Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - KalleDK

#1
26.1 Series / Re: Dnsmasq and IPv6
February 10, 2026, 08:07:44 AM
Quote from: Maurice on February 09, 2026, 01:28:10 PM2000::1:1/64 and 2000::2:1/64 is the same network - 2000::/64. You shouldn't have the same network on two interfaces.

Cheers
Maurice

Sorry masked the ip's wrong in the example - have updated some more real
#2
26.1 Series / Dnsmasq and IPv6
February 09, 2026, 12:07:14 PM
### TLDR ###

Clients can reach dnsmasq on all ipv4 addresses
Clients can only reach dnsmasq on it's uplink ipv6 address

####

I rule only dnsmasq and have dualstack ipv4 and ipv6.

If I have two interfaces

NET1
192.168.1.1/24
2000:1234:1::1/64

NET2
192.168.2.1/24
2000:1234:2::1/64


Then I experience following on a client on NET1

Works
nslookup ifconfig.co 192.168.1.1
nslookup ifconfig.co 2000:1234:1::1
nslookup ifconfig.co 192.168.2.1

Doesn't work
nslookup ifconfig.co 2000:1234:2::1

The same is happening the other way round if I do it from NET2

I can't see any firewall rules that should block it
#3
26.1 Series / Re: SSHFP Unbound with Dnsmasq
February 09, 2026, 12:00:49 PM
To others facing this - I ended up ditching Unbound and go pure Dnsmasq
#4
26.1 Series / SSHFP Unbound with Dnsmasq
January 30, 2026, 02:38:11 PM
My setup right now is Unbound handling DNS.
I forward "example.com" to Dnsmasq with the setting (Forward First) and disallow Dnsmasq to use other nameservers.
This allows me to lookup serv01.example.com, that Dnsmaq replies with 192.168.1.10
And lookup serv02.example.com, that Dnsmasq does not know, and Unbound then asks out on the internet and get 80.80.80.80
Everything works - nearly.

Now If I ask for SSHFP records, that Dnsmasq does not know about. I get the records from cloudflare via Unbound, but Unbound does not set the flag
.... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server

Which makes ssh fails when using sshfp.

If I disable the forward to Dnsmasq everything sshfp works because now Unbound sets, but I can no longer lookup local ip's
.... .... ..1. .... = Answer authenticated: Answer/authority portion was authenticated by the server