From f9f61e19ad0c55f3b1f8ed1f32cc907a2d152182 Mon Sep 17 00:00:00 2001 From: Jack O'Sullivan Date: Mon, 3 Aug 2026 14:15:40 +0100 Subject: [PATCH] docs/home: Document switches/AP must not route jim, dave and the vibe AP are pure L2, but RouterOS ships ip-forward and IPv6 forward on, and with IPv6 forwarding enabled it also advertises itself as a default router. After the 7.18 -> 7.23 upgrade clients began picking up the switches as IPv6 default routers alongside river. Replace the earlier advertise-dns framing (which only strips RA options, not the router lifetime) with the actual requirement: ip-forward=no, IPv6 forward=no, accept-router-advertisements=no, ra-lifetime=0, and a re-check after every RouterOS upgrade. Co-Authored-By: Claude Opus 4.8 --- docs/sites/home/aps.md | 6 ++++++ docs/sites/home/switches.md | 31 ++++++++++++++++++++++++++++++- 2 files changed, 36 insertions(+), 1 deletion(-) diff --git a/docs/sites/home/aps.md b/docs/sites/home/aps.md index 53f64b1..5a97530 100644 --- a/docs/sites/home/aps.md +++ b/docs/sites/home/aps.md @@ -77,6 +77,12 @@ Management uses host `.15`: `192.168.64.15` on native/core as a backup, route through its VIP; `untrusted` has no address. With `l2mtu 9214`, `vibe` can use the jumbo `hi` network unlike `wave`. +Like the switches, `vibe` is **pure L2 and must not route** — `ip-forward=no`, IPv6 `forward=no`, +`accept-router-advertisements=no`, `ra-lifetime=0`. RouterOS ships these forwarding-on and then +advertises itself as an IPv6 router; re-check after any upgrade. See +[switches.md#switches-must-not-route](switches.md#switches-must-not-route) for the rationale and +commands. + ## wave (Cudy AX3000, OpenWrt) Single-port AP, so the port is a VLAN **trunk** carrying management + both SSIDs. diff --git a/docs/sites/home/switches.md b/docs/sites/home/switches.md index 7b99810..7b12a97 100644 --- a/docs/sites/home/switches.md +++ b/docs/sites/home/switches.md @@ -86,7 +86,9 @@ from a box that does not depend on it, or power `castle` off cleanly first. Switch L3 presence (`/interface vlan` on `main`) exists **only** for VLANs the switch is managed from — `hi` (100) and `lo` (110), plus native core. WAN and guest VLANs deliberately have no switch -L3 interface. +L3 interface. jim and dave carry a static IPv4 and **global IPv6** address on `hi`/`lo` (plus a +static default route on each stack) purely for management — they are **pure L2, never routers**. See +[Switches must not route](#switches-must-not-route). ## The Digiweb WAN path (trunked VLAN 10 + PVID 140) @@ -147,6 +149,33 @@ this is plain tagged bridging. 10/140/141 rows. `wan-pon-in` (`sfp-sfpplus2`) sits at `pvid=1` as a spare port. jim only handles stream's VLAN-130 WAN and the LAN VLANs. +## Switches must not route + +jim and dave (and the `vibe` AP) are **pure L2** — river/stream do all routing. Their per-stack +management addresses and static default routes exist only so the boxes themselves can be reached and +reach out; they must **never** forward traffic or advertise themselves as routers. RouterOS defaults +work against this: `ip-forward` and IPv6 `forward` ship **on**, and with IPv6 forwarding on RouterOS +also emits Router Advertisements (`ra-lifetime=30m`) on every L3 interface — so a switch silently +becomes a competing IPv6 default router. This surfaced after the 7.18 → 7.23 upgrade, when clients +picked up dave/jim as default routers alongside river. + +The required config on each RouterOS box: +``` +/ip settings set ip-forward=no +/ipv6 settings set forward=no accept-router-advertisements=no +/ipv6 nd set [find] ra-lifetime=0 +``` +- `ip-forward=no` / `forward=no` — no L3 forwarding on either stack; IPv6 `forward=no` also stops RA + emission at the source. +- `accept-router-advertisements=no` — with forwarding off RouterOS would otherwise start *accepting* + RAs; this keeps the box on its deterministic **static** default route. +- `ra-lifetime=0` — belt-and-suspenders: even if forwarding is ever re-enabled the box advertises + router-lifetime 0 (i.e. "not a default router"). Setting it also emits a withdrawal RA that + actively clears the rogue default from clients (they otherwise cache it for up to ~30 min). + +**After any RouterOS upgrade, re-check `/ip settings` and `/ipv6 settings`** — an upgrade can reset +these to the forwarding-on defaults. brian (UniFi) is not a RouterOS box and was not affected. + ## Future: multiple ONTs (per-port VLAN translation) If a second ONT arrives (e.g. a Digiweb line for stream, or a second river), trunking breaks: both