BUG: networkmanager not able to disable IPv6 on OpenVPN Tap interface

Bug #1769392 reported by Gijs Peskens
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
network-manager-openvpn (Ubuntu)
New
Undecided
Unassigned

Bug Description

The system is configured to connect to an OpenVPN server set-up with tap bridging.

On the remote server radvd is running on the bridged interface, in assisted set-up mode. radvd advertises a ULA prefix (assisted with DHCPv6) and a GUA prefix (slaac only)

The remote-server is set-up to push def1 gateway by default.

On the client 2 profiles are created; one with the intention of routing all traffic through the VPN, one with the intention of only accessing remote network sources.

For the secondary profile IPv4 address assignment is left on automatic, route on manual with a static route configured for 10.0.0.0/8 through 10.0.1.1, the checkbox 'use network only for resources on its network' is ticked.

For IPv6 every permutation of settings has been tried, none result in no IPv6 addresses and associated routes getting assigned.
Even setting the IPv6 address assignment to Disabled still results in RA addresses getting assigned.

Setting assignment to 'Disabled' /must/ remove the link local address on the tap interface, automatically failing any autoconf (RA autoconf depends on link local multicast)
Setting assignment to 'Link-Local only' /must/ leave the ll address intact, while disabling autoconf (perhaps via sysctl)

Ideally (low priority) an extra variant setting would be introduced that disallows GUA addressing to be assigned, but allows ULA addressing to be assigned.

ProblemType: Bug
DistroRelease: Ubuntu 17.10
Package: network-manager-openvpn-gnome 1.2.10-0ubuntu2
ProcVersionSignature: Ubuntu 4.13.0-39.44-generic 4.13.16
Uname: Linux 4.13.0-39-generic x86_64
ApportVersion: 2.20.7-0ubuntu3.8
Architecture: amd64
CurrentDesktop: ubuntu:GNOME
Date: Sat May 5 21:25:43 2018
EcryptfsInUse: Yes
InstallationDate: Installed on 2018-03-18 (47 days ago)
InstallationMedia: Ubuntu 17.10 "Artful Aardvark" - Release amd64 (20180105.1)
SourcePackage: network-manager-openvpn
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
Gijs Peskens (gijspeskens) wrote :
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.