I dug deep into many sources, many attempts to configure my opnsense, completely reinstalling it, running it directly from installer medium and so on.
My findings:
1) the unwanted address seems to be the vodafone kabel net that seems to be configured automatically via slaac (that i cannot deactivate since freebsd kernel apparently auto-accepts slaac RAs on interfaces)
2) the reason why i have ipv6 working in the beginning and after a while it stops could be that the docsis modem potentially ignores the prefix delegation lease request. since it is not extended it just silently expires and i have not working ipv6 anymore eventhough i still have this "seemingly valid" slaac configured provider address.
I even managed to completely reset my opnsese to factory and the v6 seemed to work at first...but after i made enough changes to have the config i used to have (multiple wireguard instances, a couple of outboud nat rules in hybrid outbound nat setup, dnsmasq deactivated, kea configured to serve dhcpv6 based on interface v6 subnet, RAs configured to WAN: router only, LAN: assisted, at some point i loose the ipv6 connectivity. PLUS my static gateway for one of my wireguard interfaces and respective firewall rule stopped routing traffic from 1 client (1 internal host that should only use the wireguard tunnel for all outbound traffic) through the wireguard but instead route it through wan even though i configured it correctly as before (i even tried the whole thing with ablank firewall and then import the old firewall configuration i previously exported to csv)
my current other problem (even on 25.7.11_9) is, that since i get these two provider IPs , my LAN network works with ipv6, but my opnsense cant communicate with ipv6 outside my own networks since it defaults to use the wrong ipv6 interface address (the x:8101:... address) instead fo the correct one.
i know, i could use nat66 to pin all outbound traffic from my opnsense itself to use the correct IPv6 address, but somehow that breaks as well after a while (i guess, when the lease expires)
things i still haven'T tried:
deactivate slaac on WAN/the whole system all together (i dont want to deactivate it completely, but maybe only for wan?) in tunables. maybe someone could give me some advice whether i should trie that as well?
best regards
My findings:
1) the unwanted address seems to be the vodafone kabel net that seems to be configured automatically via slaac (that i cannot deactivate since freebsd kernel apparently auto-accepts slaac RAs on interfaces)
2) the reason why i have ipv6 working in the beginning and after a while it stops could be that the docsis modem potentially ignores the prefix delegation lease request. since it is not extended it just silently expires and i have not working ipv6 anymore eventhough i still have this "seemingly valid" slaac configured provider address.
I even managed to completely reset my opnsese to factory and the v6 seemed to work at first...but after i made enough changes to have the config i used to have (multiple wireguard instances, a couple of outboud nat rules in hybrid outbound nat setup, dnsmasq deactivated, kea configured to serve dhcpv6 based on interface v6 subnet, RAs configured to WAN: router only, LAN: assisted, at some point i loose the ipv6 connectivity. PLUS my static gateway for one of my wireguard interfaces and respective firewall rule stopped routing traffic from 1 client (1 internal host that should only use the wireguard tunnel for all outbound traffic) through the wireguard but instead route it through wan even though i configured it correctly as before (i even tried the whole thing with ablank firewall and then import the old firewall configuration i previously exported to csv)
my current other problem (even on 25.7.11_9) is, that since i get these two provider IPs , my LAN network works with ipv6, but my opnsense cant communicate with ipv6 outside my own networks since it defaults to use the wrong ipv6 interface address (the x:8101:... address) instead fo the correct one.
i know, i could use nat66 to pin all outbound traffic from my opnsense itself to use the correct IPv6 address, but somehow that breaks as well after a while (i guess, when the lease expires)
things i still haven'T tried:
deactivate slaac on WAN/the whole system all together (i dont want to deactivate it completely, but maybe only for wan?) in tunables. maybe someone could give me some advice whether i should trie that as well?
best regards
"