Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    A verrry basic ipv6 question

    Scheduled Pinned Locked Moved IPv6
    13 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MrPeteM
      MrPete @MrPete
      last edited by

      I forgot to include: I can't even ping6 the gateway address. Seems like I am missing something very basic.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @MrPete
        last edited by johnpoz

        @mrpete 6rd is a bit of a hack..

        https://docs.netgate.com/pfsense/en/latest/interfaces/configure-ipv6.html#rd-tunnel

        here is a CL user.. That has a guide up for using that with pfsense
        https://potatoforinter.net/553/centurylink-ipv6-with-pfsense/

        if it was me, and my isp was just going to tunnel IPv6 to me anyway - I would prob just use the Hurricane Electric tunnel. Way more info with people setting that up, and they will give you a /48 that you can use, and allow you to set PTRs for it, etc. And if you happen to move to another isp, you can still keep your /48.. I have had mine for like 11 years or so, and multiple isps during that time. Current one doesn't have any ipv6 support ;)

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        MrPeteM 1 Reply Last reply Reply Quote 0
        • MrPeteM
          MrPete @johnpoz
          last edited by

          @johnpoz That's a good insight ;)

          I'll check it out...

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @MrPete
            last edited by

            @mrpete if you end up going with HE, and need any help or have questions - just ask. Been using HE with pfsense for years.. Its a pretty easy setup to be honest. And they have pops all over the globe so should be able to find one in your neck of the woods.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            JKnottJ MrPeteM 2 Replies Last reply Reply Quote 0
            • JKnottJ
              JKnott @johnpoz
              last edited by

              @johnpoz

              Don't they require a static address? That's one thing I noticed when I was considering them.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @JKnott
                last edited by johnpoz

                @jknott said in A verrry basic ipv6 question:

                That's one thing I noticed when I was considering them.

                No.. They need to be able to ping your IP.. if your isp is one that changes your IP every hour or something you might have an issue.. But I have a dynamic IP, and it hasn't changed in years..

                Normally a dhcp assigned IP would stay the same, it is how dhcp is designed to work, you get an IP, and then renew it at the 50% mark of the lease. In theory your IP could be that same IP forever.. As long as you do not turn off your device for some extended period, or change the device so you get a different mac. But if your new device had the same mac (say clone of previous mac) you would still get the same IP.

                https://ipv6.he.net/certification/faq.php
                My IPv4 endpoint address is dynamic. Can I still create a tunnel? If yes, what do I need to do when my IP address changes?

                Yes, you can still create a tunnel even if you are using a dynamic IPv4 endpoint address. If your IPv4 endpoint address changes, you can either login to the tunnelbroker.net page and update your IPv4 endpoint address or use https://ipv4.tunnelbroker.net/nic/update which is designed to be used to update your IPv4 endpoint address.

                edit:
                If your IP is just changing on the fly for no real reason, I would assume you would have some sort of blip in your tunnel.. But if your IP is changing like that I would think you would have all kinds of blips anyway ;)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                Bob.DigB JKnottJ 2 Replies Last reply Reply Quote 0
                • Bob.DigB
                  Bob.Dig LAYER 8 @johnpoz
                  last edited by

                  @johnpoz There is a Dynamic DNS Clients for HE.net tunnelbroker in pfSense.

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @Bob.Dig
                    last edited by johnpoz

                    @bob-dig yeah I do believe so - was just linking to their faq as answer to the question.

                    There is prob multiple was to update the ddns IP.. they have like a api you use.

                    I believe you use the tunnel ID for the hostname in the HE setup.

                    And then you can generate the api key in the dns setup on HE

                    setup.jpg

                    Here is a link to their forums with info about the ddns setup
                    https://forums.he.net/index.php?topic=1994.0
                    Dyn-compliant Endpoint Updates

                    I have never needed to set it up - because my IP while dynamic hasn't changed in years, over multiple ISP. Once got an IP from isp, it stayed the same unless I changed the mac of the device connected to their modem.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • JKnottJ
                      JKnott @johnpoz
                      last edited by

                      @johnpoz

                      I don't need it for myself, as I get native IPv6 from my ISP, but a friend was wondering about getting IPv6. As I've mentioned before, my IPv4 is virtually static and my host name only changes with hardware MAC addresses. When I was looking at he.net for myself I asked them if a host name was suitable and they said no. Prior to getting IPv6 from my ISP, I used another tunnel broker that required installing client software. They had one for Windows, but Linux, Mac and BSD users had to compile theirs. They also sold a box that acted as a client, but they gave me one for free for all the help I was providing others¹. One other thing they had, which was quite useful was a single address mode. While I got a /56 prefix on my Linux firewall, I also ran the client in single address mode, when I was away from home with my notebook computer.

                      1. They also wanted me to do a presentation at some IPv6 conference in Los Angeles, but I declined.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @JKnott
                        last edited by

                        @jknott yeah I didn't think you did ;)

                        I was just filling out the blanks for anyone else reading the thread is all.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • MrPeteM
                          MrPete @johnpoz
                          last edited by

                          @johnpoz Thanks. Gonna shut down my ipv6 experiment for the next few days of Christmas and come back to it. ;)

                          FWIW I have static IP, so that is not an issue.
                          I see a lot of bugfixing in this area in OpnS***** ...maybe the two communities have something to learn from one another. ;)

                          JKnottJ 1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott @MrPete
                            last edited by

                            @mrpete

                            HEY!!! Get your priorities straight!!! 😉 🎅

                            BTW, isn't OPNsense based on pfsense? A friend of mine runs it and seems to like it.

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.