IPv6 configuration with RDNSS (RFC 6106)

Options
DCLTechnique
DCLTechnique Posts: 3 image  Freshman Member
First Comment

Hello,

We are MSP which deployed IPv6 internally on one of client's existing Zyxel firewall. The device in question is an USG Flex 200 running firmware 5.40 (latest). Coming from Fortinet / FortiOS we find the IPv6 configuration on Zyxel convoluted as there is no official knowledge base (aside from random official blog posts linking to PDFs)

We have got he following configuration enabled :

  • One /64 assigned to the WAN interface, the Zyxel obtains a SLAAC adresse from that prefixe
  • One /56 routed on the the WAN's /64, of which two /64 are assigned on LAN1 and LAN2 interfaces
  • DHCP-PD is enabled to assign AAAA:BBBB:CCCC:DDD1::/64 and
  • AAAA:BBBB:CCCC:DDD2::/64 to the LANs

SLAAC is enabled on both LANs and Windows machines get IPv6 connectivity. However this requires using stateless DHCPv6 which is not supported on Android-based devices, meaning that our devices do get an address but no DNS servers

Where can we configure IPv6 RDNSS (RFC 6106) in order to transmit DNS servers through Router Advertisements ? I cannot find this anywhere on any public documentation nor any CLI reference

Thank you

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 401 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @DCLTechnique,

    Welcome to Zyxel Community!

    Unfortunately, USG FLEX firewalls, including the USG Flex 200 running firmware 5.40, do not support IPv6 RDNSS options (RFC 6106) for Router Advertisements. This functionality is not available in the current firmware or via CLI. As a result, devices such as Android clients that rely on RA-based DNS distribution cannot obtain DNS information automatically in the current implementation.

    We fully understand this requirement, as RDNSS is essential for IPv6 environments using SLAAC without DHCPv6. Therefore, this will be noted as a feature request. Thank you for your understanding.

    Zyxel Tina

  • DCLTechnique
    DCLTechnique Posts: 3 image  Freshman Member
    First Comment

    Hello Tina,

    Thanks for the response. I managed to find this similar topic from 2021 also tagged as feature request
    https://community.zyxel.com/en/discussion/10068/google-android-isnt-supporting-dhcpv6-and-usg-is-missing-rdnss

    It's been 4 years since and still no progress besides

    Given that full IPv6 support in general for Zyxel does not seem to be priority, we will be switching to more serious brands

    Regard