OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • IPV6 on LAN only
« previous next »
  • Print
Pages: [1]

Author Topic: IPV6 on LAN only  (Read 1480 times)

JoK

  • Full Member
  • ***
  • Posts: 108
  • Karma: 4
    • View Profile
IPV6 on LAN only
« on: May 23, 2024, 06:24:15 pm »
Hi

I have some problems with blocking devices from access Internet if they use IPV6, IPV4 is no problem, just setting up an alias and add static IP adresse from the devices. As I understand, its not the same with IPV6.

My MACs has a feature to only use IPV6 on LAN, is it possible to make OpnSense to do the same…block all IPV6 traffic from LAN to WAN 🙂   That would really be helpfull, i dont want to disable IPV6 completely.

Maybe this could be a feature request…

TIA

John
Logged

Monviech (Cedrik)

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 1660
  • Karma: 178
    • View Profile
Re: IPV6 on LAN only
« Reply #1 on: May 23, 2024, 06:26:56 pm »
Just change the default allow rule on LAN from "IPv4 + IPv6" to only "IPv4".

And then add a rule before that with aliases containing the IPv6 addresses that are allowed access to the internet.

Since IPv6 has Privacy Extension enabled, it can be hard to choose the exact devices since the IP adresses change multiple times a day. You might have to disable that for those devices to get one real static GUA per device. (Of course this can also be set up as block list, but allow lists give you even more control since new devices are blocked per default)
« Last Edit: May 23, 2024, 06:31:42 pm by Monviech »
Logged
Hardware:
DEC740

JoK

  • Full Member
  • ***
  • Posts: 108
  • Karma: 4
    • View Profile
Re: IPV6 on LAN only
« Reply #2 on: May 23, 2024, 06:38:14 pm »
Thanks, that sounds complex 😜 I dont want any IPV6 traffic from LAN to WAN, IPV6 for LAN only. A feature like MAC with tick a box with, “IPV6 for LAN only” would be so much easier….wish thinking probably 😜
Logged

Monviech (Cedrik)

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 1660
  • Karma: 178
    • View Profile
Re: IPV6 on LAN only
« Reply #3 on: May 23, 2024, 06:41:21 pm »
But you will have IPv6 for LAN only if you remove it from the standard allow rule in the LAN. (Turn IPv4/IPv6 into IPv4)

The devices communicate directly with each other, the firewall doesn't block that traffic. But it will block all traffic going to the WAN that way.
Logged
Hardware:
DEC740

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: IPV6 on LAN only
« Reply #4 on: May 23, 2024, 06:41:56 pm »
Block IPv6 to any on your LAN interface. Traffic between devices on the same network does not pass through OPNsense.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

JoK

  • Full Member
  • ***
  • Posts: 108
  • Karma: 4
    • View Profile
Re: IPV6 on LAN only
« Reply #5 on: May 23, 2024, 07:19:24 pm »
Quote from: Monviech on May 23, 2024, 06:41:21 pm
But you will have IPv6 for LAN only if you remove it from the standard allow rule in the LAN. (Turn IPv4/IPv6 into IPv4)

The devices communicate directly with each other, the firewall doesn't block that traffic. But it will block all traffic going to the WAN that way.

Hmmm….is that enough to just remove IPV6? Will that do the trick?
Where exactly do i do that
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: IPV6 on LAN only
« Reply #6 on: May 23, 2024, 07:22:48 pm »
What do your LAN rules look like?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

JoK

  • Full Member
  • ***
  • Posts: 108
  • Karma: 4
    • View Profile
Re: IPV6 on LAN only
« Reply #7 on: May 23, 2024, 07:55:39 pm »
Sorry, cant get my screenshot to get below max size for posting, using ipad at the moment. My settings are standard.
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: IPV6 on LAN only
« Reply #8 on: May 23, 2024, 09:10:50 pm »
If all your LAN rules are for IPv4 only, then IPv6 is categorically blocked and no IPv6 connections will leave your LAN towards the Internet.

I wonder why anyone would want such a setup, but you do you.

Hint: IPv6 is the Internet. IPv4 is "that legacy protocol".
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

JoK

  • Full Member
  • ***
  • Posts: 108
  • Karma: 4
    • View Profile
Re: IPV6 on LAN only
« Reply #9 on: May 25, 2024, 05:09:29 pm »
Well, I got some homer surveillance that records to a Mac server, and I dont want any of these to access the Internet, I got there IPV4 blocked by an Alias and the Mac set up to only allow IPV6 to LAN only. I know its not that easy to block IPV6 adreess...a MAC block would problaly solve this issue...dont know.

 
Logged

JoK

  • Full Member
  • ***
  • Posts: 108
  • Karma: 4
    • View Profile
Re: IPV6 on LAN only
« Reply #10 on: June 20, 2024, 09:07:12 pm »
Kinda late to post a screenshot, i disabled IPV6 on LAN rules in Firewall, is this OK, will it block all IPV6 traffic from LAN to WAN??

Is it that easy? 🙂

The “Direction” in the rule, should I leave that to “in”? The only thing I have done, is to change the “Action” to “Block” in stead of “Allow”
« Last Edit: June 20, 2024, 09:13:01 pm by JoK »
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: IPV6 on LAN only
« Reply #11 on: June 20, 2024, 09:11:25 pm »
You do not need to block anything explicitly. If there is no allow rule for IPv6 access will be blocked. Just remove everything IPv6 related from your rules on LAN.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

JoK

  • Full Member
  • ***
  • Posts: 108
  • Karma: 4
    • View Profile
Re: IPV6 on LAN only
« Reply #12 on: June 21, 2024, 05:50:50 pm »
Thanks, the Block rule, is my "Block internet acces for specific IPv4 adresses" its restrict Internet access for some devices on my network, it works perfectly. My problem was, if these devices also support IPV6, they are not blocked anymore, they just pop over to IPV6....and since I cant block specific IPV6 adresses, my blocks are useless.

I just modified the rule to only "IPV4" and not "IPV4+IPV6"...didnt work for IPV6 anyway 🙂

This seems to block all IPV6 traffic from LAN to WAN, perfect...thanks
« Last Edit: June 21, 2024, 05:54:26 pm by JoK »
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • IPV6 on LAN only
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2