» Click to show Spoiler - click again to hide... «
QUOTE(Anime4000 @ May 12 2022, 06:52 PM)
I have successfully adding 2nd IPv6 Subnet, since our ISP refuse to give atleast /60, we do NAT6 in second subnet



This what I do
IPv6 ➡ Pool

IPv6 ➡ Address ➡ ➕

IPv6 ➡ Firewall ➡ NAT ➡ ➕



[General]
Chain: srcnat
Src. Address: 2000::/64
Out. Interface List: WAN
[Advanced]
IPsec Policy: out : none
[Action]
Action: masquerade
Only works in ROS7+
Windows and browser refuse to using fc00::/7 ULA Space, we had to break IANA IPv6 Assignment because of our ISP mistake, just break it
IPv6 NAT will break P2P, good firewall layer to protect IoT, VPN Users, etc...
I just found out that, when Metric/Distance same Value, Windows will choose lowest IP Address Number, my plan to use funny address like 2000:dead:cafe:b00b::/64, I choose 2000::/64 because is the lowest value valid
More details I put on my blog here:
https://www.hitoha.moe/second-ipv6-subnet-v...os-7-using-nat/



This what I do
IPv6 ➡ Pool

IPv6 ➡ Address ➡ ➕

IPv6 ➡ Firewall ➡ NAT ➡ ➕



CODE
[General]
Chain: srcnat
Src. Address: 2000::/64
Out. Interface List: WAN
[Advanced]
IPsec Policy: out : none
[Action]
Action: masquerade
Only works in ROS7+
Windows and browser refuse to using fc00::/7 ULA Space, we had to break IANA IPv6 Assignment because of our ISP mistake, just break it
IPv6 NAT will break P2P, good firewall layer to protect IoT, VPN Users, etc...
I just found out that, when Metric/Distance same Value, Windows will choose lowest IP Address Number, my plan to use funny address like 2000:dead:cafe:b00b::/64, I choose 2000::/64 because is the lowest value valid
More details I put on my blog here:
https://www.hitoha.moe/second-ipv6-subnet-v...os-7-using-nat/
Thank you for sharing ya
This post has been edited by ahlong: May 13 2022, 10:15 AM
May 13 2022, 10:13 AM

Quote





0.1794sec
0.62
6 queries
GZIP Disabled