@tschaefer ich habe eher Bedarf nach #NAT46 in #Deutschland.

A new headscratcher: in VyOS, a #6in4 tunnel (eg HE #TunnelBroker) the tunnel's source IPv4 address can be set to 0.0.0.0, to mean that egress tunnel traffic will use the src IPv4 from the interface going to the tunnel endpoint. This is helpful when that IP is DHCP assigned.

But in FreeBSD, gif(4) disallows 0.0.0.0, requiring an IP to listen for tunnel traffic. Presumably, gif doesn't want to listen on all interfaces.

My solution: dhclient-script(8) to configure gif once binding a DHCP addr.

Was ich gar nicht wußte: Bei #Vodafone bekommt man mittlerweile einfach so ein /64, ohne das irgendwo beantragen zu müssen.
Und es funktioniert noch dazu, kein Gehampel mit #tunnelbroker mehr, der #Mikrotik macht das sauber inklusive Sonderlocken wie "ignoriere die Nameserver, die Vodafone Dir aufs Auge drücken möchte, nimm den #pihole!"

#ipv6 wie es sein soll. Na gut, größer als /64 bekomme ich als Privatkunde wohl nicht, d.h, #Vlans im Heimnetz gehen dann eben nicht, jedenfalls nicht mit v6.
Irgendwas ist ja immer, für jetzt bin ich zufrieden.

My latest blog post is talking about how I have configured a #tunnelbroker on my #mikrotik thanks to #route64
Now I'm a happy owner of a #ipv6 subnet

#networking #homelab #selfhosted #wireguard #vpn #cgnat

https://www.schwitzd.me/posts/mikrotik-tunnelbroker-with-route64/

Mikrotik - Tunnelbroker with Route64

For learning purposes, I started looking into IPv6. First, I enabled a Unique local address subnet to leverage K3s dual-stack on my Home Cluster. Then I thought it would be cool to be able to connect to my home from abroad, so I started investigating VPNs. It is at this point that I discovered that my ISP currently is only offering IPv4 behind CGNAT for mobile devices (My Mikrotik connects to internet over LTE. Surfing the web I learned about tunnel broker is a service that provides IPv6 connectivity over an existing IPv4-only internet connection by encapsulating IPv6 traffic inside IPv4 packets.

Schwitzd

@neu3no @halva yes and no.

  • I can see the benefit of a miniaturized retro gaming system (I think legacy systems need to be served with properly maintained software & hardware).

https://www.youtube.com/watch?v=2P1E2vjpcRo
https://www.youtube.com/watch?v=B8WfiRRvQXo

As with #IPv4 the problem is that there is no mandate to provide users with static prefixes and I'm stuck on a /28 of IPv4's and can't even get a singoe /64.

  • And before you ask: No, #Tunnelbroker is not a valid solution as HE.net's tunnel will get #USA #GeoIP'd even eith the PoP in FRA so it bricks a shitload of things due to #Geoblocking and bad #peering. Believe me, I tried that already!
TINY DOS gaming PC build guide - weeCee Part 2

YouTube

I've over-riden DNS lookup in our network to no longer serve AAAA records for #google / youtube / etc.

Their hate of #tunnelbroker IPs, for people who don't get native #IPv6, no matter via which endpoint, finally got to me.

If you don't want me to reach you via #IPv6, then I wont.

@landley @jschauma @ryanc @0xabad1dea yeah, the exhaustion problem would've been shoved back with a #64bit or sufficiently delayed by a 40bit number.

Unless we also hate #NAT and expect every device to have a unique static #IP (which is a #privacy nightmare at best that "#PrivacyExtensions" barely fixed.)

  • I mean they could've also gone the #DECnet approach and use the #EUI48 / #MAC-Address (or #EUI64) as static addressing system, but that would've made #vendors and not #ISPs the powerful forces of allocation. (Similar to how technically the #ICCID dictates #GSM / #4G / #5G access and not the #IMEI unless places like Australia ban imported devices.

I guess using a #128bit address space was inspired by #ZFS doing the same before, as the folks who designed both wanted to design a solution that clearly will outlive them (way harder than COBOL has outlived Grace Hopper)...

If I was @BNetzA I would've mandated #DualStack and banned #CGNAT (or at least the use of CGNAT in #RFC1918 address spaces) as well as #DualStackLite!

@shoppingtonz @alternativeto @torproject also every #Tunneling - regardless if #SSH or #VPN or whatever - will inevitably introduce #latency (unless you happen to be customer of a shitty #ISP with horrible #peering and thus can cut down on hops needed, which is AFAIK only a theoretical scenario)...

In fact I stopped using #HEnet #Tunnelbroker and #IPv6-#GIF-Tunneling because it created more issued than it solved on my #IPv4only #Internet connection…

Today I've finally traced the strange issue plaguing Microsoft Intune on my company laptop at home: apparently it is unhappy with my #TunnelBroker #IPv6 tunnel.

I guess this is the last hint I needed to consider renting a /48 and a VPS to get a subnet that isn't handled weird due to being perceived as an open proxy.

Hey #homelab users!

You probably already know me by my free @BoxyBSD project and I often got asked about IPv4 addresses. Currebtly, I tinker with a new but also honestly not free service. The idea is creating a static IP service for homelab users. I'm aware that there're already some around, so what could be some benefits here?

- Static single #IPv4 & #IPv6 /48 (so you can subnet your homelab to several /64 without breaking #slacc)
- Bigger subnets (IPv4: /29, /28, /27 | IPv6: /32)
- Full RIPE personalization (inc. abuse & Co)
- #OpenVPN, #Wireguard, #GRE Support
- Auto configure (e.g., you load the wireguard config on any client and the addresses Arena immediately bound to that interface)
- Split usage / multiple tunnels: Use different IPs from your subnets at different locations
- Integration into #BoxyBSD
- Location in Germany or Netherlands (selectable)
- Hosted on redundant #FreeBSD nodes

Pricing:
- The starter package probably around 10€/month (not more) + 15€ setup including 2T traffic
- Pricing for addiriinal/larger subnets not yet sure, probably higher setup fees to avoid hoppers and spamers to keep the addresses clean
- Optional traffic packages (when exceeding speed Limit of 10Mbit which should still be ok for most homelabs)

World this be interesting? Im aware that many ones already do this by VPS themselves, so this might just be a bit easier and optionally offering whole networks including RIPE personalizations.

#hosting #Server #kubernetes #Lab #homelab #home #homelabs #homelabcommunity #homelabnetworking #network #networking #tunnel #tunnelbroker #proxmox #XCPng #Virtualisation #virtualization #traffic #BGP