Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ipv6 works, how do I vlan?

    Scheduled Pinned Locked Moved IPv6
    14 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cyth @JKnott
      last edited by

      @jknott ty for your reply. Exactly, I want them to have internet access but not access to the other vlans. I'll give it a shot and do some testing.

      Thanks!

      JKnottJ T 2 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @Cyth
        last edited by

        @cyth

        Here's my rules for my guest WiFi. It allows access to the Internet only and pinging the guest interface.

        e5a45585-e26a-4088-be6a-db63b4867b39-image.png

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        T 1 Reply Last reply Reply Quote 0
        • T
          tcw @Cyth
          last edited by tcw

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • T
            tcw @JKnott
            last edited by

            @jknott What is your "Prefix" alias?

            JKnottJ 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @tcw
              last edited by

              @tcw

              It's my entire /56 prefix. This is to prevent guests from even attempting to connect to anything within that range.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              T 1 Reply Last reply Reply Quote 0
              • T
                tcw @JKnott
                last edited by tcw

                @jknott Thanks for the reply. Sorry, I should have asked a better question--do you manually enter your prefix (is it static) or can the firewall update it if it changes via DHCPv6? I am using the "suffix" part of the capability to address individual devices (let's say ::0102:0304:0506 for MAC address 01:02:03:04:05:06) but is there a way to use that dynamically updated prefix in an alias?

                JKnottJ 1 Reply Last reply Reply Quote 0
                • JKnottJ
                  JKnott @tcw
                  last edited by JKnott

                  @tcw

                  If there is a dynamic method, I don't know what it is. However, my prefix hasn't changed for years.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  1 Reply Last reply Reply Quote 1
                  • C
                    Cyth
                    last edited by

                    So I updated my vlan interface to track the wan and assigned the prefix id to 1. My lan has prefix id 0. I also enabled the dhcp6 and ra for that vlan. I am not getting an ipv6 address though. I did this roughly 6 hours ago, thought maybe it needed more time. Did I miss something? Maybe this isn't assigned till my lease is up?

                    Thanks!

                    T JKnottJ 2 Replies Last reply Reply Quote 0
                    • T
                      tcw @Cyth
                      last edited by tcw

                      @cyth Power cycle first your modem and then your router, if you haven't already, and you may need to change the last two settings under "DHCP6 Client Configuration" for your WAN interface depending on your ISP.

                      1 Reply Last reply Reply Quote 1
                      • JKnottJ
                        JKnott @Cyth
                        last edited by

                        @cyth said in ipv6 works, how do I vlan?:

                        My lan has prefix id 0. I also enabled the dhcp6 and ra for that vlan.

                        Why are you using DHCPv6 on the VLAN? Unless you have a specific need for it, I recommend against it. SLAAC is the easiest way to provide device addresses. You can add RDNSS to provide DNS info and if and only if you need more, you can use stateless DHCPv6. Also, Android devices won't work with DHCPv6, thanks to some genius at Google.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        C 1 Reply Last reply Reply Quote 0
                        • C
                          Cyth @JKnott
                          last edited by

                          @jknott thx for the info. Do I need the dhcp6 server running for clients to pickup the gateway, dns, and ntp server addresses? I see under the ra section I can set the dns, but what about the gateway and ntp? Would you suggest I disable the dhcp6 server and switch the ra mode to Unmanaged, is this slaac? Also I made a prefix alias but I am not sure where I get my prefix from, so I copied from the lan's dhcp6 info at the top of the screen. I have set my fw rules up like so:

                          ec25bba5-6d97-4d3d-aa1b-37bd8276ef4f-image.png

                          Goal was to allow any communication within the vlan, internet access, and allow a few other exceptions to some internal services I have going on.

                          Thanks again for your help.

                          JKnottJ 1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott @Cyth
                            last edited by JKnott

                            @cyth

                            The gateway is part of the basic RA. The DNS server is an optional part of it and NTP server would require stateless DHCPv6. If needed, you could still rely on IPv4 for those too. However, using DHCPv6 for device addresses will fail for Android devices. Unmanaged is fine, unless you need stateless DHCPv6. The prefix for the alias is the first 56 bits of the addresses (assuming /56).

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.