent mode.
In order to allow my station to get dynamically EUI64 ip address (Kind of DHCP) i have to make rule in the Policy6 of " Any(All)-Any(All)-Allow"
I' ve tried creating new customer service with ICMPv6 and no port, tried using the implicit ICMP-ANY service, nothing allow it to pass.
Tried also :
Interface level --> l2forward enable
Interface level --> broadcast-forward enable
System Level --> multicast-skip-policy enable
Debug from Cisco (When the any-any-allow disabled):
Aug 23 19:20:36: ICMPv6-ND: Sending RA to FF02::1 on Vlan1
Aug 23 19:20:36: ICMPv6-ND: MTU = 1500
Aug 23 19:20:36: ICMPv6-ND: prefix = <Omitted>:B00::/64 onlink autoconfig
Aug 23 19:20:36: ICMPv6-ND: 2592000/604800 (valid/preferred)
Debug with the Rule enabled:
Aug 23 19:22:15: ICMPv6-ND: Sending RA to FF02::1 on Vlan1
Aug 23 19:22:15: ICMPv6-ND: MTU = 1500
Aug 23 19:22:15: ICMPv6-ND: prefix = <Omitted>:B00::/64 onlink autoconfig
Aug 23 19:22:15: ICMPv6-ND: 2592000/604800 (valid/preferred)
Aug 23 19:22:15: ICMPv6: Received ICMPv6 packet from FE80::21D:46FF:FED3:92AE, type 134
Aug 23 19:22:15: ICMPv6-ND: Received RA from FE80::21D:46FF:FED3:92AE on Vlan1
Aug 23 19:22:15: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 143
Aug 23 19:22:15: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 143
Aug 23 19:22:16: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 143
Aug 23 19:22:16: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 143
Aug 23 19:22:17: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 136
Aug 23 19:22:17: ICMPv6-ND: Received NA for <Omitted>:B00:6C6E:572E:6E48:682C on Vlan1 from FE80::225:FF:FE4A:AB5
Aug 23 19:22:17: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 136
Aug 23 19:22:17: ICMPv6-ND: Received NA for <Omitted>:B00:6C6E:572E:6E48:682C on Vlan1 from FE80::225:FF:FE4A:AB5
Aug 23 19:22:17: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 136
Aug 23 19:22:17: ICMPv6-ND: Received NA for <Omitted>:B00:225:FF:FE4A:AB5 on Vlan1 from FE80::225:FF:FE4A:AB5
Aug 23 19:22:17: ICMPv6: Received ICMPv6 packet from FE80::225:FF:FE4A:AB5, type 136
Aug 23 19:22:17: ICMPv6-ND: Received NA for <Omitted>:B00:225:FF:FE4A:AB5 on Vlan1 from FE80::225:FF:FE4A:AB5
//Chura
CCIE, NSE7, CCSE+