Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Distributing IPv6 to multiple VLANS

    Scheduled Pinned Locked Moved IPv6
    8 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • lohphatL
      lohphat
      last edited by

      I have IPv6 working between the WAN and LAN segments but don't know how to add it to a VLAN i/f.

      The LAN config is set to tract WAN interface. When I try to do the same for the VLAN i/f I get that the tracking interface is in use by the LAN segment.

      The WAN config is DHCP6. ISP Spectrum (yeah, I know).

      SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_5)

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @lohphat
        last edited by

        @lohphat

        Assuming your ISP provides multiple /64s, you choose a different Prefix ID for each VLAN. How many /64s do you get? I have a /56 prefix, which provides 256 /64s. Others get a /48 for 65536 /64s or /60 for 16. For example, with a /56, my prefix IDs range from 0 - ff. I use 0 for the main LAN, 4 for a test LAN and ff for my VPN.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • H
          HG
          last edited by HG

          Make sure you set the correct DHCPv6 Prefix Delegation size for your ISP (e.g. 56) in the DHCP6 Client Configuration of the WAN interface. You probably also have to set "Send an IPv6 prefix hint to indicate the desired prefix size for delegation". If this works, then go to the LAN configuration and set the IPv6 Prefix ID in the Track IPv6 Interface configuration.

          What I usually do:

          • My prefix size is 56 bit which means I have 256 (= 64bit - 56bit = 8 bit) IPv6 Prefix IDs available.
          • In my IPv4 setup, I have /24 networks, i.e. 192.168.x.0/24, so I have 256 networks available as well.
          • To keep it well organized, I set the VLAN ID, the IPv4 network (so x above) and the IPv6 Prefix ID (converted to hex) to the same number. E.g. VLAN 25, IPv4 192.168.25.0/24, IPv6 Prefix ID 19.
          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @HG
            last edited by

            @HG said in Distributing IPv6 to multiple VLANS:

            To keep it well organized, I set the VLAN ID, the IPv4 network (so x above) and the IPv6 Prefix ID (converted to hex) to the same number. E.g. VLAN 25, IPv4 192.168.25.0/24, IPv6 Prefix ID 19.

            Me too, except I have IPv4 in the 172.16.x.0/24 range. I went with that to avoid conflicts when travelling, when I used my VPN.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • lohphatL
              lohphat
              last edited by

              I've been trying all the permutations just on one internal segment and it looks like the local Spectrum is only providing a /64. I've tried /56 and /60 and am working through the permutations of send hint or not. The problem is they are sporadic in sending IPv6 configs so I have to reboot the modem each time and wait,

              SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_5)

              JKnottJ 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @lohphat
                last edited by

                @lohphat

                Maybe you can call their support line and ask. Or perhaps they have a support forum, the way my ISP does.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                lohphatL 1 Reply Last reply Reply Quote 0
                • lohphatL
                  lohphat @JKnott
                  last edited by

                  @JKnott I would rather chew glass than deal with Spectrum (aka Speculum) "tech support".

                  At least they're offering native IPv6, FiOS STILL isn't offering it.

                  SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_5)

                  1 Reply Last reply Reply Quote 0
                  • lohphatL
                    lohphat
                    last edited by

                    FINALLY, success!

                    After retrying what should have worked the first time, but didn't, I can report I have a /56 and proper delegations to the different segments.

                    The problem was the ISP, even after a modem reboot, would be inconsistent issuing IPv6 configs. It was 24 hours of tweaking and rebooting.

                    Thanks for the advice, it did help to narrow down the options.

                    SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_5)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.