Quote from: nero355 on April 03, 2026, 10:37:24 PMIn case your IPv6 Prefix changes the amount of editing you need to do is minimal this way :)
Unfortunately this won't do as my ISP assigns me a new IPv6 prefix every time the router reconnects.
Quote from: drosophila on April 04, 2026, 04:05:07 AMI wonder however, shouldn't the default "block any from any" last match rule catch everything already? It should, so you wouldn't need to create aliases for this, is the LAN even reachable from the OPT8 interface by default? This won't show from the OPNsense box due to the "let out anything from the firewall host itself" rule, so you'd need to test it with an actual device on OPT8. From what I see, it should work that way, but I cannot test this because I only have WAN and LAN interfaces.
The default rule does indeed block everything. However it also blocks access to external networks such as ping -6 google.com gets caught in the "default state violation" rule. I followed the "Allow access to all external networks and block all internal networks for local network isolation" rule from here: https://homenetworkguy.com/how-to/create-basic-dmz-network-opnsense/
This makes it possible to access the internet while preventing access to private networks. Is there a better approach to do this?
Quote from: JamesFrisch on April 04, 2026, 09:32:53 AMYou sure it is /59?
That is pretty odd. And not following RIPE recommendations. What is the name of that ISP?
Is it at least static? Or does your ISP there also not follow RIPE recommendations?
It shows up as /59 in the FritzBox:
You cannot view this attachment.
The ISP is Vodafone Germany providing cable internet here.
The prefix is not static and I get assigned a new prefix if the FritzBox reconnects.
"