Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Forward port on IPv6

    Scheduled Pinned Locked Moved IPv6
    7 Posts 4 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nahun
      last edited by

      Hey everyone,

      I've got IPv6 working great with Comcast. My machines behind pfsense get a global v6 IP and I can browse IPv6 sites just fine.

      My question is about forwarding ports from pfsense to various machines behind it. I have one DNS name that I want to use for every port (80, 22, 443, etc…), but since I obviously don't want to use NAT anymore with IPv6 what is the best way to accomplish this?

      I can do it with load balancing just fine, but that seems overkill since this is a home network and I'm never going to actually need to load balance anything.

      Is there a best practice for this type of thing with IPv6?

      thanks.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Port forwarding is NAT. NAT and IPv6 is bad.

        There isn't going to be a way to properly use one DNS hostname for services on multiple IPs the way you're after. Use unique hostnames per IP.

        Port forwarding with IPv6 may work already, but I'd still avoid it like the plague where possible.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • N
          nahun
          last edited by

          Thats what I was afraid of. Thanks for confirming!

          1 Reply Last reply Reply Quote 0
          • K
            kejianshi
            last edited by

            We have waited so long to be cured of NAT.  Resist the addiction.

            1 Reply Last reply Reply Quote 0
            • N
              nahun
              last edited by

              @kejianshi:

              We have waited so long to be cured of NAT.  Resist the addiction.

              haha, yeah I'm definitely going to avoid port forwarding. It is VERY nice to have a global IP on all my desktops with just a firewall in front to protect. Such a weird thing to have though after all these years.

              1 Reply Last reply Reply Quote 0
              • R
                razzfazz
                last edited by

                That said, it would be very nice if the miniupnpd version included in pfSense supported WANIPv6Firewall / pinholes / PCP.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  @razzfazz:

                  That said, it would be very nice if the miniupnpd version included in pfSense supported WANIPv6Firewall / pinholes / PCP.

                  Last time we tried to enable IPv6 for miniupnpd, it broke in various ways. Maybe a newer version would help there, but at the time we tried it, it was the most current version available. It has been a while though, we may revisit that for 2.2.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.