In an IPv6 Router Advertisement, what do the M and O flags and the prefix option's A and L flags each tell a host?
answer
- two in the header, two per prefix
- managed versus other
- autonomous: may I build an address?
- on-link: may I skip the router?
- DNS has its own RA option
basics
~20 sIn an IPv6 Router Advertisement, M says addresses are available from DHCPv6 and O says other settings such as DNS are; in each Prefix Information option, A permits SLAAC on that prefix and L says the prefix is on-link.
solid answer
~50 sA **Router Advertisement** carries two header flags and, per advertised prefix, two option flags. **M** (managed address configuration) says addresses are available via DHCPv6; when it is set, **O** is redundant. **O** (other configuration) says DHCPv6 offers other information, typically DNS. In each **Prefix Information option**, **A** (autonomous) lets the host build a SLAAC address from the prefix, and **L** (on-link) says destinations in the prefix are reached directly, without the router. They are independent: `A=1` with `M=1` gives a host both a SLAAC and a DHCPv6 address, and only `A=0` stops SLAAC on a prefix. RFC 4861 describes M and O as statements of what is available, and RFC 4862 no longer prescribes how hosts react, so client behaviour varies. DNS servers can also arrive in the RA itself through RFC 8106's RDNSS option.
go deeper
Recall the four letters: M for managed addresses and O for other settings, both pointing at DHCPv6; A and L sit on each advertised prefix.
Explain that the four flags are independent, walk through the common combinations, and say why the gateway always comes from the Router Advertisement.
Show you can debug mixed results — hosts with two addresses, hosts without DNS — from the flags, the prefix length and RDNSS support, knowing host reactions to M and O vary.
Weigh SLAAC with RDNSS against DHCPv6-managed addressing for a whole network: client support, address accountability, and the operating cost of running both.
## Where the flags live A **Router Advertisement (RA)** is the ICMPv6 type 134 message an IPv6 router sends periodically to all-nodes `ff02::1` and in answer to Router Solicitations (RFC 4861). Its fixed header carries two one-bit flags that describe the link as a whole; each **Prefix Information option (PIO)** inside it carries two more that describe one prefix. | Flag | Where | Name in RFC 4861 | Meaning when set | |---|---|---|---| | `M` | RA header | Managed address configuration | addresses are available via DHCPv6 | | `O` | RA header | Other configuration | other information, such as DNS, is available via DHCPv6 | | `A` | each PIO | autonomous address-configuration | the prefix may be used for SLAAC | | `L` | each PIO | on-link | the prefix may be used for on-link determination | RFC 4191 later took bits of the RA header for a **default router preference** (High, Medium, Low), which is separate from these four. ## M and O: pointers to DHCPv6 `M` and `O` configure nothing themselves; they tell the host that a DHCPv6 service exists and what it offers. - `M=1`: addresses can be obtained from DHCPv6. RFC 4861 adds that `O` is then redundant, because DHCPv6 will return all available configuration. - `M=0, O=1`: no DHCPv6 addresses, but other settings — usually DNS servers and search domains — can be fetched from DHCPv6. - `M=0, O=0`: no information is available via DHCPv6. RFC 4862 (2007) deliberately removed the earlier text that told hosts exactly how to act on these flags, noting that this does not deprecate them. The practical result is that host operating systems differ in when they start DHCPv6. Treat the flags as a strong statement of the network's design, not a guarantee of client behaviour. What the host then asks DHCPv6 for, and how that exchange runs, belongs to DHCPv6 itself. ## A: permission to autoconfigure For each PIO, RFC 4862 forms a SLAAC address only if: 1. the **A** flag is set; 2. the prefix is not the link-local prefix; 3. the preferred lifetime does not exceed the valid lifetime; 4. the prefix length plus the link's interface-identifier length equals 128 — on Ethernet, a **/64**. When these hold, the host appends an interface identifier, runs duplicate address detection and uses the address for the advertised lifetimes. With `A=0` the prefix can still be advertised, but no SLAAC address comes from it — the usual way to make addressing DHCPv6-only, paired with `M=1`. ## L: on-link determination `L=1` puts the prefix on the host's **prefix list**: destinations inside it are on-link, so the host resolves them with Neighbor Solicitations and sends directly, skipping the router. `L=0` makes **no statement** either way; RFC 4861 forbids the host from concluding that the prefix is off-link because of it. A host sends traffic for destinations it does not know to be on-link to a default router, which may answer with a Redirect when the destination is in fact a neighbour. `L` and `A` are independent: a prefix can be autoconfigured without being declared on-link. ## Common combinations | RA header | PIO flags | What a typical host ends up with | |---|---|---| | `M=0 O=0` | `A=1 L=1` | SLAAC address; DNS only if the RA carries an RDNSS option | | `M=0 O=1` | `A=1 L=1` | SLAAC address plus DNS and similar from DHCPv6, often called stateless DHCPv6 | | `M=1` | `A=0 L=1` | address from DHCPv6 only; the prefix is still on-link | | `M=1` | `A=1 L=1` | both a SLAAC and a DHCPv6 address | In every row the **default router** comes from the RA's Router Lifetime, never from DHCPv6. ## DNS without DHCPv6: RDNSS RFC 8106 defines the **RDNSS** option (type 25), carrying recursive DNS server addresses, and the **DNSSL** option (type 31), carrying search domains, each with its own lifetime. With RDNSS a network can run `M=0 O=0` and still give hosts working DNS, provided the hosts implement the option; hosts that do not need the `O` path. ## Pitfalls - Reading `M=1` as "SLAAC is off": only `A=0` on a prefix stops SLAAC there. - Reading `L=0` as "off-link": it means "no statement". - Advertising a /56 or /48 in a PIO with `A=1`: on Ethernet the option is ignored for SLAAC, because the prefix plus a 64-bit identifier would not total 128 bits. - Expecting DHCPv6 to supply a gateway: it cannot, so RAs remain necessary.
- An IPv6 network sets M=1 in its Router Advertisements, yet hosts still configure SLAAC addresses; why?M only says DHCPv6 offers addresses; it does not switch SLAAC off. Each Prefix Information option with the A flag set still authorises autoconfiguration, so hosts form a SLAAC address and may also take a DHCPv6 one. To make addressing DHCPv6-only, clear A on the prefix while keeping L set so the prefix stays on-link.
- Why does RFC 8106 matter for an IPv6 network that wants no DHCPv6 at all?SLAAC alone gives a host an address and a default router but no DNS server. RFC 8106's RDNSS option puts recursive DNS server addresses, and its DNSSL option search domains, directly into the Router Advertisement, so a network with M=0 and O=0 can still configure name resolution, provided its hosts implement the options.
saying these in an interview costs you the question
- Setting M=1 disables SLAAC on every advertised prefix.
- An L flag of 0 tells hosts the prefix is off-link.
- O=1 means the host must take its address from DHCPv6.
- The A flag sits in the RA header and applies to every prefix.
- With M set, DHCPv6 hands the host its default gateway.
- DNS servers can only reach a SLAAC host through DHCPv6.