AZTCOFW / DOCUMENTATION
Configuring IPv6 Through A Tunnel Broker Service
Configuration guides, troubleshooting and practical advice for AZTCOFW.
Articles
12 resultsAdd Firewall Rules
Once LAN addresses have been assigned, add firewall rules to allow the IPv6 traffic to flow. Navigate to Firewall > Rules , LAN tab. Check the list for an existing IPv6 rule. If a rule to pass IPv6 traffic already exists
Allow ICMP
ICMP echo requests must be allowed on the WAN address that is terminating the tunnel to ensure that it is online and reachable. If ICMP is blocked, the tunnel broker may refuse to setup the tunnel to the IPv4 address. Ed
Allow IPv6 Traffic
On new installations of pfSense after 2.1, IPv6 traffic is allowed by default. If the configuration on the firewall has been upgraded from older versions, then IPv6 would still be blocked. To enable IPv6 traffic, perform
Configure the New OPT Interface
The new interface is now accessible under Interfaces > OPTx , where x depends on the number assigned to the interface. Navigate to the new interface configuration page. ( Interfaces > OPTx ) Check Enable Interface . Ente
Create and Assign the GIF Interface
Next, create the interface for the GIF tunnel in AZTCO-FW. Complete the fields with the corresponding information from the tunnel broker configuration summary. Navigate to Interfaces > Assignments on the GIF tab. Click A
Setup DHCPv6 and/or Router Advertisements
To assign IPv6 addresses to clients automatically, setup Router Advertisements and/or DHCPv6. A brief overview is as follows: Navigate to Services > DHCPv6 Server/RA Check Enable Enter a range of IPv6 IP addresses inside
Setup IPv6 DNS
The DNS servers likely answer DNS queries with AAAA results already. Entering the DNS servers supplied by the tunnel broker service under System > General Setup is recommended. Enter at least one IPv6 DNS server or use G
Setup LAN for IPv6
Once the tunnel is configured and online, the firewall itself has IPv6 connectivity. To ensure clients can access the internet on IPV6, the LAN must be configured also. One method is to set LAN as dual stack IPv4 and IPv
Setup the IPv6 Gateway
When the interface is configured as listed above, a dynamic IPv6 gateway is added automatically, but it is not yet marked as default. Navigate to System > RoutingEdit the dynamic IPv6 gateway with the same name as the IP
Sign Up for Service
Before a tunnel can be created, ICMP echo requests must be allowed to the WAN. A rule to pass ICMP echo requests from a source of any is a good temporary measure. Once the tunnel endpoint for HE.net has been chosen, the
Try It!
Once firewall rules are in place, check for IPv6 connectivity. A good site to test with is test-ipv6.com. An example of the output results of a successful configuration from a client on LAN is shown here Figure 65: IPv6
Updating the Tunnel Endpoint
For a dynamic WAN, such as DHCP or PPPoE, HE.net can still be used as a tunnel broker. AZTCO-FW includes a DynDNS type that will update the tunnel endpoint IP address whenever the WAN interface IP changes. If DynDNS is d