Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 subneting and DHCP PD how to

    Scheduled Pinned Locked Moved IPv6
    14 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      ssjoco85
      last edited by

      Now pfsense have some big IPv6 limitation. If Wan has dynamic prefix you can't use private IPv6 addresses or DHCP PD. Both service require static WAN address. Until then pfsense can't handle IPv6 subnetworks.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @ssjoco85
        last edited by

        @ssjoco85

        ????

        I have set up interfaces with both GUA and ULA addresses. I use DHCPv6-PD to get my prefixes. Here is my ULA prefix, on the same interface as my GUA:

        fd48:1a37:2160:0::

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        S 1 Reply Last reply Reply Quote 0
        • S
          ssjoco85 @JKnott
          last edited by

          @JKnott Your GUA address is fix? My is dynamic. You can't use ULA because NPt alias NAT66 address has to be set manually.
          I can receive prefix with DHCP PD but I want to send the unused prefixes in DHCP PD to an another router.

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @ssjoco85
            last edited by JKnott

            @ssjoco85

            Why are you using NAT? There's no need for it with all the addresses available with IPv6. NAT is a hack to get around the IPv4 address shortage. My GUA is obtained via DHCPv6-PD and SLAAC.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • S
              ssjoco85
              last edited by

              As I mentioned neither DHCPv6 PD nor NAT66 not working in a complex network. I'm not talking about one or two IPv6 network on pfsense's LAN port. Yes, I have IPv6 on pfsense. DHCPv6 PD client work perfectly on WAN, but I need a DHCP server on the LAN side! DHCPv6 server can't use dynamixc prefixes, only fix. I need that the pfsense send the unused prefixes to another routers. Inn my case. I receive /56 from my ISP, pfsense use 2 /64 prefixes on LAN1 and LAN2. The unused 254 pcs /64 prefix will be available in the DHCPv6 server, and other routers on LAN also can request one-one prefix from pfsense.
              I tried NAT66 as a last resort, but it has the same limitation. Therefore I have to wait until pfsense can handle dynamic DHCPv6 Server prefixes, or NAT66 can use dynamic WAN address.

              JKnottJ 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @ssjoco85
                last edited by

                @ssjoco85

                How often do your prefixes change? They normally shouldn't change at all.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  @ssjoco85 said in IPv6 subneting and DHCP PD how to:

                  can handle dynamic DHCPv6 Server prefixes

                  And exactly what box can do that now? That seems like something with no real world use case.. And who says you have to use dhcpv6 anyway for your clients?

                  If you have need of your prefix not changing - then go get your IPv6 block from Arin or your region of the worlds RIR and do whatever you want with your space.

                  Or just get a free tunnel from HE and now your /48 doesn't change and you can do whatever you want with it... Or get your ISP to actually assign you /xx that doesn't change so you don't have to go tracking shit via PD from your isp, etc.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • S
                    ssjoco85
                    last edited by

                    Always when my WAN reconnect. I have PPPoE on WAN. Most of the ISPs use dynamic IPv6 prefixes on consumer lines.

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz

                      @ssjoco85 said in IPv6 subneting and DHCP PD how to:

                      IPv6 prefixes on consumer lines.

                      Then don't use a consumer line - duh!!! Your trying to do business shit with user connection..

                      If your going to use consumer level connections, and you want to do fancy shit with IPv6 then just get your free /48 from HE and you can do whatever you want with that /48 - and it never changes... I have had my /48 since 2011..

                      With multiple isp over that period - just take my /48 with me no matter what ISP I use, etc. etc.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @ssjoco85
                        last edited by JKnott

                        @ssjoco85 said in IPv6 subneting and DHCP PD how to:

                        Always when my WAN reconnect. I have PPPoE on WAN. Most of the ISPs use dynamic IPv6 prefixes on consumer lines.

                        I'm on a consumer service and my prefixes are solid, ever since the "Do not allow PD/Address release" option was added to pfSense. DHCPv6-PD uses something called "Device Unique IDentifier" (DUID) to lock the prefix to the customer.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.