ronwit
Member
OP
Budget King
- Joined:
- Jun 2024
- Posts:
- 122
- From:
- Osaka, Japan
So basically I got tired of my ISP not giving me proper v6 prefix so actually I just tunnel from my cheap Contabo VPS and delegate /60 to my home router (´・ω・`)
Works like this:
- VPS gets /48 from provider (Contabo gives this actually)
- Ndppd or tayga on VPS for proto-41 tunnel
- Radvd at home advertising delegated /60
- Profit
My setup is basically debian 12 on both ends, wireguard backup for when proto-41 blocked. Actually took me whole weekend to get right (´・ω・`)
Tested with OVHcloud and Vultr too, both work. Hetzner only gives /64 so no delegation there
Will update if I find better way
instant noodles, instant deploys
olespete
Member
Trust No One
- Joined:
- Jun 2024
- Posts:
- 270
- From:
- Unknown
WARNINGS before anyone runs this.
What could go wrong:
- You just punched a hole through your firewall for proto-41
- Your home network is now ROUTABLE from the entire IPv6 internet
- No NAT to hide behind anymore
- fail2ban on the VPS won't save your LAN devices
I hope you at least have ip6tables on BOTH ends with default DROP. And audit your radvd configs for rogue RAs!
This is clever but the attack surface is MASSIVE
airgapped, encrypted, faraday'd, still worried
zoekyo
Member
Less Is More
- Joined:
- May 2024
- Posts:
- 102
- From:
- Kyoto, JP
Complexity kills
wireguard plus /64
No proto-41 headaches
No ISP games
rm -rf / --no-preserve-root ☯