• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPv6 with prefix delegation for OpenVPN remote users

Scheduled Pinned Locked Moved OpenVPN
6 Posts 2 Posters 927 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kohenkatz
    last edited by Aug 30, 2023, 10:49 PM

    I have Verizon Fios service, with a /56 delegated IPv6 prefix. I have seen that the prefix does occasionally change. All of my regular interfaces (physical and VLAN) are set to "Track Interface" on the WAN with appropriate prefix IDs.

    I would like to also have IPv6 available for remote users on OpenVPN. To do that, I need to put a value in the "IPv6 Tunnel Network" box on the OpenVPN Server settings page.

    If I use one of my delegated /64 networks, it won't update automatically when the ISP's prefix changes, so it will no longer be able to route traffic if the prefix changes, until someone logs in and updates the value.

    Other than writing some kind of scheduled script that monitors the prefix I have and updates the OpenVPN configuration, is there any better way to do this?

    I've seen a few references to NPt (and I read the pfSense documentation for it), which seems like it might allow me to use ULA addresses on the VPN and translate them to a prefix, but I don't see any way to set a tracked interface in there either, only to choose a specific prefix or the delegated prefix of another LAN interface. Would this feature help me, and how would I set it up?

    J 1 Reply Last reply Aug 31, 2023, 1:31 PM Reply Quote 0
    • J
      JKnott @kohenkatz
      last edited by Aug 31, 2023, 1:31 PM

      @kohenkatz

      To access stuff on your network, you can use Unique Local Addresses. Use the ULA addresses in DNS rather than global.
      ULA is the IPv6 equivalent of RFC1918 on IPv4.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      K 1 Reply Last reply Aug 31, 2023, 1:43 PM Reply Quote 0
      • K
        kohenkatz @JKnott
        last edited by Aug 31, 2023, 1:43 PM

        @JKnott I guess I should have been more clear - I want these users to be able to access the Internet via this VPN as well.

        J 1 Reply Last reply Sep 1, 2023, 12:32 PM Reply Quote 0
        • J
          JKnott @kohenkatz
          last edited by Sep 1, 2023, 12:32 PM

          @kohenkatz

          Do you have System/Advanced/Networking/Do not allow PD/Address release checked?

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          K 1 Reply Last reply Sep 1, 2023, 12:59 PM Reply Quote 0
          • K
            kohenkatz @JKnott
            last edited by Sep 1, 2023, 12:59 PM

            @JKnott I do have that option checked. I think the prefix only changes if the connection is disconnected (for power outages, cables being unplugged or broken, etc.) for a long enough period of time that Verizon expires the lease, but I do not know how long that period is. (For IPv4, the DHCP lease period is 2 hours, but I've seen reports online that the IPv6 lease time is only one hour.)

            J 1 Reply Last reply Sep 1, 2023, 3:44 PM Reply Quote 0
            • J
              JKnott @kohenkatz
              last edited by Sep 1, 2023, 3:44 PM

              @kohenkatz

              I've had the same prefix for a few years. It's even survived replacing both the computer I run pfSense on and the cable modem. The IPv4 lease wouldn't survive either. IPv6 uses something called DUID, which is supposed to tell the ISP what your prefix is. I understand some ISPs ignore it. I have no idea what Verizon does. Maybe someone else here knows.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received