Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Is it possible to advertise ULA prefix only to IPv6 client?
« previous
next »
Print
Pages: [
1
]
Author
Topic: Is it possible to advertise ULA prefix only to IPv6 client? (Read 2322 times)
ccy
Newbie
Posts: 4
Karma: 0
Is it possible to advertise ULA prefix only to IPv6 client?
«
on:
October 26, 2021, 12:00:12 pm »
Hi,
When configure the IPv6 network access via PPPoE to my ISP, I am able to obtain an GUA IPv6 address (/64) on LAN interface. The /64 public GUA prefix do advertise to my Windows configure the IPv6 only network. The Windows OS have a unique GUA IPv6 too. It can access to IPv6 internet too, so far so good.
Next, I try ULA IPv6. I configure a virtual IP on the LAN interface with ULA IPv6 fd01:2:3:4::1/64. Restart the radvd service, the Windows can has both GUA and ULA address.
Can OPNsense configure to advertise only ULA to the Windows client only?
Logged
Greelan
Hero Member
Posts: 1028
Karma: 72
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #1 on:
October 26, 2021, 01:52:46 pm »
I suspect not, unless there is a manual way through config files. But curious - what is your use case for this?
Logged
ccy
Newbie
Posts: 4
Karma: 0
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #2 on:
October 27, 2021, 02:34:46 am »
I am trying NPTv6. As the windows IPv6 client received both GUA and ULA address, I couldn't confirm if IPv6 traffic was evaluated against NPT rule defined in OPNsense.
My next use case is I have configure a IPv6 load balance multi WAN. I have 3 WAN connections. All 3 WAN offered only /64 IPv6 GUA. I think the only option for internal host to utilize the IPv6 multi wan is via ULA.
Logged
bimbar
Sr. Member
Posts: 435
Karma: 25
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #3 on:
October 28, 2021, 04:51:56 pm »
Yes, you can do local ULA only + NAT or NPTv6 (just like IPv4).
Logged
meschmesch
Full Member
Posts: 184
Karma: 5
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #4 on:
November 05, 2021, 11:51:30 am »
How would a NAT rule look like for ULA? E.g. fd00::
Logged
bimbar
Sr. Member
Posts: 435
Karma: 25
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #5 on:
November 05, 2021, 12:18:32 pm »
Internal Networks (possibly fc00::/7) to Any NAT Outgoing on WAN for IPv6, pretty much.
Logged
Greelan
Hero Member
Posts: 1028
Karma: 72
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #6 on:
November 05, 2021, 12:22:48 pm »
But geez, why persist with NAT on IPv6 unless it is really necessary?
Logged
bimbar
Sr. Member
Posts: 435
Karma: 25
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #7 on:
November 05, 2021, 12:37:21 pm »
Because it is really necessary. There are two main cases:
- You don't have a static IPv6 prefix but still want to do clustering.
- You have a static IPv6 prefix, but want to do multi-wan (you can do NPTv6 in that case).
God knows I tried, but with poor IPv6 support from clients for environments with more than one next-hop, it's not possible to go GUA.
Logged
meschmesch
Full Member
Posts: 184
Karma: 5
Re: Is it possible to advertise ULA prefix only to IPv6 client?
«
Reply #8 on:
November 05, 2021, 12:40:09 pm »
Any modifications to Router advertisement? At the moment it is unmanaged. Dhcpv6?
Is there a reason to construct ipv6 subnets for different interfaces?
«
Last Edit: November 05, 2021, 02:12:35 pm by meschmesch
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Is it possible to advertise ULA prefix only to IPv6 client?