ipv6 fw rule with dynamic prefix

Started by Perun, September 25, 2018, 08:46:48 AM

Previous topic - Next topic
Hi

how can I set a ipv6 firewall rule with a dynamic prefix?

Greetz

You can't. Either run a HE tunnel https://tunnelbroker.net/ or change to an ISP that is not stuck in the dark ages.

Bart...

This is on my long-term TODO list. Martin added a prefix merge feature for DHCPv6 / RADVD, but moving this into the firewall is trickier than just merging the prefixes on a flat config file rewrite.


Cheers,
Franco

In release 20.7.2. there is a new alias type based on MAC addresses. You could define rules based on MAC address for the hosts with dynamically assigned IPv6 prefixes.

I had to take a closer look, but yes, MAC alias resolves arp and ndp output so both IPv4 and IPv6 are supported.


Cheers,
Franco