skip to content

How is an IPv6 solicited-node multicast address derived from a unicast address, and why does such a group usually reach just one node?

level: middleimportance: should knowfreq 34%

answer

  1. a fixed prefix plus a tail
  2. the end of the interface identifier
  3. low-order 24 bits
  4. ff02::1:ff00:0/104

basics

~10 s

Append the low-order 24 bits of the unicast or anycast address to ff02::1:ff00:0/104. Those bits come from the interface identifier, so normally only the node holding that address has joined the group.

solid answer

~40 s

RFC 4291 builds a **solicited-node** address by taking the low-order 24 bits of a unicast or anycast address and appending them to `ff02::1:ff00:0/104`: `2001:db8:0:7:4c1d:8e02:9f6a:31b7` gives `ff02::1:ff6a:31b7`. Every node must join the group for each address it holds, announcing it with MLD. The 24 bits come from the interface identifier and rarely collide on one link, so the group normally contains just the owner, and when Neighbor Discovery resolves an address it reaches one node instead of interrupting every host the way an ARP broadcast does. Addresses that differ only in their high-order bits, such as a link-local and a global address sharing one interface identifier, map to the same group, which keeps the number of joins small. On Ethernet the frame goes to `33:33:ff:6a:31:b7`, so other cards drop it in hardware.

code

pseudocode · 13 lines
pseudocode
function solicitedNode(addr):            # addr: 16 octets, index 0..15
    group = parse("ff02::1:ff00:0")      # ff02:0:0:0:0:1:ff00:0000
    group[13] = addr[13]                 # low-order 24 bits are
    group[14] = addr[14]                 # the last three octets
    group[15] = addr[15]
    return group

function ethernetMulticast(group):       # RFC 2464, section 7
    return [0x33, 0x33, group[12], group[13], group[14], group[15]]

# 2001:db8:0:7:4c1d:8e02:9f6a:31b7
#   -> ff02::1:ff6a:31b7
#   -> 33:33:ff:6a:31:b7

go deeper

for a junior

Recall that IPv6 resolves neighbours through a multicast group built from the address rather than through broadcast, and that these groups start with ff02::1:ff.

for a middle

Derive the group by hand from the low 24 bits, map it to its 33:33 Ethernet address, and explain why addresses sharing an interface identifier share one group.

for a senior

Explain what happens when 24-bit tails collide or a switch does not snoop MLD, and why a node must keep a group while another of its addresses still maps to it.

for a principal

Judge the design trade: one group per identifier tail rather than per address keeps joins and snooping state small, at the price of rare, harmless collisions.

## Building the address A **solicited-node multicast address** is defined in RFC 4291 (section 2.7.1) as the prefix `ff02:0:0:0:0:1:ff00::/104` followed by the **low-order 24 bits** of a unicast or anycast address. Step by step, for `2001:db8:0:7:4c1d:8e02:9f6a:31b7`: 1. Write the address in full: `2001:0db8:0000:0007:4c1d:8e02:9f6a:31b7`. 2. Take the last 24 bits, which are the last three octets: `6a`, `31`, `b7`. 3. Append them to the 104-bit prefix: `ff02:0:0:0:0:1:ff6a:31b7`. 4. Compress it: `ff02::1:ff6a:31b7`. The result always lies between `ff02::1:ff00:0` and `ff02::1:ffff:ffff`. | Address held by the node | Low 24 bits | Solicited-node group | |---|---|---| | `2001:db8:0:7:4c1d:8e02:9f6a:31b7` | `6a31b7` | `ff02::1:ff6a:31b7` | | `fe80::4c1d:8e02:9f6a:31b7` | `6a31b7` | `ff02::1:ff6a:31b7` (the same group) | | `2001:db8::12:3456:789a` | `56789a` | `ff02::1:ff56:789a` | | `2001:db8:0:7::` (Subnet-Router anycast) | `000000` | `ff02::1:ff00:0` | ## Why the group is usually one node - The low 24 bits come from the **interface identifier**, the part that tells hosts on a link apart. Two hosts on one link share them only by coincidence: 24 bits allow 16,777,216 values. - The group has **link-local scope** (`ff02`), so routers never forward it; it means "on this link only". - A collision is harmless. Both nodes join the same group, each receives solicitations meant for the other, and each ignores any whose target address it does not hold. The cost is a little wasted processing. - Addresses that differ only in their high-order bits, such as a link-local and a global address built on the same interface identifier, map to the **same** group. RFC 4291 calls this out as deliberate: it reduces the number of groups a node must join. - Compare the alternative of sending every lookup to all-nodes `ff02::1`: every IPv6 node on the link would have to process every solicitation, which is IPv4's broadcast cost under a new name. A group per 24-bit tail keeps that cost on the one node that holds the address, plus the occasional node whose tail collides. ## Which groups a node joins RFC 4291 requires a node to compute and join the solicited-node group for **every unicast and anycast address** configured on its interfaces, manually or automatically. RFC 4861 adds the bookkeeping: 1. When a multicast-capable interface comes up, the node joins all-nodes `ff02::1` and the solicited-node group of each of its addresses. 2. When an address is added or removed, the node joins or leaves the matching group, using MLD (version 2 is RFC 3810). 3. It must **not** leave a group while any of its remaining addresses still maps to it. Routers are no exception. Each router holds the Subnet-Router anycast address of every subnet it routes for, so each one joins `ff02::1:ff00:0` on those links. ## On the wire RFC 2464 maps any IPv6 multicast group to an Ethernet destination of `33:33` followed by the group's last four octets. | Traffic | Ethernet destination | Who processes it beyond the network card | |---|---|---| | IPv4 ARP request (a broadcast) | `ff:ff:ff:ff:ff:ff` | every host on the segment | | IPv6 all-nodes `ff02::1` | `33:33:00:00:00:01` | every IPv6 node on the link | | IPv6 solicited-node `ff02::1:ff6a:31b7` | `33:33:ff:6a:31:b7` | normally only the owner | A switch that snoops MLD (RFC 4541) can send the frame only to ports with members. A switch that does not snoop floods it, and the saving then comes from every other card discarding a MAC address it has not been told to accept. ## Who sends to it Neighbor Discovery sends address-resolution solicitations to the target's solicited-node group, and Duplicate Address Detection sends its probe there from the unspecified address `::`; the message exchanges themselves belong with Neighbor Discovery. What this address type contributes is the narrowing: a lookup that IPv4 shouts to every host becomes a packet to a group of, usually, one. ## Common confusions - "It uses the low 32 bits": the group takes 24 bits; 32 bits is what the Ethernet mapping copies from the finished group. - "One group per address": one group per distinct 24-bit tail. - "Remote nodes can resolve you through it": it is link-scoped and never routed.

  • Two hosts on one link happen to share the low 24 bits of their addresses; what goes wrong?
    Nothing breaks. Both join the same solicited-node group, so each receives Neighbor Solicitations meant for the other and ignores any whose target address it does not hold. The cost is a little extra processing. The design accepts that rare collision in exchange for one group per interface-identifier tail rather than per address.
  • Why must a node not leave a solicited-node group when it removes just one of its addresses?
    Several of its own addresses can map to the same group; a link-local and a global address built on one interface identifier always do. RFC 4861 says a node MUST NOT leave the group until every assigned address that maps to it has been removed. Leaving early would make the remaining addresses unreachable for address resolution.

saying these in an interview costs you the question

  • The solicited-node group is built from the low 32 bits of the address.
  • Every unicast address needs its own distinct solicited-node group.
  • Solicited-node groups are routed across the site so remote hosts can resolve you.
  • Anycast addresses have no solicited-node group because they are shared.
  • Two hosts sharing the low 24 bits have an address conflict.