Router has IPv6 Internet access, but client doesn't

Setup

I built a x86 OpenWrt router with two LAN (lan_vault, lan_guest) and six WAN (wan_a to wan_f, and wan_a_6 to wan_f_6 for IPv6)

Each of the six wan_*_6 interface is assigned a public IPv6 address with prefix 60 by ISP, so I distribute the 64 address to my two LAN. RA server mode. MWAN3 is not installed.

Problem

  • Clients in LAN have no IPv6 Internet access

Troubleshooting

  • ping6 test result
╔════════════════════╦════════╦═════════════╦══════════════════╗
║             source ║ router ║ host in LAN ║ host on Internet ║
║ dest               ║        ║             ║                  ║
╠════════════════════╬════════╬═════════════╬══════════════════╣
║ router             ║        ║ Y           ║ Y                ║
╠════════════════════╬════════╬═════════════╬══════════════════╣
║ other hosts in LAN ║ Y      ║ Y           ║ N                ║
╠════════════════════╬════════╬═════════════╬══════════════════╣
║ host on Internet   ║ Y      ║ N           ║                  ║
╚════════════════════╩════════╩═════════════╩══════════════════╝

OpenWrt config

/etc/config/network

config interface 'loopback'
        option ifname 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config globals 'globals'

config interface 'lan_vault'
        option type 'bridge'
        option ifname 'eth0.10'
        option proto 'static'
        option ipaddr '10.0.0.1'
        option netmask '255.255.255.0'
        option ip6assign '64'
        option macaddr '52:54:00:40:6F:BE'
        option ip6hint '0'
        option ip6ifaceid '::1'

config interface 'lan_guest'
        option type 'bridge'
        option ifname 'eth0.20'
        option proto 'static'
        option ipaddr '172.16.1.1'
        option netmask '255.255.255.0'
        option ip6assign '64'
        option macaddr '52:54:00:40:6F:BF'
        option ip6hint '1'
        option ip6ifaceid '::1'

config interface 'wan_a'
        option ifname 'eth4.100'
        option proto 'pppoe'
        option password '***'
        option username '***'
        option metric '100'
        option macaddr '52:54:00:4E:7D:78'
        option ipv6 '1'

config interface 'wan_b'
        option ifname 'eth4.110'
        option proto 'pppoe'
        option password '***'
        option username '***'
        option metric '110'
        option macaddr '52:54:00:4E:7D:79'
        option ipv6 '1'

config interface 'wan_c'
        option ifname 'eth4.120'
        option proto 'pppoe'
        option password '***'
        option username '***'
        option metric '120'
        option macaddr '52:54:00:4E:7D:7A'
        option ipv6 '1'

config interface 'wan_d'
        option ifname 'eth4.130'
        option proto 'pppoe'
        option password '***'
        option username '***'
        option metric '130'
        option macaddr '52:54:00:4E:7D:7B'
        option ipv6 '1'

config interface 'wan_e'
        option ifname 'eth4.140'
        option proto 'pppoe'
        option password '***'
        option username '***'
        option metric '140'
        option macaddr '52:54:00:4E:7D:7C'
        option ipv6 '1'

config interface 'wan_f'
        option ifname 'eth4.150'
        option proto 'pppoe'
        option username '***'
        option password '***'
        option metric '150'
        option macaddr '52:54:00:4E:7D:7D'
        option ipv6 '1'

config interface 'wan_a_6'
        option proto 'dhcpv6'
        option ifname '@wan_a'
        option reqaddress 'try'
        option reqprefix 'auto'

config interface 'wan_b_6'
        option proto 'dhcpv6'
        option ifname '@wan_b'
        option reqaddress 'try'
        option reqprefix 'auto'

config interface 'wan_c_6'
        option proto 'dhcpv6'
        option ifname '@wan_c'
        option reqaddress 'try'
        option reqprefix 'auto'

config interface 'wan_d_6'
        option proto 'dhcpv6'
        option ifname '@wan_d'
        option reqaddress 'try'
        option reqprefix 'auto'

config interface 'wan_e_6'
        option proto 'dhcpv6'
        option ifname '@wan_e'
        option reqaddress 'try'
        option reqprefix 'auto'

config interface 'wan_f_6'
        option proto 'dhcpv6'
        option ifname '@wan_f'
        option reqaddress 'try'
        option reqprefix 'auto'

/etc/config/firewall

config defaults
        option syn_flood '1'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'

config zone
        option name 'lan_guest'
        list network 'lan_guest'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'

config zone
        option name 'lan_vault'
        list network 'lan_vault'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'

config zone
        option name 'wan'
        list network 'wan_a'
        list network 'wan_b'
        list network 'wan_c'
        list network 'wan_d'
        list network 'wan_e'
        list network 'wan_f'
        list network 'wan_a_6'
        list network 'wan_b_6'
        list network 'wan_c_6'
        list network 'wan_d_6'
        list network 'wan_e_6'
        list network 'wan_f_6'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'

config forwarding
        option src 'lan_guest'
        option dest 'wan'

config forwarding
        option src 'lan_vault'
        option dest 'wan'

config forwarding
        option src 'lan_vault'
        option dest 'lan_guest'

config rule
        option src 'wan'
        option name 'Allow IPv6'
        option family 'ipv6'
        option target 'ACCEPT'
        option dest 'lan_guest'
        list proto 'all'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-IGMP'
        option src 'wan'
        option proto 'igmp'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option src_ip 'fc00::/6'
        option dest_ip 'fc00::/6'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-MLD'
        option src 'wan'
        option proto 'icmp'
        option src_ip 'fe80::/10'
        list icmp_type '130/0'
        list icmp_type '131/0'
        list icmp_type '132/0'
        list icmp_type '143/0'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-IPSec-ESP'
        option src 'wan'
        option proto 'esp'
        option target 'ACCEPT'
        option dest 'lan_guest'

config rule
        option name 'Allow-ISAKMP'
        option src 'wan'
        option dest_port '500'
        option proto 'udp'
        option target 'ACCEPT'
        option dest 'lan_guest'

config include
        option path '/etc/firewall.user'
  • Client output of ip a
2: eno1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether a8:a1:59:02:9f:24 brd ff:ff:ff:ff:ff:ff
    inet 172.16.1.177/24 brd 172.16.1.255 scope global dynamic noprefixroute eno1
       valid_lft 830sec preferred_lft 830sec
    inet6 2606:2b1:4cd1:5371:289c:6fab:ed83:6e77/64 scope global deprecated dynamic noprefixroute
       valid_lft 2444sec preferred_lft 0sec
    inet6 2606:2b1:4cd3:97b1:7cab:f309:6cdc:9f90/64 scope global deprecated dynamic noprefixroute
       valid_lft 2439sec preferred_lft 0sec
    inet6 2606:2b1:4ce3:f621:1c77:a1e9:2e9a:fce9/64 scope global deprecated dynamic noprefixroute
       valid_lft 870sec preferred_lft 0sec
    inet6 2606:2b1:4ce3:f601:da35:6ef3:ae0a:c457/64 scope global deprecated dynamic noprefixroute
       valid_lft 871sec preferred_lft 0sec
    inet6 2606:2b1:4ce3:85d1:ba3f:102b:68a7:5d55/64 scope global deprecated dynamic noprefixroute
       valid_lft 250sec preferred_lft 0sec
    inet6 2606:2b1:4cd1:51:8d3d:89c2:aed5:d246/64 scope global deprecated dynamic noprefixroute
       valid_lft 24sec preferred_lft 0sec
    inet6 fe80::2787:25d4:6f25:919e/64 scope link noprefixroute
       valid_lft forever preferred_lft forever
  • Client output of route -6n
Kernel IPv6 routing table
Destination                    Next Hop                   Flag Met Ref Use If
::/0                           ::                         !n   -1  1     0 lo
::1/128                        ::                         U    256 2     0 lo
2606:2b1:4cd0:8741::/64        ::                         U    100 5     0 eno1
2606:2b1:4cd0:8740::/60        fe80::5054:ff:fe40:6fbf    UG   100 3     0 eno1
2606:2b1:4cd2:c081::/64        ::                         U    100 1     0 eno1
2606:2b1:4cd2:c080::/60        fe80::5054:ff:fe40:6fbf    UG   100 1     0 eno1
2606:2b1:4cd2:d421::/64        ::                         U    100 2     0 eno1
2606:2b1:4cd2:d420::/60        fe80::5054:ff:fe40:6fbf    UG   100 1     0 eno1
2606:2b1:4ce2:861::/64         ::                         U    100 1     0 eno1
2606:2b1:4ce2:860::/60         fe80::5054:ff:fe40:6fbf    UG   100 1     0 eno1
2606:2b1:4ce2:dfc1::/64        ::                         U    100 1     0 eno1
2606:2b1:4ce2:dfc0::/60        fe80::5054:ff:fe40:6fbf    UG   100 3     0 eno1
2606:2b1:4ce4:e131::/64        ::                         U    100 1     0 eno1
2606:2b1:4ce4:e130::/60        fe80::5054:ff:fe40:6fbf    UG   100 1     0 eno1
fe80::/64                      ::                         U    100 3     0 eno1
::/0                           fe80::5054:ff:fe40:6fbf    UG   100 5     0 eno1
::1/128                        ::                         Un   0   7     0 lo
2606:2b1:4cd0:8741:1794:e3f5:e18e:277f/128 ::                         Un   0   5     0 eno1
2606:2b1:4cd2:c081:1215:4436:b7b7:7e2c/128 ::                         Un   0   3     0 eno1
2606:2b1:4cd2:d421:1988:3a66:ebc0:b5b6/128 ::                         Un   0   3     0 eno1
2606:2b1:4ce2:861:2985:417e:9b5:e333/128 ::                         Un   0   2     0 eno1
2606:2b1:4ce2:dfc1:978f:b6e1:6514:d1f7/128 ::                         Un   0   4     0 eno1
2606:2b1:4ce4:e131:f6a2:6190:3475:3c16/128 ::                         Un   0   2     0 eno1
fe80::2787:25d4:6f25:919e/128  ::                         Un   0   3     0 eno1
ff00::/8                       ::                         U    256 6     0 eno1
::/0                           ::                         !n   -1  1     0 lo
  • Router output of ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: ip6tnl0@NONE: <NOARP> mtu 1452 qdisc noop state DOWN group default qlen 1000
    link/tunnel6 :: brd ::
3: ip_vti0@NONE: <NOARP> mtu 1480 qdisc noop state DOWN group default qlen 1000
    link/ipip 0.0.0.0 brd 0.0.0.0
4: ip6_vti0@NONE: <NOARP> mtu 1500 qdisc noop state DOWN group default qlen 1000
    link/tunnel6 :: brd ::
5: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 1c:fd:08:73:29:30 brd ff:ff:ff:ff:ff:ff
    inet6 fe80::1efd:8ff:fe73:2930/64 scope link 
       valid_lft forever preferred_lft forever
6: eth1: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
    link/ether 1c:fd:08:73:29:31 brd ff:ff:ff:ff:ff:ff
7: eth2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
    link/ether 1c:fd:08:73:29:32 brd ff:ff:ff:ff:ff:ff
8: eth3: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN group default qlen 1000
    link/ether 1c:fd:08:73:29:33 brd ff:ff:ff:ff:ff:ff
9: eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 1c:fd:08:73:85:03 brd ff:ff:ff:ff:ff:ff
    inet6 fe80::1efd:8ff:fe73:8503/64 scope link 
       valid_lft forever preferred_lft forever
10: bond0: <BROADCAST,MULTICAST,MASTER> mtu 1500 qdisc noop state DOWN group default qlen 1000
    link/ether 42:5c:53:59:e0:34 brd ff:ff:ff:ff:ff:ff
11: br-lan_guest: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:40:6f:bf brd ff:ff:ff:ff:ff:ff
    inet 172.16.1.1/24 brd 172.16.1.255 scope global br-lan_guest
       valid_lft forever preferred_lft forever
    inet6 2606:2b1:4cd1:6bb1::1/64 scope global dynamic noprefixroute 
       valid_lft 4683sec preferred_lft 1083sec
    inet6 2606:2b1:4ce5:d11::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 3004sec preferred_lft 0sec
    inet6 2606:2b1:4ce5:e11::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 3003sec preferred_lft 0sec
    inet6 2606:2b1:4ce3:3c71::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 2388sec preferred_lft 0sec
    inet6 2606:2b1:4cd7:a511::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 2329sec preferred_lft 0sec
    inet6 fe80::5054:ff:fe40:6fbf/64 scope link 
       valid_lft forever preferred_lft forever
12: eth0.20@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan_guest state UP group default qlen 1000
    link/ether 1c:fd:08:73:29:30 brd ff:ff:ff:ff:ff:ff
14: br-lan_vault: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:40:6f:be brd ff:ff:ff:ff:ff:ff
    inet 10.0.0.1/24 brd 10.0.0.255 scope global br-lan_vault
       valid_lft forever preferred_lft forever
    inet6 2606:2b1:4cd1:6bb0::1/64 scope global dynamic noprefixroute 
       valid_lft 4683sec preferred_lft 1083sec
    inet6 2606:2b1:4ce5:d10::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 3004sec preferred_lft 0sec
    inet6 2606:2b1:4ce5:e10::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 3003sec preferred_lft 0sec
    inet6 2606:2b1:4ce3:3c70::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 2388sec preferred_lft 0sec
    inet6 2606:2b1:4cd7:a510::1/64 scope global deprecated dynamic noprefixroute 
       valid_lft 2329sec preferred_lft 0sec
    inet6 fe80::5054:ff:fe40:6fbe/64 scope link 
       valid_lft forever preferred_lft forever
15: eth0.10@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan_vault state UP group default qlen 1000
    link/ether 1c:fd:08:73:29:30 brd ff:ff:ff:ff:ff:ff
81: eth4.100@eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:4e:7d:78 brd ff:ff:ff:ff:ff:ff
    inet6 fe80::5054:ff:fe4e:7d78/64 scope link 
       valid_lft forever preferred_lft forever
82: eth4.120@eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:4e:7d:7a brd ff:ff:ff:ff:ff:ff
    inet6 fe80::5054:ff:fe4e:7d7a/64 scope link 
       valid_lft forever preferred_lft forever
83: eth4.110@eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:4e:7d:79 brd ff:ff:ff:ff:ff:ff
    inet6 fe80::5054:ff:fe4e:7d79/64 scope link 
       valid_lft forever preferred_lft forever
84: pppoe-wan_a: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    link/ppp 
    inet 221.225.87.65 peer 221.225.87.1/32 scope global pppoe-wan_a
       valid_lft forever preferred_lft forever
    inet6 2606:2b0:4c0d:9702:5254:3d:c24e:7d78/64 scope global dynamic noprefixroute 
       valid_lft 2591455sec preferred_lft 604255sec
    inet6 fe80::5254:3d:c24e:7d78/10 scope link 
       valid_lft forever preferred_lft forever
85: pppoe-wan_c: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    link/ppp 
    inet 49.72.42.178 peer 49.72.42.1/32 scope global pppoe-wan_c
       valid_lft forever preferred_lft forever
    inet6 2606:2b0:4c0e:dc86:5254:54:824e:7d7a/64 scope global dynamic noprefixroute 
       valid_lft 2591989sec preferred_lft 604789sec
    inet6 fe80::5254:54:824e:7d7a/10 scope link 
       valid_lft forever preferred_lft forever
86: pppoe-wan_b: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    link/ppp 
    inet 221.225.87.80 peer 221.225.87.1/32 scope global pppoe-wan_b
       valid_lft forever preferred_lft forever
    inet6 2606:2b0:4c0d:96e9:5254:5:314e:7d79/64 scope global dynamic noprefixroute 
       valid_lft 2591455sec preferred_lft 604255sec
    inet6 fe80::5254:5:314e:7d79/10 scope link 
       valid_lft forever preferred_lft forever
134: eth4.130@eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:4e:7d:7b brd ff:ff:ff:ff:ff:ff
    inet6 fe80::5054:ff:fe4e:7d7b/64 scope link 
       valid_lft forever preferred_lft forever
135: eth4.140@eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:4e:7d:7c brd ff:ff:ff:ff:ff:ff
    inet6 fe80::5054:ff:fe4e:7d7c/64 scope link 
       valid_lft forever preferred_lft forever
136: eth4.150@eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 52:54:00:4e:7d:7d brd ff:ff:ff:ff:ff:ff
    inet6 fe80::5054:ff:fe4e:7d7d/64 scope link 
       valid_lft forever preferred_lft forever
137: pppoe-wan_d: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    link/ppp 
    inet 49.73.86.165 peer 49.73.86.1/32 scope global pppoe-wan_d
       valid_lft forever preferred_lft forever
    inet6 2606:2b0:4c0e:a03e:5254:73:774e:7d7b/64 scope global dynamic noprefixroute 
       valid_lft 2591404sec preferred_lft 604204sec
    inet6 fe80::5254:73:774e:7d7b/10 scope link 
       valid_lft forever preferred_lft forever
138: pppoe-wan_f: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    link/ppp 
    inet 221.225.43.254 peer 221.225.43.1/32 scope global pppoe-wan_f
       valid_lft forever preferred_lft forever
    inet6 2606:2b0:4c0d:a832:5254:90:7a4e:7d7d/64 scope global dynamic noprefixroute 
       valid_lft 2591902sec preferred_lft 604702sec
    inet6 fe80::5254:90:7a4e:7d7d/10 scope link 
       valid_lft forever preferred_lft forever
139: pppoe-wan_e: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    link/ppp 
    inet 49.73.86.185 peer 49.73.86.1/32 scope global pppoe-wan_e
       valid_lft forever preferred_lft forever
    inet6 2606:2b0:4c0e:a089:5254:fe:ce4e:7d7c/64 scope global dynamic noprefixroute 
       valid_lft 2591989sec preferred_lft 604789sec
    inet6 fe80::5254:fe:ce4e:7d7c/10 scope link 
       valid_lft forever preferred_lft forever
  • Router output of route -A inet6 -n
Kernel IPv6 routing table
Destination                                 Next Hop                                Flags Metric Ref    Use Iface
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UG    512    1        0 pppoe-wan_b
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UG    512    1        0 pppoe-wan_a
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UG    512    1        0 pppoe-wan_f
::/0                                        fe80::4e09:b4ff:fefc:b930               UG    512    1        0 pppoe-wan_d
::/0                                        fe80::4e09:b4ff:fefc:b930               UG    512    8     5738 pppoe-wan_e
::/0                                        fe80::4e09:b4ff:fefc:b930               UG    512    1        0 pppoe-wan_c
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UG    512    1        0 pppoe-wan_b
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UG    512    1        0 pppoe-wan_a
::/0                                        fe80::4e09:b4ff:fefc:b930               UG    512    1        0 pppoe-wan_c
::/0                                        fe80::4e09:b4ff:fefc:b930               UG    512    1        0 pppoe-wan_e
::/0                                        fe80::4e09:b4ff:fefc:b930               UG    512    1        0 pppoe-wan_d
2606:2b0:4c0d:96e9::/64                     ::                                      UA    256    3        2 pppoe-wan_b
2606:2b0:4c0d:96e9::/64                     ::                                      !n    2147483647 1        0 lo      
2606:2b0:4c0d:9702::/64                     ::                                      UA    256    8     2394 pppoe-wan_a
2606:2b0:4c0d:9702::/64                     ::                                      !n    2147483647 1        0 lo      
2606:2b0:4c0d:a832::/64                     ::                                      UA    256    1        0 pppoe-wan_f
2606:2b0:4c0d:a832::/64                     ::                                      !n    2147483647 1        0 lo      
2606:2b0:4c0e:a03e::/64                     ::                                      UA    256    1        0 pppoe-wan_d
2606:2b0:4c0e:a03e::/64                     ::                                      !n    2147483647 1        0 lo      
2606:2b0:4c0e:a089::/64                     ::                                      UA    256    8      381 pppoe-wan_e
2606:2b0:4c0e:a089::/64                     ::                                      !n    2147483647 1        0 lo      
2606:2b0:4c0e:dc86::/64                     ::                                      UA    256    1        0 pppoe-wan_c
2606:2b0:4c0e:dc86::/64                     ::                                      !n    2147483647 1        0 lo      
2606:2b1:4cd1:6bb0::/64                     ::                                      U     1024   1        0 br-lan_vault
2606:2b1:4cd1:6bb1::/64                     ::                                      U     1024   1        0 br-lan_guest
2606:2b1:4cd1:6bb0::/60                     ::                                      !n    2147483647 1        0 lo      
2606:2b1:4cd7:a510::/64                     ::                                      U     1024   1        0 br-lan_vault
2606:2b1:4cd7:a511::/64                     ::                                      U     1024   1        0 br-lan_guest
2606:2b1:4cd7:a510::/60                     ::                                      !n    2147483647 1        0 lo      
2606:2b1:4ce3:3c70::/64                     ::                                      U     1024   1        0 br-lan_vault
2606:2b1:4ce3:3c71::/64                     ::                                      U     1024   1        0 br-lan_guest
2606:2b1:4ce3:3c70::/60                     ::                                      !n    2147483647 1        0 lo      
2606:2b1:4ce5:d10::/64                      ::                                      U     1024   1        0 br-lan_vault
2606:2b1:4ce5:d11::/64                      ::                                      U     1024   1        0 br-lan_guest
2606:2b1:4ce5:d10::/60                      ::                                      !n    2147483647 1        0 lo      
2606:2b1:4ce5:e10::/64                      ::                                      U     1024   1        0 br-lan_vault
2606:2b1:4ce5:e11::/64                      ::                                      U     1024   1        0 br-lan_guest
2606:2b1:4ce5:e10::/60                      ::                                      !n    2147483647 1        0 lo      
fe80::/64                                   ::                                      U     256    1        0 eth4    
fe80::/64                                   ::                                      U     256    1        0 eth0    
fe80::/64                                   ::                                      U     256    1        0 br-lan_vault
fe80::/64                                   ::                                      U     256    9   224854 br-lan_guest
fe80::/64                                   ::                                      U     256    1        0 eth4.100
fe80::/64                                   ::                                      U     256    1        0 eth4.120
fe80::/64                                   ::                                      U     256    1        0 eth4.110
fe80::/64                                   ::                                      U     256    1        0 eth4.130
fe80::/64                                   ::                                      U     256    1        0 eth4.140
fe80::/64                                   ::                                      U     256    1        0 eth4.150
fe80::/10                                   ::                                      U     1      2        9 pppoe-wan_a
fe80::/10                                   ::                                      U     1      2       12 pppoe-wan_c
fe80::/10                                   ::                                      U     1      3      102 pppoe-wan_b
fe80::/10                                   ::                                      U     1      3      103 pppoe-wan_f
fe80::/10                                   ::                                      U     1      3       18 pppoe-wan_e
fe80::/10                                   ::                                      U     1      3       18 pppoe-wan_d
fe80::/10                                   ::                                      U     256    1        0 pppoe-wan_a
fe80::/10                                   ::                                      U     256    1        0 pppoe-wan_c
fe80::/10                                   ::                                      U     256    1        0 pppoe-wan_b
fe80::/10                                   ::                                      U     256    1        0 pppoe-wan_f
fe80::/10                                   ::                                      U     256    1        0 pppoe-wan_e
fe80::/10                                   ::                                      U     256    1        0 pppoe-wan_d
::/0                                        fe80::4e09:b4ff:fefc:b930               UGDA  1024   9   477626 pppoe-wan_e
::/0                                        fe80::4e09:b4ff:fefc:b930               UGDA  1024   2        4 pppoe-wan_c
::/0                                        fe80::4e09:b4ff:fefc:b930               UGDA  1024   1        0 pppoe-wan_d
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UGDA  1024   1        0 pppoe-wan_b
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UGDA  1024   1        0 pppoe-wan_f
::/0                                        fe80::4e09:b4ff:fefc:a9b0               UGDA  1024   8      188 pppoe-wan_a
::/0                                        ::                                      !n    -1     1  57144853 lo      
::1/128                                     ::                                      Un    0      10   60360 lo      
2606:2b0:4c0d:96e9::/128                    ::                                      Un    0      2        0 pppoe-wan_b
2606:2b0:4c0d:96e9:5254:5:314e:7d79/128     ::                                      Un    0      2        0 pppoe-wan_b
2606:2b0:4c0d:9702::/128                    ::                                      Un    0      2        0 pppoe-wan_a
2606:2b0:4c0d:9702:5254:3d:c24e:7d78/128    ::                                      Un    0      2        0 pppoe-wan_a
2606:2b0:4c0d:a832::/128                    ::                                      Un    0      2        0 pppoe-wan_f
2606:2b0:4c0d:a832:5254:90:7a4e:7d7d/128    ::                                      Un    0      2        0 pppoe-wan_f
2606:2b0:4c0e:a03e::/128                    ::                                      Un    0      2        0 pppoe-wan_d
2606:2b0:4c0e:a03e:5254:73:774e:7d7b/128    ::                                      Un    0      2        0 pppoe-wan_d
2606:2b0:4c0e:a089::/128                    ::                                      Un    0      2        0 pppoe-wan_e
2606:2b0:4c0e:a089:5254:fe:ce4e:7d7c/128    ::                                      Un    0      9     6001 pppoe-wan_e
2606:2b0:4c0e:dc86::/128                    ::                                      Un    0      2        0 pppoe-wan_c
2606:2b0:4c0e:dc86:5254:54:824e:7d7a/128    ::                                      Un    0      2        0 pppoe-wan_c
2606:2b1:4cd1:6bb0::/128                    ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4cd1:6bb0::1/128                   ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4cd1:6bb1::/128                    ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4cd1:6bb1::1/128                   ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4cd7:a510::/128                    ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4cd7:a510::1/128                   ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4cd7:a511::/128                    ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4cd7:a511::1/128                   ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4ce3:3c70::/128                    ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4ce3:3c70::1/128                   ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4ce3:3c71::/128                    ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4ce3:3c71::1/128                   ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4ce5:d10::/128                     ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4ce5:d10::1/128                    ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4ce5:d11::/128                     ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4ce5:d11::1/128                    ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4ce5:e10::/128                     ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4ce5:e10::1/128                    ::                                      Un    0      2        0 br-lan_vault
2606:2b1:4ce5:e11::/128                     ::                                      Un    0      2        0 br-lan_guest
2606:2b1:4ce5:e11::1/128                    ::                                      Un    0      2        0 br-lan_guest
fe80::/128                                  ::                                      Un    0      2        0 eth4    
fe80::/128                                  ::                                      Un    0      2        0 eth0    
fe80::/128                                  ::                                      Un    0      2        0 br-lan_vault
fe80::/128                                  ::                                      Un    0      2        0 br-lan_guest
fe80::/128                                  ::                                      Un    0      2        0 eth4.100
fe80::/128                                  ::                                      Un    0      2        0 eth4.120
fe80::/128                                  ::                                      Un    0      2        0 eth4.110
fe80::/128                                  ::                                      Un    0      2        0 pppoe-wan_a
fe80::/128                                  ::                                      Un    0      2        0 pppoe-wan_c
fe80::/128                                  ::                                      Un    0      2        0 pppoe-wan_b
fe80::/128                                  ::                                      Un    0      2        0 eth4.130
fe80::/128                                  ::                                      Un    0      2        0 eth4.140
fe80::/128                                  ::                                      Un    0      2        0 eth4.150
fe80::/128                                  ::                                      Un    0      2        0 pppoe-wan_f
fe80::/128                                  ::                                      Un    0      2        0 pppoe-wan_e
fe80::/128                                  ::                                      Un    0      2        0 pppoe-wan_d
fe80::1efd:8ff:fe73:2930/128                ::                                      Un    0      2        0 eth0    
fe80::1efd:8ff:fe73:8503/128                ::                                      Un    0      2        0 eth4    
fe80::5054:ff:fe40:6fbe/128                 ::                                      Un    0      2        0 br-lan_vault
fe80::5054:ff:fe40:6fbf/128                 ::                                      Un    0      9    84640 br-lan_guest
fe80::5054:ff:fe4e:7d78/128                 ::                                      Un    0      3        2 eth4.100
fe80::5054:ff:fe4e:7d79/128                 ::                                      Un    0      3        2 eth4.110
fe80::5054:ff:fe4e:7d7a/128                 ::                                      Un    0      4        2 eth4.120
fe80::5054:ff:fe4e:7d7b/128                 ::                                      Un    0      4        2 eth4.130
fe80::5054:ff:fe4e:7d7c/128                 ::                                      Un    0      4        2 eth4.140
fe80::5054:ff:fe4e:7d7d/128                 ::                                      Un    0      4        2 eth4.150
fe80::5254:5:314e:7d79/128                  ::                                      Un    0      4     2633 pppoe-wan_b
fe80::5254:3d:c24e:7d78/128                 ::                                      Un    0      4     2546 pppoe-wan_a
fe80::5254:54:824e:7d7a/128                 ::                                      Un    0      4     2551 pppoe-wan_c
fe80::5254:73:774e:7d7b/128                 ::                                      Un    0      4     2611 pppoe-wan_d
fe80::5254:90:7a4e:7d7d/128                 ::                                      Un    0      4     2621 pppoe-wan_f
fe80::5254:fe:ce4e:7d7c/128                 ::                                      Un    0      4     2618 pppoe-wan_e
ff00::/8                                    ::                                      U     256    1        0 eth4    
ff00::/8                                    ::                                      U     256    1        0 eth0    
ff00::/8                                    ::                                      U     256    8     2760 br-lan_vault
ff00::/8                                    ::                                      U     256    9  1517721 br-lan_guest
ff00::/8                                    ::                                      U     256    3        8 eth4.100
ff00::/8                                    ::                                      U     256    4        8 eth4.120
ff00::/8                                    ::                                      U     256    3        8 eth4.110
ff00::/8                                    ::                                      U     256    9     4458 pppoe-wan_a
ff00::/8                                    ::                                      U     256    9     4464 pppoe-wan_c
ff00::/8                                    ::                                      U     256    9     4479 pppoe-wan_b
ff00::/8                                    ::                                      U     256    3        2 eth4.130
ff00::/8                                    ::                                      U     256    3        2 eth4.140
ff00::/8                                    ::                                      U     256    3        2 eth4.150
ff00::/8                                    ::                                      U     256    9     4451 pppoe-wan_f
ff00::/8                                    ::                                      U     256    9     4462 pppoe-wan_e
ff00::/8                                    ::                                      U     256    9     4435 pppoe-wan_d
::/0
  • Router output of ip6tables -L
Chain INPUT (policy ACCEPT)
target     prot opt source               destination         
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */
input_rule  all      ::/0                 ::/0                 /* !fw3: Custom input rule chain */
ACCEPT     all      ::/0                 ::/0                 ctstate RELATED,ESTABLISHED /* !fw3 */
syn_flood  tcp      ::/0                 ::/0                 tcp flags:0x17/0x02 /* !fw3 */
zone_lan_guest_input  all      ::/0                 ::/0                 /* !fw3 */
zone_lan_vault_input  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_input  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_input  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_input  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_input  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_input  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_input  all      ::/0                 ::/0                 /* !fw3 */

Chain FORWARD (policy DROP)
target     prot opt source               destination         
forwarding_rule  all      ::/0                 ::/0                 /* !fw3: Custom forwarding rule chain */
ACCEPT     all      ::/0                 ::/0                 ctstate RELATED,ESTABLISHED /* !fw3 */
zone_lan_guest_forward  all      ::/0                 ::/0                 /* !fw3 */
zone_lan_vault_forward  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_forward  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_forward  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_forward  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_forward  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_forward  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_forward  all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination         
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */
output_rule  all      ::/0                 ::/0                 /* !fw3: Custom output rule chain */
ACCEPT     all      ::/0                 ::/0                 ctstate RELATED,ESTABLISHED /* !fw3 */
zone_lan_guest_output  all      ::/0                 ::/0                 /* !fw3 */
zone_lan_vault_output  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_output  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_output  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_output  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_output  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_output  all      ::/0                 ::/0                 /* !fw3 */
zone_wan_output  all      ::/0                 ::/0                 /* !fw3 */

Chain forwarding_lan_guest_rule (1 references)
target     prot opt source               destination         

Chain forwarding_lan_vault_rule (1 references)
target     prot opt source               destination         

Chain forwarding_rule (1 references)
target     prot opt source               destination         

Chain forwarding_wan_rule (1 references)
target     prot opt source               destination         

Chain input_lan_guest_rule (1 references)
target     prot opt source               destination         

Chain input_lan_vault_rule (1 references)
target     prot opt source               destination         

Chain input_rule (1 references)
target     prot opt source               destination         

Chain input_wan_rule (1 references)
target     prot opt source               destination         

Chain output_lan_guest_rule (1 references)
target     prot opt source               destination         

Chain output_lan_vault_rule (1 references)
target     prot opt source               destination         

Chain output_rule (1 references)
target     prot opt source               destination         

Chain output_wan_rule (1 references)
target     prot opt source               destination         

Chain reject (13 references)
target     prot opt source               destination         
REJECT     tcp      ::/0                 ::/0                 /* !fw3 */ reject-with tcp-reset
REJECT     all      ::/0                 ::/0                 /* !fw3 */ reject-with icmp6-port-unreachable

Chain syn_flood (1 references)
target     prot opt source               destination         
RETURN     tcp      ::/0                 ::/0                 tcp flags:0x17/0x02 limit: avg 25/sec burst 50 /* !fw3 */
DROP       all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_guest_dest_ACCEPT (6 references)
target     prot opt source               destination         
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_guest_forward (1 references)
target     prot opt source               destination         
forwarding_lan_guest_rule  all      ::/0                 ::/0                 /* !fw3: Custom lan_guest forwarding rule chain */
zone_wan_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3: Zone lan_guest to wan forwarding policy */
zone_lan_guest_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_guest_input (1 references)
target     prot opt source               destination         
input_lan_guest_rule  all      ::/0                 ::/0                 /* !fw3: Custom lan_guest input rule chain */
zone_lan_guest_src_ACCEPT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_guest_output (1 references)
target     prot opt source               destination         
output_lan_guest_rule  all      ::/0                 ::/0                 /* !fw3: Custom lan_guest output rule chain */
zone_lan_guest_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_guest_src_ACCEPT (1 references)
target     prot opt source               destination         
ACCEPT     all      ::/0                 ::/0                 ctstate NEW,UNTRACKED /* !fw3 */

Chain zone_lan_vault_dest_ACCEPT (2 references)
target     prot opt source               destination         
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_vault_forward (1 references)
target     prot opt source               destination         
forwarding_lan_vault_rule  all      ::/0                 ::/0                 /* !fw3: Custom lan_vault forwarding rule chain */
zone_wan_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3: Zone lan_vault to wan forwarding policy */
zone_lan_guest_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3: Zone lan_vault to lan_guest forwarding policy */
zone_lan_vault_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_vault_input (1 references)
target     prot opt source               destination         
input_lan_vault_rule  all      ::/0                 ::/0                 /* !fw3: Custom lan_vault input rule chain */
zone_lan_vault_src_ACCEPT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_vault_output (1 references)
target     prot opt source               destination         
output_lan_vault_rule  all      ::/0                 ::/0                 /* !fw3: Custom lan_vault output rule chain */
zone_lan_vault_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_lan_vault_src_ACCEPT (1 references)
target     prot opt source               destination         
ACCEPT     all      ::/0                 ::/0                 ctstate NEW,UNTRACKED /* !fw3 */

Chain zone_wan_dest_ACCEPT (3 references)
target     prot opt source               destination         
DROP       all      ::/0                 ::/0                 ctstate INVALID /* !fw3: Prevent NAT leakage */
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */
DROP       all      ::/0                 ::/0                 ctstate INVALID /* !fw3: Prevent NAT leakage */
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */
DROP       all      ::/0                 ::/0                 ctstate INVALID /* !fw3: Prevent NAT leakage */
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */
DROP       all      ::/0                 ::/0                 ctstate INVALID /* !fw3: Prevent NAT leakage */
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */
DROP       all      ::/0                 ::/0                 ctstate INVALID /* !fw3: Prevent NAT leakage */
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */
DROP       all      ::/0                 ::/0                 ctstate INVALID /* !fw3: Prevent NAT leakage */
ACCEPT     all      ::/0                 ::/0                 /* !fw3 */

Chain zone_wan_dest_REJECT (1 references)
target     prot opt source               destination         
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */

Chain zone_wan_forward (6 references)
target     prot opt source               destination         
forwarding_wan_rule  all      ::/0                 ::/0                 /* !fw3: Custom wan forwarding rule chain */
zone_lan_guest_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3: Allow IPv6 */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 128 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Forward */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 129 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Forward */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 1 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Forward */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 2 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Forward */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 3 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Forward */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 4 code 0 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Forward */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 4 code 1 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Forward */
zone_lan_guest_dest_ACCEPT  esp      ::/0                 ::/0                 /* !fw3: Allow-IPSec-ESP */
zone_lan_guest_dest_ACCEPT  udp      ::/0                 ::/0                 udp dpt:500 /* !fw3: Allow-ISAKMP */
zone_wan_dest_REJECT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_wan_input (6 references)
target     prot opt source               destination         
input_wan_rule  all      ::/0                 ::/0                 /* !fw3: Custom wan input rule chain */
ACCEPT     udp      fc00::/6             fc00::/6             udp dpt:546 /* !fw3: Allow-DHCPv6 */
ACCEPT     icmpv6    fe80::/10            ::/0                 ipv6-icmptype 130 code 0 /* !fw3: Allow-MLD */
ACCEPT     icmpv6    fe80::/10            ::/0                 ipv6-icmptype 131 code 0 /* !fw3: Allow-MLD */
ACCEPT     icmpv6    fe80::/10            ::/0                 ipv6-icmptype 132 code 0 /* !fw3: Allow-MLD */
ACCEPT     icmpv6    fe80::/10            ::/0                 ipv6-icmptype 143 code 0 /* !fw3: Allow-MLD */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 128 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 129 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 1 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 2 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 3 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 4 code 0 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 4 code 1 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 133 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 135 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 134 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
ACCEPT     icmpv6    ::/0                 ::/0                 ipv6-icmptype 136 limit: avg 1000/sec burst 5 /* !fw3: Allow-ICMPv6-Input */
zone_wan_src_REJECT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_wan_output (6 references)
target     prot opt source               destination         
output_wan_rule  all      ::/0                 ::/0                 /* !fw3: Custom wan output rule chain */
zone_wan_dest_ACCEPT  all      ::/0                 ::/0                 /* !fw3 */

Chain zone_wan_src_REJECT (1 references)
target     prot opt source               destination         
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */
reject     all      ::/0                 ::/0                 /* !fw3 */

Wireshark capture from router when pinging from a LAN host

ssh router tcpdump -i eth0.20 -U -s0 -w - 'icmp6' | wireshark -k -i -

3	0.028491	2606:2b0:4ce2:7391:7b82:c11b:9cfe:1296	2a03:b0c0:3:d0::1af1:1	ICMPv6	118	Echo (ping) request id=0x004e, seq=1130, hop limit=64 (no response found!)
4	1.047142	2606:2b1:4ce2:7391:7b82:c11b:9cfe:1296	2a03:b0c0:3:d0::1af1:1	ICMPv6	118	Echo (ping) request id=0x004e, seq=1131, hop limit=64 (no response found!)
5	2.071122	2606:2b1:4ce2:7391:7b82:c11b:9cfe:1296	2a03:b0c0:3:d0::1af1:1	ICMPv6	118	Echo (ping) request id=0x004e, seq=1132, hop limit=64 (no response found!)
6	3.095154	2606:2b1:4ce2:7391:7b82:c11b:9cfe:1296	2a03:b0c0:3:d0::1af1:1	ICMPv6	118	Echo (ping) request id=0x004e, seq=1133, hop limit=64 (no response found!)
7	4.119122	2606:2b1:4ce2:7391:7b82:c11b:9cfe:1296	2a03:b0c0:3:d0::1af1:1	ICMPv6	118	Echo (ping) request id=0x004e, seq=1134, hop limit=64 (no response found!)
8	5.143333	2606:2b1:4ce2:7391:7b82:c11b:9cfe:1296	2a03:b0c0:3:d0::1af1:1	ICMPv6	118	Echo (ping) request id=0x004e, seq=1135, hop limit=64 (no response found!)

Collect the diagnostics and paste it to pastebin.com:

ubus call system board; ifstatus wan_a_6; ifstatus wan_b_6; \
uci show network; uci show dhcp; uci show firewall; \
ip -6 address show; ip -6 route show table all; \
ip -6 rule show; ip6tables-save -c
1 Like

I just did a ping test overnight. It seems the issue is intermittent, the LAN host's IPv6 works for some time(about an hour), then suddenly fails again. I haven't found any patterns yet, nor any interesting log at the time it fails. :disappointed_relieved:

Looks like a similar issue:
Multi-homed IPv6 with dynamic addresses

You can isolate the problem by using a single prefix and disabling the other ones.
Reconnect the client to make sure it has no stale prefixes.

Also consider delegating prefixes selectively:
Downstream configuration for LAN interfaces