IPv6 on the EdgeRouter Lite

Bradley Heilbrun
Nov 15, 2015 · 4 min read


Below are the commands and my thoughts on setting up IPv6 on a Ubiquiti Networks EdgeRouter Lite (ERLite-3). Were one to follow this as a guide, the results should be functioning IPv6 on the WAN and LAN side.

Note: As of EdgeMax v1.9.0, most IPv6 functionality is not available via the GUI. But, there is a new wizard as of this release which may work for the most basic case.

EdgeMax software version: 1.9.0 (works for 1.7.0 and above)
LAN: eth0
WAN: eth1
ISP: WebPass.net

Detailed Steps


First, it’s important that we setup the firewall as the default policy is “accept” and your LAN clients will have routable IPs. That’s bad. Unlike IPv4, there will be no NAT’ing.

Compared to our IPv4 firewall rules, there is one important difference: we need to permit ICMPv6 and DHCP in order for DHCPv6-PD to function.

Create a policy for WAN->LAN Clients:

Now create a policy for WAN->Router (aka local):

Now attach the policies to your WAN interface:

Again, it’s important to note that we had to explicitly allow ICMP and DHCPv6.

DHCPv6 Prefix Delegation

Now we’ll request IPv6 addresses from our ISP.

You may need to manually discover the prefix length that your ISP provides. The two most common lengths appear to /56 and /64 (WebPass uses the latter).

Note: We’ll be using SLAAC (Stateless Address Autoconfiguration) instead of stateful DHCP (which is how IPv4 DHCP works).

eth0 and eth1 are both referenced above, be sure to note the correct interface. In short, we’re telling eth1 (WAN) to provide prefix-delegation to eth0 (LAN).

If you are also using eth2 for a second LAN port, you’ll need to use the prefix-id :1 for that interface.

If you are running an EdgeMax OS version released since February 2016 (v1.8.0), you can skip down to Committing the Changes. If not, keeping reading.

Router Advertisement — pre v1.8.0

Note: This section should only be necessary if you’re running an EdgeMax version older than v1.8.0.

It will also work with newer versions but is unnecessary.

If you run commit at this point, you will receive an error like this,

The EdgeMax software is trying to start the radvd daemon because we setup dhcpv6-pd, but it failed to find a configuration file. I consider this a bug and hope the authors resolve this in future versions, as it’s entirely opaque to the casual hacker. (Update: they have!)

The solution is adding a router-advert section to your LAN interface, like so:

In the background, the EdgeMax software will write a valid radvd.conf, which will resolve the problem mentioned above.

Committing the Changes

You’re done!

Verification and Testing

If you exit the config CLI, you should be able to see IPv4 and IPv6 addresses on your LAN and WAN interfaces,

Test from your router and your LAN clients,

Don’t forget to save your config!


I found that the EdgeMax forums to be a bit unhelpful for this case because comments would often lack sufficient detail or a complete solution. Information was of course scattered across threads, dates, versions, etc. But, there is an active community and plenty of configuration examples, so it’s definitely worth checking out. https://community.ubnt.com/t5/EdgeMAX/bd-p/EdgeMAX

A similar guide that I found helpful: https://techsmix.net/ubiquti-edgemax-lite/ . Note however that it does not contain any firewall rules!


2016/Oct/31: EdgeMax v1.9.0 tested. Updated recommendation about router-advert.

2016/Jun/6: Fix applied to example firewall commands. Reported by Joe Hettiarachchy, thanks!

2016/Mar/1: EdgeMax v1.8.0 tested. No changes, just noted to work.

Welcome to a place where words matter. On Medium, smart voices and original ideas take center stage - with no ads in sight. Watch

Follow all the topics you care about, and we’ll deliver the best stories for you to your homepage and inbox. Explore

Get unlimited access to the best stories on Medium — and support writers while you’re at it. Just $5/month. Upgrade

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store