Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DHCP IPv6

    Scheduled Pinned Locked Moved DHCP and DNS
    19 Posts 5 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • SamTzuS
      SamTzu
      last edited by

      So that I don't have to bother with NAT.
      I'm trying to provision IPv6 address's to my Proxmox (virtual machine) clients.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by johnpoz

        What??

        Don't even know what to say to something like that..

        No ipv6 you don't need nat.. But your clients would be behind pfsense, ie on your LAN... the WAN side is the internet side, ie the network connection that gets you to other networks..

        Please draw up how you have your stuff connected.. And where pfsense is in the mix.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8 @johnpoz
          last edited by

          @johnpoz said in DHCP IPv6:

          Why would you be enabling dhcpv6 server on your "WAN" ???

          didn't noticed that 😂

          @SamTzu
          you need to enable the dhcp on the lan side only, ipv6 does not need nat but your device that need the address are on the lan side not on the wan

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          1 Reply Last reply Reply Quote 0
          • SamTzuS
            SamTzu
            last edited by

            I have been moving clients to WAN side for some time now to simplify VM management.
            Firewall rules are now managed by Proxmox and pfsense is basically used only for routing.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              How and the F would that routing work?? Makes ZERO sense!

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • SamTzuS
                SamTzu
                last edited by

                So I can't use DHCP6 on WAN side? Only on LAN?

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  Dude draw up you network!! You seem to have a MESS if you think you should be handing out dhcpv6 to the wan side of pfsense.

                  If you have clients on the wan side of pfsense any your routing them to pfsense wan to get out to the internet via some other device on pfsene wan its going to be an asymmetrical mess.

                  Even if your just routing to pfsense for networks behind pfsense, its going to be asymmetrical if you are not doing host routing on each devices in the wan network of pfsense.

                  Is your network something like this?
                  likethis.png

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • SamTzuS
                    SamTzu
                    last edited by SamTzu

                    I only want pfsense to deliver IPv6 addresses. No routing, no NAT. No need to draw up network. If pfsense dies or malfunctions it won't kill client connectivity.

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz

                      That is BORKED!!

                      So you want to use pfsense as just a dhcpv6 server? How do you think that will work as its RA would be handing clients self as a gateway.

                      If dhcpv6 dies, then yeah connectivity will die as well - since clients will not be able to get an IP.. etc..

                      Clients in IPv6 find their gateway via RA.. not dhcpv6.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @SamTzu
                        last edited by

                        @SamTzu said in DHCP IPv6:

                        I only want pfsense to deliver IPv6 addresses. No routing, no NAT. No need to draw up network. If pfsense dies or malfunctions it won't kill client connectivity.

                        Use DHCPv6-PD on the WAN. Use SLAAC or DHCPv6 on the LAN. The "PD" in DHCPv6-PD provides the prefix for use on your LAN. The only thing that should be on the WAN side is your ISP. The users MUST be on the LAN. If you put a DHCP server on the WAN side, you could be providing it to other customers, which means you could be disrupting their service. Most ISPs take a dim view of that!

                        Also, there is no need for NAT on IPv6. You should be getting a block of at least 2^64 address from your ISP, possibly many more. I get 256 /64 blocks with my /56 prefix.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        NogBadTheBadN 1 Reply Last reply Reply Quote 0
                        • NogBadTheBadN
                          NogBadTheBad @JKnott
                          last edited by

                          @JKnott

                          Looks like he has a /48 from his ISP.

                          Andy

                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                          1 Reply Last reply Reply Quote 0
                          • SamTzuS
                            SamTzu
                            last edited by

                            I do.

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              You could have a /32 from your ISP, has zero to do with any of this..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.