Quote from: userbenutzer on April 23, 2025, 08:33:32 AMThe internal network identifier (optXX) must be the same on your devices!
Thanks userbenutzer, that was the issue.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: userbenutzer on April 23, 2025, 08:33:32 AMThe internal network identifier (optXX) must be the same on your devices!
Quote from: viragomann on April 22, 2025, 02:02:47 PMQuote from: FlangeMonkey on April 22, 2025, 01:43:48 PMthe rule itself is being removed by the sync process.The rule is removed from the secondary node, because it's not present on the primary, who syncs its rule to it.
But I created the rule in the primary.
Quote from: viragomann on April 22, 2025, 01:33:33 PMI set the rules on the primary with these settings:
source: SYNC subnet
destination: This firewall
This fits for the secondary as well and hence can be synced.
Quote from: Maurice on April 26, 2024, 02:36:43 AM
So you want to use the entire /56 PD for NPT? No GUAs in the LANs at all?
Set the internal IPv6 prefix (source) to your ULA /56, leave the external IPv6 prefix (target) empty and set the track interface to an interface which tracks the WAN interface. Since you don't seem to be using tracking at all, you'll have to create a dummy interface for this purpose. Make sure the IPv6 Prefix ID used there isn't in use for any of your "real" LAN interfaces.
This is a rather new workaround and I haven't personally tested it yet, but I think that's how it's supposed to work. There's currently no "direct" way to use a delegated prefix for NPT.
Quote from: mimugmail on October 06, 2021, 03:20:50 PM
In server instance there should be a checkbox called "Username is Common Name" .. this should help there too, but using certificates is always better than User Auth only