Internet routing from static /64 LAN subnet
-
I have a pfSense VM running on ESXi hosted in a datacenter. The hosting provider has assigned me two /64 prefixes. I've assigned one /64 to a WAN interface and verified that it can ping its gateway and hosts on the internet.
I assigned an address from the second /64 to the LAN interface, but although the LAN interface can ping the WAN interface, it can't reach the default gateway or anything beyond.
When I try to traceroute from the LAN interface address it doesn't even appear to reach the WAN interface. It seems like something is not routing correctly, but I don't know ipv6 enough to understand the problem.
Can anyone help me understand what I'm doing wrong?
Successful ping from WANv6 to google.com:
Successful ping from LAN to WANv6:
Unsuccessful ping from LAN to google.com:
Unsuccessful ping from LAN to WANv6 gateway:
Traceroute from WANv6 to google.com
Traceroute from LAN to google.com
-
@korin said in Internet routing from static /64 LAN subnet:
The hosting provider has assigned me two /64 prefixes.
Did they assign you the two prefixes to the same link-local segment? If you swap the prefixes around is prefix B usable on the WAN? Typically in this scenario where you're getting additional prefixes the provider would use Prefix Delegation which would allow you to request prefix B to assign to the LAN interface. If that's not an option with your provider, you may need to tell them to route prefix B to the router's IPv6 address (either the link-local fe80 or the assigned IPv6 address) on prefix A.
-
Did you ever figure this out? I have literally the same problem. The internet is awash with endless threads of failure regarding what you would think is such a simple a common problem.
-
@supernoob No, I never got it to work, unfortunately. @theit8514 provided really helpful information but I've had a difficult time communicating to my hosting provider what I need from them. I think they are accustomed to hosting single physical servers and not virtual hosts with routed subnets. I struggled with them for several hours but finally gave up.
-
Our data center set up a /125 IIRC for our IPv6 WAN and routes our LAN subnet to a specific IP. (We have a HA setup so two IPs plus the shared IP)
Like this but IPv6: https://docs.netgate.com/pfsense/en/latest/recipes/route-public-ip-addresses.html#ip-assignments