Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 [Guide] OPNsense Unifi setup with ipv6

views
     
Dothan
post Sep 27 2025, 03:27 PM

Dingle Berries
******
Senior Member
1,053 posts

Joined: Jan 2003


I am using OPNSense ver 25.7 and Unifi 500 Mbps package.

I believe this is the most up-to-date version of setting up the OPNSense for TM Unifi's IPv6.

Assumption:
You already have a working PPPoE WAN. If not, use OPNSense wizard to assist you to setup the PPPoE WAN.
Your Interface naming might be different from mine. But I hope your understand which interface is meant for WAN and LAN.
If you have setup a bridge for bridging your device ethernet ports traffic like switch, your LAN interface should be your bridge
If your OPNSense device only have 2 ethernet ports setup, then skip Step 2.

Step 1:
In Interface -> WAN -> IPv6 Configuration, select DHCPv6

Same page, Interface -> WAN -> DHCPv6 client configuration portion.
Set Configuration Mode: Basic.
Prefix delegation size: 64.
Tick Request prefix only checkbox.
Tick Send prefix hint checkbox.
Leave both Optional prefix ID and Optional interface ID empty (no value entered)
Click Save button

Step 2 (optional: only application for those setup Bridge)
Interface -> Devices -> Bridge, select the bridge you have setup.
Tick Enable link-local address checkbox
Click Save button

Step 3:
Interface -> LAN -> IPv6 Configuration Type
Select Track Interface

Same page, Interface -> LAN -> Track IPv6 Interface -> Parent Interface
Select WAN.
Leave Assign prefix ID and Optional interface ID empty (no value entered)
Tick Allow manual adjustment of DHCPv6 and Router Advertisements checkbox
Click Save button

Step 4:
Services -> Router Advertisement -> LAN (because you ticked the checkbox in Step 3)
Set Router Advertisment: Assisted
Router Priority: Normal
Source Address: Automatic
DNS Options: up to you whether tick or untick both checkboxes
Click Save button and check the Router Advertisement service has started.

By finishing the above steps, you should have enabled IPv6 for your TM Unifi.
Some devices might not able to get IPv6 address, reboot your OPNSense device should do.

This post has been edited by Dothan: Sep 27 2025, 03:29 PM
Dothan
post Nov 6 2025, 07:59 PM

Dingle Berries
******
Senior Member
1,053 posts

Joined: Jan 2003


QUOTE(Moogle Stiltzkin @ Oct 28 2025, 03:39 PM)
Set Configuration Mode: Basic.  for pfsense what is this? static? dhcp? slaac?
*
Sorry for late reply.

Under the System -> Interfaces -> WAN:
The IPv4 Configuration Type in the Generic Configuration should be PPPoE.
The IPv6 Configuration Type in the Generic Configuration should be DHCPv6.
Dothan
post Nov 8 2025, 09:30 AM

Dingle Berries
******
Senior Member
1,053 posts

Joined: Jan 2003


QUOTE(Moogle Stiltzkin @ Nov 7 2025, 06:37 PM)
im using dhcpv6 but something is very wrong.

For vlan e.g. guest vlan, when i put DHVPv6 it break the internet. wont work at all. So for guest vlan had to remove that.

what this does, ipv4 works on guest vlan. Only the vlan1 network has working ip6 and ipv4 both.

So i donno why that is.
*
I guess you want to isolate guest devices from your usual network with different IP ranges right?

Supposedly the DHCPv6 is getting IPv6 ranges assigned by TM Unifi over PPPoE connection.

Let me research what I can help you.
Dothan
post Nov 10 2025, 07:38 AM

Dingle Berries
******
Senior Member
1,053 posts

Joined: Jan 2003


QUOTE(Moogle Stiltzkin @ Nov 10 2025, 05:36 AM)
i donno why but when i copy the lan DHCP6 in the ipv6 advertisement and stuff to the guest vlan, it made the guest vlan internet partly work

meaning some sites work, while others didn't. so the internet was partly working. it was a mess  laugh.gif
so my work around, ipv6 only for lan, and for guest vlan only ipv4. thats the only working setting i got to work.

posted the full story here
https://www.reddit.com/r/TPLink_Omada/comme...erly_on_eap773/
so i'm just wondering, any of u setup any vlans, did your ipv6 go nuts and break the internet? for pfsense with tmnut  sweat.gif

i scoured the setting and honestly donno what i did to mess up.

for the ipv6 setting, i copied exact from the private vlan and use same for guest vlan.

only difference is for the ipv4 they use different subnet since on a separate vlan of course.
*
Do you setup the firewall rules allowing passthrough of IPv6 traffic from your guest vlan?
Dothan
post Nov 10 2025, 05:01 PM

Dingle Berries
******
Senior Member
1,053 posts

Joined: Jan 2003


QUOTE(Moogle Stiltzkin @ Nov 10 2025, 03:41 PM)
passthorough?

hm...

under firewall rules

for lan, allow both ipv4 and ipv6 for lan subnets.

for guest vlan also same but for guest subnets.
if thats what u meant?  hmm.gif
*
Yes, since you mention certain site not reachable from guest vlan.

Try ping -4 and ping -6 on www.google.com from your guest vlan, see which one or both could reach out the respective IPv4 and IPv6 address.


 

Change to:
| Lo-Fi Version
0.0135sec    0.48    7 queries    GZIP Disabled
Time is now: 25th November 2025 - 08:59 PM