{"id":66138,"date":"2022-08-01T09:00:42","date_gmt":"2022-08-01T09:00:42","guid":{"rendered":"https:\/\/www.cryptocabaret.com\/?p=66138"},"modified":"2022-08-01T09:00:42","modified_gmt":"2022-08-01T09:00:42","slug":"how-i-disabled-ipv6-on-linux","status":"publish","type":"post","link":"https:\/\/www.cryptocabaret.com\/?p=66138","title":{"rendered":"How I disabled IPv6 on Linux"},"content":{"rendered":"<p><span class=\"field field--name-title field--type-string field--label-hidden\">How I disabled IPv6 on Linux<\/span><br \/>\n<span class=\"field field--name-uid field--type-entity-reference field--label-hidden\"><a title=\"View user profile.\" href=\"https:\/\/opensource.com\/users\/dboth\" class=\"username\">David Both<\/a><\/span><br \/>\n<span class=\"field field--name-created field--type-created field--label-hidden\">Mon, 08\/01\/2022 &#8211; 03:00<\/span><\/p>\n<div data-drupal-selector=\"rate-node-70132\" class=\"rate-widget-thumbs-up\" title=\"Register or Login to like.\">\n<div class=\"rate-thumbs-up-btn-up vote-pending\"><a href=\"https:\/\/opensource.com\/user\/register\">Register<\/a> or <a href=\"https:\/\/opensource.com\/user\/login?current=\/rss.xml\">Login<\/a> to like<\/div>\n<div class=\"rate-score\"><a href=\"https:\/\/opensource.com\/user\/register\">Register<\/a> or <a href=\"https:\/\/opensource.com\/user\/login?current=\/rss.xml\">Login<\/a> to like<\/div>\n<\/div>\n<div class=\"clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item\">\n<p>IPv6 is a good thing for the Internet in general, but I find it unnecessarily complex for use in most home and small- to medium-size businesses. Like many others, I continue to use private IPv4 address ranges for my own internal networks and those for which I have some level of responsibility. My ISP only provides IPv4 addresses anyway, so it makes no sense to use IPv6 internally when all external packets are IPv4. Besides, IPv4 is much simpler, and one of my Linux Philosophy tenets is &#8220;Find the Simplicity.&#8221;<\/p>\n<p>As a result, I disabled IPv6 on all my hosts. It seemed easy\u2014at first. Here is how I did it.<\/p>\n<\/p>\n<div class=\"embedded-resource-list callout-float-right\">\n<div class=\"field field--name-title field--type-string field--label-hidden field__item\">More Linux resources<\/div>\n<div class=\"field field--name-links field--type-link field--label-hidden field__items\">\n<div class=\"field__item\"><a href=\"https:\/\/developers.redhat.com\/cheat-sheets\/linux-commands-cheat-sheet\/?intcmp=70160000000h1jYAAQ\">Linux commands cheat sheet<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/developers.redhat.com\/cheat-sheets\/advanced-linux-commands\/?intcmp=70160000000h1jYAAQ\">Advanced Linux commands cheat sheet<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/www.redhat.com\/en\/services\/training\/rh024-red-hat-linux-technical-overview?intcmp=70160000000h1jYAAQ\">Free online course: RHEL technical overview<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/downloads\/cheat-sheet-networking?intcmp=70160000000h1jYAAQ\">Linux networking cheat sheet<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/downloads\/cheat-sheet-selinux?intcmp=70160000000h1jYAAQ\">SELinux cheat sheet<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/downloads\/linux-common-commands-cheat-sheet?intcmp=70160000000h1jYAAQ\">Linux common commands cheat sheet<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/resources\/what-are-linux-containers?intcmp=70160000000h1jYAAQ\">What are Linux containers?<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/tags\/linux?intcmp=70160000000h1jYAAQ\">Our latest Linux articles<\/a><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2>Testing for IPv6<\/h2>\n<p>My hosts run the <a href=\"https:\/\/spins.fedoraproject.org\/xfce\/download\/index.html\" target=\"_blank\" rel=\"noopener\">Fedora 36 Xfce spin<\/a> along with many packages and configuration changes I perform after the initial default installation. All of my hosts have the most recent updates installed. One of those hosts is my firewall\/router, which is the first host on which I disabled IPv6.<\/p>\n<p>You can check to see whether IPv6 is currently active on your Linux host. The <code>nmcli<\/code> command results below are from my router\/firewall host. All the active NICs have both IPv4 and IPv6 addresses.<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\"><span class=\"co0\"># nmcli<\/span><br>\nenp4s0: connected to enp4s0<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"Realtek RTL8111\/8168\/8411\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ethernet <span class=\"br0\">(<\/span>r8169<span class=\"br0\">)<\/span>, <span class=\"nu0\">84<\/span>:<span class=\"nu0\">16<\/span>:F9:04:<span class=\"nu0\">44<\/span>:03, hw, mtu <span class=\"nu0\">1500<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ip4 default<br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet4 45.20.209.41<span class=\"sy0\">\/<\/span><span class=\"nu0\">29<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 45.20.209.40<span class=\"sy0\">\/<\/span><span class=\"nu0\">29<\/span> metric <span class=\"nu0\">102<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 default via 45.20.209.46 metric <span class=\"nu0\">102<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet6 <span class=\"nu0\">2600<\/span>:<span class=\"nu0\">1700<\/span>:7c0:<span class=\"nu0\">860<\/span>:<span class=\"nu0\">8616<\/span>:f9ff:fe04:<span class=\"nu0\">4403<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet6 fe80::<span class=\"nu0\">8616<\/span>:f9ff:fe04:<span class=\"nu0\">4403<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route6 fe80::<span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span> metric <span class=\"nu0\">256<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route6 default via fe80::a698:13ff:fee5:fa10 metric <span class=\"nu0\">1024<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route6 <span class=\"nu0\">2600<\/span>:<span class=\"nu0\">1700<\/span>:7c0:<span class=\"nu0\">860<\/span>::<span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span> metric <span class=\"nu0\">256<\/span><br><br>\nenp1s0: connected to enp1s0<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"Realtek RTL8111\/8168\/8411\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ethernet <span class=\"br0\">(<\/span>r8169<span class=\"br0\">)<\/span>, <span class=\"nu0\">84<\/span>:<span class=\"nu0\">16<\/span>:F9:03:E9:<span class=\"nu0\">89<\/span>, hw, mtu <span class=\"nu0\">1500<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet4 192.168.10.1<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 192.168.10.0<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span> metric <span class=\"nu0\">101<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet6 fe80::<span class=\"nu0\">8616<\/span>:f9ff:fe03:e989<span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route6 fe80::<span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span> metric <span class=\"nu0\">256<\/span><br><br>\nenp2s0: connected to enp2s0<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"Realtek RTL8111\/8168\/8411\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ethernet <span class=\"br0\">(<\/span>r8169<span class=\"br0\">)<\/span>, <span class=\"nu0\">84<\/span>:<span class=\"nu0\">16<\/span>:F9:03:FD:<span class=\"nu0\">85<\/span>, hw, mtu <span class=\"nu0\">1500<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet4 192.168.0.254<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 192.168.0.0<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span> metric <span class=\"nu0\">100<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet6 fe80::<span class=\"nu0\">8616<\/span>:f9ff:fe03:fd85<span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route6 fe80::<span class=\"sy0\">\/<\/span><span class=\"nu0\">64<\/span> metric <span class=\"nu0\">256<\/span><br><br>\nlo: unmanaged<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"lo\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 loopback <span class=\"br0\">(<\/span>unknown<span class=\"br0\">)<\/span>, 00:00:00:00:00:00, sw, mtu <span class=\"nu0\">65536<\/span><br><br>\nDNS configuration:<br>\n\u00a0 \u00a0 \u00a0 \u00a0 servers: 192.168.0.52 8.8.8.8 8.8.4.4<br>\n\u00a0 \u00a0 \u00a0 \u00a0 interface: enp4s0<br><br>\n\u00a0 \u00a0 \u00a0 \u00a0 servers: 192.168.0.52 8.8.8.8<br>\n\u00a0 \u00a0 \u00a0 \u00a0 interface: enp2s0<br><br>\n\u00a0 \u00a0 \u00a0 \u00a0 servers: 192.168.0.52 8.8.8.8<br>\n\u00a0 \u00a0 \u00a0 \u00a0 interface: enp1s0<\/div><\/div><\/pre>\n<h2>Use GRUB to configure the kernel<\/h2>\n<p>GRUB\u2013the Grand Unified Bootloader\u2013loads the kernel into memory and sets many kernel parameters during the Linux boot process. The current bootloader is actually GRUB2, the second major version of GRUB, but it is easier just to call it GRUB.<\/p>\n<p>The GRUB configuration file <code>\/boot\/grub2\/grub.cfg<\/code> provides the startup configuration for the kernel, but you should not modify it directly. The location of the UEFI GRUB configuration file may vary depending on your distribution. However, its location is irrelevant for this purpose. Linux startup kernel configuration can be easily modified using the <code>\/etc\/default\/grub<\/code> configuration file, which configures the kernel properly regardless of whether it boots using UEFI.<\/p>\n<p>There are two command line arguments to add to the <code>\/etc\/default\/grub<\/code> file to configure the Linux kernel to disable IPv6. The first, <strong>GRUB_CMDLINE_LINUX=&#8221;ipv6.disable=1&#8243;<\/strong> adds <strong>&#8220;ipv6.disable=1&#8221;<\/strong> to the kernel command line.<\/p>\n<p>The second, <strong>GRUB_CMDLINE_LINUX_DEFAULT=&#8221;ipv6.disable=1 quiet splash&#8221;<\/strong> is a little more complicated. When you set <strong>GRUB_DISABLE_RECOVERY<\/strong> to <strong>true<\/strong>, one menu entry will be generated for each Linux kernel. When set to <strong>false<\/strong>, two menu entries are created for each kernel: One default entry and one entry for recovery mode. This option lists command-line arguments to be added only to the default menu entry, after those listed in <strong>GRUB_CMDLINE_LINUX<\/strong>.<\/p>\n<p>The other two arguments define how the kernel startup looks on the display. The <strong>&#8220;quiet&#8221;<\/strong> argument disables most of the informational messages emitted by the kernel during its startup and self-configuration. The <strong>&#8220;splash&#8221;<\/strong> argument causes the splash screen to be displayed during kernel startup. The splash screen can be a graphic such as a logo or an animation.<\/p>\n<p>My <code>\/etc\/default\/grub<\/code> file looks like this after making those additions:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"text geshifilter-text\">GRUB_TIMEOUT=5<br>\nGRUB_DISTRIBUTOR=\"$(sed 's, release .*$,,g' \/etc\/system-release)\"<br>\nGRUB_DEFAULT=saved<br>\nGRUB_DISABLE_SUBMENU=true<br>\nGRUB_TERMINAL_OUTPUT=\"console\"<br>\nGRUB_CMDLINE_LINUX=\"rhgb quiet\"<br>\nGRUB_DISABLE_RECOVERY=\"true\"<br>\nGRUB_ENABLE_BLSCFG=true<br>\nGRUB_CMDLINE_LINUX_DEFAULT=\"ipv6.disable=1 quiet splash\"<br>\nGRUB_CMDLINE_LINUX=\"ipv6.disable=1\"<\/div><\/div><\/pre>\n<p>After making these (or any) additions to the <code>\/etc\/default\/grub<\/code> file, run the <code>grub2-mkconfig<\/code> command, which adds these arguments to the kernel command line in the <code>grub.cfg<\/code> configuration file for each installed kernel. These changes do not take effect immediately. You must reboot the hosts for IPv6 to be disabled.<\/p>\n<h2>Automate this solution<\/h2>\n<p>Automating these tasks using Ansible is straightforward. Just create a playbook with the following settings and run it against the list of hosts that need this change. The first two tasks in this playbook append the desired configuration:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"yaml geshifilter-yaml\"><span class=\"co3\">- name<\/span><span class=\"sy2\">: <\/span>Play 1 - Modify \/etc\/default\/grub to configure kernel boot parameters.<span class=\"co3\"><br>\n\u00a0 hosts<\/span><span class=\"sy2\">: <\/span>f36vm<br><span class=\"co4\"><br>\n\u00a0 tasks<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>Append GRUB_CMDLINE_LINUX_DEFAULT variable to \/etc\/default\/grub<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 lineinfile<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 path<\/span><span class=\"sy2\">: <\/span>\/etc\/default\/grub<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 insertafter<\/span><span class=\"sy2\">: <\/span>EOF<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 line<\/span><span class=\"sy2\">: <\/span>'GRUB_CMDLINE_LINUX_DEFAULT=<span class=\"st0\">\"ipv6.disable=1 quiet splash\"<\/span>'<br><span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>Append GRUB_CMDLINE_LINUX variable to \/etc\/default\/grub<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 lineinfile<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 path<\/span><span class=\"sy2\">: <\/span>\/etc\/default\/grub<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 insertafter<\/span><span class=\"sy2\">: <\/span>EOF<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 line<\/span><span class=\"sy2\">: <\/span>'GRUB_CMDLINE_LINUX=<span class=\"st0\">\"ipv6.disable=1\"<\/span>'<br><span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>Run grub2-mkconfig to update \/boot\/grub\/grub.cfg<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 command<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 cmd<\/span><span class=\"sy2\">: <\/span>grub2-mkconfig<\/div><\/div><\/pre>\n<p>Once again, you must reboot the hosts for IPv6 to be disabled. You can add the reboot to the playbook so that the changes take effect immediately, or wait until the next time the hosts need to be rebooted for other reasons.<\/p>\n<h2>The other solution<\/h2>\n<p>I created another solution; it is just not the best and most elegant option. However, I want to show my thought process because there is some information here that might be useful.<\/p>\n<h3>Add a local file to sysctl.d<\/h3>\n<p>You can use the <code>\/etc\/sysctl<\/code> file to add the configuration settings necessary, but it is much better to add a local file to the <code>\/etc\/sysctl.d<\/code> directory so that it won&#8217;t be overwritten during updates or upgrades. Note that there is already a file named <code>99-sysctl.conf<\/code>. You can use that file to set the configuration, but I created a file named <code>99-local-network.conf<\/code> with the following content for this purpose. That way, if the <code>99-sysctl.conf<\/code> changes with future updates or upgrades, my file will remain untouched. This is not an executable file; it is a configuration file.<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"text geshifilter-text\">################################################################################<br>\n# Local NetworkManager settings - Specifically to disable IPV6 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 #<br>\n################################################################################<br>\n#<br>\nnet.ipv6.conf.all.disable_ipv6 = 1<br>\nnet.ipv6.conf.default.disable_ipv6 = 1<\/div><\/div><\/pre>\n<p><strong>Note<\/strong>: Like many configuration files in configuration directories like this one, the files contained in the directory are read in natural sorted order. That means the value for a variable declared in a file with a later sort order will override an earlier declaration for the same variable.<\/p>\n<p>A reboot is usually used to cause these changes to take effect, but I later learned how to do so without a reboot. I rebooted my system and reran the <code>nmcli<\/code> command with the following results:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\"><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>wally ~<span class=\"br0\">]<\/span><span class=\"co0\"># nmcli<\/span><br>\nenp4s0: connected to enp4s0<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"Realtek RTL8111\/8168\/8411\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ethernet <span class=\"br0\">(<\/span>r8169<span class=\"br0\">)<\/span>, <span class=\"nu0\">84<\/span>:<span class=\"nu0\">16<\/span>:F9:04:<span class=\"nu0\">44<\/span>:03, hw, mtu <span class=\"nu0\">1500<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ip4 default<br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet4 45.20.209.41<span class=\"sy0\">\/<\/span><span class=\"nu0\">29<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 45.20.209.40<span class=\"sy0\">\/<\/span><span class=\"nu0\">29<\/span> metric <span class=\"nu0\">101<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 default via 45.20.209.46 metric <span class=\"nu0\">101<\/span><br><br>\nenp1s0: connected to enp1s0<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"Realtek RTL8111\/8168\/8411\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ethernet <span class=\"br0\">(<\/span>r8169<span class=\"br0\">)<\/span>, <span class=\"nu0\">84<\/span>:<span class=\"nu0\">16<\/span>:F9:03:E9:<span class=\"nu0\">89<\/span>, hw, mtu <span class=\"nu0\">1500<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet4 192.168.10.1<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 192.168.10.0<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span> metric <span class=\"nu0\">102<\/span><br><br>\nenp2s0: connected to enp2s0<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"Realtek RTL8111\/8168\/8411\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ethernet <span class=\"br0\">(<\/span>r8169<span class=\"br0\">)<\/span>, <span class=\"nu0\">84<\/span>:<span class=\"nu0\">16<\/span>:F9:03:FD:<span class=\"nu0\">85<\/span>, hw, mtu <span class=\"nu0\">1500<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet4 192.168.0.254<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 192.168.0.0<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span> metric <span class=\"nu0\">100<\/span><br><br>\nlo: unmanaged<br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"lo\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 loopback <span class=\"br0\">(<\/span>unknown<span class=\"br0\">)<\/span>, 00:00:00:00:00:00, sw, mtu <span class=\"nu0\">65536<\/span><br><br>\nDNS configuration:<br>\n\u00a0 \u00a0 \u00a0 \u00a0 servers: 192.168.0.52 8.8.8.8 8.8.4.4<br>\n\u00a0 \u00a0 \u00a0 \u00a0 interface: enp4s0<br><br>\n\u00a0 \u00a0 \u00a0 \u00a0 servers: 192.168.0.52 8.8.8.8<br>\n\u00a0 \u00a0 \u00a0 \u00a0 interface: enp2s0<br><br>\n\u00a0 \u00a0 \u00a0 \u00a0 servers: 192.168.0.52 8.8.8.8<br>\n\u00a0 \u00a0 \u00a0 \u00a0 interface: enp1s0<\/div><\/div><\/pre>\n<p>This shows that my simple fix worked.<\/p>\n<h3>Except&#8230;<\/h3>\n<p>Except that solution only works on one of my twelve Linux computers. After writing the above part of this article, I started installing this fix on all of my other hosts. I had only done one system when I realized that this approach did not always work. I then tried it on one of my VMs and it also failed there. As best I can tell, it only works on one host\u2014the one I use as my firewall and router.<\/p>\n<p>After some additional research on a VM, I discovered that these settings could also be issued as commands using <code>sysctl<\/code> so that the system would not need a reboot. I could enter those commands from the command line to deactivate IPv6. Here&#8217;s an example:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\"><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\"># sysctl -w net.ipv6.conf.all.disable_ipv6=1<\/span><br>\nnet.ipv6.conf.all.disable_ipv6 = <span class=\"nu0\">1<\/span><br><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\"># sysctl -w net.ipv6.conf.default.disable_ipv6=1<\/span><br>\nnet.ipv6.conf.default.disable_ipv6 = <span class=\"nu0\">1<\/span><br><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\"># nmcli<\/span><br>\nenp0s3: connected to Wired connection <span class=\"nu0\">1<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 <span class=\"st0\">\"Intel 82540EM\"<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ethernet <span class=\"br0\">(<\/span>e1000<span class=\"br0\">)<\/span>, 08:00:<span class=\"nu0\">27<\/span>:07:CD:FE, hw, mtu <span class=\"nu0\">1500<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 ip4 default<br>\n\u00a0 \u00a0 \u00a0 \u00a0 inet4 192.168.0.136<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 192.168.0.0<span class=\"sy0\">\/<\/span><span class=\"nu0\">24<\/span> metric <span class=\"nu0\">100<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 route4 default via 192.168.0.254 metric <span class=\"nu0\">100<\/span><br><br>\nlo: unmanaged<br><span class=\"sy0\">SNIP<span class=\"sy0\">&gt;<\/span><\/span><\/div><\/div><\/pre>\n<p>It took some time to research this and determine that the file I created was not being read\u2013or at least not processed\u2013by <code>sysctl<\/code> during the Linux startup. Or, if it was, it was being ignored or the settings were being overwritten later by the same variables with different values. After this, I knew that there was no deeper problem preventing it.<\/p>\n<h3>About sysctl<\/h3>\n<p>At this point, I looked into the <code>sysctl<\/code> command in more detail. The purpose of the <code>sysctl<\/code> command is to set kernel parameters in the <code>\/proc<\/code> directory. The root user can use it to set individual parameters from the command line. In addition\u2013and this is the key to my solution\u2013you can use it to view and set all of the kernel parameters stored in several locations, including <code>\/etc\/sysctl.conf<\/code> and in files located in <code>\/etc\/sysctl.d<\/code>. The <code>sysctl<\/code> command is used during Linux startup to set the kernel parameters.<\/p>\n<p>I repeat: The system and the sysadmin can use the <code>sysctl<\/code> command to view and set kernel variables while the system is up and running and without a reboot. This command and the power it offers the Linux sysadmin is one of the most significant differences between Linux and other operating systems. It gives us a tool to do things impossible on other OSs.<\/p>\n<p>I tested this by rebooting the VM and running the following command to set the variables in all locations listed on the <code>sysctl<\/code> man page:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\"><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\"># sysctl --system<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">10<\/span>-default-yama-scope.conf ...<br>\nkernel.yama.ptrace_scope = <span class=\"nu0\">0<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">50<\/span>-coredump.conf ...<br>\nkernel.core_pattern = <span class=\"sy0\">|\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>systemd<span class=\"sy0\">\/<\/span>systemd-coredump <span class=\"sy0\">%<\/span>P <span class=\"sy0\">%<\/span>u <span class=\"sy0\">%<\/span>g <span class=\"sy0\">%<\/span>s <span class=\"sy0\">%<\/span>t <span class=\"sy0\">%<\/span>c <span class=\"sy0\">%<\/span>h<br>\nkernel.core_pipe_limit = <span class=\"nu0\">16<\/span><br>\nfs.suid_dumpable = <span class=\"nu0\">2<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">50<\/span>-default.conf ...<br>\nkernel.sysrq = <span class=\"nu0\">16<\/span><br>\nkernel.core_uses_pid = <span class=\"nu0\">1<\/span><br>\nnet.ipv4.conf.default.rp_filter = <span class=\"nu0\">2<\/span><br>\nsysctl: setting key <span class=\"st0\">\"net.ipv4.conf.all.rp_filter\"<\/span>: Invalid argument<br>\nnet.ipv4.conf.default.accept_source_route = <span class=\"nu0\">0<\/span><br>\nsysctl: setting key <span class=\"st0\">\"net.ipv4.conf.all.accept_source_route\"<\/span>: Invalid argument<br>\nnet.ipv4.conf.default.promote_secondaries = <span class=\"nu0\">1<\/span><br>\nsysctl: setting key <span class=\"st0\">\"net.ipv4.conf.all.promote_secondaries\"<\/span>: Invalid argument<br>\nnet.ipv4.ping_group_range = <span class=\"nu0\">0<\/span> <span class=\"nu0\">2147483647<\/span><br>\nnet.core.default_qdisc = fq_codel<br>\nfs.protected_hardlinks = <span class=\"nu0\">1<\/span><br>\nfs.protected_symlinks = <span class=\"nu0\">1<\/span><br>\nfs.protected_regular = <span class=\"nu0\">1<\/span><br>\nfs.protected_fifos = <span class=\"nu0\">1<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">50<\/span>-libkcapi-optmem_max.conf ...<br>\nnet.core.optmem_max = <span class=\"nu0\">81920<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">50<\/span>-libreswan.conf ...<br>\nnet.ipv6.conf.default.accept_redirects = <span class=\"nu0\">0<\/span><br>\nnet.ipv6.conf.all.accept_redirects = <span class=\"nu0\">0<\/span><br>\nnet.ipv4.conf.default.send_redirects = <span class=\"nu0\">0<\/span><br>\nnet.ipv4.conf.default.accept_redirects = <span class=\"nu0\">0<\/span><br>\nnet.ipv4.conf.all.send_redirects = <span class=\"nu0\">0<\/span><br>\nnet.ipv4.conf.all.accept_redirects = <span class=\"nu0\">0<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">50<\/span>-pid-max.conf ...<br>\nkernel.pid_max = <span class=\"nu0\">4194304<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>etc<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">99<\/span>-local-network.conf ...<br>\nnet.ipv6.conf.all.disable_ipv6 = <span class=\"nu0\">1<\/span><br>\nnet.ipv6.conf.default.disable_ipv6 = <span class=\"nu0\">1<\/span><br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>etc<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">99<\/span>-sysctl.conf ...<br><span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>etc<span class=\"sy0\">\/<\/span>sysctl.conf ...<br><br><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\">#<\/span><\/div><\/div><\/pre>\n<p>Checking the status of the NIC with the <code>nmcli<\/code> command showed that IPv6 had been disabled and that IPv4 was still up and running. Yes, I do see the other errors in that data stream, but I am ignoring them for now. Be sure to read the man page for the <code>sysctl<\/code> command as it is quite interesting. It provides a method for processing all <code>sysctl<\/code> configuration files with the <code>--service<\/code> option.<\/p>\n<h3>The solution<\/h3>\n<p>Now that I understood the true nature of the problem, I could create a real solution\u2013even if it might be only a temporary circumvention. I was able to do so in a way that is in keeping with the original intent of the Linux startup sequence and the <code>sysctl.d<\/code> method for configuring the kernel.<\/p>\n<p>I left my new configuration file in place in <code>\/etc\/sysctl.d<\/code>. I created the simple Bash script shown below to run the <code>sysctl --system<\/code> command and stored it in <code>\/usr\/local\/bin<\/code>.<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\"><span class=\"co0\">#!\/bin\/bash<\/span><br><span class=\"sy0\">SNIP \u2013 discarded a bunch of comments to save space<span class=\"sy0\">&gt;<\/span><br>\nsysctl <span class=\"re5\">--system<\/span><\/span><\/div><\/div><\/pre>\n<p>I tested this script multiple times before proceeding to ensure that it worked. If you do this, be sure to test it multiple times, both with and without rebooting, to return to the original kernel configuration.<\/p>\n<h3>Create the service<\/h3>\n<p>The real key to this solution was to create a new <code>systemd<\/code> service that would work similarly to the old <code>rc.local<\/code> SystemV script. In this case, I called it the <code>MyStartup.service<\/code>, and I renamed the script I created above and called it <code>MyStartup.sh<\/code>. To create the service itself, I created a new <code>systemd<\/code> unit file in the <code>\/usr\/local\/lib\/systemd\/system<\/code> directory, which I also had to make. This service will run once at startup. I named this new file <code>MyStartup.service<\/code> and added the following content:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"text geshifilter-text\"><snip discarded a bunch of comments to save space><br>\n[Unit]<br>\nDescription=Runs \/usr\/local\/bin\/MyStartup.sh<br><br>\n[Service]<br>\nExecStart=\/usr\/local\/bin\/MyStartup.sh<br><br>\n[Install]<br>\nWantedBy=multi-user.target<\/snip><\/div><\/div><\/pre>\n<p>Note that <code>systemd<\/code> unit files like this one don&#8217;t need to be executable. It is owned by root.root with 664 permissions. It&#8217;s pretty simple to create this service, and I can use it for so many local startup tasks that I plan to keep it even when there is a permanent fix to the extant problem.<\/p>\n<p>The command below enables the new service. Note that the <code>systemctl<\/code> command searches the new directory by default without any options, arguments, or prodding from me to locate the new unit file.<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\"><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\"># systemctl enable MyStartup.service<\/span><br>\nCreated symlink <span class=\"sy0\">\/<\/span>etc<span class=\"sy0\">\/<\/span>systemd<span class=\"sy0\">\/<\/span>system<span class=\"sy0\">\/<\/span>multi-user.target.wants<span class=\"sy0\">\/<\/span>MyStartup.service \u2192 <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>systemd<span class=\"sy0\">\/<\/span>system<span class=\"sy0\">\/<\/span>MyStartup.service.<\/div><\/div><\/pre>\n<p>Enabling the service does not run the <code>MyStartup.sh<\/code> script. This service will run the script at every reboot.<\/p>\n<h3>Testing<\/h3>\n<p>As soon as the VM rebooted, I logged in as root and ran the following command to check the status of IPv6, but it was still active. After more testing, I determined that the service was running the commands too soon, so I added a command to the <code>MyStartup.sh<\/code> script to sleep for 25 seconds before running the commands. Here is the edited script:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"text geshifilter-text\">#!\/bin\/bash<br><snip discarded a bunch of comments to save space><br>\n# Wait a bit for things to start up and settle. It doesn't work without this.<br>\nsleep 25<br>\n# Run the sysctl command.<br>\nsysctl --system<\/snip><\/div><\/div><\/pre>\n<p>I rebooted again and verified the status as soon as I could log in, with the result that the service was still sleeping.<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\"><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\"># systemctl status MyStartup.service<\/span><br>\n\u25cf MyStartup.service - Runs <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>bin<span class=\"sy0\">\/<\/span>MyStartup.sh<br>\n\u00a0 \u00a0 \u00a0Loaded: loaded <span class=\"br0\">(<\/span><span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>systemd<span class=\"sy0\">\/<\/span>system<span class=\"sy0\">\/<\/span>MyStartup.service; enabled; vendor preset: disabled<span class=\"br0\">)<\/span><br>\n\u00a0 \u00a0 \u00a0Active: active <span class=\"br0\">(<\/span>running<span class=\"br0\">)<\/span> since Fri <span class=\"nu0\">2022<\/span>-07-01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">22<\/span> EDT; 14s ago<br>\n\u00a0 \u00a0Main PID: <span class=\"nu0\">667<\/span> <span class=\"br0\">(<\/span>MyStartup.sh<span class=\"br0\">)<\/span><br>\n\u00a0 \u00a0 \u00a0 Tasks: <span class=\"nu0\">2<\/span> <span class=\"br0\">(<\/span>limit: <span class=\"nu0\">14129<\/span><span class=\"br0\">)<\/span><br>\n\u00a0 \u00a0 \u00a0Memory: 592.0K<br>\n\u00a0 \u00a0 \u00a0 \u00a0 CPU: 1ms<br>\n\u00a0 \u00a0 \u00a0CGroup: <span class=\"sy0\">\/<\/span>system.slice<span class=\"sy0\">\/<\/span>MyStartup.service<br>\n\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u251c\u2500 <span class=\"nu0\">667<\/span> <span class=\"sy0\">\/<\/span>bin<span class=\"sy0\">\/<\/span><span class=\"kw2\">bash<\/span> <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>bin<span class=\"sy0\">\/<\/span>MyStartup.sh<br>\n\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u2514\u2500 <span class=\"nu0\">669<\/span> <span class=\"kw2\">sleep<\/span> <span class=\"nu0\">25<\/span><\/div><\/div><\/pre>\n<p>After waiting some additional time, I checked again, and the service had completed successfully, with the results clearly shown in the last few journal entries. Further testing showed that a delay of three seconds works reliably, while a delay of only one second always fails.<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"bash geshifilter-bash\">Jul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">22<\/span> f36vm.both.org systemd<span class=\"br0\">[<\/span><span class=\"nu0\">1<\/span><span class=\"br0\">]<\/span>: Started MyStartup.service - Runs <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>bin<span class=\"sy0\">\/<\/span>MyStartup.sh.<br><br><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\"># systemctl status MyStartup.service<\/span><br>\n\u25cb MyStartup.service - Runs <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>bin<span class=\"sy0\">\/<\/span>MyStartup.sh<br>\n\u00a0 \u00a0 \u00a0Loaded: loaded <span class=\"br0\">(<\/span><span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>systemd<span class=\"sy0\">\/<\/span>system<span class=\"sy0\">\/<\/span>MyStartup.service; enabled; vendor preset: disabled<span class=\"br0\">)<\/span><br>\n\u00a0 \u00a0 \u00a0Active: inactive <span class=\"br0\">(<\/span>dead<span class=\"br0\">)<\/span> since Fri <span class=\"nu0\">2022<\/span>-07-01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> EDT; 358ms ago<br>\n\u00a0 \u00a0 Process: <span class=\"nu0\">667<\/span> <span class=\"re2\">ExecStart<\/span>=<span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>local<span class=\"sy0\">\/<\/span>bin<span class=\"sy0\">\/<\/span>MyStartup.sh <span class=\"br0\">(<\/span><span class=\"re2\">code<\/span>=exited, <span class=\"re2\">status<\/span>=<span class=\"nu0\">0<\/span><span class=\"sy0\">\/<\/span>SUCCESS<span class=\"br0\">)<\/span><br>\n\u00a0 \u00a0Main PID: <span class=\"nu0\">667<\/span> <span class=\"br0\">(<\/span><span class=\"re2\">code<\/span>=exited, <span class=\"re2\">status<\/span>=<span class=\"nu0\">0<\/span><span class=\"sy0\">\/<\/span>SUCCESS<span class=\"br0\">)<\/span><br>\n\u00a0 \u00a0 \u00a0 \u00a0 CPU: 9ms<br><br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: net.ipv4.conf.all.send_redirects = <span class=\"nu0\">0<\/span><br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: net.ipv4.conf.all.accept_redirects = <span class=\"nu0\">0<\/span><br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: <span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>lib<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">50<\/span>-pid-max.conf ...<br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: kernel.pid_max = <span class=\"nu0\">4194304<\/span><br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: <span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>etc<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">99<\/span>-local-network.conf ...<br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: net.ipv6.conf.all.disable_ipv6 = <span class=\"nu0\">1<\/span><br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: net.ipv6.conf.default.disable_ipv6 = <span class=\"nu0\">1<\/span><br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: <span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>etc<span class=\"sy0\">\/<\/span>sysctl.d<span class=\"sy0\">\/<\/span><span class=\"nu0\">99<\/span>-sysctl.conf ...<br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org MyStartup.sh<span class=\"br0\">[<\/span><span class=\"nu0\">1020<\/span><span class=\"br0\">]<\/span>: <span class=\"sy0\">*<\/span> Applying <span class=\"sy0\">\/<\/span>etc<span class=\"sy0\">\/<\/span>sysctl.conf ...<br>\nJul 01 <span class=\"nu0\">13<\/span>:<span class=\"nu0\">24<\/span>:<span class=\"nu0\">47<\/span> f36vm.both.org systemd<span class=\"br0\">[<\/span><span class=\"nu0\">1<\/span><span class=\"br0\">]<\/span>: MyStartup.service: Deactivated successfully.<br><br><span class=\"br0\">[<\/span>root<span class=\"sy0\">@<\/span>f36vm ~<span class=\"br0\">]<\/span><span class=\"co0\">#<\/span><\/div><\/div><\/pre>\n<p>You can see in the data output above that the configuration statements in the <code>99-sysctl.conf<\/code> file were applied. I also used the <code>nmcli<\/code> command to verify that IPv6 has been disabled.<\/p>\n<h3>Automate it<\/h3>\n<p>After figuring out how to consistently accomplish this solution, I added a set of tasks to do this to the Ansible playbook I use to distribute new and updated configuration files. That makes it easy for me to manage my 12 current hosts. I also added it to the playbook I use immediately after performing a basic installation on new hosts or ones that need a reinstallation for some reason. I added the following tasks to those playbooks.<\/p>\n<p>This first set of tasks is for my solution to add a new service:<\/p>\n<pre>\n<div class=\"geshifilter\"><div class=\"yaml geshifilter-yaml\"><span class=\"co3\"> \u00a0 \u00a0- name<\/span><span class=\"sy2\">: <\/span>Install 99-local-network.conf file to disable IPV6<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 copy<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 src<\/span><span class=\"sy2\">: <\/span>\/root\/ansible\/system-scripts\/files\/99-local-network.conf<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 dest<\/span><span class=\"sy2\">: <\/span>\/etc\/sysctl.d<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 mode<\/span><span class=\"sy2\">: <\/span>0644<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 owner<\/span><span class=\"sy2\">: <\/span>root<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 group<\/span><span class=\"sy2\">: <\/span>root<br><span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>Install MyStartup.sh<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 copy<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 src<\/span><span class=\"sy2\">: <\/span>\/root\/ansible\/system-scripts\/files\/MyStartup.sh<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 dest<\/span><span class=\"sy2\">: <\/span>\/usr\/local\/bin<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 mode<\/span><span class=\"sy2\">: <\/span>0754<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 owner<\/span><span class=\"sy2\">: <\/span>root<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 group<\/span><span class=\"sy2\">: <\/span>root<br><span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>create \/root\/ansible\/system-scripts\/files\/ directory<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 file<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 path<\/span><span class=\"sy2\">: <\/span>\/root\/ansible\/system-scripts\/files\/<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 state<\/span><span class=\"sy2\">: <\/span>directory<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 mode<\/span><span class=\"sy2\">: <\/span>0755<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 owner<\/span><span class=\"sy2\">: <\/span>root<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 group<\/span><span class=\"sy2\">: <\/span>root \u00a0<br>\n\u00a0 \u00a0 \u00a0 <span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>Install MyStartup.service<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 copy<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 src<\/span><span class=\"sy2\">: <\/span>\/root\/ansible\/system-scripts\/files\/MyStartup.service<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 dest<\/span><span class=\"sy2\">: <\/span>\/usr\/local\/lib\/systemd\/system\/<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 mode<\/span><span class=\"sy2\">: <\/span>0664<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 owner<\/span><span class=\"sy2\">: <\/span>root<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 group<\/span><span class=\"sy2\">: <\/span>root<br><span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>Enable the MyStartup.service<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 systemd<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 name<\/span><span class=\"sy2\">: <\/span>MyStartup.service<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 state<\/span><span class=\"sy2\">: <\/span>stopped<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 enabled<\/span><span class=\"sy2\">: <\/span><span class=\"kw1\">yes<\/span><br><span class=\"co3\"><br>\n\u00a0 \u00a0 - name<\/span><span class=\"sy2\">: <\/span>Run the raw command to disable IPV4 so a reboot is not required at this time<span class=\"co4\"><br>\n\u00a0 \u00a0 \u00a0 command<\/span>:<span class=\"co3\"><br>\n\u00a0 \u00a0 \u00a0 \u00a0 cmd<\/span><span class=\"sy2\">: <\/span>sysctl --system<\/div><\/div><\/pre>\n<p>The advantage of this more complex solution of adding the configuration file to the <code>sysctl.d<\/code> directory and then running a playbook with this series of tasks is it disables IPv6 without requiring a reboot.<\/p>\n<\/p>\n<div class=\"embedded-resource-list callout-float-right\">\n<div class=\"field field--name-title field--type-string field--label-hidden field__item\">More for sysadmins<\/div>\n<div class=\"field field--name-links field--type-link field--label-hidden field__items\">\n<div class=\"field__item\"><a href=\"https:\/\/www.redhat.com\/sysadmin\/?intcmp=7013a000002CxqpAAC\">Enable Sysadmin blog<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/go.redhat.com\/automated-enterprise-ebook-20180920?intcmp=7013a000002CxqpAAC\">The Automated Enterprise: A guide to managing IT with automation<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/downloads\/ansible-quickstart?intcmp=7013a000002CxqpAAC\">eBook: Ansible automation for Sysadmins<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/www.redhat.com\/en\/engage\/system-administrator-guide-s-202107300146?intcmp=7013a000002CxqpAAC\">Tales from the field: A system administrator&#8217;s guide to IT automation<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/downloads\/kubernetes-sysadmin?intcmp=7013a000002CxqpAAC\">eBook: A guide to Kubernetes for SREs and sysadmins<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/tags\/sysadmin?intcmp=7013a000002CxqpAAC\">Latest sysadmin articles<\/a><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2>Final thoughts<\/h2>\n<p>Although just installing the file with the correct kernel parameters and rebooting worked fine on one of my hosts, it failed on all of the others I tried. I looked for differences that might explain why it failed on the others while working on my router\/firewall but found nothing that provided a clue as to why this is so. I discovered this problem exists on hosts with newly installed Fedora 36 without any of the changes and post-installation configuration that I always perform and on those with my usual changes. I do plan to keep investigating. I intend to submit a bug report to Red Hat so that there might be an actual fix to this instead of either of these circumventions.<\/p>\n<p>Neither circumvention depends upon the existence of any NIC configuration files\u2014either the old-style interface configuration files that used to be located in <code>\/etc\/sysconfig\/network-scripts<\/code> or the newer NetworkManager interface connection files located in the <code>\/etc\/NetworkManager\/system-connections<\/code> directory. It works with or without those files. The result is global for all network interfaces on the host.<\/p>\n<p>My own solution is a somewhat general approach that you can use in lieu of the old <code>rc.local<\/code> script of the old SystemV startup days.<\/p>\n<h3>Resources<\/h3>\n<p>The following resources are kept as current as possible but may not be completely accurate at any given time.<\/p>\n<ul>\n<li>The GRUB manual is available in multiple formats from the <a href=\"https:\/\/www.gnu.org\/\" target=\"_blank\" rel=\"noopener\">GNU website<\/a>.<\/li>\n<li>The Fedora documentation website has an excellent page, <a href=\"https:\/\/docs.fedoraproject.org\/en-US\/quick-docs\/bootloading-with-grub2\/\" target=\"_blank\" rel=\"noopener\">Bootloading with GRUB2<\/a>.<\/li>\n<li>The Red Hat RHEL 7 online documentation also has a good chapter about working with the GRUB2 boot loader.<\/li>\n<li>The <a href=\"https:\/\/kernel.org\/\" target=\"_blank\" rel=\"noopener\">kernel.org<\/a> website has a long list of kernel parameters and a huge amount of other information about the Linux kernel.<\/li>\n<\/ul>\n<\/div>\n<div class=\"clearfix text-formatted field field--name-field-article-subhead field--type-text-long field--label-hidden field__item\">\n<p>Simplify your home network by disabling IPv6.<\/p>\n<\/div>\n<div class=\"field field--name-field-lead-image field--type-entity-reference field--label-hidden field__item\">\n<article class=\"media media--type-image media--view-mode-caption\">\n<div class=\"field field--name-field-media-image field--type-image field--label-hidden field__item\">  <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2022\/08\/connections_wires_sysadmin_cable.png\" width=\"1040\" height=\"584\" alt=\"Multi-colored and directional network computer cables\" title=\"Multi-colored and directional network computer cables\"><\/div>\n<\/article>\n<\/div>\n<div class=\"field field--name-field-tags field--type-entity-reference field--label-hidden field__items\">\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/tags\/sysadmin\" hreflang=\"en\">Sysadmin<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/tags\/networking\" hreflang=\"en\">Networking<\/a><\/div>\n<div class=\"field__item\"><a href=\"https:\/\/opensource.com\/tags\/linux\" hreflang=\"en\">Linux<\/a><\/div>\n<\/p><\/div>\n<div class=\"hidden field field--name-field-listicle-title field--type-string field--label-hidden field__item\">What to read next<\/div>\n<div class=\"field field--name-field-default-license field--type-list-string field--label-hidden field__item\"><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><br \/>\n        <img decoding=\"async\" alt=\"Creative Commons License\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2022\/08\/cc-by-sa-4-1.png\" title=\"This work is licensed under a Creative Commons Attribution-Share Alike 4.0 International License.\"><\/a>This work is licensed under a Creative Commons Attribution-Share Alike 4.0 International License.<\/div>\n<section class=\"field field--name-field-comments field--type-comment field--label-hidden comment-wrapper\">\n<div class=\"comments__count\">\n<div class=\"login\"><a href=\"https:\/\/opensource.com\/user\/register?absolute=1\">Register<\/a> or <a href=\"https:\/\/opensource.com\/user\/login?current=\/rss.xml&amp;absolute=1\">Login<\/a> to post a comment.<\/div>\n<\/p><\/div>\n<\/section>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How I disabled IPv6 on Linux David Both Mon, 08\/01\/2022 &#8211; 03:00 Register or Login to like Register or Login to like IPv6 is a good thing for the Internet in general, but I find it unnecessarily complex for use in most home and small- to medium-size businesses. Like many others, I continue to use [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":66139,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[307],"tags":[],"class_list":["post-66138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-open-source"],"_links":{"self":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/66138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=66138"}],"version-history":[{"count":0,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/66138\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/media\/66139"}],"wp:attachment":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=66138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=66138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=66138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}