Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Setup IPv6 provided by ARIN

    Scheduled Pinned Locked Moved IPv6
    10 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      shar0119
      last edited by

      I have received a /36 block of IPv6 which I would like to setup in pfSense. When I try to put '2603:FF43::1' under Static IPv6 Configuration for IPv6 Address, it asks for a valid format and does not accept it. Could someone please help me setup the /36 in pfSense?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Why on Earth would you be putting an entire /36 on one pfSense node?

        If you really want to do it, try lower-casing all the hex digits in the IPv6 address. I think there is an input validation issue there in certain places.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott
          last edited by

          How did you manage to get a /36? That's an ISP size block.  Did you mean /56?  Many ISPs hand out those.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            /36 is a x-small from arin..  Its only a $500 year fee for such small ipv6 network.

            I don't show that block assigned to anyone, its still listed as arin.  So I don't that is the correct IP block..  Unless they are trying to use public IPv6 space that is not theirs?

            But I am with Derelict - why would you you be trying to put a specific /36 address on anything??  Other than say a route entry??  Or maybe a summary firewall rule?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott
              last edited by

              /36 is a x-small from arin..  Its only a $500 year fee for such small ipv6 network.

              Small??? A /36 can be split into over a million /56s.  That would make for a decent sized ISP.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                From arin that is a 2x-small ;) I had typo before

                https://www.arin.net/fees/fee_schedule.html

                extrasmall.png
                extrasmall.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  In IPv6 that's small.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott
                    last edited by

                    ^^^^
                    5X-Large /4 or larger???  That would be half or the entire IPv6 GUA range, as currently allocated.  Every address currently available is within a /3, with 1/8 of all IPv6 addresses allocated to GUAs.  Over 3/4s has yet to be allocated to anything.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      You do understand that the current /3 for Global address space is a bit a mere fraction of the total space right??

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott
                        last edited by

                        ^^^^
                        Yep, that why I said "Every address currently available is within a /3, with 1/8 of all IPv6 addresses allocated to GUAs".

                        Of the entire 2^128 IPv6 addresses, only 2^125 are used for GUAs.

                        Since /3 represents all currently available GUAs, a /4 would be half of them.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.