Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Unifi TMnet Streamyx/Unifi & IPv6, Now live!

views
     
ssslayerrr
post Oct 29 2013, 07:05 PM

Enthusiast
*****
Senior Member
805 posts

Joined: Dec 2004


Followed the instructions from TMNET, it now works at my home near Sg Long, but not at my workplace, near Jalan Kuchai Lama, TMNETs DHCPv6 not giving out ipv6 prefixes there. Same router, both sides, Asus RT-N16.

Security is a big issue, since I was previously behind the router's firewall, so everything was open within my network, and ASUS's firmware does not support ipv6 firewall.
Initially, doing an IPv6 port scan here showed a lot of the common were open and responding from the internet!!

ipv6.chappell-family.com/ipv6tcptest/

Fortunately merlins firmware for the RT N16 does enable an ipv6 firewall, he supports a few routers.

http://www.lostrealm.ca/tower/node/79

So now my rt n16 firewalls ipv6 traffic, and a recheck shows that all my ports are in stealth mode now. Saved me the pain of having to secure each pc in my network.

Anyway, for the RT-N16, you just need to click on the ipv6 tab on the left navigation bar, then choose 'Native' as the connection type, 'PPP' interface, and enable DHCP-PD. If you are using merlin's firmware, you can then go the the firewall tab and enable the ipv6 firewall there, but it's enabled by default.

As for my workplace at Kuchai Lama, its really frustrating. I have IPv6 connectivity from the router itself, I can ping ipv6.google.com from the router, but Router Advertisement is disabled because radvd can't get the ipv6 prefix from TMNET.

radvd[439]: no auto-selected prefix on interface br0, disabling advertisements.

If only there is a way for me to specify my own prefix......, have been looking this up but to no avail.
ssslayerrr
post Oct 29 2013, 07:40 PM

Enthusiast
*****
Senior Member
805 posts

Joined: Dec 2004


Wouldn't a host based firewall block unsolicited tcp connections as well?

ssslayerrr
post Oct 29 2013, 09:19 PM

Enthusiast
*****
Senior Member
805 posts

Joined: Dec 2004


QUOTE(wKkaY @ Oct 29 2013, 08:59 PM)
Yes, however the difference is where control lies. A host-based firewall can be configured by the host, either manually by the user or programatically like Windows INetFwRule. I think the Windows implementation is pretty nice where it gives you the choice of trusted/untrusted whitelist for each network you join and each application.

With a perimeter firewall, how would a home user do that? I believe troubleshooting firewalls or logging into one's router to edit firewall rules is beyond most lusers ability - and that is assuming the ISP even offer that option. TM for example is known not to disclose password to their routers.

UPNP to punch holes in the firewall? A complicated solution to a problem which should be solved at the host anyway. For example, what if you bring your computer somewhere which doesn't block incoming connections by default? You will want a host firewall protecting you by default.

Perimeter firewalls still have their place to enforce security in depth, but it should be in addition to host firewalls and not in place of it... and for it to be effective it should be locked down with no way for holes to be punched by hosts.
*
Thanks for the explanation dude, understood, I totally didn't think of that, but now that you explained it, it seems so obvious
ssslayerrr
post Oct 30 2013, 06:07 PM

Enthusiast
*****
Senior Member
805 posts

Joined: Dec 2004


QUOTE(Victek @ Oct 30 2013, 05:05 PM)
IPv6 test with Tomato RAF firmware runs well.

@ssslayerrr , you can try other firmware versions where prefix options are enabled ....
*
Hi, hahaha, the man himself. I've used your tomato firmware on my wrt54gl s, thanks for that. Actually, the Asus firmware allows me to disable the dhcp-pd and hence, specify my own prefixes, it's just that I have no idea on what to put in there, just blindly googling now hoping to find some info on this, no luck so far......


ssslayerrr
post Nov 5 2013, 09:25 PM

Enthusiast
*****
Senior Member
805 posts

Joined: Dec 2004


QUOTE(andrew9292 @ Nov 5 2013, 06:43 PM)
How would the configuration be in OpenWRT? There are so many options & methods, have tried it for a day and still no go. Even broke the DHCP and probably some other stuff, now i'm back with TM's router.

I'm using TM's DIR615 as a VLAN Bridge, stripped the v.500 there.
With a DIR615-C2 on OpenWRT to simply dail PPPoE via the bridge.
That's for IPv4.

So what direction should i be heading? What packages to download and what to input? I'm not a network guy i just follow online instructions really well tongue.gif

If i get it correctly, what i need to do is configure it for Dual-Stack as we're running ipv6 concurrently with v4.
And TM uses SLAAC with DHCPv6 to assign addresses.
The address needs to be routed to clients via something like radvd, something like a DHCP for ipv6?
Anything else needed? 6to4 / 6rd?

At one point i managed to get TM's ipv6 assigned address.
But there was no network connectivity, some routing somewhere didnt work out...
I'm veri confused rclxub.gif
Any detailed guides or ideas? notworthy.gif
*
I have access to 3 locations with unifi and all 3 have different 'situations'.

No. 1. The first location gets an wan, lan ipv6 address and lan prefix, ipv6 works with tm's dir 615, but now I'm using the asus RT N16 over there. no problems.

No. 2. The second location is able to get a wan ipv6 address, but no lan ipv6 address and no lan prefix, so, while the router itself has ipv6 internet connectivity (can ping ipv6.google.com etc), the lan clients don't.

No. 3. The third location, doesnt even get a wan ipv6 address.

So, it could be very frustrating trying to configure it when it might not be 'fully' available. I suggest you try tm's dir 615 router first and confirm that you are getting complete ipv6 functionality, if you are, then go ahead and try openwrt.

What you describe in your last paragraph sounds like the my situation no. 2, ie, your area is not getting ipv6 prefixes from tmnet yet.
ssslayerrr
post Nov 6 2013, 05:37 PM

Enthusiast
*****
Senior Member
805 posts

Joined: Dec 2004


QUOTE(yeam @ Nov 6 2013, 05:26 PM)
Noob question.

How to configure router/client to use "IPv6"?

Router: Asus RT-N56u

From the rounter ping tool service "ipv6.google.com".

Seem the router got IPv6 WAN IP.

user posted image

but the client doesn't pick up any IPv6 address.

How can i proceed from bellow? need some manual config? or everythings should be handle by DHCP?

user posted image

user posted image
*
I don't see anything wrong with your config, its the same as my Asus RT N16. Not much more you can do, other than wait till tm starts giving out lan prefixes to your area. If you click on System Log>IPV6, you will see that you have a wan ipv6 address, but no lan ipv6 address, no prefix either.

 

Change to:
| Lo-Fi Version
0.0165sec    0.47    7 queries    GZIP Disabled
Time is now: 27th November 2025 - 01:33 PM