Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    reaching firewall itself via ipv6

    Scheduled Pinned Locked Moved IPv6
    24 Posts 6 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott @MikeV7896
      last edited by

      @mikev7896 said in reaching firewall itself via ipv6:

      On their own routers, they use the "ff" prefix ID and assign a global address from that prefix to the WAN interface (usually ::1).

      ff00/8 is a multicast address and certainly not global, which starts with 2 or 3. Perhaps you meant fc or fd, which are unique local addresses and entirely suitable for network management.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      MikeV7896M 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @ddbnj
        last edited by

        @ddbnj said in reaching firewall itself via ipv6:

        I didn't want to be wrong again.

        I thought I was wrong once, but I was mistaken. 😉

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 1
        • MikeV7896M
          MikeV7896 @JKnott
          last edited by

          @jknott said in reaching firewall itself via ipv6:

          @mikev7896 said in reaching firewall itself via ipv6:

          On their own routers, they use the "ff" prefix ID and assign a global address from that prefix to the WAN interface (usually ::1).

          ff00/8 is a multicast address and certainly not global, which starts with 2 or 3. Perhaps you meant fc or fd, which are unique local addresses and entirely suitable for network management.

          I mean that they use prefix ID "ff" out of the /56 that was delegated... that would be xxxx:xxxx:xxxx:xxFF::

          The S in IOT stands for Security

          1 Reply Last reply Reply Quote 1
          • luckman212L
            luckman212 LAYER 8 @ddbnj
            last edited by

            @ddbnj I'm on FIOS too (NYC) and spent just about the entire week messing around with and learning the ins and outs of Verizon's implementation. There are definitely some sharp edges but I'm pretty happy now with the way things are working.

            You might want to check out my helper script to assign a routable IP (GUA) to your WAN from one of the delegated prefix subnets. Link below

            luckman212/assign-gua-from-iapd - GitHub

            1 Reply Last reply Reply Quote 2
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.