Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ask help about BASIC ipv6 setup with /48 static address

    Scheduled Pinned Locked Moved IPv6
    7 Posts 3 Posters 947 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      imfan
      last edited by

      Hi everyone,

      I recently doing something on Proxmox VE(KVM) + Pfsense + IPv6 address block.

      Here is what happened on me :

      I setup two brs:

      vmbr0 to physical interface (enp5s0f0) as pfSense WAN running on a KVM VM

      vmbr1 to none as p'fSense LAN running on the same KVM VM

      the server IDC provide an IPv6 address block 2607:fca8:1a::/48 and Gateway address on ::1

      I tested setup VM on vmbr0 setup address like 2607:fca8:1a::f/48 and 2607:fca8:1a:1000::2/48 (Both gateway ::1/48), they all works fine ping google dns or something else.

      So I delete the test VM , then set pfsense VM WAN address 2607:fca8:1a::f/48 (Use pfsense gui),but then I try to setup LAN address as I thought (2607:fca8:1a:1000::1/56), it says address already in use by WAN

      So I searched some article says I should select DHCPv6 Client mode on WAN , so I can get PD to use on the LAN side.But the IDC i'm using now didn't enable DHCPv6.

      Then I thought maybe I should try set /64 on WAN, set another /64 on LAN, but seems cant get access from LAN side to the world.And if I set WAN to second /64 it even cant reach the ::1/48 gateway address.

      Sorry for my poor english, I have no choice but come here to ask help. What should I set the WAN(vmbr0 to physical interface) and LAN(vmbr1 to none interface but assign VMs to it) address to make VMs on the LAN(vmbr1) can access the world.

      PS: vmbr0 set 2607:fca8:1a::2/48 with gw 2607:fca8:1a::1 on the host system ( cause need it to access host web panel)

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You likely do not need any IPv6 on WAN. They are probably routing the /48 to a link-local address but that is just a guess.

        | the server IDC provide an IPv6 address block 2607:fca8:1a::/48 and Gateway address on ::1

        If they have that /48 on the interface and not routed to you that is hopelessly broken and idiotic. Post the exact instructions they gave you regarding the IPv6 provisioning on that interface.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        JKnottJ 1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @Derelict
          last edited by

          @derelict said in Ask help about BASIC ipv6 setup with /48 static address:

          You likely do not need any IPv6 on WAN.

          You do not need a routeable IPv6 address on the WAN interface. However, you do need an IPv6 link local address. You normally get one of those when IPv6 is enabled on an interface.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • I
            imfan
            last edited by

            @derelict

            Hi there ,

            Sorry for the delay

            I send a ticket ask about if they just forget to tell me about the ipv6 address which the /48 routed to , and they send me these:

            "The default configuration is to assign the /48 to the switch port which it sounds like that is not what you need for your setup."

            Seems that they just assign the address block to the port, then I tell them it should be routed to an IPv6 address outside the block , there were no respond several days......

            Wanna to know if they didnt or unable to change the situation right now, will my address block work ?

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by Derelict

              No. That's a completely asinine way to do IPv6. They should route it to you, not put it on the interface. I can't think of any valid reason for 65536 /64 networks on one interface.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              I 1 Reply Last reply Reply Quote 0
              • I
                imfan @Derelict
                last edited by

                @derelict

                Well....Sounds like the only option right now is waiting...

                Thanks for your help

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  "The default configuration is to assign the /48 to the switch port which it sounds like that is not what you need for your setup."

                  It's not what anyone needs for any setup.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.