« Back to all recent discussions

GS1200-8 IPv6 neighbor discovery multicast on VLAN not filtered properly?!

peter314peter314 Posts: 5  Junior Member
edited July 18 in Questions
Hello,
I observed this strange behavior on my GS1200-8 switch, that IPv6 neighbor discovery multicast packets are not filtered properly according to their VLAN-ID.
The attached picture shows the VLAN configuration. Port 1 and 2 are used for trunking to the router and another managed switch. All the other ports show the anomaly, that mentioned packets from VLAN 16 show up on the ports 3 to 8.
What is wrong here? Is that a bug or did I do anything wrong? Thanks in advance!



#Home_Switch_July
Tagged:

Best Answer

  • Zyxel_StevenZyxel_Steven Posts: 142  Zyxel Moderator
    Accepted Answer
    I have sent you the firmware link of GS1200-8 about this problem via private message.
    Please kindly check your message box. :)

Answers

  • HillHill Posts: 38  Junior Member
    Can you share the firmware version of GS1200-8 and your network topology?
    May I know the configuration purpose? What kind of application?
    If there are more information, it will help to check this problem.
  • peter314peter314 Posts: 5  Junior Member
    The firmware version is the most recent V1.00(ABME.0)C0.

    VLAN1 is the standard internal network, while VLAN16 is meant to be the guest network.

    The network topology looks like the following:

    cable-modem -- router/firewall (pfsense) -- [port 1] GS1200-8 [port 2] -- GS1200-5HPv1 -- WIFI/AP

    The problem showed up when devices directly connected to the GS1200-8 got IPv6 addresses from both VLANs. I can't see this effect on devices connected to the GS1200-5HPv1 or on the WIFI/AP (WPA2-Enterprise).
    The normal broadcast messages, DHCP, ARP, etc. seem to be filtered correctly. AFAICS the problem seems to be limited to ICMPv6 multicast messages.

  • WiasoudaWiasouda Posts: 41  Junior Member
    edited July 18
    Hi @peter314
    The original question you mentioned is port 3~8 received port 1/2's packet, do you want block/exclude port 3~8 to connect to port 1 and 2?

    The problem showed up when devices directly connected to the GS1200-8 got IPv6 addresses from both VLANs. I can't see this effect on devices connected to the GS1200-5HPv1 or on the WIFI/AP (WPA2-Enterprise).
    Check user manual and there is not the IPv6 client or feature in GS1200-8, so do you mean that ICMPv6 can't be transfer correct while through GS1200-8?

  • peter314peter314 Posts: 5  Junior Member
    The ports 1/2 are for trunking to the router and the next switch. As you can see in the screenshot the ports 3 to 8 are assigned to VLAN1 only. But there are ICMPv6 multicast packets from VLAN16 that get through to VLAN1 that should not.

    Some more observations: The problem occurs only if "IGMP Snooping" is enabled. If disabled the packets are filtered correctly. My guess is that this is a bug and not a feature :/

  • peter314peter314 Posts: 5  Junior Member
    Hi again! Are there any Zyxel employees here that may comment on this? Is this a bug? Will there be a fix? Thanks in advance!
  • Zyxel_StevenZyxel_Steven Posts: 142  Zyxel Moderator
    Thanks for the information. We're still checking this problem.
    If there are any update, we will let you know.
  • peter314peter314 Posts: 5  Junior Member
    Hi Steven, thanks for the quick response! I tested the firmware and the v6 multicast packets seem to be filtered correctly now. :) Will let you know if any issues pop up.
    Hope the official firmware can be released soon.
Sign In or Register to comment.