OPNsense Forum

Archive => 22.7 Legacy Series => Topic started by: ylu on December 12, 2022, 08:06:37 AM

Title: ipv6 can't generate outbound rules
Post by: ylu on December 12, 2022, 08:06:37 AM
When I set IPv4 and IPv6 addresses at the same time on the LAN and WAN interfaces, the system can automatically generate IPv4 outbound rules, but cannot generate IPv6 outbound rules. I need to add these Outbound rules for IPv6 manually.
Title: Re: ipv6 can't generate outbound rules
Post by: robgnu on December 12, 2022, 08:13:49 AM
Hey,
do you mean "automatic outbound rules" in Firewall/NAT settings?
You should know that IPv6 does not require NATing, so you don't need any automatic rules.

Best
Robert
Title: Re: ipv6 can't generate outbound rules
Post by: ylu on December 12, 2022, 08:34:05 AM
Yes,But I just want to use IPv6 NAT like in IPv4.Because IPS cannot provide dynamic IPv6 address correctly by dhcpv6 or SLAAC.
Title: Re: ipv6 can't generate outbound rules
Post by: robgnu on December 14, 2022, 06:44:10 AM
Ok, this is not recommended and a bad idea. You should really have a good reason. You can configure IPv6 NAT rules by yourself. This will not happen automatically.

I've tested it here and configured a manual rule. Its working. So if you really want to do this, what exactly doesn't work on your setup?

Bye
Title: Re: ipv6 can't generate outbound rules
Post by: ylu on December 15, 2022, 01:18:11 AM
Be careful! I didn't mean that adding manually not work. I just want automatic generation should be supported like IPv4. Although IPv6 is enough, it does not mean that NATv6 technology is obsolete.
Title: Re: ipv6 can't generate outbound rules
Post by: Patrick M. Hausen on December 15, 2022, 07:50:17 AM
No, it should not. IPv6 was explicitly designed to eliminate NAT.
Title: Re: ipv6 can't generate outbound rules
Post by: bimbar on December 15, 2022, 10:36:36 AM
I might add that even manual outbound didn't work for me with dynamic public ipv6 addresses. After a few changes it stopped switching the outbound NAT IP.