Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
17.7 Legacy Series
»
[SOLVED] IPv6 and letsencrypt
« previous
next »
Print
Pages: [
1
]
Author
Topic: [SOLVED] IPv6 and letsencrypt (Read 3804 times)
bringha
Sr. Member
Posts: 252
Karma: 19
[SOLVED] IPv6 and letsencrypt
«
on:
October 26, 2017, 10:37:39 pm »
Hi there,
I am running a configuration like
FritzBox<-->opnsense (dmz interface) <--> web server with dyndns.
The web server acts as a public subdomain (sub.example.com) and shall now get an ssl certificate via letsencrypt. As I have a dual stack running, Dyndns takes the ipv6 address of the Fritzbox as the ipv6 subdomain address. So far so good.
Due to the fact that Dyndns now offers ipv4 AND ipv6 a DNS AAAA record iss created for the domain and therefore lets encrypts certbot is using ipv6 for certificate installation and renewal; obviously fallback to ipv4 is still not working in case that there is no answer from the server from ipv6. Currently certbot is failing as it does not reach the servers directory via ipv6
As with public ipv6 addresses NAT is no longer the valid method, how do I tell opnsense, that it should 'forward' the Fritzbox ipv6 address to the (public ?) ipv6 address of the webserver?
Looking forward to your reply
Br br
[EDIT] For those who are interested: The workaround is to configure the dyndns client on the FritzBox to update ipv4 only; this eliminates the AAAA record in DNS and letsencrypt is using Ipv4. To do so (here for dyn.com) Goto the Fritzbox in Internet->Freigaben->Dyndns and select user defined; then put the following URL in the field:
https://members.dyndns.org/nic/update?hostname
<DOMAIN>&myip<ipaddr>&wildcard=NOCHG&mx=NOCHG&backmx=NOCHG
Click apply and then wait for 5 min; the AAAA record has been disappeared; certbot renew then runs fine ....
«
Last Edit: October 27, 2017, 08:44:09 pm by bringha
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
17.7 Legacy Series
»
[SOLVED] IPv6 and letsencrypt