DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Vigor 2860 IPv6 Firewall

  • majicf
  • Topic Author
  • User
  • User
More
11 Sep 2017 10:41 #1 by majicf
Vigor 2860 IPv6 Firewall was created by majicf
I've noticed online on some Draytek interfaces there is a dedicated IPv6 section that contains things like firewall applications etc.

I don't see this on the 2860 but with IPv6 I see there is the firewall filtering that would allow connections from the WAN to an IPv6 address on a LAN client. I wanted to make sure that I'm understanding the firewalling side correctly.

In order to allow a port through the firewall to a specific client on the networking via IPv6, you would create it as an IPv6 object first, then use the filter rules to allow the port to that IPV6 object. You can't add a filter directly for an IPv6 address or link-local address as it only supports IPv4 addressing.

This seems a little long winded, but it makes sense and is ok, but is this right?

If I set up an IPv6 object to use mac addressing only, what happens? Does it identify the correct client based on the filter rule matching the IPv6 address that belongs to the mac address?

Please Log in or Create an account to join the conversation.

  • majicf
  • Topic Author
  • User
  • User
More
12 Sep 2017 23:50 #2 by majicf
Replied by majicf on topic Re: Vigor 2860 IPv6 Firewall
These rules aren't working. Anyone got IPv6 firewall rules to work so you can allow certain ports access to IPv6 client machines?

Please Log in or Create an account to join the conversation.

  • majicf
  • Topic Author
  • User
  • User
More
14 Sep 2017 15:21 #3 by majicf
Replied by majicf on topic Re: Vigor 2860 IPv6 Firewall
I managed to get it working. This set up is correct, but there were a few woods and trees moments as well as some odd ones..

Firstly I wanted to get port 80 allowed to some IPv6 clients through the firewall. Even if the management of the router is not allowed over the WAN, they still block anything if set up to use port 80 (the default). I had to move them to another port, same as 443 for https. Once those were cleared and I corrected the amateur mistake of setting http to only have TCP protocol not TCP and UDP, it all started working.

Deep dive into IPv6.. There is a lot to understand and a new set of problem solving, but I really like it.. Prefer it to IPv4 already.

Just thought I'd share in case there was another person beating their heads against a wall to work out these issues.

Please Log in or Create an account to join the conversation.

  • florenceanne
  • User
  • User
More
18 Oct 2017 11:35 #4 by florenceanne
Replied by florenceanne on topic Re: Vigor 2860 IPv6 Firewall
I am struggling with IPv6 totally lost on what needs to be enabled and what doesn't, IPV6 is working somewhat but if I set up a graph on thinkbroadband it shows as down all time red blanket is best way to describe it.

I can take screenshots of the router settings if I know which you need to see to help me.

Please Log in or Create an account to join the conversation.