Forum Discussion
Firmware Check Error
- Oct 10, 2021
All fixed up. There were two issues, double NAT configuration and a public IP address on the Netgear router. Bridge mode now enabled on the Viasat router, and Netgear router given private IP address and address pool.
Here's what I'm getting on tests.
IPv6 test: https://owncloud.teambelgium.net/index.php/s/3qQ4cBf0jwDvbDV
.63 firmware option: https://owncloud.teambelgium.net/index.php/s/SZU8EXD4hHOqlfW
Here's a guide for Windows to allow ICMPv6 (scroll to the middle): https://www.howtogeek.com/howto/windows-vista/allow-pings-icmp-echo-request-through-your-windows-vista-firewall/
————————————————
As per our router specification "An implementation MUST NOT send out the ICMPv6 echo reply on the router’s WAN interface if the “Respond to Ping on Internet Port” option is not enabled” for security reasons. So that means in order to allow this user must enable respond to ping on internet port. R7800 should have an option for IPv6 ping on the debug page. If you go to debug page you should see an option called “Allow external IPv6 hosts ping internal IPv6 hosts” and user need to enable this if he wants external IPv6 address to ping internal ones."
To access the debug page, just type this address on your browser 192.168.1.1/debug.htm or routerlogin.net/debug.htm and login using the router's credentials. Scroll down to the bottom and look for Allow external IPv6 hosts ping internal IPv6 hosts and enable it.
——————————————-
Should I try this or is this a security concern? Not sure what to make of this. Thanks
- microchip8Feb 01, 2020Master
it's not really a security issue as NG's firewall throttles ping replies after a certain amount. For IPv6, ICMPv6 is crucial for the correct working of IPv6. The following below must be passed
router-advertisement
router-solicitation
neighbour-advertisement
neighbour-solicitation
destination-unreachable
packet-too-big
time-exceeded
parameter-problem
unknown-header-type
- microchip8Feb 01, 2020Master
After reboot, the settings are set to defaults in the debug page. This is normal and you have to enable them after each reboot