Adding IPv6 to My Home Network (2024-11-03)
code.jeremyevans.net
code.jeremyevans.net
The author forgot Step 1. Ensure your ISP provides IPV6 services.
Otherwise, good documentation for the record.
...Then decided that NAT64 was "good enough" for people who wanted IPv6 instead of just doing fucking dual-stack
I count myself lucky, since I can at least get a public (dynamic) IPv4 address. The other option is DSLite with a single /64 via DHCP6. Well, I can't use that. So yeah, while it would be a fun journey trying out IPv6 - it's not feasable for me. And most likely, that holds true for others aswell.
There are options available - like the HE tunnelbroker - but those come with their own set of drawbacks.
It all worked ok until I noticed I could access open ports on my Mac from the public internet, and then found out my router does not support blocking incoming traffic for IPV6.
Granted, it’s probably unfeasible for attackers to scan the entire space to find open ports, but I still wasn’t comfortable with leaving all my stuff exposed, so I disabled ipv6 again and came crawling back to v4.
Maybe when/if I get a better router that supports firewalling ipv6 I’ll try again.
I put my “trusted” devices in a special vlan and untrusted devices (IoT) in another one. Only trusted devices can access IoT devices but not vice versa.
Works pretty well.
But yeah that does require a more advanced router / switch as well.
With IPv6, that's going to change again, and firewalls are going to become much more important once more - but It would explain why people can run without firewalls, right now. After all, currently the only things they're protecting against are from your local network, since your router is probably doing most of the external blocking already with NAT.
Of course, this doesn't help IPv6 adoption at all...
But hey, why think about it rationally, if you can throw crappy and corrupted around?
I believe the V2 models have updated firmware to support IPV6 firewalling but I made the mistake of buying the V1
(((spends weeks trying to find a router that supports it. Spends longer finding an ISP that supports it. Finds an ISP, multiple stacks poorly support it. Web browsers barely support it. major large websites still aren't running it. tools break with it enabled. Any ipv6 code needs a cluster-fuck of bind hacks to work cross-platform)))
Are you ready for the future, lads! Get ready! its coming!
I use a third-party router (Synology) and only had to check the IPv6 box to get it running—even with multiple VLANs in my network.
There are plenty of IPv6 services around. If a service is behind Cloudflare, it's likely IPv6 will be enabled by default. It is the same with other services, including some cloud providers now giving IPv6 addresses but charging for IPv4.
Only thing I had to do was tick the "use ipv6" button on my router.
It seems to be that you have to choose the ISPs that support it if you want it here (im based in Australia.)
? You managed to buy a router in 2024 that doesn't support IPv6?
Same reason cable modems don't mess with anything above L2 but are still reachable at http://192.168.100.1/ (no IPv6 equivalent).
Isn't that what fe80::/10 is for? (Or ff02::1 but I grant that's harder to use)
The closest analog would be something in fc00::/8 (which belongs to fc00::/7 which is the IPv6 analog to 10/8, 172.16/12, 192.168/16), but good luck getting cable modem firmware vendors to all agree on which random address to use within that and then actually implement web administration and diagnostics on it. That's what I was getting at by saying there's no IPv6 equivalent; they haven't done that.
Normally IPv6 is added as an afterthought. So it won't support many of the advanced features that the V4 interface does. E.g. its very basic to want to set static IPs -> MAC entries when running DHCP. Of the many routers I've tried that 'support' IPv6 they don't offer these features. V4 will also have features for UPnP and even though most routers are probably using miniupnpd (which has support for IPv6) the chances of it having been setup for the router are slim.
It's quite useful because UPnP can dynamically let traffic reach IPv6 global scope addresses in your network (with pin holing.) So without this feature networked software can't run services easily (arguably what was meant to be a key benefit for v6.) You know -- the funny thing is -- V6 was meant to give everyone 'public', 'routable' addresses. But the reality is because its firewalled (both at the router and the OS) coupled with the availability of services to automatically let traffic through -- I'd say its less reachable than IPv4. Those who hope that V6 is going to be the future of P2P are in for a bad surprise.
I switched to OpenWRT which has worked well enough.
Trying to get it to run from scratch on an OpenWRT x86 image is also a royal PITA, but that might be just a quirk of how the x86 image is configured by default; I haven't had a chance to try it on hardware they support properly.
I was able to finally get it work on one of my subnets, but then everything sort of just fell apart because I have a segregated network aside from my main home network and for the life of me I couldn't get it to work on two different subnets. Then throw in the whole issue of firewall rules, since since the prefix my ISP assigns is dynamic; it changes every time the router reboots. I figured I'd have to write a little service to watch the prefixes and adjust the rules as needed but just seems too like too much grief to deal with.
Left it until now when I found that android does some weird shenanigans with DNS so it's back on my radar but it's not something I'm particularly looking forward to struggling with again.
[0] https://openwrt.org/docs/guide-user/firewall/fw3_configurati...
My router does route ipv6 traffic, but does not firewall it, and has other critical security breaches with ipv6.
I have a netgear Orbi at home that works just fine, but when I turn on IPv6 it loses internet connectivity after a few hours and takes minutes to reset. Not wanting to be bothered with it, and not having a need for IPv6 I just turned it off. That setup is about a year old.