Page 76 / 414 Scroll up to view Page 71 - 75
LAN Configuration
76
ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N
IPv6 LAN Prefixes for Prefix Delegation
If you configure a
stateless
DHCPv6 server for the LAN and select the Prefix Delegation
check box (both on the ISP Broadband Settings screen for IPv6 and on the LAN Setup
screen for IPv6, a prefix delegation pool is automatically added to the List of Prefixes for
Prefix Delegation table. You can also manually add prefixes to the List of Prefixes for Prefix
Delegation table to enable the DHCPv6 server to assign these prefixes to its IPv6 LAN
clients.
To add an IPv6 prefix:
1.
On the LAN Setup screen for IPv6, under the List of Prefixes for Prefix Delegation table,
click
Add
. The Add Prefix Delegation Prefixes screen displays:
Figure 38.
2.
Enter the following settings:
IPv6 Prefix
. Enter a prefix, for example, 2001:db8::.
IPv6 Prefix Length
. Enter the IPv6 prefix length, for example, 64.
3.
Click
Apply
to save your changes and add the new prefix to the List of Prefixes for Prefix
Delegation table on the LAN Setup screen for IPv6.
To edit a prefix:
1.
On the LAN Setup screen for IPv6 (see
Figure 36
on page 72), click the
Edit
button in
the Action column for the prefix that you want to modify. The Edit Prefix Delegation
Prefixes screen displays.
2.
Modify the settings as explained in
Step 2
of the previous procedure.
3.
Click
Apply
to save your settings.
To delete one or more prefixes:
1.
On the LAN Setup screen for IPv6 (see
Figure 36
on page 72), select the check box to
the left of each prefix that you want to delete, or click the
Select All
table button to
select all prefixes.
2.
Click the
Delete
table button.
Page 77 / 414
LAN Configuration
77
ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N
Configure the IPv6 Router Advertisement Daemon and
Advertisement Prefixes for the LAN
Note:
If you do not configure stateful DHCPv6 for the LAN but use
stateless DHCPv6, you need to configure the Router Advertisement
Deamon (RADVD) and advertisement prefixes.
The RADVD is an application that uses the Neighbor Discovery Protocol (NDP) to collect
link-local advertisements of IPv6 addresses and IPv6 prefixes in the LAN. The RADVD then
distributes this information in the LAN, which allows IPv6 clients to configure their own IPv6
address.
Hosts and routers in the LAN use NDP to determine the link-layer addresses and related
information of neighbors in the LAN that can forward packets on their behalf. The wireless
VPN firewall periodically distributes router advertisements (RAs) throughout the LAN to
provide such information to the hosts and routers in the LAN. RAs include IPv6 addresses,
types of prefixes, prefix addresses, prefix lifetimes, the maximum transmission unit (MTU),
and so on. In addition to configuring the RADVD, you also need to configure the prefixes that
are advertised in the LAN RAs.
The following table provides an overview of how information is obtained in the LAN when you
have configured a stateless DHCPv6 server and the RADVD:
When the Managed flag is set in the RADVD, the DHCPv6 server can assign IP addresses,
and the RADVD also assigns IP addresses in the sense that it provides information that
allows IPv6 clients to configure their own IPv6 address.
When the Other flag is set, the DHCPv6 server does not assign IP addresses but provides
DNS server and other configuration information only.
To configure the Router Advertisement Daemon for the LAN:
1.
Select
Network Configuration > LAN Setup
.
Table 14.
DHCPv6 and RADVD interaction in the LAN
Flags in the RADVD
DHCPv6 Server Provides
RADVD Provides
Managed RA flag is set
• IP address assignment
• DNS server and other configuration information
• IP address assignment
• Prefix
• Prefix length
• Gateway address
Other RA flag is set
DNS server and other configuration information
• IP address assignment
• Prefix
• Prefix length
• Gateway address
Page 78 / 414
LAN Configuration
78
ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N
2.
In the upper right of the screen, select the
IPv6
radio button. The LAN Setup screen displays
the IPv6 settings (see
Figure 36
on page 72.)
3.
To the right of the LAN Setup tab, click the
RADVD
option arrow. The RADVD screen for the
LAN displays. (The following figure contains some examples.)
Figure 39.
4.
Enter the settings as explained in the following table:
Table 15.
RADVD screen settings for the LAN
Setting
Description
RADVD Status
Specify the RADVD status by making a selection from the drop-down list:
Enable
. The RADVD is enabled, and the RADVD fields become available for you to
configure.
Disable
. The RADVD is disabled, and the RADVD fields are masked out. This is the
default setting.
Advertise Mode
Specify the advertisement mode by making a selection from the drop-down list:
Unsolicited Multicast
. The wireless VPN firewall advertises unsolicited multicast
packets at a rate that is specified by the advertisement interval.
Unicast only
. The wireless VPN firewall responds to unicast packet requests only.
No unsolicited packets are advertised. Select this option for nonbroadcast multiple
access (NBMA) links such as ISATAP.
Page 79 / 414
LAN Configuration
79
ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N
5.
Click
Apply
to save your changes.
Advertisement Prefixes for the LAN
You need to configure the prefixes that are advertised in the LAN RAs. For a 6to4 address,
you need to specify only the site level aggregation identifier (SLA ID) and the prefix lifetime.
For a global, local, or ISATAP address, you need to specify the prefix, prefix length, and
prefix lifetime.
To add an advertisement prefix for the LAN:
1.
On the RADVD screen for the LAN, under the List of Prefixes to Advertise table, click
Add
. The Add Advertisement Prefix screen displays:
Advertise Interval
Enter the advertisement interval of unsolicited multicast packets in seconds. The
minimum value is 10 seconds; the maximum value is 1800 seconds.
RA Flags
Specify what type of information the DHCPv6 server provides in the LAN by making a
selection from the drop-down list:
Managed
. The DHCPv6 server is used for autoconfiguration of the IP address.
Other
. The DHCPv6 server is not used for autoconfiguration of the IP address, but
other configuration information such as DNS information is available through the
DHCPv6 server.
Note:
Irrespective of the RA flag settings, the RADVD provides information about the
prefix, prefix length, and gateway addresses and is also used for autoconfiguration of
the IP address.
Router Preference
Specify the wireless VPN firewall’s preference in relation to other hosts and routers in
the LAN by making a selection from the drop-down list:
Low
. The wireless VPN firewall is treated as a nonpreferred router in the LAN.
Medium
. The wireless VPN firewall is treated as a neutral router in the LAN.
High
. The wireless VPN firewall is treated as a preferred router in the LAN.
MTU
The maximum transmission unit (MTU) size for a packet in one transmission over a
link. The default setting is 1500.
Router Lifetime
The router lifetime specifies how long the default route that was created as a result of
the router advertisement should remain valid.
Enter the router lifetime in seconds. This is the period that the advertised prefixes are
valid for route determination. The default period is 3600 seconds (one hour). The
minimum value is 30 seconds; the maximum value is 9000 seconds.
Table 15.
RADVD screen settings for the LAN (continued)
Setting
Description
Page 80 / 414
LAN Configuration
80
ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N
Figure 40.
2.
Enter the settings as explained in the following table:
3.
Click
Apply
to save your changes and add the new IPv6 address pool to the List of Prefixes
to Advertise table on the RADVD screen for the LAN.
To edit an advertisement prefix:
1.
On the RADVD screen for the LAN (see
Figure 39
on page 78), click the
Edit
button in
the Action column for the advertisement prefix that you want to modify. The Add
Advertisement Prefix screen displays.
2.
Modify the settings as explained in the previous table.
3.
Click
Apply
to save your settings.
Table 16.
Add Advertisement Prefix screen settings for the LAN
Setting
Description
IPv6 Prefix Type
Specify the IPv6 prefix type by making a selection from the drop-down list:
6to4
. The prefix is for a 6to4 address. You need to complete the SLA ID field and
Prefix Lifetime field. The other fields are masked out.
Global/Local/ISATAP
. The prefix is for a global, local, or ISATAP address. This
needs to be a global prefix or a site-local prefix; it cannot be a link-local prefix. You
need to complete the IPv6 Prefix field, IPv6 Prefix Length field, and Prefix Lifetime
field. The SLA ID field is masked out.
SLA ID
Enter the site level aggregation identifier (SLA ID) for the 6to4 address prefix that
should be included in the advertisement.
IPv6 Prefix
Enter the IPv6 prefix for the wireless VPN firewall’s LAN that should be included in the
advertisement.
IPv6 Prefix Length
Enter the IPv6 prefix length (typically 64) that should be included in the advertisement.
Prefix Lifetime
The prefix lifetime specifies how long the IP address that was created as a result of the
router advertisement should remain valid.
Enter the prefix lifetime in seconds that should be included in the advertisement. The
minimum period is 0 seconds; the maximum period is 65536 seconds.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top