[solved] Restrict IPv6 access
Posted: Fri Dec 27, 2024 11:55 am
Hello,
What is the best way to restrict access to IPv6 clients to Mikrotik router and, obviously, Internet ?
Setup:
All LAN interfaces have ARP set to reply-only, IPv4 DHCP-Server has AddressPool set to static-only and IPV4 ARP list is populated with allowed mac addresses.
But a new, "rogue" device connected to the network get a valid IPv6 address (invalid/non-routable 169.x.y.z IPv4 address) and can access most of the Internet.
How can I prevent that, other that using IPv6 firewall MAC rules ? Not so many rules, but seems to be the slowest method.
Thank you!
What is the best way to restrict access to IPv6 clients to Mikrotik router and, obviously, Internet ?
Setup:
All LAN interfaces have ARP set to reply-only, IPv4 DHCP-Server has AddressPool set to static-only and IPV4 ARP list is populated with allowed mac addresses.
But a new, "rogue" device connected to the network get a valid IPv6 address (invalid/non-routable 169.x.y.z IPv4 address) and can access most of the Internet.
How can I prevent that, other that using IPv6 firewall MAC rules ? Not so many rules, but seems to be the slowest method.
Thank you!