• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPv6 and HE certification web server question

Scheduled Pinned Locked Moved IPv6
24 Posts 5 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    Bob.Dig LAYER 8 @Gertjan
    last edited by Bob.Dig Jul 24, 2024, 9:47 AM Jul 24, 2024, 9:46 AM

    @Gertjan said in IPv6 and HE certification web server question:

    I don't think HE will ask you to fire up a mail server

    You misunderstand. You need to be "sage" to be able to open port 25 incoming with HE. I just asked what else you gonna gain.

    G J 2 Replies Last reply Jul 24, 2024, 9:48 AM Reply Quote 0
    • G
      Gertjan @Bob.Dig
      last edited by Jul 24, 2024, 9:48 AM

      @Bob-Dig

      aahhhh, I get it.
      HE can be considered as an ISP, and as such - see above - the will block "TCP 25".
      So being sage unblocks that ? Nice to know.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      B 1 Reply Last reply Jul 24, 2024, 9:51 AM Reply Quote 0
      • B
        Bob.Dig LAYER 8 @Gertjan
        last edited by Bob.Dig Jul 24, 2024, 9:52 AM Jul 24, 2024, 9:51 AM

        @Gertjan Yepp. Go to your tunnel and then klick on advanced. If it is not there when you are "sage", you might have to contact support.

        1 Reply Last reply Reply Quote 0
        • B
          Bob.Dig LAYER 8 @Gertjan
          last edited by Bob.Dig Jul 24, 2024, 9:59 AM Jul 24, 2024, 9:57 AM

          @Gertjan said in IPv6 and HE certification web server question:

          Btw : there should also be a comparable test for DNSSEC test. And a Letsencrypt-like certificate (certification 😊 ) test. With these two, "DANE" becomes possible and that will be the end of all CA's as they are not needed anymore.

          I stopped using DANE because it became to burdensome with Letsencrypt. Sadly. 😉

          But you are right, something certbot-like together with DANE could end things.

          G 1 Reply Last reply Jul 24, 2024, 10:21 AM Reply Quote 0
          • G
            Gertjan @Bob.Dig
            last edited by Gertjan Jul 24, 2024, 10:22 AM Jul 24, 2024, 10:21 AM

            @Bob-Dig said in IPv6 and HE certification web server question:

            I stopped using DANE because it became to burdensome with Letsencrypt.

            Here : this will take care of your issues : https://dnssec-stats.ant.isi.edu/~viktor/x3hosts.html

            Add these to your zone :
            I have a domain name 'test-domaine.fr', and added the current 5 signing certificate hashes :

            $ORIGIN mail.test-domaine.fr.
            _25._tcp	TLSA	2 1 1	2bbad93ab5c79279ec121507f272cbe0c6647a3aae52e22f388afab426b4adba
            _25._tcp	TLSA	2 1 1	6ddac18698f7f1f7e1c69b9bce420d974ac6f94ca8b2c761701623f99c767dc7
            _25._tcp	TLSA	2 1 1	919c0df7a787b597ed056ace654b1de9c0387acf349f73734a4fd7b58cf612a4
            _25._tcp	TLSA	2 1 1	025490860b498ab73c6a12f27a49ad5fe230fafe3ac8f6112c9b7d0aad46941d
            _25._tcp	TLSA	2 1 1	f1647a5ee3efac54c892e930584fe47979b7acd1c76c1271bca1c5076d869888
            _25._tcp	TLSA	2 1 1	8D02536C887482BC34FF54E41D2BA659BF85B341A0A20AFADB5813DCFBCF286D
            

            and now I'm good up until the moment these start to fade out, and new one get added and used.

            Check here : https://dane.sys4.de/smtp/test-domaine.fr - one of them matches, so DANE will be ok.
            I'm using Letsencrypt certs for everything : web, smtp, pop, imap, you name it.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            B 1 Reply Last reply Jul 24, 2024, 11:07 AM Reply Quote 2
            • B
              Bob.Dig LAYER 8 @Gertjan
              last edited by Jul 24, 2024, 11:07 AM

              @Gertjan Thanks but I pass. Also, no one had a problem with my servers when DANE was failing... 🙄

              G 1 Reply Last reply Jul 24, 2024, 11:23 AM Reply Quote 0
              • G
                Gertjan @Bob.Dig
                last edited by Jul 24, 2024, 11:23 AM

                @Bob-Dig said in IPv6 and HE certification web server question:

                no one had a problem with my servers

                Well 😊 they had a problem with the info you published in your DNS zone info ^^
                Publish the correct info, and everybody is happy.
                Like DKIM - like SPF - like DMARC. Like a correct reverse host name. H*ll, like a certificate on your web and mail server that is in the 'valid' for your servers. Like DNSSEC.
                Some of them are a must have these days, some are more or less optional.
                Try sending a mail from your domain - mail server to a gmail, and then check how gmail 'scores' your mail.

                And normally, we don't want a A+ because it's looks nice (no one cares actually), we want the A+ because it means we probably, maybe, understood the things we work with.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                B 1 Reply Last reply Jul 24, 2024, 12:22 PM Reply Quote 0
                • B
                  Bob.Dig LAYER 8 @Gertjan
                  last edited by Bob.Dig Jul 24, 2024, 12:22 PM Jul 24, 2024, 12:22 PM

                  @Gertjan No A+ for me because I don't run any public web server.
                  And there is no score in an email to gmail right? It just says if you passed the usual stuff.
                  But I "enabled" gmail's Postmaster Tools now. Probably will do nothing because I rarely send email.

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator @Bob.Dig
                    last edited by Jul 24, 2024, 12:51 PM

                    @Bob-Dig said in IPv6 and HE certification web server question:

                    I just asked what else you gonna gain.

                    Understanding of IPv6 and how it functions being the top one to be honest. And the cool tshirt..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 2
                    • J
                      JonathanLee @Gertjan
                      last edited by JonathanLee Jul 24, 2024, 5:36 PM Jul 24, 2024, 5:16 PM

                      @Gertjan Ooooo yeah!!!

                      Screenshot 2024-07-24 at 10.15.44.png

                      mirroredanalytics.com is up and running :) ipv6 and ipv4

                      Now I have to create a ipv6 webserver with the port 25 thing you guys are talking about. I am going to use iRedMail over Kali. I just have to make a new copy of Kali my current one is to old to download anything anymore...

                      Got to tell you I loved my old CD days with PHLAK linux Pen testing software

                      Make sure to upvote

                      1 Reply Last reply Reply Quote 0
                      • J
                        JonathanLee
                        last edited by JonathanLee Jul 24, 2024, 5:41 PM Jul 24, 2024, 5:39 PM

                        Screenshot 2024-07-24 at 10.38.41.png

                        I can almost make a post in the HE forum ... almost to sage...

                        I just need An IPv6 enabled mail system, with working RDNS.

                        The last step took my gmail as a working ipv6 email. I guess there was a time that was not the case...

                        Make sure to upvote

                        J 1 Reply Last reply Jul 24, 2024, 6:22 PM Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator @JonathanLee
                          last edited by Jul 24, 2024, 6:22 PM

                          @JonathanLee If I recall with the email section - I just used their free dns and setup the PTR records, etc.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          J 1 Reply Last reply Jul 24, 2024, 6:26 PM Reply Quote 1
                          • J
                            JonathanLee @johnpoz
                            last edited by JonathanLee Jul 24, 2024, 6:27 PM Jul 24, 2024, 6:26 PM

                            @johnpoz thanks for the recommendations again!!

                            I know the basics of IPv6. I can configure an ipv6 webserver that is behind a secure firewall inside of a IPv6 tunnel broker that tunnels inside of a IPv4 only ISP provider. I can manage and parse out AAAA records for streaming services that do not support tunnel brokers. I understand glue-records and have my website mirroredanalytics.com working (just the basics I have not spent any time really designing it. Right now, my web server is still under construction) YEAHHHH Buddy!

                            Screenshot 2024-07-24 at 11.25.59.png

                            Plus they said I get a T-Shirt :)

                            Make sure to upvote

                            1 Reply Last reply Reply Quote 1
                            • J
                              JonathanLee
                              last edited by JonathanLee Jan 2, 2025, 7:45 PM Jan 2, 2025, 7:44 PM

                              YEAH!!!!!!!!!!

                              Kachow!!!

                              Screenshot 2025-01-02 at 11.40.36.jpg

                              YEAH!!!! Check it out !!!! New T-Shirt SAGE!!!

                              Make sure to upvote

                              J 1 Reply Last reply Jan 2, 2025, 8:03 PM Reply Quote 1
                              • J
                                johnpoz LAYER 8 Global Moderator @JonathanLee
                                last edited by johnpoz Jan 2, 2025, 8:06 PM Jan 2, 2025, 8:03 PM

                                @JonathanLee nice to see they still sending those out. I got mine back in 2011.. I still have it in a drawer some where I think.. Wear it with pride - but highly unlikely anyone will have any clue to what it means ;) Unless your at some nerd/geek fest - hahahha

                                I use to wear it to work on casual fridays - and even fellow tech guys didn't really have a clue.

                                edit: well shit - I just looked through my t-shirt drawer, and I don't see it - my wife prob donated it to goodwill or something.. I don't recall if mine that http link at the top or not was wanting to check..

                                Still got some grateful dead shirts from concerts 30 years ago though - she better never donate those!!!

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                JKnottJ 1 Reply Last reply Jan 3, 2025, 3:23 AM Reply Quote 1
                                • JKnottJ
                                  JKnott @johnpoz
                                  last edited by Jan 3, 2025, 3:23 AM

                                  @johnpoz said in IPv6 and HE certification web server question:

                                  Still got some grateful dead shirts from concerts 30 years ago though - she better never donate those!!!

                                  She might use them as cleaning rags though! 😉

                                  I went to an Emerson, Lake and Palmer concert in 1973! Didn't get any shirt though. 😭

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                    [[user:consent.lead]]
                                    [[user:consent.not_received]]