Re: IPv6 VIPs and deprecated flag

"Ryan O'Hara" <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <[email protected]>
On Sun, Jun 19, 2016 at 07:09:46PM +0200, Tore Anderson wrote:
> * Ryan O'Hara
> 
> > Can anyone explain why the depracated flag is only set if the IPv6
> > address has a prefix of 128? Thanks in advance.
> 
> I believe the reasoning is that if the VIP is a /128 it is most likely a 
> secondary address and that the operator would like for the primary (permanent) 
> address to be the source of outgoing packets from the router.

Right. I completely understand the reason for the deprecated flag,
just not why it is only used when the prefix is /128. That said, I
think it would be better is the VIP was set to deprecated by an
explicit flag in the configuration. Anyway ...

> On the other hand if the VIP is a /64 it is most likely the only address in 
> the prefix (i.e., backup routers do not have global addresses configured at 
> all) and thus the above consideration does not apply.

That is interesting. Thanks for the information.

On a related note, has anyone tried this with SLAAC? I've been
investigating some strange behavior with IPv6 SLAAC where keepalived
will initially bring up a VIP with /128 prefix and correctly set the
deprecated flag, but after a few minutes I see the keepalived netlink
reflector report the global IPv6 address and VIP are "added" (which
seems to correspond to the lifetime being refreshed). As this point
the IPv6 VIP loses the deprecated flag and the load balancer ceases to
work. Thoughts?

Ryan


------------------------------------------------------------------------------
Attend Shape: An AT&T Tech Expo July 15-16. Meet us at AT&T Park in San
Francisco, CA to explore cutting-edge tech and listen to tech luminaries
present their vision of the future. This family event has something for
everyone, including kids. Get more information and register today.
http://sdm.link/attshape
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.