OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • IPv6 Prefix Alias
« previous next »
  • Print
Pages: [1]

Author Topic: IPv6 Prefix Alias  (Read 2201 times)

Dr.Disk

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
IPv6 Prefix Alias
« on: February 03, 2024, 03:03:53 pm »
Hi all.

My provider assigns me an IPv4 Address and an IPv6 Prefix /56. I use "Track Interface" for my internal VLANs. That all works great, no problem here. I am looking for an easy way to get a firewall alias with that /56 prefix from my internet provider. I only find aliases for the prefixes of the individual NICs, but none for the prefix from the provider.

Thanks,
Steffen
Logged

emzy

  • Newbie
  • *
  • Posts: 16
  • Karma: 1
    • View Profile
Re: IPv6 Prefix Alias
« Reply #1 on: February 03, 2024, 07:01:02 pm »
I'm not sure I fully understand your question, but under Firewall > Aliases you can configure Dynamic ipv6 Host aliases where only the last 64 bits are static. Just write ::1234:1234:1234:1234 in the content section (obviously replace 1234 with your suffix).
Logged

Dr.Disk

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: IPv6 Prefix Alias
« Reply #2 on: February 03, 2024, 07:17:58 pm »
A short example what i mean. When I connect to the internet I will get a prefix like this:

2a00:abcd:1234:9300::/56

With tracking I could assign for example the id 0x12 for the KIDS network. So the KIDS Network uses addresses like 2a00:abcd:1234:9312::/64. With the Dynamic IPv6 Host alias it is possible to address one pc/server/... in the KIDS network. Just use a mask like ::2345:6789:abcd:0001 and the alias would contain 2a00:abcd:1234:9312:2345:6789:abcd:0001/128. Also there is an alias __opt# containing 2a00:abcd:1234:9312::/64. That is all fine and works for me.

I am looking for an alias containing 2a00:abcd:1234:9300::/56.
 



Logged

emzy

  • Newbie
  • *
  • Posts: 16
  • Karma: 1
    • View Profile
Re: IPv6 Prefix Alias
« Reply #3 on: February 03, 2024, 07:22:36 pm »
Hmm, I'm not sure if you can create an alias like that. Maybe someone else knows.

But there might be another way to achieve your end goal. What are you trying to do?
Logged

Maurice

  • Hero Member
  • *****
  • Posts: 1213
  • Karma: 158
    • View Profile
    • GitHub
Re: IPv6 Prefix Alias
« Reply #4 on: February 04, 2024, 02:42:19 am »
Unfortunately, that's not possible yet. It was discussed back when the dynamic IPv6 alias type was implemented. A decision was made to implement the host alias first and a network alias later (maybe).

Cheers
Maurice
Logged
OPNsense virtual machine images
OPNsense aarch64 firmware repository

Commercial support & engineering available. PM for details (en / de).

Dr.Disk

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: IPv6 Prefix Alias
« Reply #5 on: February 04, 2024, 02:16:27 pm »
@Maurice: Thank you for that information.

@emzy: Yes, there is another way to implement what I want to achieve. But it would be more convenient with the alias described. A small example: I want to allow the access to the internet via IPv6 for all destination addresses, expect the local used prefix.
Logged

zoechi

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: IPv6 Prefix Alias
« Reply #6 on: June 18, 2024, 04:20:05 pm »
The existing/auto-generated aliases that start with double underline (
Code: [Select]
__an_interface_name) look like they could do what I need, but I haven't found a way to use them.
Logged

deasmi

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: IPv6 Prefix Alias
« Reply #7 on: September 05, 2024, 02:42:44 pm »
Quote from: zoechi on June 18, 2024, 04:20:05 pm
The existing/auto-generated aliases that start with double underline (
Code: [Select]
__an_interface_name) look like they could do what I need, but I haven't found a way to use them.

I tried this and it seems to work perfectly.

I created an ngroup_local_network network alias and added __lan_network and __optX_network as appropriate to it.


I then created a rule using destination invert to allow access.

This seems to be working exactly as I want it to
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • IPv6 Prefix Alias
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2