Netgear FVS336Gv2 – ProSafe Dual WAN Gigabit Firewall with SSL & IPSec VPN 참조 매뉴얼
Configure the IPv6 LAN Settings
153
ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2
Manage the IPv6 LAN
The following sections provide information about managing the IPv6 LAN:
•
•
•
•
•
•
IPv6 LANs
An IPv6 LAN typically functions with site-local and link-local unicast addresses. Each
physical interface requires an IPv6 link-local address that is automatically derived from the
MAC addresses of the IPv4 interface and that is used for address configuration and neighbor
discovery. (Normally, you would not manually configure a link-local address.)
MAC addresses of the IPv4 interface and that is used for address configuration and neighbor
discovery. (Normally, you would not manually configure a link-local address.)
The VPN firewall (or any other router) never forwards traffic with site-local or link-local
addresses, that is, the traffic remains in the LAN subnet and is processed over the default
VLAN only. A site-local address always starts with fec0 (hexadecimal); a link-local unicast
address always starts with FE80 (hexadecimal). For more information about link-local unicast
addresses, see
addresses, that is, the traffic remains in the LAN subnet and is processed over the default
VLAN only. A site-local address always starts with fec0 (hexadecimal); a link-local unicast
address always starts with FE80 (hexadecimal). For more information about link-local unicast
addresses, see
103.
Because each interface is automatically assigned a link-local IP address, it is not useful to
assign another link-local IP address as the default IPv6 LAN address. The default IPv6 LAN
address is a site-local address. You can change this address to any other IPv6 address for
LAN use.
assign another link-local IP address as the default IPv6 LAN address. The default IPv6 LAN
address is a site-local address. You can change this address to any other IPv6 address for
LAN use.
To forward traffic from sources with a site local or link-local unicast address in the LAN, you
must use a DHCPv6 server. (By default, the DHCPv6 server is disabled.) For information
about the DHCPv6 server options that the VPN firewall provides, see
must use a DHCPv6 server. (By default, the DHCPv6 server is disabled.) For information
about the DHCPv6 server options that the VPN firewall provides, see
153.
Note:
Site-local addresses, that is, addresses that start with fec0, are
depreciated. However, NETGEAR has implemented a site-local
address as a temporary default IPv6 LAN address that you can
replace with another LAN address. The firewall restricts external
communication of this default site-local address.
depreciated. However, NETGEAR has implemented a site-local
address as a temporary default IPv6 LAN address that you can
replace with another LAN address. The firewall restricts external
communication of this default site-local address.
DHCPv6 LAN Server Concepts and Configuration Roadmap
The IPv6 clients in the LAN can autoconfigure their own IPv6 address or obtain an IPv6
address through the VPN firewall’s DHCPv6 server.
address through the VPN firewall’s DHCPv6 server.