Trying to make this work with my on-prem K8s ingress.
The scenario is
- k8s cluster that peers with opnsense via BGP (and FRR of course)
- service subnet advertisement is done with a ULA subnet (and ingress pinned to a static LB IP)
- All hosted on a separate VLAN
Target setup
- Use NPTv6 to direct all external traffic to that specific ULA ipv6 address
Questions
- what are my settings for nptv6?
I've tried it and I *think* it should listen to the K8s vlan interface since that technically has an ipv6 address (courtesy of track interface), then internal should be...the entire ULA ipv6 address? And then lastly track interface being my K8s vlan interface yes?
When doing that it says "not listening on that interface" but selecting WAN as the interface works (maybe I misunderstand but I feel like that would be wrong but maybe it still is the right choice as providing all the actual external traffic.)
Then lastly I'd set up dynamic DNS to query the IP for traffic on the K8s vlan interface (like the rest I do, just with listening to that interface instead.) Or should that also be on WAN?
Apologies. I've looked but seems there is not a lot of info out there via blogs/videos and the opnsense docs have me confused just a bit (my lack of knowledge, not their lack of detail.)
The scenario is
- k8s cluster that peers with opnsense via BGP (and FRR of course)
- service subnet advertisement is done with a ULA subnet (and ingress pinned to a static LB IP)
- All hosted on a separate VLAN
Target setup
- Use NPTv6 to direct all external traffic to that specific ULA ipv6 address
Questions
- what are my settings for nptv6?
I've tried it and I *think* it should listen to the K8s vlan interface since that technically has an ipv6 address (courtesy of track interface), then internal should be...the entire ULA ipv6 address? And then lastly track interface being my K8s vlan interface yes?
When doing that it says "not listening on that interface" but selecting WAN as the interface works (maybe I misunderstand but I feel like that would be wrong but maybe it still is the right choice as providing all the actual external traffic.)
Then lastly I'd set up dynamic DNS to query the IP for traffic on the K8s vlan interface (like the rest I do, just with listening to that interface instead.) Or should that also be on WAN?
Apologies. I've looked but seems there is not a lot of info out there via blogs/videos and the opnsense docs have me confused just a bit (my lack of knowledge, not their lack of detail.)
"