Adventures with Verizon FiOS IPv6
git.hardenedbsd.org
git.hardenedbsd.org
You can probably do the same on other platforms.
But all existing leases on your network are invalid until they refresh and won't route traffic.
When you catch it in the act, it is very annoying.
I wish I had that problem. Spectrum doesn't even offer IPv6 in my area. :(
So far, AT&T Fiber is behaving the same here too. I might somehow just be lucky with ISPs :)
As I understand it, we (admins of ipv6 networks) are expected to run both public and private sets of addresses internally. The public ones may change if your ISP makes you, but your ULAs never do.
"ULA per RFC 6724 is less preferred (the Precedence value is lower) than all IPv4 (represented by ::ffff:0:0/96 in the table). Because of the lower Precedence value, if you have IPv4 enabled on a host, it will use IPv4 before using ULA."
https://blogs.infoblox.com/ipv6-coe/ula-is-broken-in-dual-st...
[0] - https://github.com/commscope-ruckus/RUCKUS_ICX_Ansible
edit: well for some reason I can't reply to you anymore, but for firewall rules I have had good luck using aliases instead of static addresses
One solution I was considering, but never implemented, was to use a ULA addres range internally and doing 1:1 NAT mapping on the external delegation to the internal ULA range
One gotcha is that when I replace the firewall, I gotta make sure I keep the same ethernet MAC address to avoid re-IPing on the IPv4 side (the line in my FreeBSD firewall's config is "ifconfig_ix0="DHCP ether 00:0d:b9:48:92:48".
The other gotcha, for IPv6, is I have to migrate my client DHCP Unique Identifier (DUID) (`/var/db/dhcp6c_duid`) to my new firewall to retain my existing IPv6 subnets.
One great thing about ipv6 is your not limited to 1 IP address per interface
The internal lan issues didn't bother me because I still prefer a local fd##::/64.
For a few firewall rules that used the prefix, I noticed that the /56s I'd get weren't completely unbound so it was easy to keep a list in an nftables var.
For inbound access, I have DNS rfc2136 with frequent updates for IPv4 so adding v6 was trivial.
I think that would work for IPv6 as well but not with the use case where you’re using the public IP address as your hosts’ DNS server.
Could you assign an internal IPv6 address to your DNS server that is static and have it also get a second address from FiOS? Then all your clients could be configured to go to the static internal address.
ip=`curl --silent ipinfo.io/ip`
ssh -i <CREDENTIALS> <MY-CLOUD-HOST> "echo $ip > lastlog"
Then anytime I need to know where home is: ssh MY-CLOUD-HOST -C cat lastlog
[ EDIT: having posted this, i realized you could do the same thing just using whoami(1) on MY-CLOUD-HOST and avoid ipinfo.ip entirely ]mine looks sort of like this.
echo "${SSH_CONNECTION}" | awk '{print $1}' | cat "/var/ip_log" - | uniq > "/var/ip_log.new"
mv "/var/ip_log.new" "/var/ip_log"
ssh <MY-CLOUD-HOST> "echo \$SSH_CLIENT" | cut -f1 -d' '
works tooI handle this exclusively with WireGuard or Nebula now, though I'm sure other stuff like ZeroTier would work too. At worst a $5 VPS is enough to act as a lighthouse/relay, although as it happens for one of my virtual networks I do have a fixed IP to work with. But everything else can be whatever, completely dynamic, and all the tunnels stay up fine 24/7/365 and traffic can be routed through them as I wish and extremely minimal exposure. On my own sites I use OPNsense to mix and match whole VLANs.
If one explicitly wants to run services to the general world from home that's of course no good, but if it's all private I think modern point to point tunnels or high level dynamic meshes are an excellent option now, and can be fully self-hosted super easily. It's very exciting how fast, reliable and powerful completely FOSS options are nowadays.
I have all my IPs configured static internally, and have DNS going over to AdGuard Home. Even have the firewall set up to force all DNS traffic over there. Doesn't work so well if all my IPs change because Verizon had an outage.
It clicked when I learned about some of the ways devices can get ipv6 ips. Those /64 subnets provide a large enough space for devices to randomly self-assign their own address without a high risk of collisions. https://datatracker.ietf.org/doc/html/rfc4193#section-3.2.1
All devices need to know is the prefix to generate their own a unique local address (ULA). This can provide for stable local IPs for a device too. This eliminates the need for dhcp since ipv6 provides a standard udp / icmpv6 based protocol for routers to announce the prefix. Icmpv6 also replaces arp so in all it’s a much more elegant system. It can be much more stable too.
Can anyone recommend an EU-based server provider that could be used as a tunnel?
With IPv4 it has always made far more sense for hobbyists to just use a dynamic DNS service, of which there are many free options. Some registrars like Namecheap even offer it when you buy a domain. IPv6 obviously complicates the hell out of this and I haven't really seen a solution as easy as for your average hobbyist.
Why is it different? Can't you just dynamically update a AAAA record?
This makes dynamic DNS much more complicated because you can't just update the AAAA record with the address of your router, you need to update records for all clients that need to be externally accessible.
This is not an unsolvable problem, but it does make things a bit more complicated than just punching your DynDNS credentials into your router config or running Namecheap's DNS tool on one of your machines.
OTOH 10G fiber.