It is possible by prefix delegation to split an IPv6 network (assigned by the provider) (e.g.:2001:0db8:aaaa:bb::/56) into /64 networks (e.g.:2001:0db8:aaaa:bb00::/64, 2001:0db8:aaaa:bb01::/64 etc.) and assign them to individual interfaces. All devices in this network segment can then receive an IPv6 address from their interface identifier and the prefix if router advertisement is activated. The respective interface of the UTM receives the first address, in the example 2001:0db8:aaaa:bb00::1/64.
IPv6 prefix delegation is enabled on the interface that is connected to the WAN.
notempty
The UTM can request an IPv6 prefix from the provider via the PPPoE connection and divide it into smaller /64 subnets and automatically place them on the interfaces.
Configuration
In dieser Seite werden die Variablen für unterschiedliche Sprachen definiert.
Diese Seite wird auf folgenden Seiten eingebunden
In the menu Network Network configuration Area Network interfaces button the interface (e.g. wan0 ) that is assigned to a larger IPv6 network via PPPoE must be configured. In the bottom section of the General tab:
Only IPv6 networks from a delegated prefix are placed on an interface if they have the Router Advertisement feature and do not have a fixed configured IPv6 address.
Click Save and close to apply the changes.
Transfer to interface by router Advertisement
In the menu Network Network configuration Area Network interfaces the interface to which the smaller /64 subnet is to be assigned (e.g.: LAN2) must be configured:
With this function, the allocation of a prefix is taken over by the router (here: the UTM firewall)
Assign IPv6 addresses:
On
This function enables the router to distribute IPv6 addresses
IPv6 Prefix Delegation:
off
Prefix delegation is only permitted for external interfaces.
Only IPv6 networks from a delegated prefix are placed on an interface if they have the Router Advertisement feature and do not have a fixed configured IPv6 address.
notempty
Die Subnetze werden der Reihe nach zugeordnet. Wird nachträglich IPv6 über das Router Advertisement auf einer Schnittstelle de-/aktiviert oder werden weitere VLANs hinzugefügt wird die Zuordnung erneut durchgeführt. Durch die geänderte Reihenfolge erhalten die Schnittstellen anschließend ggf. neue Subnetze!
Click Save and close to apply the changes.
Network configuration UTMuser@firewall.name.fqdnNetwork Display in the network configuration
Add default route
In order to route the IPv6 addresses, a default route must be added under Network Network configuration Area Routing button Add default route.
Under Network Network tools tab Ping , a ping is performed on an address that reliably uses (and also answers) IPv6. This verifies that the routing is working properly.
Options
Caption
Value
Description
IPv6 Ping-Test
IPv6
On
Enable for IPv6 to be used at all
IPv6 Ping-Test
Source:
2001:db08:aaaa:bbb00::1
Selection of the IPv6 address to be pinged with
Destination:
k.root-servers.net
Destination name or IP address
Submit
Start Ping-Test
Response
The root server k.root-servers.net of the Ripe NCC should respond as shown in the picture
Adjust packet filter rules
notempty
When using IPv6, all packet filter rules must additionally be created for IPv6.
Create IPv6 network objects
External zone
Create the Internet zone for IPv6 under Firewall Network objects button Add object.