Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Neighbor Discovery Protocol (NDP) Proxy

    Scheduled Pinned Locked Moved 2.1 Snapshot Feedback and Problems - RETIRED
    9 Posts 4 Posters 5.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      itsmorefun
      last edited by

      Hello,

      Any chance to add a NDP proxy like one of them:

      http://gitweb.fperrin.net/?p=ndp6.git;a=summary
      http://priv.nu/projects/ndppd/

      Thank :)

      1 Reply Last reply Reply Quote 0
      • A
        athurdent
        last edited by

        So you would basically be able to use the same IPv6 subnet on both WAN and LAN? Strange. Wouldn't it be more elegant to just bridge the two interfaces and use transparent firewalling instead? Never tried that with IPv6, though…

        1 Reply Last reply Reply Quote 0
        • I
          itsmorefun
          last edited by

          @athurdent:

          So you would basically be able to use the same IPv6 subnet on both WAN and LAN? Strange. Wouldn't it be more elegant to just bridge the two interfaces and use transparent firewalling instead? Never tried that with IPv6, though…

          Need NAT for ipv4.
          Static routing only.  (Provider want to see all ipv6 on the WAN side of the dedicated server.

          http://linux-attitude.fr/post/proxy-ndp-ipv6
          http://www.kueisaho.com/blog/mesfluxrss/author/frederic-perrin/
          http://x0r.fr/blog/12
          http://blog.vsense.fr/maj-vyatta-6-5-et-proxy-ndp/
          http://resel.eu/

          1 Reply Last reply Reply Quote 0
          • A
            athurdent
            last edited by

            You might be able to create a workaround using NAT: http://forum.pfsense.org/index.php/topic,58937.0.html together with IPv6 aliases on your WAN and ULA on the LAN side I guess. But maybe one of the IPv6 pro's here can come up with a better solution, I only tried "IPv6-Hide-NAT" so far which worked fairly well.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              I think that just broke my brain.

              Why on earth would they do that? That goes against the purpose of IPv6. IPv4 logic doesn't apply to IPv6, there is no scarcity of addresses forcing them to make you do that.

              Demand a routed /64 at least or find a new ISP… (if you can)

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • I
                itsmorefun
                last edited by

                @jimp:

                Demand a routed /64 at least or find a new ISP… (if you can)

                I have a /64 BUT can't add route to it in the ISP router….
                With tcpdump on wan side of pfsense i see "[ISP IPV6 'sGATEWAY]> ff02::1:ff79:8611: ICMP6, neighbor solicitation, who has [LAN COMPUTER'S IPV6], length 32

                The ISP gateway know that the IPV6 of the wan pfsense is on @mac of the wan pfsense card because pfsense answer for his own ipv6.
                But for ipv6 on my LAN side a NDP proxy is need…

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by

                  there is a feature request open for a NDP proxy, which won't happen for 2.1 but maybe some point. But that isn't the intended use case, rather to have a proxy ARP equivalent for VIPs strictly at layer 2 w/v6. The described scenario is trying to fix something that's broken in ways that NDP proxy isn't a solution for, a proper routed v6 setup is the solution there.

                  1 Reply Last reply Reply Quote 0
                  • I
                    itsmorefun
                    last edited by

                    @cmb:

                    a proper routed v6 setup is the solution there.

                    but not possibly with my dedicated server hoster…

                    You understand that it's not me that don't want, but that i technically can't...

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      Then find a hoster that isn't trying to implement broken IPv6?

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.