Debian/Mint/Raspbian/Ubuntu下如何强制启用SLAAC EUI64 IPv6自动配置?
Got it, let's walk through exactly how to set this up so you get predictable EUI64-based IPv6 addresses across your network, bypassing Linux's default privacy extensions. We'll cover both the Debian router's radvd configuration and client-side tweaks to force EUI64 addressing.
Step 1: Configure radvd on your Debian router
First, make sure your router has the correct static IPv6 address assigned. Let's assume your allocated /62 prefix is 2001:db8:1234::/62—we'll carve out 2001:db8:1234:0::/64 as the subnet to advertise. Assign the router the address 2001:db8:1234:0::1/64 on your LAN interface (replace eth0 with your actual interface, like enp0s3 or br0).
Next, edit your radvd configuration file at /etc/radvd.conf with these settings:
interface eth0 { AdvSendAdvert on; prefix 2001:db8:1234:0::/64 { AdvOnLink on; AdvAutonomous on; # Allows clients to auto-configure addresses from the prefix AdvRouterAddr on; # Includes the router's address in advertisements }; };
Save the file, then restart the radvd service to apply changes:
sudo systemctl restart radvd
Double-check that radvd is running without errors with sudo systemctl status radvd.
Step 2: Force Linux clients to use EUI64 addressing
By default, most modern Linux distros use privacy extensions to generate random IPv6 suffixes. We need to disable this and enforce EUI64 matching the link-local fe80:: address suffix.
For systemd-networkd users
Edit the network configuration file for your LAN interface (e.g., /etc/systemd/network/00-lan.network) and add these lines under the [Network] section:
[Network] IPv6AcceptRA=yes IPv6PrivacyExtensions=no IPv6AddressGenMode=eui64
Restart the service to apply:
sudo systemctl restart systemd-networkd
For NetworkManager users
You can use the nmcli command to modify your active connection:
# Replace "LAN Connection" with your actual connection name sudo nmcli connection modify "LAN Connection" ipv6.addr-gen-mode eui64 ipv6.privacy no sudo nmcli connection up "LAN Connection"
Alternatively, edit the connection file directly (found in /etc/NetworkManager/system-connections/) and update the [ipv6] section:
[ipv6] addr-gen-mode=eui64 ipv6.privacy=0
Then restart NetworkManager:
sudo systemctl restart NetworkManager
For traditional ifupdown (Debian oldstable) users
Edit /etc/network/interfaces and add privext 0 to your IPv6 interface config:
iface eth0 inet6 auto privext 0
Restart the interface to apply changes:
sudo ifdown eth0 && sudo ifup eth0
Step 3: Verify the setup
On a client machine, run this command to check your IPv6 addresses:
ip -6 addr show eth0
You should see a global IPv6 address (starting with your /64 prefix) that shares the same suffix as your link-local fe80:: address. For example:
inet6 2001:db8:1234:0::aabb:ccff:ddee:1122/64 scope global dynamic mngtmpaddr noprefixroute
inet6 fe80::aabb:ccff:ddee:1122/64 scope link
If the suffixes match, you're good to go—your clients will now use predictable EUI64 addresses perfect for services like sshd.
内容的提问来源于stack exchange,提问作者Jim MacKenzie

