Table of Contents

NAT66 and IPv6 masquerading

Introduction

Command-line instructions

1. Firewall

Enable IPv6 masquerading on the upstream zone.

# Configure firewall
uci set firewall.@zone[1].masq6="1"
uci commit firewall
service firewall restart

2. Network

Disable IPv6 source filter on the upstream interface.

# Configure network
uci set network.wan6.sourcefilter="0"
uci commit network
service network restart

Prefer IPv6 by default or announce IPv6 default route if necessary.

Troubleshooting

Collect and analyze the following information.

# Log and status
service firewall restart
 
# Runtime configuration
ip -6 address show; ip -6 route show table all
ip -6 rule show; nft list ruleset
 
# Persistent configuration
uci show network; uci show firewall