Juniper SRX and Private IPv6 Addresses
Using the following configuration I am able to have clients behind my SRX300 access the Internet using IPv6.
I have tested this using Charter cable modem, Comcast cable modem and Starlink. Note – Not all Charter/Spectrum connections I tested had IPv6 working.
First and foremost – enable ipv6 on your srx
set security forwarding-options family inet6 mode flow-based commit
if your srx prompts you to reboot your srx because you enabled this command – please do so – right now – before you do anything else.
I called the security zone for my office network OFFICE1 and the Internet connection zone ISPOFFICE1
#if you dont have a name server on the srx -pls add it now
set system name-server 9.9.9.9
#Put an ipv6 and ipv4 address on your “Office” network
set interfaces irb unit 0 description "Office Network" set interfaces irb unit 0 family inet address 10.10.1.1/24 set interfaces irb unit 0 family inet6 address fd00:80:2::1/64
#Get an ipv6 and ipv4 address on your “Internet” Connection
set interfaces irb unit 10 description ISP-OFFICE1 set interfaces irb unit 10 family inet dhcp set interfaces irb unit 10 family inet6 dhcpv6-client client-type autoconfig set interfaces irb unit 10 family inet6 dhcpv6-client client-ia-type ia-na set interfaces irb unit 10 family inet6 dhcpv6-client client-identifier duid-type duid-ll set interfaces irb unit 10 family inet6 dhcpv6-client retransmission-attempt 6 set interfaces irb unit 10 family inet6 dhcpv6-client update-server
#Send out router advertisement requests to your ISP
set protocols router-advertisement interface irb.10 managed-configuration set protocols router-advertisement interface irb.10 other-stateful-configuration
#I am being lazy and assigning IPv6 addresses using SLAAC on my Office network.
#Later on I will set up an IPv6 dhcp server
set protocols router-advertisement interface irb.0 max-advertisement-interval 10 set protocols router-advertisement interface irb.0 min-advertisement-interval 5 set protocols router-advertisement interface irb.0 managed-configuration set protocols router-advertisement interface irb.0 prefix fd00:80:1::/64
#I trust my own network
set security zones security-zone OFFICE1 interfaces irb.0 host-inbound-traffic system-services all set security zones security-zone OFFICE1 interfaces irb.0 host-inbound-traffic protocols all
# I dont trust my ISP – so I am limiting what is coming in
set security zones security-zone ISPOFFICE1 interfaces irb.10 host-inbound-traffic protocols router-discovery set security zones security-zone ISPOFFICE1 interfaces irb.10 host-inbound-traffic system-services dhcp set security zones security-zone ISPOFFICE1 interfaces irb.10 host-inbound-traffic system-services ssh set security zones security-zone ISPOFFICE1 interfaces irb.10 host-inbound-traffic system-services ping set security zones security-zone ISPOFFICE1 interfaces irb.10 host-inbound-traffic system-services dhcpv6
#we will need these later
set security zones security-zone ISPOFFICE1 interfaces irb.10 host-inbound-traffic system-services tcp-encap set security zones security-zone ISPOFFICE1 interfaces irb.10 host-inbound-traffic system-services ike
#I want traffic from my office network to get to the Intertubes
set security policies from-zone OFFICE1 to-zone ISPOFFICE1 policy OFFICE1-to-ISPOFFICE1 match source-address any set security policies from-zone OFFICE1 to-zone ISPOFFICE1 policy OFFICE1-to-ISPOFFICE1 match destination-address any set security policies from-zone OFFICE1 to-zone ISPOFFICE1 policy OFFICE1-to-ISPOFFICE1 match application any set security policies from-zone OFFICE1 to-zone ISPOFFICE1 policy OFFICE1-to-ISPOFFICE1 then permit
#and I want traffic to travel intra-network
set security policies from-zone OFFICE1 to-zone OFFICE1 policy OFFICE1-to-OFFICE1 match source-address any set security policies from-zone OFFICE1 to-zone OFFICE1 policy OFFICE1-to-OFFICE1 match destination-address any set security policies from-zone OFFICE1 to-zone OFFICE1 policy OFFICE1-to-OFFICE1 match application any set security policies from-zone OFFICE1 to-zone OFFICE1 policy OFFICE1-to-OFFICE1 then permit
# As we are using “private” ip addresses – we need to nat our traffic going to the Intertubes so we
# can get replies from the servers we connect to
set security nat source rule-set OFFICE1-to-ISPOFFICE1 from zone OFFICE1 set security nat source rule-set OFFICE1-to-ISPOFFICE1 to zone ISPOFFICE1 set security nat source rule-set OFFICE1-to-ISPOFFICE1 rule source-nat-rule match source-address 0.0.0.0/0 set security nat source rule-set OFFICE1-to-ISPOFFICE1 rule source-nat-rule match destination-address 0.0.0.0/0 set security nat source rule-set OFFICE1-to-ISPOFFICE1 rule source-nat-rule then source-nat interface set security nat source rule-set OFFICE1-to-ISPOFFICE1 rule source-nat-rule6 match source-address ::/0 set security nat source rule-set OFFICE1-to-ISPOFFICE1 rule source-nat-rule6 then source-nat interface
# now – as I set up my device to use irb instead of going directly to the ge interfaces, I need to finish setting
#vlans and assign the vlans to interfaces
set vlans ISPOFFICE1 vlan-id 10 set vlans ISPOFFICE1 l3-interface irb.10 set vlans OFFICE1 vlan-id 3 set vlans OFFICE1 l3-interface irb.0
set interfaces ge-0/0/0 description INTERNET set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members ISPOFFICE1 set interfaces ge-0/0/1 description OFFICE set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members OFFICE1 commit
now – lets give it a minute to get an ip address (goes off to get a cup off coffee)
Now lets test our IPv4
root@Office1# run ping inet count 3 google.com PING google.com (some.google.ip.address): 56 data bytes 64 bytes from some.google.ip.address: icmp_seq=0 ttl=103 time=21.017 ms 64 bytes from some.google.ip.address: icmp_seq=1 ttl=103 time=21.017 ms 64 bytes from some.google.ip.address: icmp_seq=2 ttl=103 time=20.929 ms --- google.com ping statistics --- 3 packets transmitted, 3 packets received, 0% packet loss round-trip min/avg/max/stddev = 20.929/20.988/21.017/0.041 ms
If the above does not work – dont bother testing IPv6 – pls go back and double check all settings and your cabling
Now lets test IPv6 – lets make sure we got an address
root@TESTIPv6Num2# run show interfaces irb.10 terse Interface Admin Link Proto Local Remote irb.10 up up inet 192.168.1.106/24 inet6 2600:aaaa:bbbb:cccc::ba6 fe80::428f:9d00:ad5:8431/64
Note the above has 2 ipv6 addresses – on that starts with 2600, and one that starts with fe80. If you only get an ip address that starts with fe80 – you either have a configuration issue and/or your isp is not providing IPv6
Now test to see if things are routing
root@Office1# run ping count 3 google.com PING6(56=40+8+8 bytes) your:ip:v6::address --> some:google:ipv6::address 16 bytes from some:google:ipv6::address, icmp_seq=0 hlim=103 time=34.216 ms 16 bytes from some:google:ipv6::address, icmp_seq=1 hlim=103 time=32.232 ms 16 bytes from some:google:ipv6::address, icmp_seq=2 hlim=103 time=25.501 ms --- google.com ping6 statistics --- 3 packets transmitted, 3 packets received, 0% packet loss round-trip min/avg/max/std-dev = 25.501/30.650/34.216/3.730 ms
If the above does not work – this could indicate a configuration issue on the srx -or – your isp has not fully implemented ipv6. Double check your configuration before you call your isp!!
