• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Host Specific IPV6 Rules

Scheduled Pinned Locked Moved IPv6
5 Posts 3 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    robertn
    last edited by Jul 1, 2014, 6:14 PM

    I have IPV6 set up and working, my ISP is Comcast and I'm using DHCP6 to get the WAN address and Track Interface WAN on the LAN interface.

    How do I create rules to allow traffic on some ports to reach LAN hosts?  I haven't found any way to make the IPV6 address assigned be deterministic.

    1 Reply Last reply Reply Quote 0
    • C
      Cino
      last edited by Jul 1, 2014, 6:43 PM

      @robertn:

      I haven't found any way to make the IPV6 address assigned be deterministic.

      There is a way using DHCPv6 if you already know your PD addresses but may cause issues down the road if your ISP changes your PD range.

      I haven't try in a while but add rules to your LAN interface, nothing is needed is on your WAN interface if i remember correctly.
      try something like this:

      src - any
      dst - ipv6 of your host
      dst port - 80

      1 Reply Last reply Reply Quote 0
      • R
        robertn
        last edited by Jul 1, 2014, 7:10 PM

        I know I can do this, but I'm looking for something that works properly even if a different prefix is assigned by the ISP.

        1 Reply Last reply Reply Quote 0
        • C
          Cino
          last edited by Jul 1, 2014, 7:26 PM

          There isn't  anyway to configure it via the gui the I know of.

          1 Reply Last reply Reply Quote 0
          • R
            razzfazz
            last edited by Jul 14, 2014, 1:56 AM

            Can you just put them on different LANs or VLANs? Comcast will give you up to 16 /64 prefixes, so you could just put the "open" hosts in one (basically, a DMZ) and the locked down ones in another.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              [[user:consent.lead]]
              [[user:consent.not_received]]