IPv6 SLAAC vs DHCPv6: RA Flags M, O and A Explained - 夜莺博客

IPv6 SLAAC vs DHCPv6: RA Flags M, O and A Explained

Almost every "IPv6 works on my laptop but not on the server" problem traces back to the Router Advertisement flags, not to routing. The RA carries a small set of bits that tell hosts how to build addresses and where to get everything else, and because those bits are advisory rather than prescriptive, two hosts on the same link can legitimately behave differently. Here is what each flag actually does.

The RA itself

Routers multicast Router Advertisements periodically (and in response to a Router Solicitation), carrying a current hop limit, a router lifetime, and zero or more Prefix Information options. Hosts use the on-link prefixes to decide whether a destination is on-link, and the autonomous flag within each prefix to decide whether to build an address from it.

M, O and A

Flag Location Meaning
M (Managed) RA header Addresses are available via DHCPv6. If M is set, O is redundant because DHCPv6 returns all configuration.
O (Other) RA header Other configuration (for example DNS information) is available via DHCPv6, without DHCPv6 handing out addresses.
A (Autonomous) Prefix Information option This prefix may be used for stateless address autoconfiguration.

M, O and A are semantically independent. All four combinations of M and A are legal, and the A flag applies per prefix, not per RA — a router can advertise one prefix that hosts may SLAAC from and another that they must not.

The three common designs

  • SLAAC only: M=0, O=0, A=1 on the prefix. Hosts build their own addresses; DNS must come from somewhere else (RDNSS option or a static configuration).
  • SLAAC for addresses, DHCPv6 for DNS: M=0, O=1, A=1. Stateless DHCPv6 — the most common enterprise compromise.
  • Stateful DHCPv6: M=1, A=0. Addresses come from DHCPv6; RA is still needed for the default route.

Lifetimes and the silent outages they cause

# Junos: advertise a prefix with a shorter valid lifetime
set protocols router-advertisement interface ge-0/0/1.0 prefix 2001:db8:10::/64
set protocols router-advertisement interface ge-0/0/1.0 prefix 2001:db8:10::/64 valid-lifetime 2592000
set protocols router-advertisement interface ge-0/0/1.0 prefix 2001:db8:10::/64 preferred-lifetime 604800

Preferred lifetime is how long an address stays preferred for new connections; valid lifetime is how long it may still be used at all. Set preferred longer than valid and the option is silently ignored. Set router lifetime to 0 and the router is not a default router — useful for a prefix-only advertisement, catastrophic if it was meant to be the gateway. Practical deployments often advertise a valid lifetime of 30 days and preferred of 7 days, refreshed by regular RAs.

Operational checks

# Linux host
ip -6 addr show
ip -6 route show default
sysctl net.ipv6.conf.all.accept_ra

# Cisco IOS-XE
show ipv6 interface GigabitEthernet1/0/1
show ipv6 routers

Confirm on the host which addresses came from SLAAC versus DHCPv6, that a default route exists, and that accept_ra is not disabled by a hardening template — a Linux server with forwarding enabled will ignore RAs by default, which is a frequent cause of a host that has an address and no route. On the network side, pairing RA with RA Guard at the access edge prevents a rogue host from advertising itself as a router.

Related reading: IPv6 address planning for enterprises, NAT64 and 464XLAT for IPv6-only networks, Anycast DNS design and failure modes.

原文链接:RFC 4861 - Neighbor Discovery for IPv6