1
General Discussion / Re: Ipv6 not staying blocked
« on: June 23, 2021, 02:25:11 pm »ICMP is pretty important for IPv6 functionality and the automatic floating ICMP rule is probably letting the pings out (the logs suggest that).
BTW, “LAN address” just means the interface address on OPNsense. I think you really want “LAN net”. And your “no WAN out” rule won’t do anything.
Thank you for the reply. I'd heard of ICMP but, I didn't know much about it. So, I did a little reading and now I know a little more. If I'm reading things correctly, ICMP might allow someone on the internet to see that the devices in the NoWAN alias exist and who my ISP is but, that's about all.
That also explains the ipv6 leak that allowed DNSLeakTest.com to see my ISP for my VPN group until I disabled ipv6 on the nodes. It may not be possible but, I'll try to come up with a floating rule that will block this.
Thank you for the info on the LAN addresses. I'll make that change. I didn't see a problem with communication on the LAN but, that's probably because my switches were routing the traffic and it never went to the router. Yeah I never saw the out rule triggered. I'll dump it.
Please educate me a little. I believe the ICMP hypothesis is correct but, why don't I see this issue until it's connected a while?