4 ms·
I really don't get why it's terrifying. Maybe it would help to just do it rather than reading docs about it? As an example, let's say your ISP gives you the de
by Dagger2 3y ago
I really don't get why it's terrifying. Maybe it would help to just do it rather than reading docs about it?
As an example, let's say your ISP gives you the details:
WAN IP: 2001:db8:ffff:200::2/64 (like "203.0.113.2/24")
Default router: 2001:db8:ffff:200::1 (like "203.0.113.1")
Routed prefix: 2001:db8:42::/48 (like "192.168.0.0/16")
On a Linux router, you would set this up by doing:
ip addr add 2001:db8:ffff:200::2/64 dev wan0
ip route add default via 2001:db8:ffff:200::1
ip addr add 2001:db8:42:1::1/64 dev lan0 [like "192.168.1.1/24"]
Then install radvd, put the following into /etc/radvd.conf and start the radvd daemon:
interface lan0 {
AdvSendAdvert on;
prefix ::/64 { DeprecatePrefix on; };
RDNSS 2001:4860:4860::8888 { };
};
This is enough to give you a functioning network. Your machines will pick up the announcement, assign themselves addresses and default routes, and can talk to each other and the Internet. And as you can see, this L3 setup isn't any different to v4 -- you've got a WAN IP, a LAN IP and a route. Devices get IPs from 2001:db8:42:1::/64 like they get IPs from 192.168.1.0/24. The client autoconfig is different but it's a lot simpler than DHCP.
What am I glossing over? Most ISPs aren't static, which means you need to automate the above setup, and even for a static ISP you'd need to persist the `ip` commands (e.g. via /etc/network/interfaces or whatever your distro uses to do network config). If your ISP needs ppp or VLANs or whatever then you gotta deal with those too, but that's not v6-specific.
You're also going to want a firewall, but that will look very similar to your v4 one: deny new connections from the WAN, allow new connections from the LAN, allow packets from existing connections in both directions. I can give you ip6tables or ferm for that if you want.
Lastly, I'll point this out explicitly, but you don't need NAT which is why there's no mention of it above. It's just not necessary. The ISP has an inbound route set for 2001:db8:42::/48 to your router, and a /48 is more than enough address space.
Other than that, those three commands + radvd config really are enough for a fully-functioning network. It doesn't seem terrifying to me, nor does it seem inaccessible to someone that already knows how v4 networks work.
- hnbear 3y agoThis actually did more to explain the implementation basics that most intros I’ve read. I’m not the parent but I just end up not wanting to have to debug network traffic across two protocols where I don’t know how to deterministically work out which is in use. Then I need to work out new firewall rules and replacements for things like Pi-hole, home DNS, etc. Realistically that’s just me reading docs for 10 minutes, and double-checking everything has the “work with ipv6 box” toggled. But personally my hesitation is getting stuck in this in between and maintaining two network setups. Not terrifying, just a lot of work I don’t need to do. But thank you. Now I’m inspired to do it.