ISP blacklisting OpenWrt? Loss of IPv6 connection

For more than a week ago I lost my IPv6 connection and so far I am not able to get it back. IPv4 i OK. IPv6 has worked perfectly for years, allowing me to run an openvpn server on my OpenWrt router. Now I get no IPv6 address or prefix.

My ISP is Altibox/Eidsiva (Norway) which forces me to use their own router, but sets this in bridge mode so I can use OpenWrt.
Tried all reboots and power cycling. ISP claims there is no fault on their side, but are not very helpful, as I don't use their router.

os-release:

NAME="OpenWrt"
VERSION="23.05.4"
ID="openwrt"
ID_LIKE="lede openwrt"
PRETTY_NAME="OpenWrt 23.05.4"
VERSION_ID="23.05.4"
HOME_URL="https://openwrt.org/"
BUG_URL="https://bugs.openwrt.org/"
SUPPORT_URL="https://forum.openwrt.org/"
BUILD_ID="r24012-d8dd03c46f"
OPENWRT_BOARD="ipq40xx/generic"
OPENWRT_ARCH="arm_cortex-a7_neon-vfpv4"
OPENWRT_TAINTS=""
OPENWRT_DEVICE_MANUFACTURER="OpenWrt"
OPENWRT_DEVICE_MANUFACTURER_URL="https://openwrt.org/"
OPENWRT_DEVICE_PRODUCT="Generic"
OPENWRT_DEVICE_REVISION="v0"
OPENWRT_RELEASE="OpenWrt 23.05.4 r24012-d8dd03c46f"

network

config interface 'loopback'
	option device 'lo'
	option proto 'static'
	option ipaddr '127.0.0.1'
	option netmask '255.0.0.0'

config globals 'globals'
	option ula_prefix 'fd7f:3800:73fb::/48'

config device
	option name 'br-lan'
	option type 'bridge'
	list ports 'lan1'
	list ports 'lan2'
	list ports 'lan3'

config interface 'lan'
	option device 'br-lan'
	option proto 'static'
	option ip6assign '60'
	list ipaddr '10.23.11.2/24'

config interface 'wan'
	option device 'wan'
	option proto 'dhcp'

config interface 'guest'
	option type 'bridge'
	option proto 'static'
	option ipaddr '192.168.3.1'
	option netmask '255.255.255.0'

config interface 'vpn0'
	option proto 'static'
	option device 'tun0'

config interface 'wan6'
	option proto 'dhcpv6'
	option device 'wan'
	option reqaddress 'try'
	option reqprefix 'auto'

tcpdump when restarting wan6:

root@OpenWrt2ax3600:~# tcpdump -i wan ip6
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on wan, link-type EN10MB (Ethernet), snapshot length 262144 bytes
11:50:28.883778 IP6 fe80::2ad1:27ff:fe70:7a1c > ip6-allrouters: ICMP6, router solicitation, length 16
11:50:28.887101 IP6 fe80::201:2ff:fe61:1 > ip6-allnodes: ICMP6, router advertisement, length 32
11:50:29.203512 IP6 fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: dhcp6 solicit
11:50:30.264835 IP6 fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: dhcp6 solicit
11:50:32.344779 IP6 fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: dhcp6 solicit
11:50:36.424758 IP6 fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: dhcp6 solicit
11:50:44.104866 IP6 fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: dhcp6 solicit
11:51:00.264780 IP6 fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: dhcp6 solicit
11:51:16.312667 IP6 fe80::201:2ff:fe61:1 > ip6-allnodes: ICMP6, router advertisement, length 32
11:51:30.984773 IP6 fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: dhcp6 solicit
^C
10 packets captured
10 packets received by filter
0 packets dropped by kernel

Any hints? Thanks in advance

Run tcpdump in verbose mode (-vvv) to see what is inside the RA packets they are sending you.

tcpdump:

root@OpenWrt2ax3600:~# tcpdump -i wan -vvv ip6
tcpdump: listening on wan, link-type EN10MB (Ethernet), snapshot length 262144 bytes
15:05:53.328678 IP6 (class 0xe0, hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::201:2ff:fe61:1 > ip6-allnodes: [icmp6 sum ok] ICMP6, neighbor advertisement, length 32, tgt is fe80::201:2ff:fe61:1, Flags [router, override]
          destination link-address option (2), length 8 (1): 00:01:02:61:00:01
            0x0000:  0001 0261 0001
15:05:55.764896 IP6 (flowlabel 0x8e3be, hlim 255, next-header ICMPv6 (58) payload length: 16) fe80::2ad1:27ff:fe70:7a1c > ip6-allrouters: [icmp6 sum ok] ICMP6, router solicitation, length 16
          source link-address option (1), length 8 (1): 28:d1:27:70:7a:1c
            0x0000:  28d1 2770 7a1c
15:05:55.768109 IP6 (class 0xe0, hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::201:2ff:fe61:1 > ip6-allnodes: [icmp6 sum ok] ICMP6, router advertisement, length 32
        hop limit 64, Flags [managed, other stateful], pref medium, router lifetime 1800s, reachable time 0ms, retrans timer 0ms
          source link-address option (1), length 8 (1): 00:01:02:61:00:01
            0x0000:  0001 0261 0001
          mtu option (5), length 8 (1):  1500
            0x0000:  0000 0000 05dc
15:05:56.359872 IP6 (flowlabel 0xab644, hlim 1, next-header UDP (17) payload length: 117) fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: [udp sum ok] dhcp6 solicit (xid=bda0ec (elapsed-time 0) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 28d127707a1c) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
15:05:57.384805 IP6 (flowlabel 0xab644, hlim 1, next-header UDP (17) payload length: 117) fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: [udp sum ok] dhcp6 solicit (xid=bda0ec (elapsed-time 102) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 28d127707a1c) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
15:05:59.544775 IP6 (flowlabel 0xab644, hlim 1, next-header UDP (17) payload length: 117) fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: [udp sum ok] dhcp6 solicit (xid=bda0ec (elapsed-time 318) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 28d127707a1c) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
15:06:03.784794 IP6 (flowlabel 0xab644, hlim 1, next-header UDP (17) payload length: 117) fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: [udp sum ok] dhcp6 solicit (xid=bda0ec (elapsed-time 742) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 28d127707a1c) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
15:06:12.264796 IP6 (flowlabel 0xab644, hlim 1, next-header UDP (17) payload length: 117) fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: [udp sum ok] dhcp6 solicit (xid=bda0ec (elapsed-time 1590) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 28d127707a1c) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
15:06:28.264788 IP6 (flowlabel 0xab644, hlim 1, next-header UDP (17) payload length: 117) fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: [udp sum ok] dhcp6 solicit (xid=bda0ec (elapsed-time 3190) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 28d127707a1c) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
15:06:58.984791 IP6 (flowlabel 0xab644, hlim 1, next-header UDP (17) payload length: 117) fe80::2ad1:27ff:fe70:7a1c.546 > ff02::1:2.547: [udp sum ok] dhcp6 solicit (xid=bda0ec (elapsed-time 6262) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 28d127707a1c) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
^C
10 packets captured
10 packets received by filter
0 packets dropped by kernel

I have another OpenWrt router with similar network configuration, so I connected its wan port to ISPs wan. Then I got a working IPv6 address and prefix, but only on the first connection. Further attempts failed.

tcpdump from the succesful connection:

root@OpenWrt2mf286d:~# tcpdump -i wan -vvv ip6
tcpdump: listening on wan, link-type EN10MB (Ethernet), snapshot length 262144 bytes
12:14:46.001077 IP6 (flowlabel 0x68012, hlim 1, next-header UDP (17) payload length: 117) fe80::caea:f8ff:fec1:859e.546 > ff02::1:2.547: [bad udp cksum 0x4658 -> 0x446f!] dhcp6 solicit (xid=7296af (elapsed-time 343) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 c8eaf8c1859e) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
12:14:46.278858 IP6 (flowlabel 0x6dd69, hlim 255, next-header ICMPv6 (58) payload length: 8) fe80::caea:f8ff:fec1:859e > ip6-allrouters: [icmp6 sum ok] ICMP6, router solicitation, length 8
12:14:50.279179 IP6 (flowlabel 0x6dd69, hlim 255, next-header ICMPv6 (58) payload length: 16) fe80::caea:f8ff:fec1:859e > ip6-allrouters: [icmp6 sum ok] ICMP6, router solicitation, length 16
          source link-address option (1), length 8 (1): c8:ea:f8:c1:85:9e
            0x0000:  c8ea f8c1 859e
12:14:50.581067 IP6 (flowlabel 0x68012, hlim 1, next-header UDP (17) payload length: 117) fe80::caea:f8ff:fec1:859e.546 > ff02::1:2.547: [bad udp cksum 0x4658 -> 0x42a5!] dhcp6 solicit (xid=7296af (elapsed-time 801) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 c8eaf8c1859e) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
12:14:54.279494 IP6 (flowlabel 0x6dd69, hlim 255, next-header ICMPv6 (58) payload length: 8) fe80::caea:f8ff:fec1:859e > ip6-allrouters: [icmp6 sum ok] ICMP6, router solicitation, length 8
12:14:59.921074 IP6 (flowlabel 0x68012, hlim 1, next-header UDP (17) payload length: 117) fe80::caea:f8ff:fec1:859e.546 > ff02::1:2.547: [bad udp cksum 0x4658 -> 0x3eff!] dhcp6 solicit (xid=7296af (elapsed-time 1735) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 c8eaf8c1859e) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
12:15:19.121079 IP6 (flowlabel 0x68012, hlim 1, next-header UDP (17) payload length: 117) fe80::caea:f8ff:fec1:859e.546 > ff02::1:2.547: [bad udp cksum 0x4658 -> 0x377f!] dhcp6 solicit (xid=7296af (elapsed-time 3655) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 c8eaf8c1859e) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
12:15:19.130388 IP6 (class 0xe0, hlim 128, next-header UDP (17) payload length: 137) fe80::201:2ff:fe61:1.547 > fe80::caea:f8ff:fec1:859e.546: [udp sum ok] dhcp6 advertise (xid=7296af (client-ID hwaddr type 1 c8eaf8c1859e) (server-ID hwaddr/time type 1 time 430923862 001a4aa88e40) (IA_NA IAID:1 T1:1800 T2:2880 (IA_ADDR 2a01:798:100:5800:c585:c0af:d40f:6851 pltime:3600 vltime:3600)) (IA_PD IAID:1 T1:1800 T2:2880 (IA_PD-prefix 2a01:799:161b:2400::/56 pltime:3600 vltime:3600)) (reconfigure-accept))
12:15:19.980024 IP6 (flowlabel 0x68012, hlim 1, next-header UDP (17) payload length: 190) fe80::caea:f8ff:fec1:859e.546 > ff02::1:2.547: [bad udp cksum 0x46a1 -> 0x0db9!] dhcp6 request (xid=4b1418 (elapsed-time 0) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96) (client-ID hwaddr type 1 c8eaf8c1859e) (server-ID hwaddr/time type 1 time 430923862 001a4aa88e40) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0 (IA_ADDR 2a01:798:100:5800:c585:c0af:d40f:6851 pltime:3600 vltime:3600)) (IA_PD IAID:1 T1:0 T2:0 (IA_PD-prefix 2a01:799:161b:2400::/56 pltime:3600 vltime:3600)))
12:15:20.149983 IP6 (class 0xe0, hlim 128, next-header UDP (17) payload length: 169) fe80::201:2ff:fe61:1.547 > fe80::caea:f8ff:fec1:859e.546: [udp sum ok] dhcp6 reply (xid=4b1418 (client-ID hwaddr type 1 c8eaf8c1859e) (server-ID hwaddr/time type 1 time 430923862 001a4aa88e40) (IA_NA IAID:1 T1:1800 T2:2880 (IA_ADDR 2a01:798:100:5800:c585:c0af:d40f:6851 pltime:3600 vltime:3600)) (IA_PD IAID:1 T1:1800 T2:2880 (IA_PD-prefix 2a01:799:161b:2400::/56 pltime:3600 vltime:3600)) (reconfigure-accept) (authentication proto: reconfigure, alg: HMAC-MD5, RDM: mono, RD: 2e44 7f93 056f 2f39 reconfig-key value: 36a11293 37f35bf6 cdaf64f9 e5917c16))
12:15:21.111963 IP6 (class 0xe0, hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::201:2ff:fe61:1 > ip6-allnodes: [icmp6 sum ok] ICMP6, router advertisement, length 32
        hop limit 64, Flags [managed, other stateful], pref medium, router lifetime 1800s, reachable time 0ms, retrans timer 0ms
          source link-address option (1), length 8 (1): 00:01:02:61:00:01
            0x0000:  0001 0261 0001
          mtu option (5), length 8 (1):  1500
            0x0000:  0000 0000 05dc
12:15:21.221035 IP6 (hlim 1, next-header Options (0) payload length: 116) fe80::caea:f8ff:fec1:859e > ff02::16: HBH (rtalert: 0x0000) (padn) [icmp6 sum ok] ICMP6, multicast listener report v2, 5 group record(s) [gaddr ff02::1:ff0f:6851 to_ex { }] [gaddr ff02::1:ff00:0 to_ex { }] [gaddr ff02::1:ffc1:859e to_ex { }] [gaddr ff05::2 to_ex { }] [gaddr ip6-allrouters to_ex { }]
12:15:21.920993 IP6 (hlim 1, next-header Options (0) payload length: 116) fe80::caea:f8ff:fec1:859e > ff02::16: HBH (rtalert: 0x0000) (padn) [icmp6 sum ok] ICMP6, multicast listener report v2, 5 group record(s) [gaddr ff02::1:ff0f:6851 to_ex { }] [gaddr ff02::1:ff00:0 to_ex { }] [gaddr ff02::1:ffc1:859e to_ex { }] [gaddr ff05::2 to_ex { }] [gaddr ip6-allrouters to_ex { }]
12:15:21.921107 IP6 (hlim 255, next-header ICMPv6 (58) payload length: 32) :: > ff02::1:ff0f:6851: [icmp6 sum ok] ICMP6, neighbor solicitation, length 32, who has 2a01:798:100:5800:c585:c0af:d40f:6851
          unknown option (14), length 8 (1):
            0x0000:  ac7f 2aee 92f5
12:15:23.427429 IP6 (flowlabel 0xac077, hlim 64, next-header UDP (17) payload length: 39) 2a01:798:100:5800:c585:c0af:d40f:6851.56501 > 2a01:798:0:9002::70.53: [bad udp cksum 0x0f74 -> 0x7916!] 28609+ A? time.nist.gov. (31)
12:15:23.427862 IP6 (flowlabel 0x86419, hlim 64, next-header UDP (17) payload length: 39) 2a01:798:100:5800:c585:c0af:d40f:6851.40647 > 2a01:798:0:9002::70.53: [bad udp cksum 0x0f74 -> 0xdc2f!] 12182+ AAAA? time.nist.gov. (31)
12:15:23.430530 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 78) 2a01:798:0:9002::70.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.56501: [udp sum ok] 28609 q: A? time.nist.gov. 2/0/0 time.nist.gov. [1m47s] CNAME ntp1.glb.nist.gov., ntp1.glb.nist.gov. [6m47s] A 132.163.96.2 (70)
12:15:23.430671 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 90) 2a01:798:0:9002::70.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.40647: [udp sum ok] 12182 q: AAAA? time.nist.gov. 2/0/0 time.nist.gov. [1m47s] CNAME ntp1.glb.nist.gov., ntp1.glb.nist.gov. [38s] AAAA 2610:20:6f97:97::4 (82)
12:15:23.522376 IP6 (flowlabel 0xa4222, hlim 64, next-header UDP (17) payload length: 98) 2a01:798:100:5800:c585:c0af:d40f:6851.55539 > 2a01:798:0:9002::70.53: [bad udp cksum 0x0faf -> 0x446f!] 24441+ PTR? 0.7.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.9.0.0.0.0.8.9.7.0.1.0.a.2.ip6.arpa. (90)
12:15:23.525461 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 151) 2a01:798:0:9002::70.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.55539: [udp sum ok] 24441 NXDomain q: PTR? 0.7.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.9.0.0.0.0.8.9.7.0.1.0.a.2.ip6.arpa. 0/1/0 ns: 8.9.7.0.1.0.a.2.ip6.arpa. [33m31s] SOA ns1.lyse.net. root.lyse.net. 1575373077 28800 7200 2419200 3600 (143)
12:15:26.929569 IP6 (flowlabel 0x337b6, hlim 64, next-header UDP (17) payload length: 39) 2a01:798:100:5800:c585:c0af:d40f:6851.44009 > 2a01:798:0:9002::70.53: [bad udp cksum 0x0f74 -> 0x7332!] 6970+ A? api.easee.com. (31)
12:15:26.930223 IP6 (flowlabel 0x04b79, hlim 64, next-header UDP (17) payload length: 39) 2a01:798:100:5800:c585:c0af:d40f:6851.41131 > 2a01:798:0:9002::70.53: [bad udp cksum 0x0f74 -> 0x588d!] 9757+ AAAA? api.easee.com. (31)
12:15:26.932940 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 130) 2a01:798:0:9002::70.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.44009: [udp sum ok] 6970 q: A? api.easee.com. 3/0/0 api.easee.com. [59s] CNAME d-wvxoekiiy7.execute-api.eu-west-1.amazonaws.com., d-wvxoekiiy7.execute-api.eu-west-1.amazonaws.com. [1s] A 54.229.114.46, d-wvxoekiiy7.execute-api.eu-west-1.amazonaws.com. [1s] A 54.195.64.214 (122)
12:15:26.933101 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 180) 2a01:798:0:9002::70.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.41131: [udp sum ok] 9757 q: AAAA? api.easee.com. 1/1/0 api.easee.com. [59s] CNAME d-wvxoekiiy7.execute-api.eu-west-1.amazonaws.com. ns: execute-api.eu-west-1.amazonaws.com. [5m39s] SOA ns-1028.awsdns-00.org. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400 (172)
12:15:28.480897 IP6 (hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::caea:f8ff:fec1:859e > fe80::201:2ff:fe61:1: [icmp6 sum ok] ICMP6, neighbor solicitation, length 32, who has fe80::201:2ff:fe61:1
          source link-address option (1), length 8 (1): c8:ea:f8:c1:85:9e
            0x0000:  c8ea f8c1 859e
12:15:28.484195 IP6 (class 0xe0, hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::201:2ff:fe61:1 > fe80::caea:f8ff:fec1:859e: [icmp6 sum ok] ICMP6, neighbor advertisement, length 32, tgt is fe80::201:2ff:fe61:1, Flags [router, solicited, override]
          destination link-address option (2), length 8 (1): 00:01:02:61:00:01
            0x0000:  0001 0261 0001
12:15:28.484395 IP6 (class 0xe0, hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::201:2ff:fe61:1 > ff02::1:ffc1:859e: [icmp6 sum ok] ICMP6, neighbor solicitation, length 32, who has fe80::caea:f8ff:fec1:859e
          source link-address option (1), length 8 (1): 00:01:02:61:00:01
            0x0000:  0001 0261 0001
12:15:28.484520 IP6 (hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::caea:f8ff:fec1:859e > fe80::201:2ff:fe61:1: [icmp6 sum ok] ICMP6, neighbor advertisement, length 32, tgt is fe80::caea:f8ff:fec1:859e, Flags [router, solicited, override]
          destination link-address option (2), length 8 (1): c8:ea:f8:c1:85:9e
            0x0000:  c8ea f8c1 859e
12:15:37.112101 IP6 (class 0xe0, hlim 255, next-header ICMPv6 (58) payload length: 32) fe80::201:2ff:fe61:1 > ip6-allnodes: [icmp6 sum ok] ICMP6, router advertisement, length 32
        hop limit 64, Flags [managed, other stateful], pref medium, router lifetime 1800s, reachable time 0ms, retrans timer 0ms
          source link-address option (1), length 8 (1): 00:01:02:61:00:01
            0x0000:  0001 0261 0001
          mtu option (5), length 8 (1):  1500
            0x0000:  0000 0000 05dc
12:15:42.226164 IP6 (flowlabel 0xeb805, hlim 64, next-header UDP (17) payload length: 56) 2a01:798:100:5800:c585:c0af:d40f:6851.49070 > 2a01:798:0:9002::70.53: [bad udp cksum 0x0f85 -> 0x7bbf!] 59731+ A? self.events.data.microsoft.com. (48)
12:15:42.226303 IP6 (flowlabel 0xd5959, hlim 64, next-header UDP (17) payload length: 56) 2a01:798:100:5800:c585:c0af:d40f:6851.49070 > dns-site-a.altibox.no.53: [bad udp cksum 0xff28 -> 0x8c1b!] 59731+ A? self.events.data.microsoft.com. (48)
12:15:42.226956 IP6 (flowlabel 0x1d862, hlim 64, next-header UDP (17) payload length: 56) 2a01:798:100:5800:c585:c0af:d40f:6851.56967 > 2a01:798:0:9002::70.53: [bad udp cksum 0x0f85 -> 0xe9a5!] 23673+ AAAA? self.events.data.microsoft.com. (48)
12:15:42.228507 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 178) 2a01:798:0:9002::70.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.49070: [udp sum ok] 59731 q: A? self.events.data.microsoft.com. 3/0/0 self.events.data.microsoft.com. [26s] CNAME self-events-data.trafficmanager.net., self-events-data.trafficmanager.net. [25s] CNAME onedscolprdweu00.westeurope.cloudapp.azure.com., onedscolprdweu00.westeurope.cloudapp.azure.com. [8s] A 13.69.109.130 (170)
12:15:42.229123 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 178) dns-site-a.altibox.no.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.49070: [udp sum ok] 59731 q: A? self.events.data.microsoft.com. 3/0/0 self.events.data.microsoft.com. [26s] CNAME self-events-data.trafficmanager.net., self-events-data.trafficmanager.net. [25s] CNAME onedscolprdweu00.westeurope.cloudapp.azure.com., onedscolprdweu00.westeurope.cloudapp.azure.com. [8s] A 13.69.109.130 (170)
12:15:42.229202 IP6 (class 0x60, hlim 62, next-header UDP (17) payload length: 223) 2a01:798:0:9002::70.53 > 2a01:798:100:5800:c585:c0af:d40f:6851.56967: [udp sum ok] 23673 q: AAAA? self.events.data.microsoft.com. 2/1/0 self.events.data.microsoft.com. [26s] CNAME self-events-data.trafficmanager.net., self-events-data.trafficmanager.net. [25s] CNAME onedscolprdweu00.westeurope.cloudapp.azure.com. ns: westeurope.cloudapp.azure.com. [33s] SOA ns1-201.azure-dns.com. msnhst.microsoft.com. 10001 900 300 604800 60 (215)
12:15:42.229396 IP6 (flowlabel 0xf03d2, hlim 64, next-header ICMPv6 (58) payload length: 226) 2a01:798:100:5800:c585:c0af:d40f:6851 > dns-site-a.altibox.no: [icmp6 sum ok] ICMP6, destination unreachable, unreachable port, 2a01:798:100:5800:c585:c0af:d40f:6851 udp port 49070
^C
36 packets captured
38 packets received by filter
0 packets dropped by kernel

Then I changed the mac-address on the wan and tried another connect, but no success.
Repeated this with a third OpenWrt. Succes on first attempt, and then failed on succeding attempts. Sadly I have no other routers for test.

It looks like the ISP is doing some blacklisting on my routers. May anyone have a hypothesis on what is going on?

This is a wild guess you probably considered already: your ISP assigns static IA_NA and IA_PD per DUID. Even though the valid lifetime and preferred lifetime are both set to 3600 seconds, those options don't change.

What happens when OpenWrt sends renew or rebind messages?

Changing the DUID (!) results in a IPv6 address and prefix, but only the first request after the change. If interface is restarted no address or prefix i received unless I set option norelease '1'. When address and prefix is OK, renew seems to work. I never saw any rebind messages.

Will it be risky to set up an address obtained by DHCPv6 as a static address? Any chance DHCPv6 server will assign this IP to another client, or will it always check if an address is live before assigning it?

According to your description, there seems to be implemention issues on your ISP's end, so there's a chance you'll get null-routed. Have you tried using earlier prefixes? Do they work?

I am using adress and prefix from last DHCP as static just now. Works OK.

Then I guess you are safe to use them until your ISP's NOC gets wind of this issue or upgrades equipment next time.

1 Like

Now the original setup with DHCPv6 client works again, even with default DUID. Concluding this was a problem by the ISP :thinking:

1 Like

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.