Wireless Access

last person joined: 12 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

This thread has been viewed 14 times
  • 1.  Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    Posted May 17, 2020 01:40 PM
      |   view attached

    Hi Airheads,

     

    I have a running deployment with 7240xm (Standalone) with ArubaOS 8.5.0.8 installed , recently i looked over the user-table via CLI and notice a lot of records of IPv6 client.

    Screenshot:

    2020-05-17_20-15-59.jpg

    In the running-cfg i triple check , there is no ipv6 enabled in anyway or interface, i even just to be sure ran the command no ipv6 enable...but yet..client with ipv6 address are poping at the user-table.

     

    Please advise. (Any fix? anyone also bumped into it?)

     

     

     



  • 2.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!



  • 3.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    Posted May 18, 2020 01:23 AM

    Hi ,

    Thanks for the response,As i wrote in my post.

     

    no ipv6 enable .... i triple did it (even due there isnt any ipv6 enabled in the running-cfg

     

    regarding the no ipv6 firewall. ... (even due that in the GUI there isnt any V marked on the firewall ipv6 section , i notice the ipv6 firewall command at the running-cfg) BUT there isnt no command for ipv6 firewall,screenshot attached

    2020-05-18_8-14-42.jpg

    is this the cause? why it's running ?! i didn't checked ON ipv6 in stage of the deployment: 

    2020-05-18_8-22-26.jpg

    Please advise.

     

     

     



  • 4.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    EMPLOYEE
    Posted May 18, 2020 06:13 AM

    I apologize.  Wrong command.

     

    What is the output of "show ipv6 global" on the controller?



  • 5.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    Posted May 18, 2020 06:59 AM

    Disabled.

    disabled.jpg



  • 6.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    EMPLOYEE
    Posted May 18, 2020 08:10 AM

    Did you try a "aaa user delete" to see if those users return when deleted?



  • 7.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    Posted May 18, 2020 08:42 AM

    0del.jpg

    0 users deleted - even due it's on on the user-table (every day)



  • 8.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    Posted May 18, 2020 08:44 AM

    Also....

    ( I tried name & IP ) even due it's not an IPv4 address at all.

    notipv4.jpg



  • 9.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    EMPLOYEE
    Posted May 18, 2020 08:54 AM

    try aaa user delete all.

     

    If that doesn't work, it is time to open a support case.



  • 10.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    Posted May 18, 2020 08:57 AM

    OK.
    the IPv6 records are poping on daily base , even after full controller reboot.

    So i think i will go with that to TAC.

    Thanks for all the syntax debug with me


  • 11.  RE: Arubaos 8.5.0.8 - IPv6 disable , but still active clients showed with IPv6 in user-table?!

    EMPLOYEE
    Posted May 18, 2020 10:17 AM

    The fe80:: IPv6 addresses are link-local IPs and many clients these days automatically get those, which doesn't mean you should see them in the user table. The default 'validuser' acl even blocks these out for appearing in the user table. Did you modify the validuser acl?

    ip access-list session validuser
        network 127.0.0.0 255.0.0.0 any any deny
        network 169.254.0.0 255.255.0.0 any any deny
        network 224.0.0.0 240.0.0.0 any any deny
        host 255.255.255.255 any any deny
        network 240.0.0.0 240.0.0.0 any any deny
        any any any permit
        ipv6 host fe80:: any any deny
        ipv6 network fc00::/7 any any permit
        ipv6 network fe80::/64 any any permit
        ipv6 alias ipv6-reserved-range any any deny
        ipv6 any any any permit
    !

    I agree that if IPv6 is disabled that I would not expect to see IPv6 user entries. Please open a support case if you see those.