Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DHCP IPv6

    Scheduled Pinned Locked Moved DHCP and DNS
    19 Posts 5 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      Why would you be enabling dhcpv6 server on your "WAN" ???

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      kiokomanK 1 Reply Last reply Reply Quote 0
      • SamTzuS
        SamTzu
        last edited by

        Would it not be more hassle to use DHCP on LAN with IPv6?

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          Huh??

          Your wan is the "internet" side, ie you get ipv6 address from your ISP.. You would normally then an IP range on your LAN side for your clients to use.. They would then get their IPv6 address via RA or dhcpv6, etc..

          Why would you want to be serving dhcpv6 to devices on the wan (internet) side?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • SamTzuS
            SamTzu
            last edited by

            So that I don't have to bother with NAT.
            I'm trying to provision IPv6 address's to my Proxmox (virtual machine) clients.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz

              What??

              Don't even know what to say to something like that..

              No ipv6 you don't need nat.. But your clients would be behind pfsense, ie on your LAN... the WAN side is the internet side, ie the network connection that gets you to other networks..

              Please draw up how you have your stuff connected.. And where pfsense is in the mix.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • kiokomanK
                kiokoman LAYER 8 @johnpoz
                last edited by

                @johnpoz said in DHCP IPv6:

                Why would you be enabling dhcpv6 server on your "WAN" ???

                didn't noticed that 😂

                @SamTzu
                you need to enable the dhcp on the lan side only, ipv6 does not need nat but your device that need the address are on the lan side not on the wan

                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                Please do not use chat/PM to ask for help
                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                1 Reply Last reply Reply Quote 0
                • SamTzuS
                  SamTzu
                  last edited by

                  I have been moving clients to WAN side for some time now to simplify VM management.
                  Firewall rules are now managed by Proxmox and pfsense is basically used only for routing.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    How and the F would that routing work?? Makes ZERO sense!

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • SamTzuS
                      SamTzu
                      last edited by

                      So I can't use DHCP6 on WAN side? Only on LAN?

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        Dude draw up you network!! You seem to have a MESS if you think you should be handing out dhcpv6 to the wan side of pfsense.

                        If you have clients on the wan side of pfsense any your routing them to pfsense wan to get out to the internet via some other device on pfsene wan its going to be an asymmetrical mess.

                        Even if your just routing to pfsense for networks behind pfsense, its going to be asymmetrical if you are not doing host routing on each devices in the wan network of pfsense.

                        Is your network something like this?
                        likethis.png

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • SamTzuS
                          SamTzu
                          last edited by SamTzu

                          I only want pfsense to deliver IPv6 addresses. No routing, no NAT. No need to draw up network. If pfsense dies or malfunctions it won't kill client connectivity.

                          JKnottJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by johnpoz

                            That is BORKED!!

                            So you want to use pfsense as just a dhcpv6 server? How do you think that will work as its RA would be handing clients self as a gateway.

                            If dhcpv6 dies, then yeah connectivity will die as well - since clients will not be able to get an IP.. etc..

                            Clients in IPv6 find their gateway via RA.. not dhcpv6.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • JKnottJ
                              JKnott @SamTzu
                              last edited by

                              @SamTzu said in DHCP IPv6:

                              I only want pfsense to deliver IPv6 addresses. No routing, no NAT. No need to draw up network. If pfsense dies or malfunctions it won't kill client connectivity.

                              Use DHCPv6-PD on the WAN. Use SLAAC or DHCPv6 on the LAN. The "PD" in DHCPv6-PD provides the prefix for use on your LAN. The only thing that should be on the WAN side is your ISP. The users MUST be on the LAN. If you put a DHCP server on the WAN side, you could be providing it to other customers, which means you could be disrupting their service. Most ISPs take a dim view of that!

                              Also, there is no need for NAT on IPv6. You should be getting a block of at least 2^64 address from your ISP, possibly many more. I get 256 /64 blocks with my /56 prefix.

                              PfSense running on Qotom mini PC
                              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                              UniFi AC-Lite access point

                              I haven't lost my mind. It's around here...somewhere...

                              NogBadTheBadN 1 Reply Last reply Reply Quote 0
                              • NogBadTheBadN
                                NogBadTheBad @JKnott
                                last edited by

                                @JKnott

                                Looks like he has a /48 from his ISP.

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                1 Reply Last reply Reply Quote 0
                                • SamTzuS
                                  SamTzu
                                  last edited by

                                  I do.

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by

                                    You could have a /32 from your ISP, has zero to do with any of this..

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.