Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Force IPv6 traffic to a specific host through IPv4 tunnel

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 3 Posters 484 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mquade
      last edited by

      Hi there,
      I have an IPv4 OpenVPN-Server running on my pfSense since several month. Everything works fine. I route traffic to one domain via custom options push "route 1.2.3.4 255.255.255.255"; through the tunnel. It's needed to access a backend of an eCommerce website.
      It works fine as long as the client resolves the domain to a IPv4 (nslookup foo.bar --> 1.2.3.4).
      If the domain resolves to an IPv6 (2a03:4000:xxxx:yyyy:zzzz.....) the traffic is not routed, which makes sense to me.
      I need to change that. The pfsense is currently not using IPv6. I could change that; my provider assigned a block to the server. But it would be much easier to just route the traffic to the specific IPv6 through the tunnel. If I add something with "push "route-ipv6 2a03:4000:xxxx:yyyy:zzzz/128" or check the "Redirect IPv6 Gateway" I get error like

      OpenVPN ROUTE6: OpenVPN needs a gateway parameter for a --route-ipv6 option and no default was specified by either --route-ipv6-gateway or --ifconfig-ipv6 options
      

      Is it possible to route IPv6 through IPv4 Tunnel? Or do I need to configure the whole Server to use IPv6?

      Thanks a lot in advance!
      Best,
      Matthias

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott @mquade
        last edited by

        @mquade

        You have to configure IPv6 on the tunnel.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        Q 1 Reply Last reply Reply Quote 0
        • Q Offline
          q54e3w @JKnott
          last edited by

          @JKnott because I've been struggling with this too, can you explain how to do this. I'd love to remove user error as a source of my inability to make this work.

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ Offline
            JKnott @q54e3w
            last edited by

            @q54e3w

            On the server side, I assigned the IPv6 Tunnel Network prefix. I also selected Redirect IPv6 Gateway, though that depends on your needs.

            In Advanced Configuration > Custom options, I added push "route-ipv6 ::/0".

            I also added that on the Client Export page, though I don't know if both are necessary.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.