1
General Discussion / Re: WAN DHCPv6 and IPsec
« on: November 21, 2024, 02:30:24 pm »
Thanks for that hint. This has taken me a good step forward.
I have now simply duplicated my existing IPv4 tunnel and switched it to IPv6 and connected the whole thing to the DMZ interface.
Connecting via the VPN now works already - the clients are getting an IPv4 and an IPv6 address. Unfortunately, I now have the problem that those coming via the VPNv6 tunnel have no access to the services in the network and I don't understand why I made a mistake somewhere.
Can someone help me with this?
What I don't understand:
the VPN clients all get an IPv6 with 2a00:aaaa:bbbb:cccc::[XX] - the cccc corresponds to the subnet that is assigned to the DMZ (IPv6 Prefix ID).
I am still grateful for any help
I have now simply duplicated my existing IPv4 tunnel and switched it to IPv6 and connected the whole thing to the DMZ interface.
Connecting via the VPN now works already - the clients are getting an IPv4 and an IPv6 address. Unfortunately, I now have the problem that those coming via the VPNv6 tunnel have no access to the services in the network and I don't understand why I made a mistake somewhere.
Can someone help me with this?
- My Prefix is 2a00:aaaa:bbbb::
- I edited the local subnets of phase 2 to match my prefix with 2a00:aaaa:bbbb:0::/48
- the mobile clients are assigned a virtual IPv6 from the area 2a00:aaaa:bbbb:0::/120
- the IPsec interface of the firewall rules is very liberal with IPv4+6 * * * * * *
What I don't understand:
the VPN clients all get an IPv6 with 2a00:aaaa:bbbb:cccc::[XX] - the cccc corresponds to the subnet that is assigned to the DMZ (IPv6 Prefix ID).
I am still grateful for any help