WAN6 (tried with "Use builtin IPv6-management" on and off)
WAN: IPv6 assignment length = 64. DHCP Server IPv6 settings are all disabled. Use builtin IPv6-management
is off.
LAN: IPv6 assignment length = 64. Use builtin IPv6-management is on. I tried all kinds of Router Advertisement-Service and DHCPv6-Service. I don't think I need an NDP proxy.
Could someone provide guidance on how to set this up using the GUI. there are ZERO guides for this, I searched extensively on google, github, stack sites and the forum.
Nothing should be needed for "wan", but you need most settings for the "wan6" 6in4 interface (remote tunnel endpoint ipv4, local ipv6 tunnel endpoint, routed prefix) and the ip6assign setting for "lan".
Note that you should used routed /48 prefix that he.net tunnelbroker offers. Not the small /64.
hnyman did it! thank you. please bump me to be able to post more than 2 links (or I will wait to get there) and I will post a complete Luci guide to this. thank you!
I'm currently using tunnelbroker.net, and did not need to change the firewall configuration from the default values, just configure the proper interface:
ok! can i use comma separated and range in dashes in here?
and in
can i use '41' and ommit dest_port? in case i decide to use IPv6 only at a single Ubuntu machine and have this machine create the tunnel (I really only need IPv6 on that machine anyways).
For DNAT, redirect matched incoming traffic to the given port on the internal host. For SNAT, match traffic directed at the given ports. Only a single port or range can be specified, not disparate ports as with Rules (below).
Yes. As you can see above, that's exactly what you need to do to specify a protocol other than the normal: TCP, UDP or ICMP.
ing6 ipv6.google.com
PING ipv6.google.com(lax28s01-in-x0e.1e100.net) 56 data bytes
From lax28s01-in-x0e.1e100.net icmp_seq=1 Destination unreachable: No route
From lax28s01-in-x0e.1e100.net icmp_seq=2 Destination unreachable: No route
I got the R7800 now. I already tried copying the tunnelbroker settings for Barrier Breaker. It didn't work. I have a /48, and tried it, didn't help.
It is configured it as follows:
Network:
config interface 'lan'
option type 'bridge'
option ifname 'eth1'
option proto 'static'
option netmask '255.255.255.0'
option ipaddr '192.168.1.1'
option dns '8.8.8.8 4.4.4.4'
option ip6assign '64'
config interface 'wan'
option ifname 'eth0'
option _orig_ifname 'eth0'
option _orig_bridge 'false'
option proto 'static'
option ipaddr '192.168.0.2'
option netmask '255.255.255.0'
option gateway '192.168.0.1'
# I can't put my cable modem in bridge mode
# but 6in4 works perfectly on a R6250 running tomato.
# It's firewall is completely off and all ports fwd to the R7900
option dns '208.67.222.222 208.67.220.220'
config interface 'wan6'
option _orig_ifname 'eth0'
option _orig_bridge 'false'
option proto '6in4'
option peeraddr 'x.x.x.x' #local PoP for tunnelbroker
option ip6prefix '2001:x:d:x::/64' #prefix per tunnelbroker
option ip6addr '2001:x:c:x::2/64' #Client IPv6 Address per tunnelbroker
# Server IPv6 Address per tunnelbroker doesn't get input anywhere
DHCP:
config dhcp 'lan'
option interface 'lan'
option ra 'server'
option leasetime '4h'
option start '2'
option limit '250'
list dns '2606:4700:4700::1111'
list dns '2620:fe::fe'
option dhcpv6 'server'
option ra_management '1'
Firewall (just to be safe)
config rule
option name 'Allow-Protocol-41-Tunnelbroker'
option src wan
option proto 41
option target ACCEPT
Here's the kicker. I can ping the ubuntu machine on my LAN via http://www.ipv6now.com.au/pingme.php. Some services that depend on IPv6 and are accessed by machines outside of my LAN also report the ubuntu box as up and running. Both of these increase the RX and TX counters in Luci's WAN6 status. When those services don't reach out to my machine, both counters don't increase, no matter what I do (router diag or ubuntu machine curl/ping6.
PING lede-project.org (2a03:b0c0:3:d0::1af1:1): 56 data bytes
ping6: sendto: Network unreachable
In the ubuntu box
$ ping6 ipv6.google.com
PING ipv6.google.com(lax28s10-in-x0e.1e100.net) 56 data bytes
From lax28s10-in-x0e.1e100.net icmp_seq=1 Destination unreachable: No route
Overall I've put over 12 hrs into this. I don't know what else to do. On the R7900 at least it would work for a while before stopping. On this one it just doesn't (for outbound requests, inbound seems to work fine)
I am working with Tunnelbroker support and will report back. If the router itself can't ping in IPv6, not even tunnelbroker's own 2001:470:0:76::2, there is no point in troubleshooting the LAN at this point.