OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • IPv6 Far Getway
« previous next »
  • Print
Pages: [1]

Author Topic: IPv6 Far Getway  (Read 2394 times)

ovv

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
IPv6 Far Getway
« on: January 23, 2019, 07:11:30 pm »
Hello,

I'm looking into setting up IPv6 on an virtualized opnsene @OVH. For IPv4 I need to enable "Far Gateway" as the gateway is outside the subnet and that works fine. For IPv6 the gateway is also outside the subnet (See https://docs.ovh.com/gb/en/dedicated/network-ipv6 ) but I keep getting:

Quote
The gateway address "xxxx:xxxx:xxxx:xxFF:FF:FF:FF:FF" does not lie within one of the chosen interface's IPv6 subnets.

I'm probably missing a simple thing, I'm fairly new with IPv6 and can't figure out what

Thanks for the help
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: IPv6 Far Getway
« Reply #1 on: January 23, 2019, 07:14:46 pm »
Hi,

Far gateway doesn't work in IPv6. You need to set your WAN to "include" the gateway in the subnet. Looks like /56.


Cheers,
Franco
Logged

ovv

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: IPv6 Far Getway
« Reply #2 on: January 23, 2019, 09:44:23 pm »
Couldn't get it to work even with setting it to /56.
It looks like OVH is doing some weird things with IPv6, not sure if this setup can work
Logged

ovv

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: IPv6 Far Getway
« Reply #3 on: January 23, 2019, 10:46:44 pm »
Ok got it. I forgot to allow IPv6 on the firewall.

Is there any plan to allow far gateway for IPv6 in the future ?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: IPv6 Far Getway
« Reply #4 on: January 23, 2019, 11:23:10 pm »
From multiple experiments with the BSD IPv6 implementation it looked like the stack refuses to use a gateway that does not lie within its own configured IPv6 subnet. This might be due to the assumption that there is no NAT so everything shall be reachable/attached directly.

In most cases it is better to use a link-local gateway to side-step these issues. But that is for the ISP to decide...

Glad you got it working, though. :)


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • IPv6 Far Getway
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2