Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NPt IPv6 behind double nat

    Scheduled Pinned Locked Moved IPv6
    11 Posts 3 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott @Ofloo
      last edited by

      @Ofloo said in NPt IPv6 behind double nat:

      I'm trying to establish native IPv6 from my dsl provider the wan connection is behind a double nat

      That's what's killing you. You want your modem in bridge mode, so that DHCPv6-PD can work.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      O 1 Reply Last reply Reply Quote 0
      • O
        Ofloo @JKnott
        last edited by

        @JKnott I know that's what I want but that's not possible as it also has LTE fallover basically it's doing what pfsense would do better. But this is delivered by the ISP. So is there a way to forward the packets ?

        Bob.DigB 1 Reply Last reply Reply Quote 0
        • Bob.DigB
          Bob.Dig LAYER 8 @Ofloo
          last edited by Bob.Dig

          @Ofloo If your router can't further delegate IPv6, then no. All you could do is NATing pfSense WAN-address, like with IPv4, not NPt.

          O 1 Reply Last reply Reply Quote 0
          • O
            Ofloo @Bob.Dig
            last edited by

            @Bob-Dig I guess but how would you delegate this further then? Just wondering what that exactly means. Static routes wouldn't help right?

            or something like this?

            488effcf-60a8-4c4e-9eae-7059e7d3dfbc-afbeelding.png

            Bob.DigB 1 Reply Last reply Reply Quote 0
            • Bob.DigB
              Bob.Dig LAYER 8 @Ofloo
              last edited by

              @Ofloo said in NPt IPv6 behind double nat:

              or something like this?

              So you have a Fritzbox, many are able to further delegate, you find the option here:

              Capture.PNG

              O 1 Reply Last reply Reply Quote 0
              • O
                Ofloo @Bob.Dig
                last edited by

                @Bob-Dig I've set the setting of dhcp to what you've told me and client to dhcp instead of slaac, however no difference. pfsense it self does route however the clients in a different /64 do not. Are there any additional settings I need to set to the dhcp client?

                Bob.DigB 1 Reply Last reply Reply Quote 0
                • Bob.DigB
                  Bob.Dig LAYER 8 @Ofloo
                  last edited by

                  @Ofloo WAN has to be DHCPv6, DHCPv6 Prefix Delegation size 60 for now; LAN has to be Track Interface.

                  O 1 Reply Last reply Reply Quote 0
                  • O
                    Ofloo @Bob.Dig
                    last edited by

                    @Bob-Dig I get what you're trying to do but I use NPt so actually the lan interfaces have a static ip outside that range as I want to be able to failover inside my lan and so I don't want my devices to get a IP from the isp range. As I have multiple isp.

                    Bob.DigB 1 Reply Last reply Reply Quote 0
                    • Bob.DigB
                      Bob.Dig LAYER 8 @Ofloo
                      last edited by

                      @Ofloo said in NPt IPv6 behind double nat:

                      I get what you're trying to do

                      Are your prefixes dynamic? If so you first have to make sure that Track Interface is working in general.

                      O 1 Reply Last reply Reply Quote 0
                      • O
                        Ofloo @Bob.Dig
                        last edited by

                        @Bob-Dig not dynamic prefixes but ULA prefixes which are mapped to a routable IPv6 NAT 1:1

                        like you set fc08::1000 to a client then you can route it with NPt to whatever prefixes you own you just map ULA/64 to native /64 used to do it many times you can do this with he.net native IP and have failover links and choose which interface to use.

                        So all the IPv6 are static but not in the range of the routable IPv6 prefix

                        However never done it with double NAT seems to be tricky

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.