1
24.1 Legacy Series / Dynamic IPv6 prefixes / dynamic DNS / VPN: Handling via NPTv6?
« on: May 31, 2024, 10:38:47 am »
I have two sites, each with their own VLANs, which are connected via Wireguard. Both are only assigned a dynamic /56 IPv6 prefix by the Internet service provider. This is known to cause some complications in the area of DNS and VPN firewall: e.g. devices could enter the changing IPs in the internal DNS, but these would not be routed via the VPN.
I think the easiest way would be to use a private IPv6 prefix and make it accessible to the outside world via NPTv6. As of OPNsense 24.1.x there is the new option “Track interface”. However, you can only create a rule with this if the IPv6 interface is not configured statically but via track interface. Unfortunately, this is unsuitable for this use case, as I then have all kinds of problems with the dynamic IPs in the network.
How should I deal with this problem? I would like to be able to safely activate IPv6 in the internal network at some point.
I think the easiest way would be to use a private IPv6 prefix and make it accessible to the outside world via NPTv6. As of OPNsense 24.1.x there is the new option “Track interface”. However, you can only create a rule with this if the IPv6 interface is not configured statically but via track interface. Unfortunately, this is unsuitable for this use case, as I then have all kinds of problems with the dynamic IPs in the network.
How should I deal with this problem? I would like to be able to safely activate IPv6 in the internal network at some point.

