1
18.7 Legacy Series / Re: OpenVPN with OPNsense and IPv6
« on: November 16, 2018, 02:52:00 am »If you have a working IPv6 stack on your firewall (i.e. your workstations show a swimming turtle on https://cav6tf.org) then IPv6 on your OpenVPN tunnels only need a spare /64 each. Showstoppers are:
- Mean ISP's that give you only one /64 or
- Mean ISP's that give you a dynamic range
These are usually IPv4 knee-jerk reactions and show a profound misunderstanding of how stupendously large the address space is. Vote with your feet if you can.
OK, wow, this is very different to the kind of answer that I was expecting but much more informative and educational. Thank you!!
When I finally send the cluster off to the colo facility, I don't expect them to be mean about IPv6 address space. But it adds another dimension of things that I'll need to specify and take into consideration.
Quote
If you want to avoid split tunnel on IPv6 clients you need to push the 2000::/3 route and offer an IPv6 DNS service.
Thanks Bart. Your answer is exactly the kind of thing that I need rather than playing into whatever misinformed notions I suspect that Reddit post had.