• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[solved] NPt doesn't let me do that, why?

IPv6
2
9
834
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    Bob.Dig LAYER 8
    last edited by Bob.Dig Feb 4, 2023, 11:15 AM Feb 4, 2023, 10:16 AM

    I would like to use only one /64 from the delegated prefix on WAN to be used for all of my LAN interfaces but pfSense doesn't allow me to do that. What is the reasoning behind that?

    login-to-view

    It will only allow me to select /64 but I don't see much benefit from doing that because I would have to do that for every LAN interface, one by one?

    I am on 23.01.r.20230202.1645.

    B J 2 Replies Last reply Feb 4, 2023, 11:09 AM Reply Quote 0
    • B
      Bob.Dig LAYER 8 @Bob.Dig
      last edited by Bob.Dig Feb 4, 2023, 12:08 PM Feb 4, 2023, 11:09 AM

      It looks like it is working, one /64 for many interfaces, you just have to create the NPt rules for every LAN-interface. But because there is a copy dialog, it is not that much work.
      Multi-IPv6-WAN with Failover is working like a charm for now and the problems with a changing prefix on my DSL-WAN is somewhat mitigated. 😉
      I hope I got that right.

      1 Reply Last reply Reply Quote 0
      • J
        JKnott @Bob.Dig
        last edited by Feb 4, 2023, 1:35 PM

        @bob-dig

        If you have more than 1 /64, why are you trying to do this? The only reason for NAT on IPv4 is the address shortage. No need on IPv6.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        B 1 Reply Last reply Feb 4, 2023, 1:40 PM Reply Quote 0
        • B
          Bob.Dig LAYER 8 @JKnott
          last edited by Bob.Dig Feb 4, 2023, 1:59 PM Feb 4, 2023, 1:40 PM

          @jknott it is not NAT it is NPt. 😉
          And I do it for failover purposes and the lack of pfSense to cope with changing IPv6 prefixes, which will result in a gateway going offline for some time for me.

          J 1 Reply Last reply Feb 4, 2023, 3:27 PM Reply Quote 0
          • J
            JKnott @Bob.Dig
            last edited by Feb 4, 2023, 3:27 PM

            @bob-dig

            What problem is the changing address causing? If messing up local DNS, then you can use Unique Local Addresses, which are static.

            The proper way to do fail over is to have your own routed prefix, so that it will be constant, no matter how it's delivered and a routing protocol, such as OSPF, will sort things out. Your problem occurs because you're using 2 providers, without a routed prefix, so it will change.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            B 1 Reply Last reply Feb 4, 2023, 3:34 PM Reply Quote 0
            • B
              Bob.Dig LAYER 8 @JKnott
              last edited by Bob.Dig Feb 4, 2023, 4:27 PM Feb 4, 2023, 3:34 PM

              @jknott My internet (DSL) has only dynamic IPv6. I am just a home user with now knowledge about OSPF.

              J 1 Reply Last reply Feb 4, 2023, 9:59 PM Reply Quote 0
              • J
                JKnott @Bob.Dig
                last edited by Feb 4, 2023, 9:59 PM

                @bob-dig

                Mine too. However, I have Do not allow PD/Address release set, which makes it virtually static. I've had the same prefix for a few years and it's survived replacing, at different times, both the modem and firewall/router computer. On IPv4, replacing either of those would have caused a change of address and host name.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                B 1 Reply Last reply Feb 5, 2023, 8:55 AM Reply Quote 0
                • B
                  Bob.Dig LAYER 8 @JKnott
                  last edited by Bob.Dig Feb 5, 2023, 8:56 AM Feb 5, 2023, 8:55 AM

                  @jknott said in [solved] NPt doesn't let me do that, why?:

                  Mine too. However, I have Do not allow PD/Address release set, which makes it virtually static.

                  I know that but around my place with DSL it is different. Not only is it changing daily, my last IP will be given to a different customer immediately, at least with IPv4. And I can see funny things if I don't immediately update my DDNS-records.

                  J 1 Reply Last reply Feb 5, 2023, 1:08 PM Reply Quote 0
                  • J
                    JKnott @Bob.Dig
                    last edited by Feb 5, 2023, 1:08 PM

                    @bob-dig said in [solved] NPt doesn't let me do that, why?:

                    I don't immediately update my DDNS-records.

                    Are you talking about internal or external DNS? If internal, ULA is all you need for static addresses.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.