Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Delegated prefix in firewall rules?

    Scheduled Pinned Locked Moved IPv6
    23 Posts 6 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bob.DigB
      Bob.Dig LAYER 8 @Sevi
      last edited by Bob.Dig

      @Sevi said in Delegated prefix in firewall rules?:

      Apparently dynamic prefixes with this kind of alias will never be possible in pfSense for technical reasons - at least that's what I gathered from the posts cited above.

      I don't know if you are aware and I know, it is not what was asked here about, but you can create aliases for dynamic IPv6 hosts with the help of the DHCPv6 Server and a hostname given by DHCPv6. You then can create an alias from that hostname the same way you can do that with IPv4 and it will change.

      S 1 Reply Last reply Reply Quote 0
      • S
        Sevi @Bob.Dig
        last edited by

        @Bob-Dig Good point! I believe that approach was mentioned in one of the posts above.

        As far as I understood it, the limitation with aliases, is that they cannot be something that would expand to different things in different contexts, e.g. depending on which interface the alias is used on. But a FQDN that gets translated through DNS works of course (For my own network, I just didn't want the hassle of setting up DHCPv6 in parallel to my IPv4 DHCP at the moment ๐Ÿ˜† ).

        1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @Sevi
          last edited by

          @Sevi said in Delegated prefix in firewall rules?:

          patch should also be included in upcoming releases

          ref: https://docs.netgate.com/pfsense/en/latest/releases/24-03.html#aliases-tables

          @Sevi said in Delegated prefix in firewall rules?:

          address ::123

          Hmm, thanks, will try that. Our IPv6 prefix at home changed recently and my main client (wife) was annoyed for a while without telling me.

          @johnpoz said in Delegated prefix in firewall rules?:

          free Hurricane Electric tunnel

          We did that once because of a specific setup...it functions, but the throughput is throttled, about 35 Mbps as I recall. And there are sites that consider HE IPs like a VPN and block access, for instance sites that can only show video or sports content to certain regions due to licensing.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote ๐Ÿ‘ helpful posts!

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.