Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Converting to dual stack

    Scheduled Pinned Locked Moved IPv6
    2 Posts 2 Posters 496 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nikmiddleton
      last edited by

      Hi Guys,

      I'd like to implement a dual stack on our network but I'm a little confused.

      Prior to deploying PFSense, all of our servers sat behind a cisco router. Each server had 2 connections, lan and wan.

      All the servers had static public IP's and their own firewall.

      When we deployed pfsense, we got rid of the wan connection and used port forwarding and alias's to provide the servers with their own external IP's

      We now want to enable our webserver for IP6 as well as IP4. Before the change over we simply put an IP6 address on the wan connection and it worked.

      What I can't figure out is how we would now do this with just the lan connection without exposing the LAN. (we currently have a IP6 /64 allocated)

      At the moment I have setup a gateway on PFSense pointing to the router ::1 and given the wan an ip6 address of ::15

      The web server originally had an address of ::205

      Can some kind soul tell me what I need to do to make this work?

      This is a production environment so I'm a little nervous in just trying to experiment.

      regards

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @nikmiddleton
        last edited by

        You could set firewall rules to only allow traffic to the servers' IPv6 addresses, and not allow connections to other PCs.

        You might double check your ISP's router as well...many block inbound IPv6 by default.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.