Alexandre · @alelab
34 followers · 273 posts · Server mastodon.bsd.cafe

@quux Hello, thank you for your reply. Yes, IPv6-ICMP is allowed in and out. I even tried to allow in/out INET6 without success.

But I just found the explanation and the solution.
My PF setup is correct.
As I installed I must set gateway_enable="YES" and ipv6_gateway_enable="YES" in /etc/rc.conf.
This last setting set net.inet6.ip6.forwarding to 1 (sysctl). But this setting blocks automatic IPv6 gateway settings get by IPv6 SLAAC. Even with disabled in /etc/rc.conf but with only ipv6_gateway_enable="YES", IPv6 is correctly set but no IPv6 gateway is set. I cannot ping6 or curl an IPv6 URL.
To bypass this, I must add ipv6_gateway_router="<IPv6-router-address>" in /etc/rc.conf.

#wireguard #pf #freebsd #ipv6 #slaac #bsdcafe

Last updated 2 years ago

flatplanet · @flatplanet
40 followers · 531 posts · Server mastodon.ie

Shout out to - once you get past the (endless) hassle of the the install so far the performance is excellent -pd

#eir #ipv4 #ipv6 #slaac #publicip

Last updated 2 years ago

What's the favorite chat tool of the engineers? ... πŸ₯

#network #slaac #dadjokes #badjokes

Last updated 3 years ago

Carlos Mogas da Silva · @r3pek
279 followers · 1067 posts · Server mastodon.r3pek.org

This might worth the shot... Anyone running on a server and has enabled on the Wan interface via ?

#opnsense #proxmox #ipv6 #slaac

Last updated 3 years ago

Lars Kellogg-Stedman · @larsks
70 followers · 82 posts · Server hachyderm.io

Anyone have thoughts on what might prevent from working on a network for which stateful address configuration works just fine? Details are in unix.stackexchange.com/q/72536 if you're curious.

The target system is obviously seeing router advertisements and configures the correct default route. Router advertisements have the "A" flag set, and the "accept_ra" sysctl is "2" for this interface.

#slaac #ipv6

Last updated 3 years ago

meka · @meka
274 followers · 1190 posts · Server bsd.network

It's one thing setting up the way you want it, but having jails on the bridge whose member is egress was another level for me. First, having , and on the same network was somewhat hard to achieve. Then came filtering. The hard part about it is how to drop everything on the host, but not drop packets which flow towards jails. After a while, I learned PF has <self>. And then I learned that fe80::/10 is special, and in what way is it special. The result is current pf.conf template I came up with: github.com/cbsd/reggae/blob/ma

When all that started working, I wanted my isc-dhcpd and isc-dhcpd6 to register A and AAAA records in nsd. The result of that effort is github.com/cbsd/reggae/blob/ma and it is far from perfect. I set myself a goal of not using anything outside base OS, so it took a while to handle IPv6 addresses.

If you're asking your self why i did all this, it's because I wanted to learn about dual stack and what are the problems. I am by no means network engineer, only a sys admin who decided to learn more about networking.

#ipv6 #freebsd #DHCPv4 #dhcpv6 #slaac

Last updated 3 years ago

Julien M. · @julm
485 followers · 4935 posts · Server framapiaf.org

- : A Method for Generating Semantically Opaque Interface Identifiers with Stateless Address Autoconfiguration () bortzmeyer.org/7217.html wiki.archlinux.org/index.php/I

- : and Considerations for Address Generation Mechanisms tools.ietf.org/html/rfc7721

- A Brief of Recent Advances in , Part I: Addressing si6networks.com/2020/08/06/a-b

#history #privacy #security #RFC7721 #slaac #ipv6 #rfc7217

Last updated 5 years ago

jenda · @janjaromirhorak
149 followers · 372 posts · Server mstdn.io

Ugh, does anyone know how to with ? I am confused and not able to find much information online (probably missing some important keywords to search for).

#slaac #systemd #networkd #linux #unix

Last updated 8 years ago