Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Prevent IPv6 Address Detection?

    Scheduled Pinned Locked Moved IPv6
    12 Posts 4 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mscaff
      last edited by

      Confirmed not showing an address there at all, but did show IPV6 -> V4 DNS, could that leak in any way?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Sure it wasn't your browser reporting its link-local address?  What was beginning part of this ipv6 address they detected?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • M
          mscaff
          last edited by

          Can it detect a link-local externally?

          And I'm actually asking for a friend, so I'll need to ask him if the address started with FE80.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            could of been a teredo or isatap, etc. – get the first part of the prefix and we can tell if actual global address or some other special sort of address.  And sure browsers can report their IP addresses..  I don't actually recall ever seeing a link local being reported, but browsers can leak all kinds of info.

            https://browserleaks.com/

            browserdetect.png
            browserdetect.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • M
              mscaff
              last edited by

              Ahh I see where you're coming from - fair call, I'll run that by him, pretty sure you're onto it, as I've disabled IPv6 for DHCP and am not leaking.

              I still have a local IPv6 address, from what I've heard you cant disable it, but PFsense just wont use it right?

              Also, curious, can a v6 address leak through a VPN and compromise anonymity?

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                you can disable your link local if your on windows for sure.. This will also disable all the other transition tunnel stuff that MS in their infinite wisdom thought was good idea to turn all 3 different ones all at once.. teredo, isatap and 6to4

                Simple reg key will turn it all off.
                From admin prompt
                reg add hklm\system\currentcontrolset\services\tcpip6\parameters /v DisabledComponents /t REG_DWORD /d 255

                reboot.. To put it back just delete the key
                reg delete hklm\system\currentcontrolset\services\tcpip6\parameters\ /v DisabledComponents /f

                Reboot and your back to how it was out of the box.. Everything on teredo, isatap, 6to4

                If not running windows and running a flavor of linux/bsd it might also be possible to disable the link local, etc.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • M
                  mscaff
                  last edited by

                  Can a link local be used to identity a host/person globally? Or is it similar to 192/172/10.0 networking?

                  Can a v6 address also leak through a VPN with v6 turned off and compromise anonymity?

                  1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott
                    last edited by

                    Hmmm…

                    That Browser Leaks site doesn't like IPv6.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • JKnottJ
                      JKnott
                      last edited by

                      Can a link local be used to identity a host/person globally? Or is it similar to 192/172/10.0 networking?

                      A link local address can only be used to identify a piece of hardware.  It has absolutely no info about who or where you are.  It's normally based on the MAC address.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        @JKnott - it was just the first site I found with a quick google to just show that browser can leak your local address.  It might not even do IPv6, etc.

                        Without some details its unclear to what might have been reported to this guys buddy.  But if he has ipv6 off on pfsense, I find it pretty much impossible for it to be a global IPv6 address from his isp, etc.  So it could be something like a browser leak, or could be say a teredo address..

                        There are better sites for detecting ipv6 leaks, etc.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.