Does #IPv6 have something like #UPnP? Since stateful firewalls are necessary for complimentary security but there should be a way for a client to ask the router for exceptions
so TIL i can simply just add a dhcpv6 server in mikrotik and clients will be able to request an entire /64 prefix from my /56 pool to be routed to them... it looks like it's working cause who the fuck just took a prefix???
need to firewall the main lan from the other stuff (lxc, wireguard); added a couple rules to allow dstnat'd from wan (i.e. "port forwarding") then block anything else to lan, seems to be working
but having some trouble for #ipv6... last rule drops everything else not coming from lan so I need a rule to allow from lxc to wan, but it's not working... only if i allow all from lxc. i dont get it...
I wonder how I can route an #ipv6 prefix to my server for #lxd. I think I need to route it to the ethernet interface, but it's bridged so that does not seem possible, adding the address just implicitly adds it to the entire bridge and it does not route directly to the interface. I guess I have to unbridge it? But I want it to be part of the LAN...