network/mikrotik-tool/ipv6.md
2026-05-08 17:47:42 -05:00

34 KiB
Raw Blame History

IPv6 addressing plan — vntx WISP

Status: greenfield design. Any existing IPv6 on the routers (verona /40 PD pool, climax/culleoka /52s, scattered point-to-point /128s, etc.) is to be deleted and replaced with what's defined here. Don't try to migrate it.

Allocation: 2606:1c80::/32 (already advertised to TWC AS11427 from edge, peer 2605:6000:0:8::f:372).

Customer prefix: /56 per PPPoE session via DHCPv6-PD. A /56 lets customer CPE subnet into 256 /64s (LAN, guest, IoT, VPN, etc.) — the operationally sane default that matches RIPE-690 / BCOP-690 guidance. Customer CPE that only knows /64 still works fine — RouterOS hands out the /56 and the CPE configures the first /64 from it. No NAT66.


Top-level carve

2606:1c80::/32 is sliced into two purposes:

Block Size Purpose
2606:1c80::/48 /48 Infrastructure — loopbacks, P2P, transit
2606:1c80:1::/48 2606:1c80:FFF::/48 (reserved) extra infra room
2606:1c80:1000::/36 /36 Tower allocations — one /44 per tower
2606:1c80:2000::/36 and higher bulk reserved (future expansion)

The tower block 2606:1c80:1000::/36 holds 256 /44s (4 096 /44s fits in a /32 minus the infra pad). At one /44 per tower, that's 256 towers worth of allocations — far more than you'll ever build.

Why /44 per tower? Each /44 = 16 /48s = 4 096 /56s. Subtract one /48 for tower infra (mgmt, APs, etc.) and you have 3 840 /56 customers per tower, comfortably above the ~4 000-IP v4 CGNAT capacity per tower.


Infrastructure block — 2606:1c80::/48

Subdivided into /64s, indexed by purpose. Servers get the prime all-zeros /64 so their addresses are as short as the allocation allows; loopbacks and P2P links shift down to make room.

Prefix Use
2606:1c80::/64 Core servers — DNS, NTP, monitoring, billing, internal services (static-only, no SLAAC). Lives at 380 (core); see below.
2606:1c80:0:1::/64:F::/64 reserved server expansion (DMZ, hypervisor mgmt, alt server VLANs)
2606:1c80:0:10::/64 Loopbacks — one /128 per router
2606:1c80:0:11::/64:1F::/64 Wired backbone P2P links — one /64 per link, addressed as /127
2606:1c80:0:20::/64:FF::/64 Wireless backhaul P2P links — one /64 per link, addressed as /127
2606:1c80:0:1000::/64 Edge↔TWC transit (already 2605:6000:… upstream; this slot is for future v6 transit/IX)
2606:1c80:0:1001::/64 Edge↔Spectrum / secondary upstream
2606:1c80:0:1002::/64 Edge↔Preseem (shaper)
2606:1c80:0:2000::/64:2FFF::/64 OOB / mgmt-VLAN-of-routers (one /64 per site, optional)
2606:1c80:0:F000::/64 and up reserved (future infra)

Servers — 2606:1c80::/64

The single server LAN for the entire network, located at the 380 site and hosted on the edge router (the server switch is plugged into edge's sfp-sfpplus8-server-switch port, VLAN 9, same as the existing v4 server LAN on vlan9_sfpplus8). Gateway: 2606:1c80::1/64. RA is disabled — servers get static addresses, not SLAAC. Stateful DHCPv6 is optional; prefer static config for server-class hosts.

Suggested numbering mirrors the v4 204.110.191.X last-octet so the two are easy to translate by sight:

v4 host v6 host Role
204.110.191.20 2606:1c80::20 DNS resolver (primary)
204.110.191.240 2606:1c80::240 DNS resolver (secondary)
204.110.191.250 2606:1c80::250 DNS resolver (tertiary)
204.110.191.19 2606:1c80::19 NTP

2606:1c80:0:1::/64 through :F::/64 are reserved server expansion slots (DMZ, hypervisor mgmt, alternate server VLANs) — populate them only when there's a concrete need.

Loopbacks (2606:1c80:0:10::/64)

One /128 per router, all inside 2606:1c80:0:10::/64. To keep the v6 loopback visually parallel to the v4 loopback (10.254.254.X), encode the v4 last octet as the last hextet, treated as hex (so :10::101 is the v6 loopback for the router whose v4 loopback is 10.254.254.101). Visual mnemonic, not a numeric identity.

Router v4 loopback v6 loopback
verona 10.254.254.101 2606:1c80:0:10::101/128
climax 10.254.254.102 2606:1c80:0:10::102/128
culleoka 10.254.254.104 2606:1c80:0:10::104/128
newhope 10.254.254.108 2606:1c80:0:10::108/128
lowry 10.254.254.109 2606:1c80:0:10::109/128
982 10.254.254.110 2606:1c80:0:10::110/128
494 10.254.254.111 2606:1c80:0:10::111/128
core 10.254.254.253 2606:1c80:0:10::253/128
edge 10.254.254.254 2606:1c80:0:10::254/128

Loopbacks announce into OSPFv3 only.

One /64 per physical/logical link, addressed as /127 between the two ends. Numbering follows the existing v4 /29 transport scheme. Wired/fiber transport uses :11:::1F::; wireless backhaul uses :20::+. (:10::/64 is the loopback /64.)

Link v4 /29 v6 /64 Endpoints (/127)
edge ↔ core (sfpplus7) 204.110.191.180/30 2606:1c80:0:11::/64 …:11::1 edge / …:11::2 core
core ↔ climax (ether5) 10.250.1.88/29 2606:1c80:0:12::/64 …:12::1 core / …:12::2 climax
core ↔ newhope (ether4) 10.250.1.56/29 2606:1c80:0:13::/64 …:13::1 core / …:13::2 newhope
core ↔ 982 (ether1) 10.250.1.32/29 2606:1c80:0:14::/64 …:14::1 core / …:14::2 982
core ↔ culleoka (ether6) 10.250.1.48/29 2606:1c80:0:15::/64 …:15::1 core / …:15::2 culleoka
verona ↔ climax (11 GHz) (existing v6 in use) 2606:1c80:0:20::/64 …:20::1 verona / …:20::2 climax
climax ↔ culleoka (11 GHz) 2606:1c80:0:21::/64 …:21::1 climax / …:21::2 culleoka
climax ↔ 494 (ether5) 10.250.1.64/29 2606:1c80:0:17::/64 …:17::1 climax / …:17::2 494
newhope ↔ lowry (ether6) 10.250.1.104/29 2606:1c80:0:18::/64 …:18::1 newhope / …:18::2 lowry

Pick the next free :NN::/64 (wired in :11:::1F::, wireless in :20::+) when adding a link; record it here.

The existing 2606:1c80:0:1010::/64 and 2606:1c80:0:0010::/64 get deleted and replaced with :20:: and :21:: respectively (note that the new :10::/64 slot is now the loopback /64, not a P2P link).


Tower block — 2606:1c80:1000::/36

One /44 per tower. The third hextet of the /44 encodes the v4 mgmt /20's third octet as 1<oct-hex>0, so you can map between v4 and v6 by sight:

Tower v4 mgmt v4 third oct (hex) v6 /44 Inverse mnemonic
verona 10.10.0.0/20 0 (0x00) 2606:1c80:1000::/44 100
climax 10.10.16.0/20 16 (0x10) 2606:1c80:1100::/44 110
982 10.10.48.0/20 48 (0x30) 2606:1c80:1300::/44 130
core (380) 10.10.64.0/20 64 (0x40) 2606:1c80:1400::/44 140
altoga 10.10.80.0/20 80 (0x50) 2606:1c80:1500::/44 150
culleoka 10.10.96.0/20 96 (0x60) 2606:1c80:1600::/44 160
newhope 10.10.128.0/20 128 (0x80) 2606:1c80:1800::/44 180
lowry 10.10.144.0/20 144 (0x90) 2606:1c80:1900::/44 190
494 10.10.160.0/20 160 (0xA0) 2606:1c80:1A00::/44 1A0

Slots not in the table (2606:1c80:1010::/44, :1020::/44, :1200::/44, …) are reserved. New tower at 10.10.176.0/20 (0xB0) takes 2606:1c80:1B00::/44. Don't reuse out of band.

Altoga is logical-satellite of verona but gets its own /44 — it serves its own customer base off ether6-switch on the verona router and the v4 plan already treats it as independent. Easier to operate as a peer.

Per-tower /44 layout

Each /44 = 16 /48s. The first /48 is tower infra; the other 15 carry customer /56s.

Sub-prefix Use
2606:1c80:NNN0::/48 Tower infrastructure
2606:1c80:NNN0::/64 Router-side mgmt LAN (RA + DHCPv6 stateless)
2606:1c80:NNN0:F::/64 Access points (mirrors v4 top-/24-of-/20 rule)
2606:1c80:NNN0:1::/64:E::/64 reserved (extra VLANs, IoT, voice, monitoring)
2606:1c80:NNN0:10::/64:FF::/64 reserved (sub-tower/repeater /64s)
2606:1c80:NNN1::/48 Customer PD pool slot 1 — 256 × /56
2606:1c80:NNN2::/48 Customer PD pool slot 2 — instantiate when 1 fills
2606:1c80:NNN3::/482606:1c80:NNNF::/48 Customer pool slots 315 (instantiate as needed)

Servers are not allocated per-tower — there's a single dedicated core-servers /64 in the infrastructure block (see below). Towers don't host server-class hosts.

Customer capacity per tower: 15 × 256 = 3 840 /56s.

The router itself uses 2606:1c80:NNN0::1/64 on the mgmt LAN (mirrors the v4 .X.254 gateway convention but moved to ::1 for v6 since ::1 is what humans type). APs autoconfig EUI-64 inside :NNN0:F::/64; when you need a known address, use :F::1:F::FF.

Operational note on pool growth. Start each tower with one customer pool (:NNN1::/48, prefix-length=56 → 256 /56s). When the pool drops below ~30 free /56s, add the next one (:NNN2::/48 → next 256 /56s) as a second pool and assign it to the same PPP profile. RouterOS will draw from any pool the profile references. Each pool drop is a /ipv6 pool add — no PPPoE disruption.


Routing

IGP — OSPFv3

Edge already runs OSPFv3 in area backbone. Every router gets:

/routing ospf-v3 instance
add name=default-v3 router-id=<v4-loopback> redistribute-connected=as-type-1

/routing ospf-v3 interface
add area=backbone interface=<each-transit-interface> network-type=point-to-point

Loopbacks and connected /64s redistribute as type-1. Customer PD allocations do not redistribute into OSPF — they're on-link via the PPPoE interface, and edge/core learn aggregates via iBGP.

iBGP — /44 aggregates → edge

Each tower router peers iBGP with edge (and optionally core as a route-reflector if you want to scale; today direct works fine) over its loopback. Peer config on every tower:

/routing bgp instance
set default as=<your-ASN> router-id=<v4-loopback>

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:NNN0::/44 synchronize=no

Edge already has 2606:1c80::/32 in its /routing bgp network, which covers all towers — that aggregate goes upstream to TWC. The per-tower /44s announced over iBGP are for internal longest-match so traffic returning into the network can find the right tower without flooding the default through the IGP.

(If iBGP feels overkill, OSPFv3 redistribution of the per-tower /44 works too. iBGP scales better and matches your v4 structure.)

Customer PD — DHCPv6-PD on PPPoE (/56 per session)

On each tower router:

/ipv6 pool
add name=<tower>-cust-pd-1 prefix=2606:1c80:NNN1::/48 prefix-length=56

/ppp profile
set [find name=<pppoe-profile>] \
    remote-ipv6-prefix-pool=<tower>-cust-pd-1 \
    dhcpv6-pd-pool=<tower>-cust-pd-1

/ipv6 dhcp-server
add name=<tower>-pd interface=<tower-bridge> \
    address-pool=<tower>-cust-pd-1

Each PPPoE session gets a single /56 from the pool, delegated via DHCPv6-PD. CPE configures /64s out of it on its LANs.

Mgmt-LAN / wired customers (no PPPoE)

For the wired mgmt LAN at each tower (2606:1c80:NNN0::/64), use SLAAC + RDNSS:

/ipv6 address
add address=2606:1c80:NNN0::1/64 interface=<mgmt-bridge> advertise=yes

/ipv6 nd
add interface=<mgmt-bridge> ra-interval=3m20s-10m \
    other-configuration=yes managed-address-configuration=no
/ipv6 nd prefix
add interface=<mgmt-bridge> prefix=2606:1c80:NNN0::/64 \
    autonomous=yes on-link=yes
/ipv6 dhcp-server
add interface=<mgmt-bridge> name=<tower>-mgmt-stateless \
    address-pool=none

DNS via RDNSS pointing at v6 resolvers (the v6 equivalents of 204.110.191.240 and .20); configure those on the resolver hosts when you v6-enable them.


Firewall (every router)

Mirror your v4 input chain. Minimum:

/ipv6 firewall filter
add chain=input action=accept connection-state=established,related
add chain=input action=accept protocol=icmpv6
add chain=input action=accept src-address=fe80::/10
add chain=input action=accept src-address=2606:1c80::/32   ;; internal
add chain=input action=drop

add chain=forward action=accept connection-state=established,related
add chain=forward action=accept protocol=icmpv6 hop-limit=equal:1   ;; PMTUD
add chain=forward action=accept protocol=icmpv6
add chain=forward action=accept src-address=2606:1c80::/32 \
                                  dst-address=2606:1c80::/32
add chain=forward action=accept in-interface-list=customer        ;; v6 outbound
add chain=forward action=drop

Edge keeps its existing inbound BGP rules. Do not NAT v6 — every prefix is GUA from your /32.


DNS

  • Forward DNS for 2606:1c80::/32: AAAA records under vntx.net for router loopbacks (verona-loopback.vntx.net AAAA 2606:1c80::101, etc.) and customer PTR delegations.
  • Reverse DNS: request a 1.c.8.1.6.0.6.2.ip6.arpa delegation from ARIN matching the /32. Then run a v6 PTR generator (mirror the v4 side).

Migration notes

This is a greenfield plan but the routers have some v6 already:

  • Delete on every router before applying: /ipv6 address remove [find], /ipv6 pool remove [find], /ipv6 dhcp-server remove [find], /ipv6 nd remove [find !default].
  • Keep edge's /routing bgp network add 2606:1c80::/32 synchronize=no and its TWC v6 peer.
  • Keep edge's /ipv6 firewall filter rules — extend per the template, don't replace.

Apply tower-by-tower in the same order as the CGNAT renumber sequence (see subnets.md) so you're not running two transitions in parallel.


Per-router config skeletons

edge (loopback :10::254, hosts the global server /64)

/ipv6 address
add address=2606:1c80:0:10::254/128 interface=lo advertise=no
add address=2606:1c80:0:11::1/127   interface=sfp-sfpplus7-core-direct
add address=2606:1c80:0:1002::1/64  interface=sfp-sfpplus11-preseem
add address=2606:1c80::1/64         interface=vlan9_sfpplus8   ;; server LAN
;; existing TWC peering address lives outside our /32 — leave it

;; suppress RA on the servers /64 — static-only, no SLAAC
/ipv6 nd
add interface=vlan9_sfpplus8 disabled=no advertise=no \
    managed-address-configuration=no other-configuration=no

/routing bgp network
add network=2606:1c80::/64  synchronize=no   ;; server LAN, advertised from edge
;; existing add network=2606:1c80::/32 stays — the upstream-facing aggregate

core (loopback :10::253, tower /44 1400::/44)

/ipv6 address
add address=2606:1c80:0:10::253/128 interface=lo advertise=no
add address=2606:1c80:0:11::2/127   interface=ether3-edge-direct
add address=2606:1c80:0:12::1/127   interface=ether5-climax
add address=2606:1c80:0:13::1/127   interface=ether4-newhope
add address=2606:1c80:0:14::1/127   interface=ether1-982-60ghz
add address=2606:1c80:0:15::1/127   interface=ether6-culleoka-11ghz
add address=2606:1c80:1400::1/64    interface=vlan10_combo1     ;; 380 mgmt LAN

/ipv6 pool
add name=core-cust-pd-1 prefix=2606:1c80:1401::/48 prefix-length=56

/routing bgp network
add network=2606:1c80:1400::/44 synchronize=no

verona (loopback :10::101, towers verona 1000::/44 + altoga 1500::/44)

/ipv6 address
add address=2606:1c80:0:10::101/128 interface=lo advertise=no
add address=2606:1c80:0:20::1/127 interface=ether3-climax-11ghz
add address=2606:1c80:1000::1/64  interface=verona            ;; verona mgmt LAN
add address=2606:1c80:1500::1/64  interface=ether6-switch     ;; altoga mgmt LAN

/ipv6 pool
add name=verona-cust-pd-1 prefix=2606:1c80:1001::/48 prefix-length=56
add name=altoga-cust-pd-1 prefix=2606:1c80:1501::/48 prefix-length=56

/ppp profile
set [find name=pppoe-verona] remote-ipv6-prefix-pool=verona-cust-pd-1 \
                              dhcpv6-pd-pool=verona-cust-pd-1
set [find name=pppoe-altoga] remote-ipv6-prefix-pool=altoga-cust-pd-1 \
                              dhcpv6-pd-pool=altoga-cust-pd-1

/routing bgp network
add network=2606:1c80:1000::/44 synchronize=no
add network=2606:1c80:1500::/44 synchronize=no

climax (loopback :10::102, /44 1100::/44)

/ipv6 address
add address=2606:1c80:0:10::102/128 interface=lo advertise=no
add address=2606:1c80:0:20::2/127 interface=ether6-verona-11ghz
add address=2606:1c80:0:21::1/127 interface=<climax-culleoka-11ghz>
add address=2606:1c80:0:12::2/127 interface=<climax-core-link>
add address=2606:1c80:1100::1/64  interface=climax-bridge

/ipv6 pool
add name=climax-cust-pd-1 prefix=2606:1c80:1101::/48 prefix-length=56

/routing bgp network
add network=2606:1c80:1100::/44 synchronize=no

Other towers

Same template — substitute loopback, /44, interface names from each router's .rsc, and the matching P2P /127:

Router Loopback /44 First customer pool prefix Mgmt LAN /64
culleoka 2606:1c80:0:10::104 2606:1c80:1600::/44 2606:1c80:1601::/48 2606:1c80:1600::1/64
newhope 2606:1c80:0:10::108 2606:1c80:1800::/44 2606:1c80:1801::/48 2606:1c80:1800::1/64
lowry 2606:1c80:0:10::109 2606:1c80:1900::/44 2606:1c80:1901::/48 2606:1c80:1900::1/64
982 2606:1c80:0:10::110 2606:1c80:1300::/44 2606:1c80:1301::/48 2606:1c80:1300::1/64
494 2606:1c80:0:10::111 2606:1c80:1A00::/44 2606:1c80:1A01::/48 2606:1c80:1A00::1/64

Verification checklist (per router, post-apply)

:put [/ipv6 address print]
:put [/ipv6 route print where active]
:put [/routing ospf-v3 neighbor print]
:put [/routing bgp peer print where remote-address~"2606:1c80"]
/ping 2606:1c80:0:10::254 count=3 src-address=2606:1c80:0:10::<self-last-hextet>
/ping 2606:4700:4700::1111 count=3              ;; Cloudflare, end-to-end

End-to-end CPE test: connect a known PPPoE customer, verify a /56 is delegated, verify SLAAC inside the first /64 of that /56 reaches 2606:4700:4700::1111.


Allocation registry (keep this updated)

Prefix Tower / purpose First allocated Notes
2606:1c80::/64 core servers 2026-05-08 global server LAN at 380 — static only, no RA
2606:1c80::/48 infra 2026-05-08 servers/loopbacks/P2P/transit
2606:1c80:0:10::/64 router loopbacks 2026-05-08 one /128 per router
2606:1c80:1000::/44 verona 2026-05-08 3 840 /56 customer capacity
2606:1c80:1100::/44 climax 2026-05-08
2606:1c80:1300::/44 982 2026-05-08
2606:1c80:1400::/44 core (380) 2026-05-08
2606:1c80:1500::/44 altoga 2026-05-08 served from verona router
2606:1c80:1600::/44 culleoka 2026-05-08
2606:1c80:1800::/44 newhope 2026-05-08
2606:1c80:1900::/44 lowry 2026-05-08
2606:1c80:1A00::/44 494 2026-05-08

Per-router migration commands

Two phases per router: WIPE (remove all stale internal v6 config — loopbacks, transit, tower LANs, OSPFv3, internal iBGP, customer pools) then APPLY (configure exactly per the plan above). External eBGP peerings (Charter/Spectrum, both v4 and v6) and the existing 2606:1c80::/32 aggregate on edge are preserved by filtering the wipe commands on name= and network=. The v4 control plane is never touched.

Apply order: edge → core → verona → climax → 494 → 982 → culleoka → newhope → lowry. Altoga sits on the verona router so it gets configured during verona's APPLY. Bring up edge first so the iBGP target loopback exists when each tower comes online.

WIPE (run on every router; same script everywhere)

# ---- v6 wipe — removes everything internal, leaves external peerings alone
/ipv6 address remove [find !dynamic]
/ipv6 nd prefix remove [find]
/ipv6 nd remove [find !default]
/ipv6 dhcp-server remove [find]
/ipv6 dhcp-server option remove [find]
/ipv6 dhcp-client remove [find]
/ipv6 pool remove [find]
/ipv6 route remove [find !dynamic]
/ipv6 firewall filter remove [find]
/ipv6 firewall mangle remove [find]
/ipv6 firewall raw remove [find]
/ppp profile set [find] remote-ipv6-prefix-pool="" dhcpv6-pd-pool=""
/routing ospf-v3 interface remove [find]
/routing ospf-v3 instance remove [find]
# internal iBGP only — leave external eBGP peers (twc, twc-v6) alone
/routing bgp peer remove [find name~"ibgp" and address-families~"ipv6"]
# v6 BGP networks — leave the upstream-facing 2606:1c80::/32 aggregate
/routing bgp network remove [find network~":" and network!="2606:1c80::/32"]

Common firewall + IGP baseline (run on every router AFTER its WIPE)

# ---- v6 firewall: input + forward minimum, mirrors v4 hygiene
/ipv6 firewall filter
add chain=input action=accept connection-state=established,related
add chain=input action=accept protocol=icmpv6
add chain=input action=accept src-address=fe80::/10
add chain=input action=accept src-address=2606:1c80::/32 comment="internal"
add chain=input action=drop comment="default deny"

add chain=forward action=accept connection-state=established,related
add chain=forward action=accept protocol=icmpv6 hop-limit=equal:1 comment="PMTUD"
add chain=forward action=accept protocol=icmpv6
add chain=forward action=accept src-address=2606:1c80::/32 dst-address=2606:1c80::/32
add chain=forward action=accept in-interface-list=customer comment="v6 outbound"
add chain=forward action=drop comment="default deny"

# ---- OSPFv3 (router-id = v4 loopback)
/routing ospf-v3 instance
add name=default-v3 router-id=<v4-loopback> redistribute-connected=as-type-1
# OSPFv3 interfaces are added per-router in each APPLY block below

edge — APPLY

/ipv6 address
add address=2606:1c80:0:10::254/128 interface=lo advertise=no
add address=2606:1c80:0:11::1/127   interface=sfp-sfpplus7-core-direct
add address=2606:1c80:0:1002::1/64  interface=sfp-sfpplus11-preseem
add address=2606:1c80::1/64         interface=vlan9_sfpplus8   ;; server LAN

/ipv6 nd
add interface=vlan9_sfpplus8 disabled=no advertise=no \
    managed-address-configuration=no other-configuration=no

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.254 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=sfp-sfpplus7-core-direct network-type=point-to-point

# eBGP TWC v6 peer is preserved by the wipe — do NOT re-add it here.
# /routing bgp network keeps the existing 2606:1c80::/32. Add the server /64:
/routing bgp network
add network=2606:1c80::/64 synchronize=no comment="server LAN, originated by edge"

core — APPLY

/ipv6 address
add address=2606:1c80:0:10::253/128 interface=lo advertise=no
add address=2606:1c80:0:11::2/127   interface=ether3-edge-direct
add address=2606:1c80:0:12::1/127   interface=ether5-climax
add address=2606:1c80:0:13::1/127   interface=ether4-newhope
add address=2606:1c80:0:14::1/127   interface=ether1-982-60ghz
add address=2606:1c80:0:15::1/127   interface=ether6-culleoka-11ghz
add address=2606:1c80:1400::1/64    interface=vlan10_combo1     ;; 380 mgmt LAN

/ipv6 pool
add name=core-cust-pd-1 prefix=2606:1c80:1401::/48 prefix-length=56

/ppp profile
set [find name=380] remote-ipv6-prefix-pool=core-cust-pd-1 \
                    dhcpv6-pd-pool=core-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.253 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether3-edge-direct  network-type=point-to-point
add area=backbone interface=ether5-climax       network-type=point-to-point
add area=backbone interface=ether4-newhope      network-type=point-to-point
add area=backbone interface=ether1-982-60ghz    network-type=point-to-point
add area=backbone interface=ether6-culleoka-11ghz network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1400::/44 synchronize=no

verona — APPLY (also configures altoga)

/ipv6 address
add address=2606:1c80:0:10::101/128 interface=lo advertise=no
add address=2606:1c80:0:20::1/127   interface=ether3-climax-11ghz
add address=2606:1c80:1000::1/64    interface=verona            ;; verona mgmt LAN
add address=2606:1c80:1500::1/64    interface=ether6-switch     ;; altoga mgmt LAN

/ipv6 pool
add name=verona-cust-pd-1 prefix=2606:1c80:1001::/48 prefix-length=56
add name=altoga-cust-pd-1 prefix=2606:1c80:1501::/48 prefix-length=56

/ppp profile
set [find name=pppoe-verona] remote-ipv6-prefix-pool=verona-cust-pd-1 \
                              dhcpv6-pd-pool=verona-cust-pd-1
set [find name=pppoe-altoga] remote-ipv6-prefix-pool=altoga-cust-pd-1 \
                              dhcpv6-pd-pool=altoga-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.101 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether3-climax-11ghz network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1000::/44 synchronize=no
add network=2606:1c80:1500::/44 synchronize=no

climax — APPLY

/ipv6 address
add address=2606:1c80:0:10::102/128   interface=lo advertise=no
add address=2606:1c80:0:12::2/127     interface=ether4-380-airfiber24
add address=2606:1c80:0:17::1/127     interface=ether5-494
add address=2606:1c80:0:20::2/127     interface=ether6-verona-11ghz
add address=2606:1c80:0:21::1/127     interface=ether3-culleoka-11ghz
add address=2606:1c80:1100::1/64      interface=climax-bridge

/ipv6 pool
add name=climax-cust-pd-1 prefix=2606:1c80:1101::/48 prefix-length=56

/ppp profile
set [find name=pppoe] remote-ipv6-prefix-pool=climax-cust-pd-1 \
                      dhcpv6-pd-pool=climax-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.102 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether4-380-airfiber24 network-type=point-to-point
add area=backbone interface=ether5-494            network-type=point-to-point
add area=backbone interface=ether6-verona-11ghz   network-type=point-to-point
add area=backbone interface=ether3-culleoka-11ghz network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1100::/44 synchronize=no

494 — APPLY

/ipv6 address
add address=2606:1c80:0:10::111/128 interface=lo advertise=no
add address=2606:1c80:0:17::2/127   interface=ether2-climax
add address=2606:1c80:1A00::1/64    interface=494               ;; 494 mgmt LAN

/ipv6 pool
add name=494-cust-pd-1 prefix=2606:1c80:1A01::/48 prefix-length=56

/ppp profile
set [find name=pppoe] remote-ipv6-prefix-pool=494-cust-pd-1 \
                      dhcpv6-pd-pool=494-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.111 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether2-climax network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1A00::/44 synchronize=no

982 — APPLY

/ipv6 address
add address=2606:1c80:0:10::110/128 interface=lo advertise=no
add address=2606:1c80:0:14::2/127   interface=ether7-380
add address=2606:1c80:1300::1/64    interface=982               ;; 982 mgmt LAN

/ipv6 pool
add name=982-cust-pd-1 prefix=2606:1c80:1301::/48 prefix-length=56

/ppp profile
set [find name=pppoe] remote-ipv6-prefix-pool=982-cust-pd-1 \
                      dhcpv6-pd-pool=982-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.110 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether7-380 network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1300::/44 synchronize=no

culleoka — APPLY

/ipv6 address
add address=2606:1c80:0:10::104/128 interface=lo advertise=no
add address=2606:1c80:0:15::2/127   interface=ether6-380-11ghz
add address=2606:1c80:0:21::2/127   interface=ether1-climax-11ghz
add address=2606:1c80:1600::1/64    interface=mgmt              ;; culleoka mgmt LAN

/ipv6 pool
add name=culleoka-cust-pd-1 prefix=2606:1c80:1601::/48 prefix-length=56

/ppp profile
set [find name=pppoe] remote-ipv6-prefix-pool=culleoka-cust-pd-1 \
                      dhcpv6-pd-pool=culleoka-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.104 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether6-380-11ghz   network-type=point-to-point
add area=backbone interface=ether1-climax-11ghz network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1600::/44 synchronize=no

newhope — APPLY

/ipv6 address
add address=2606:1c80:0:10::108/128 interface=lo advertise=no
add address=2606:1c80:0:13::2/127   interface=ether2-380
add address=2606:1c80:0:18::1/127   interface=ether6-lowrycrossing
add address=2606:1c80:1800::1/64    interface=newhope           ;; newhope mgmt LAN

/ipv6 pool
add name=newhope-cust-pd-1 prefix=2606:1c80:1801::/48 prefix-length=56

/ppp profile
set [find name=newhope] remote-ipv6-prefix-pool=newhope-cust-pd-1 \
                        dhcpv6-pd-pool=newhope-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.108 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether2-380           network-type=point-to-point
add area=backbone interface=ether6-lowrycrossing network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1800::/44 synchronize=no

lowry — APPLY

/ipv6 address
add address=2606:1c80:0:10::109/128 interface=lo advertise=no
add address=2606:1c80:0:18::2/127   interface=ether1-newhope
add address=2606:1c80:1900::1/64    interface=lowrycrossing     ;; lowry mgmt LAN

/ipv6 pool
add name=lowry-cust-pd-1 prefix=2606:1c80:1901::/48 prefix-length=56

/ppp profile
set [find name=pppoe] remote-ipv6-prefix-pool=lowry-cust-pd-1 \
                      dhcpv6-pd-pool=lowry-cust-pd-1

/routing ospf-v3 instance
add name=default-v3 router-id=10.254.254.109 redistribute-connected=as-type-1
/routing ospf-v3 interface
add area=backbone interface=lo passive=yes
add area=backbone interface=ether1-newhope network-type=point-to-point

/routing bgp peer
add address-families=ipv6 name=ibgp-edge \
    remote-address=2606:1c80:0:10::254 remote-as=<your-ASN> \
    update-source=lo multihop=yes

/routing bgp network
add network=2606:1c80:1900::/44 synchronize=no

Final verification (run from any tower after all APPLY blocks)

:put [/ipv6 address print]
:put [/ipv6 route print where active]
:put [/routing ospf-v3 neighbor print]
:put [/routing bgp peer print where remote-address~"2606:1c80"]
/ping 2606:1c80:0:10::254 count=3       ;; edge loopback (target of all iBGP)
/ping 2606:1c80::20       count=3       ;; primary DNS in the new server LAN
/ping 2606:4700:4700::1111 count=3      ;; Cloudflare end-to-end