Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Tutorials and FAQs
»
Possible to use IPv6 for WAN, but IPv4 only for LAN ?
« previous
next »
Print
Pages: [
1
]
Author
Topic: Possible to use IPv6 for WAN, but IPv4 only for LAN ? (Read 800 times)
Twisty2312
Newbie
Posts: 2
Karma: 0
Possible to use IPv6 for WAN, but IPv4 only for LAN ?
«
on:
July 27, 2024, 04:27:01 am »
Hey there,
my ISP now support ipv6. I can set the interface to "Track" ipv6 so each devices have a unique ipv6 from the isp. I don'T want that
1) Now websites and ISP can track a specific device instead of a building/internet connection
2) My brain get too fuzzy trying to make firewall rules on LAN for ipv6 and remembering which IP belongs to which device, etc
3) I don't have time to set all my Pi's to use ipv6, and rearrange all my setup
Is there a way for opnsense to get an ipv6 from WAN, but use NAT with ipv4 on LAN/Wireguard VLAN ?
If I disabled
Track interface
, some devices seem to not be able to use internet at all (looking at you, Android), while all our PCs can still access the internet. Not sure what is going on.
Note that I use OpnSense in a home environment for tinkering and fun.
I thank you for your time.
Logged
meyergru
Hero Member
Posts: 1655
Karma: 164
IT Aficionado
Re: Possible to use IPv6 for WAN, but IPv4 only for LAN ?
«
Reply #1 on:
July 27, 2024, 11:50:08 am »
1. Your conclusions about traceability are incorrect: when you use SLAAC and IPv6 privacy extensions (RFC 4941), the EUI-64 part of the address is randomized, so individual devices cannot be tracked. Also, there are other/better ways to track devices.
2. There is no way to easily "NAT" IPv4 to IPv6, but you could use a transparent proxy which is internally accessed via IPv4 and uses IPv6 for outgoing connections.
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005
1100 down / 440 up
,
Bufferbloat A+
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Tutorials and FAQs
»
Possible to use IPv6 for WAN, but IPv4 only for LAN ?