refer, Linux 用作 IPv6 网关 http://bigeagle.me/2011/11/linux_as_ipv6_gateway/
https://www.berrange.com/posts/2011/06/16/providing-ipv6-connectivity-to-virtual-guests-with-libvirt-and-kvm/
https://etherpad.openstack.org/IPV6-Support
l3-agent don't support ipv6br-ex: 2001:2:3:45ff:ff:ff:ff:ff/128
in physical router:
ip-6 route add 2001:2:3:4500::/56 via 2001:2:3:4500::1
in l3-agent
ip -6 route add default 2001:2:3:4500::0/56 dev qg-interface ( for every tenant router)
ip -6 route add 2001:2:3:4501::/64 dev gw-tenant1
ip -6 route add 2001:2:3:4502::/64 dev gw-tenant2
ip -6 neigh add proxy 2001:2:3:4501:221:70ff:fec0:ef3f/64 dev gw-tenant1
ip -6 neigh add proxy 2001:2:3:4501::1 dev qg-interface
ip -6 neigh add proxy 2001:2:3:4502::1 dev qg-interface
--------- physical router 2001:2:3:4500::1/56 -------------
. ----------. 2001:2:3:4500::2/56 .---------------.
sixxs | br-ex (qg-interface)
|
*----------*
1) open ipv6 function and install radvd in the l3-agent node to allocate the ipv6 address for VM.
( dhcp-range=tag:br0,::1,::FFFF,constructor:br0, ra-names, 12h
enable-ra )
cat /etc/radvd.conf
interface gw-tenant1 {};
interface gw-tenant2 {
AdvSendAdvert on;
AdvManagedFlag off;
AdvOtherConfigFlag off; # tell client vm if use DHCPv6 to allocate ip.
Prefix 2001:2:3:4502::/64{ # broadcast ipv6 prefix.
AdvOnLink on;
AdvAutonomous on;
AdvRouterAddr off;
};
};
if useing DHCPv6 to allocate ip, dhcp6s only provide ip, not provide prefix, so it needs to collaborate with radvd:
cat /etc/dhcp6s.conf
interface br-lan {
address-pool pool1 86400;
};
pool pool1 {
range 2001:2:3:4500:aaaa::1 to 2001:2:3:4500:aaaa::ffff ;
}
注意:dnsmasq也是可以代替radvd的,如使用配置(http://www.thekelleys.org.uk/dnsmasq/docs/dnsmasq-man.html):
dnsmasq# is prepared for the hardware router in the front of br-ex
ip -6 neigh add proxy 2001:2:3:4501::1 dev br-ex
ip -6 neigh add proxy 2001:2:3:4502::1 dev br-ex
if no haredware router, we can continue to demo this env user radvd.
ifconfig eth0 promisc
how to test,
1) curl --verbose -6http://localhost
2) tcpdump -ni <interface> ip6
noteson openstack ipv6 support (untested)
1, ipv6 support is not activated in /etc/nova/nova.conf, --use_ipv6=True
2, fixed ip,
nova-manage network create--label=myown \
--vlan=2511 \
--fixed_range_v4=10.145.230.0/24\
--fixed_range_v6=2a01:4f8:161:5304::0/64 \
--gateway_v6=fe80::1 \
--num_networks=1
3, floating ip,
nova-manage floating create --pool=v6pool --ip_range=2a01:4f8:161:5304::10--interface=eth0
上面配置了默认路由后,内部网络就可以访问外部网络了,但外网无法得知内网的路由。由于没向ISP申请单独的IPv6块,这里不可能在外网上添加路由,但是:
1,内网与外网同属同一个子网,不可以配置路由向外网广播路由信息包,这样会造成路由混乱。但可以通过proxy_ndp让外网的ndp请求穿过网关。
2,内网与外网不属于同一个子网的话,可以配置路由向外网广播路由信息包,这样就不需要配置proxy_ndp了
注: 路由器是按最大字符长度匹配算法来匹配路由的, 所以前缀相同, 子网长度不同的子网算不同的网段. 所以对于不同子网, 加了路由之后, 下面的就不需要再加ndp_proxy了.
sysctl -w net.ipv6.conf.all.forwarding=1
ip -6 addr add 2001:2:3:4501:221:70ff:fec0:ef3f/64 dev tap1nova-managefloating create --pool=v6pool --ip_range=2a01:4f8:161:5304::10--interface=eth0
Reference
http://blog.sina.com.cn/s/blog_4afa958f0101cm5z.html