1
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
2
24.1 Production Series / Re: IPv6 ULA with NPT, when WAN is Dynamic
« on: April 27, 2024, 12:14:44 am »
I have a static /56
3
24.1 Production Series / Re: IPv6 ULA with NPT, when WAN is Dynamic
« on: April 26, 2024, 12:18:49 pm »
No, dual stack.
But obviously being ULA the preference is IPv4 WAN, IPv6 local connectivity, IPv6 WAN
I'm quite happy with that, as we have dual leased lines and only one of them has IPv6, so the IPv4 goes out the main leased line, and the IPv6 goes out the *backup* leased line.
They are both 2GB symetrical, so it doesnt really matter.
Plus, we use wireguard for remote users, so they have IPv6 ULA, and IPv4 privates, so NPTv6 seemed so easy to implement.
But obviously being ULA the preference is IPv4 WAN, IPv6 local connectivity, IPv6 WAN
I'm quite happy with that, as we have dual leased lines and only one of them has IPv6, so the IPv4 goes out the main leased line, and the IPv6 goes out the *backup* leased line.
They are both 2GB symetrical, so it doesnt really matter.
Plus, we use wireguard for remote users, so they have IPv6 ULA, and IPv4 privates, so NPTv6 seemed so easy to implement.
4
24.1 Production Series / Re: IPv6 ULA with NPT, when WAN is Dynamic
« on: April 26, 2024, 12:05:48 pm »
I should also add, NPTv6 is stateless, so not NAT.
5
24.1 Production Series / Re: IPv6 ULA with NPT, when WAN is Dynamic
« on: April 26, 2024, 12:05:21 pm »
I use ULA internally and use NPTv6 to map to GUA.
Main reason for me is to keep a consistent IPv6 address scheme internally, even if the IPv6 prefix changes on the WAN.
I'd just like to add, NPTv6 works *brilliantly* on OPNSense.
Main reason for me is to keep a consistent IPv6 address scheme internally, even if the IPv6 prefix changes on the WAN.
I'd just like to add, NPTv6 works *brilliantly* on OPNSense.
6
24.1 Production Series / Re: Audit / connectivity IPV6 problem
« on: April 03, 2024, 09:47:20 pm »
I get the same issue on the IPv6 test. My IPv6 is via a WireGuard tunnel, but other than that test…works perfect.
7
24.1 Production Series / Re: Strange behaviour with fresh install of OPNSense, R86S and SFP+
« on: March 20, 2024, 08:42:46 am »
Yes indeed.
8
24.1 Production Series / Re: Strange behaviour with fresh install of OPNSense, R86S and SFP+
« on: March 19, 2024, 08:59:13 am »
I'm using an R86S in the exact same config as you with a 10G WAN SFP+ and the other as a 10G LAN SFP+, and I use one of the 2.5G RJ45 as a management port.
I know it doesn't really help you, but I have no issues whatsoever with mine.
I know it doesn't really help you, but I have no issues whatsoever with mine.
9
24.1 Production Series / Re: 24.1 - DHCP server moves to KEA - implications?
« on: March 11, 2024, 12:49:11 pm »
I have a very simplistic setup, so moved over from ISC to KEA.
The main thing I miss is the ability to update unbound with the leases, so currently, I do not have name resolution but other than that, its fine for me.
One little thing, on one of my reservations, I have a device called revo, but when I show it under leases it shows revo. (With a dot)
This is the only device (out of 50) that does this?!?
The main thing I miss is the ability to update unbound with the leases, so currently, I do not have name resolution but other than that, its fine for me.
One little thing, on one of my reservations, I have a device called revo, but when I show it under leases it shows revo. (With a dot)
This is the only device (out of 50) that does this?!?
10
24.1 Production Series / Re: CARP suddenly synchronizing gateway settings -- how to disable?
« on: February 06, 2024, 08:13:04 pm »
24.1.1 not 24.1_1
11
24.1 Production Series / Re: 24.1 running great
« on: February 01, 2024, 08:54:49 am »
Upgraded 2 of 3 production firewalls and all good so far.
Only thing noticed was the already mentioned tidy up of os-wireguard plugin.
Also, I had to update the squid package for it to be ultimately removed in the updates tab, but all good.
Only thing noticed was the already mentioned tidy up of os-wireguard plugin.
Also, I had to update the squid package for it to be ultimately removed in the updates tab, but all good.
12
23.7 Legacy Series / Re: Connectivity audit using weird packet sizes ...
« on: November 23, 2023, 10:40:58 pm »
Would be nice if the packets were not oversized, but an option somewhere to set it to oversize for debug purposes.
I use WireGuard to tunnel in IPv6 from a VPS. IPv6 works fine, but the connectivity check ping doesn’t, but checking packages over IPv6 works.
I use WireGuard to tunnel in IPv6 from a VPS. IPv6 works fine, but the connectivity check ping doesn’t, but checking packages over IPv6 works.
13
23.7 Legacy Series / Re: 23.7.6 update - GUI issues
« on: October 12, 2023, 02:15:23 pm »
Forgot to say Thanks.......
14
23.7 Legacy Series / Re: 23.7.6 update - GUI issues
« on: October 12, 2023, 02:14:28 pm »
I see, hmmm, was better the previous way IMHO.
I can see the delete button now, but was overlapped with text.
New way isn't as clear to me, but hey ho, I wont stand in the way of progress....
I can see the delete button now, but was overlapped with text.
New way isn't as clear to me, but hey ho, I wont stand in the way of progress....
15
23.7 Legacy Series / Re: 23.7.6 update - GUI issues
« on: October 12, 2023, 01:08:22 pm »
Nah, it's broken to the point you cant delete previous history. Let me see if i can grab a screenshot.
https://ibb.co/X4pz0M2
At the bottom of this normally you get a list of the history......not there anymore.
https://ibb.co/X4pz0M2
At the bottom of this normally you get a list of the history......not there anymore.