Like nuclear fusion, IPv6 is one of those things that feels like it's constantly about 20 years away, no matter how long we work on it.
post
Is it a subnet level address or only a single interface level address. Many ISPs, in the US at least, don't supply a block of addresses, just one. If you're only getting a single IP address or it's using 6rd (like my ISP) or similar really old, transitional technologies, then you won't be able to assign a unique GUA to your LAN (separate from the WAN address) and so you'll need additional routing configuration like NAT to properly route to locally defined IPv6 addresses.
Personally, I gave up on trying to get things to work with 6rd since NAT is way easier on IPv4 since it was never intended to be necessary on IPv6. But ISPs are just cheap, lazy, or actively trying to make self-hosting on residential plans more difficult in order to drive people to business plans and prevent businesses from using cheaper residential plans by keeping IP addresses dynamic and thus complicating DNS.
If you are getting a subnet of addresses, then ensure that configuration on the LAN side is set up properly https://docs.opnsense.org/manual/ipv6.html
How do I find out if the ISP is handling me a single address or a /64 or whatever?
Not familiar with opnSense, but on your PC, you can check the address it assigns - if it's /128, it's a single address.
My ISP does not assign a prefix for delegation unless you specifically ask for it. I had to add "request_prefix 1" to my dhclient.conf file to get a /64 I assume opnSense has a friendly setting somewhere for that. For me, the key phrase was 'prefix delegation.' After I got that, I could search around and get my solution.
What IPv6 Configuration Type are you using on the WAN interface? The Interfaces -> Overview page should also show it based on the /48 or whatever at the end of the IP and if you're using DHCPv6 then often you can request how many with the Prefix Delegation Size option, though it's not guaranteed they'll actually give you that large of a block or even pay any attention to that option.
shot in the dark, because I've made that mistake before, if you got dyndns setup, it needs to be from the server not the router for ipv6 to work.
Mm no, not using dyndns. I am missing IPv6 support on the LAN side... But I have it on the wan side
Are you using a VPN? A lot of the VPN vendors disallow IPV6.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:
| Fewer Letters | More Letters |
|---|---|
| IP | Internet Protocol |
| NAT | Network Address Translation |
| VPN | Virtual Private Network |
[Thread #240 for this comm, first seen 17th Apr 2026, 00:10] [FAQ] [Full list] [Contact] [Source code]
Set the LAN ipv6 to track interface and it should work. You will likely also need to set a static ipv6 address on your LAN that is within the address given. SLAAC should take care of the rest.
Update : my ISP does not provide GUA.... So, whatever. Stick to IPv4 for the time being, no need to get complicated with IPv6 nat when I already have IPv4 nat working fine.
I actually have two ISP and one does support ip 6 with a GUA and that's where I got confused.... Unfortunately, it's the one providing 20mb/sec FTTC that I use only for backup. The main one, the one providing 300mb/sec over FVA does not.
Look at route64 and setup a tunnel then. I'm using it after switching from Hurricane Electric's IPv6 tunnel broker. Setup is nearly identical except you can use the Wireguard tunnel for route64 and there are less blocks and issues compared to HE's offering.
My backup connection is cellular and my primary is ftth but only IPv4 support.
all 21 comments