IPv6 Day-0 Onboarding with DHCPv6 Prefix Delegation

Feature history: IPv6 day-0 onboarding with DHCPv6 prefix delegation

IPv6 day-0 onboarding with DHCPv6 prefix delegation

Feature name

Release information

Description

IPv6 day-0 onboarding with DHCPv6 prefix delegation

Cisco IOS XE Catalyst SD-WAN Release 26.2.1

Adds DHCPv6-PD as an IPv6 address-discovery option in the ZTP/PnP workflow for Cisco IOS XE Catalyst SD-WAN devices. ZTP runs IPv4 and IPv6 address discovery in parallel, and IPv6 discovery can use stateful DHCPv6, SLAAC, or DHCPv6-PD.

About IPv6 day-0 onboarding with DHCPv6 prefix delegation

Zero-touch provisioning (ZTP) automates day-0 onboarding by discovering network connectivity and obtaining the information that new Cisco IOS XE Catalyst SD-WAN devices need to join the Cisco Catalyst SD-WAN fabric.

Starting with Cisco IOS XE Catalyst SD-WAN Release 26.2.1, ZTP supports DHCPv6 prefix delegation (DHCPv6-PD) in the PnP workflow. This addition supports provider networks that delegate an IPv6 prefix instead of assigning a complete IPv6 address. The device uses the delegated prefix to create a global unicast IPv6 address for its WAN interface.

Furthermore, during ZTP, if a device obtains an IPv4 address first and the Cisco Catalyst SD-WAN Validator FQDN resolves only to IPv6 or to both IPv4 and IPv6, the PnP Agent instructs ZTP to restart IPv6 discovery.

IPv6 discovery stops when any of the following conditions is met:

  • the device successfully obtains an IPv6 address

  • the device establishes a control connection to the Cisco Catalyst SD-WAN Validator over IPv4, or

  • the user exits day-0 mode.

The IPv6 day-0 onboarding with DHCPv6 prefix delegation feature runs automatically during day-0 onboarding and does not require configuration through Cisco SD-WAN Manager or CLI commands. It supports devices in both autonomous and controller modes.

Benefits

  • Enables Cisco IOS XE Catalyst SD-WAN devices to onboard through a provider that delegates an IPv6 prefix instead of assigning a complete IPv6 address.

  • Restarts IPv6 discovery when Cisco IOS XE Catalyst SD-WAN devices obtain IPv4 first but the Cisco Catalyst SD-WAN requires IPv6 connectivity.

How IPv6 day-0 onboarding with DHCPv6 prefix delegation works

Summary

During day-0 onboarding, ZTP uses the transport-side WAN interface, a DHCP server, Cisco PnP Connect or a local ZTP server, and the Cisco Catalyst SD-WAN control components to discover connectivity and onboard the device.

Workflow

  1. At startup, ZTP uses the transport-side WAN interface to acquire address and DNS information.
  2. ZTP runs IPv4 and IPv6 address discovery in parallel. IPv6 discovery can use stateful DHCPv6, SLAAC, or DHCPv6-PD.
  3. If a DHCPv6-PD server delegates a prefix, the device uses the prefix to create a global IPv6 address for the WAN interface and reach the upstream router.
  4. The device contacts Cisco PnP Connect or, if PnP Connect is unreachable, a local ZTP server. The device authenticates using its serial number (SN), product identifier (PID), and Secure Unique Device Identifier (SUDI). The device must already be registered and associated with a controller profile. For more information, see Plug and Play onboarding workflow.
  5. After successful authentication, Cisco PnP Connect or the local ZTP server sends an HTTPS/XML payload that contains the Cisco Catalyst SD-WAN Validator IP address or FQDN, the organization name, and the intended device mode.
  6. If Cisco PnP Connect or the local ZTP server supplies a Validator FQDN, the PnP Agent resolves it. An A record identifies an IPv4 address, and an AAAA record identifies an IPv6 address. For more information, see Configure Host Entry for SD-WAN vBond Controller.
  7. If the WAN interface has only IPv4 and the Validator connection requires IPv6, the PnP Agent tells ZTP to restart IPv6 discovery.
  8. If the WAN interface has IPv6 but the Validator connection requires IPv4, treat the environment as misconfigured. Disable the IPv6 DHCP server or manually restart the ZTP/PnP process by rebooting the device.
  9. If the current device mode matches the intended mode, the PnP Agent records success, writes the required configuration, and creates a startup configuration to prevent future PnP triggers.
  10. If the current and intended modes differ, the PnP Agent changes the mode and reloads the device. After the reload, the device repeats PnP discovery in the intended mode.

Prerequisites for IPv6 day-0 onboarding with DHCPv6 prefix delegation

  • Use Cisco IOS XE Catalyst SD-WAN devices running Cisco IOS XE Catalyst SD-WAN Release 26.2.1 or later.

  • Register each device in Cisco PnP Connect and associate it with a controller profile.

  • Provide DHCP and DNS connectivity on the transport-side WAN interface. Provide internet access to Cisco PnP Connect or connectivity to a local ZTP server when Cisco PnP Connect is unreachable.

Restrictions for IPv6 day-0 onboarding with DHCPv6 prefix delegation

  • If the WAN interface obtains IPv6 but the Cisco Catalyst SD-WAN Validator connection requires IPv4, treat the environment as misconfigured.

  • To recover from the IPv6-to-IPv4 mismatch, disable the IPv6 DHCP server or manually restart the ZTP/PnP process by rebooting the device.

Configure IPv6 day-0 onboarding with DHCPv6 prefix delegation

Objective

The feature runs automatically as part of ZTP. It does not require a Cisco SD-WAN Manager setting or a device CLI command to enable DHCPv6-PD discovery.

Post-ZTP running configuration

After power-on, the running configuration reflects the address method used during onboarding. The following source-provided examples use representative interface names and masked client identifiers.

IPv4 DHCP

interface GigabitEthernet0/0/0
 ip address dhcp

Stateful DHCPv6

interface GigabitEthernet0/0/5
 ip dhcp client client-id ascii <masked-client-id>
 ip address dhcp
 ip proxy-arp
 negotiation auto
 ipv6 dhcp client request vendor
 ipv6 address dhcp
 ipv6 address autoconfig
 ipv6 enable

Stateless address autoconfiguration (SLAAC)

interface Vlan1
 no ip address
 ip proxy-arp
 ipv6 dhcp client request vendor
 ipv6 address autoconfig
 ipv6 enable
 ipv6 nd autoconfig default-route

DHCPv6 prefix delegation

interface Vlan1
 ip dhcp client client-id ascii <masked-client-id>
 ip address dhcp
 ip proxy-arp
 ipv6 dhcp client request vendor
 ipv6 dhcp client pd ZTP-PD-PREFIX-Vlan1
 ipv6 address dhcp
 ipv6 address autoconfig
 ipv6 enable

Expected result

ZTP obtains an IPv4 address, an IPv6 address, or both. The device contacts Cisco PnP Connect or a local ZTP server, receives the onboarding information, and establishes a control connection to the Cisco Catalyst SD-WAN Validator. If the device obtains IPv4 first and the Validator requires IPv6, ZTP restarts IPv6 discovery.

What to do next

Verify the address assignment, PnP discovery, generated interface configuration, and Cisco Catalyst SD-WAN control connections.

Verify IPv6 day-0 onboarding with DHCPv6 prefix delegation

Procedure

Follow these steps to verify IPv6 day-0 onboarding with DHCPv6 prefix delegation.

Procedure


Step 1

Start or reload the Cisco IOS XE Catalyst SD-WAN devices without a site-specific startup configuration.

Step 2

Confirm that the WAN interface obtains an address through IPv4 DHCP, stateful DHCPv6, SLAAC, or DHCPv6-PD.

Step 3

Confirm that the devices authenticate with Cisco PnP Connect or a local ZTP server and receive the expected organization name, device mode, and Cisco Catalyst SD-WAN Validator IP address or FQDN.

Step 4

If the device obtains IPv4 first and the Validator FQDN returns an AAAA record or both A and AAAA records, confirm that the PnP Agent restarts IPv6 discovery.

Step 5

Confirm that a device-mode mismatch, other than the IPv6-to-IPv4 address-family mismatch, causes the device to change mode, reload, and repeat PnP discovery.

Step 6

Confirm that the device establishes the Cisco Catalyst SD-WAN control connection through the intended address family.

CLI verification

Use the following command to review PnP AutoInstall status and DHCPv6-PD trace information:

Router# show pnp auto-install-tech-support
---------- show pnp auto-install tech-support ---------
IPv4 Status         : Resolving IP address
DHCP Server         : 0.0.0.0
TFTP Server         : 0.0.0.0
Network Config File :
Device Config File  :
Device Image File   :
IPv6 Status         : Failed
IPv6 Device Config File  :
AutoIP Status        : FAIL
No Auto IP data
[01/26/26 08:20:14.521 UTC 1 356] IPv6 RA other-config-flag notify for Gi0 flg 0
[01/26/26 08:20:19.084 UTC 2 440] autoinstall: start-up config empty
<snip>
[01/26/26 08:21:10.101 UTC 3C 440] IPv6 autoinstall: Mechanism #2 - autoinstall: Start Stateless (SLAAC) for Gi0/0/0, cnt=5
[01/26/26 08:21:10.101 UTC 3D 440] IPv6 autoinstall: Mechanism #2 - autoinstall: Start Stateless (SLAAC) for Gi0/0/5, cnt=5
[01/26/26 08:21:10.101 UTC 3E 440] IPv6 autoinstall: PD prefix received on Gi0/0/5 - SUCCESS!
[01/26/26 08:21:10.101 UTC 3F 440] Acquired DHCPV6 IP on Interface:GigabitEthernet0/0/5
[01/26/26 08:21:10.101 UTC 40 440] Received following DHCP options:
[01/26/26 08:21:10.101 UTC 41 440]         vendorv6         :
[01/26/26 08:21:10.101 UTC 42 440]         server-namev6    : 2001:4860:4860::8888
[01/26/26 08:21:10.101 UTC 43 440]         domain-namev6    : pd2.cisco.com
[01/26/26 08:21:10.101 UTC 44 440]         bootfilev6       :
[01/26/26 08:21:10.101 UTC 45 440] autoinstall: IPv6 PD address generated, cnt=5
[01/26/26 08:21:10.101 UTC 46 440] Resolved IPv6 address via DHCPv6-PD for Gi0/0/5

Result

Successful verification confirms that the devices obtain the required WAN address, complete PnP discovery and mode validation, and establish the Cisco Catalyst SD-WAN control connection.