Ok, I'm stuck at the basics, I do this:
echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
And it isn't forwarding traffic.
Traceroutes are working from the firewall, but I get no reply from my subnet hosts.
Traceroute from a host behind the firewall, as seen on sit1 on the firewall:
23:13:28.354957 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37549 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33437: UDP, length 40
23:13:28.355498 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37550 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33438: UDP, length 40
23:13:28.355707 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37551 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33439: UDP, length 40
23:13:28.355758 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37552 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33440: UDP, length 40
23:13:28.355788 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37554 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33441: UDP, length 40
23:13:28.355817 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37555 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33442: UDP, length 40
23:13:28.355845 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37556 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33443: UDP, length 40
23:13:28.355873 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37558 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33444: UDP, length 40
23:13:28.355902 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37559 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33445: UDP, length 40
23:13:28.355929 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37560 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33446: UDP, length 40
23:13:28.355957 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37561 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33447: UDP, length 40
23:13:28.355985 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37563 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33448: UDP, length 40
23:13:28.356013 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37564 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33449: UDP, length 40
23:13:28.358017 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37565 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33450: UDP, length 40
23:13:28.358157 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37566 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33451: UDP, length 40
23:13:28.358262 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37567 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33452: UDP, length 40
23:13:33.357315 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37568 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33453: UDP, length 40
23:13:33.357524 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37569 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33454: UDP, length 40
23:13:33.357595 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37570 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33455: UDP, length 40
23:13:33.357650 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37572 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33456: UDP, length 40
23:13:33.357695 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37574 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33457: UDP, length 40
23:13:33.357739 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37575 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33458: UDP, length 40
23:13:33.357783 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37576 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33459: UDP, length 40
23:13:33.357826 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37577 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33460: UDP, length 40
23:13:33.357870 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37578 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33461: UDP, length 40
23:13:33.357914 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37579 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33462: UDP, length 40
23:13:33.357957 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37580 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33463: UDP, length 40
23:13:33.358002 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37581 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33464: UDP, length 40
23:13:33.358048 IP6 2001:470:1f09:13b:210:a7ff:fe08:5db6.37582 > 2001:740:c000:0:2d0:b7ff:fe74:2a8b.33465: UDP, length 40
(Start of a) Traceroute from the firewall itself (using sit1 as source IP)
23:12:45.060352 IP6 2001:470:1f08:13b::2.33022 > 2001:200:0:8002:203:47ff:fea5:3085.traceroute: UDP, length 40
23:12:45.061760 IP6 2001:470:1f08:13b::2.33023 > 2001:200:0:8002:203:47ff:fea5:3085.33435: UDP, length 40
23:12:45.062699 IP6 2001:470:1f08:13b::2.33024 > 2001:200:0:8002:203:47ff:fea5:3085.33436: UDP, length 40
23:12:45.063470 IP6 2001:470:1f08:13b::2.33025 > 2001:200:0:8002:203:47ff:fea5:3085.33437: UDP, length 40
23:12:45.064215 IP6 2001:470:1f08:13b::2.33026 > 2001:200:0:8002:203:47ff:fea5:3085.33438: UDP, length 40
23:12:45.065137 IP6 2001:470:1f08:13b::2.33027 > 2001:200:0:8002:203:47ff:fea5:3085.33439: UDP, length 40
23:12:45.065851 IP6 2001:470:1f08:13b::2.33028 > 2001:200:0:8002:203:47ff:fea5:3085.33440: UDP, length 40
23:12:45.067187 IP6 2001:470:1f08:13b::2.33029 > 2001:200:0:8002:203:47ff:fea5:3085.33441: UDP, length 40
23:12:45.067876 IP6 2001:470:1f08:13b::2.33030 > 2001:200:0:8002:203:47ff:fea5:3085.33442: UDP, length 40
23:12:45.068681 IP6 2001:470:1f08:13b::2.33031 > 2001:200:0:8002:203:47ff:fea5:3085.33443: UDP, length 40
23:12:45.069415 IP6 2001:470:1f08:13b::2.33032 > 2001:200:0:8002:203:47ff:fea5:3085.33444: UDP, length 40
23:12:45.070166 IP6 2001:470:1f08:13b::2.33033 > 2001:200:0:8002:203:47ff:fea5:3085.33445: UDP, length 40
23:12:45.071440 IP6 2001:470:1f08:13b::2.33034 > 2001:200:0:8002:203:47ff:fea5:3085.33446: UDP, length 40
23:12:45.072152 IP6 2001:470:1f08:13b::2.33035 > 2001:200:0:8002:203:47ff:fea5:3085.33447: UDP, length 40
23:12:45.073007 IP6 2001:470:1f08:13b::2.33036 > 2001:200:0:8002:203:47ff:fea5:3085.33448: UDP, length 40
23:12:45.073704 IP6 2001:470:1f08:13b::2.33037 > 2001:200:0:8002:203:47ff:fea5:3085.33449: UDP, length 40
23:12:45.088658 IP6 2001:470:1f08:13b::1 > 2001:470:1f08:13b::2: ICMP6, time exceeded in-transit for 2001:200:0:8002:203:47ff:fea5:3085, length 96
23:12:45.094122 IP6 2001:470:1f08:13b::2.33038 > 2001:200:0:8002:203:47ff:fea5:3085.33450: UDP, length 40
23:12:45.096691 IP6 2001:470:1f08:13b::1 > 2001:470:1f08:13b::2: ICMP6, time exceeded in-transit for 2001:200:0:8002:203:47ff:fea5:3085, length 96
23:12:45.096699 IP6 2001:470:1f08:13b::1 > 2001:470:1f08:13b::2: ICMP6, time exceeded in-transit for 2001:200:0:8002:203:47ff:fea5:3085, length 96
23:12:45.096706 IP6 2001:470:0:67::1 > 2001:470:1f08:13b::2: ICMP6, time exceeded in-transit for 2001:200:0:8002:203:47ff:fea5:3085, length 96
23:12:45.102252 IP6 2001:470:1f08:13b::2.33039 > 2001:200:0:8002:203:47ff:fea5:3085.33451: UDP, length 40
23:12:45.103229 IP6 2001:470:1f08:13b::2.33040 > 2001:200:0:8002:203:47ff:fea5:3085.33452: UDP, length 40
23:12:45.103935 IP6 2001:470:1f08:13b::2.33041 > 2001:200:0:8002:203:47ff:fea5:3085.33453: UDP, length 40
23:12:45.104692 IP6 2001:470:0:67::1 > 2001:470:1f08:13b::2: ICMP6, time exceeded in-transit for 2001:200:0:8002:203:47ff:fea5:3085, length 96
23:12:45.104700 IP6 2001:470:0:67::1 > 2001:470:1f08:13b::2: ICMP6, time exceeded in-transit for 2001:200:0:8002:203:47ff:fea5:3085, length 96
23:12:45.108004 IP6 2001:470:1f08:13b::2.33042 > 2001:200:0:8002:203:47ff:fea5:3085.33454: UDP, length 40
23:12:45.108858 IP6 2001:470:1f08:13b::2.33043 > 2001:200:0:8002:203:47ff:fea5:3085.33455: UDP, length 40
I never get a reply for traffic for my subnet....any ideas ?