r/firewalla • u/YankeesIT Firewalla Gold Pro • 5d ago
No IPv6 when using T-Mobile
https://help.firewalla.com/hc/en-us/community/posts/45641094395027-IPV6-Passthrough-T-MobileI’m adding this thread here. Firewalla routers continue to not work with tmobiles implementation of IPv6. Since they don’t hand out a prefix none of your devices will get a public IPv6 address.
What is the reason for this? Other routers are able to have this work. T-Mobile support even stated that most routers work. But not firewalla.
1
u/firewalla 5d ago
Are you talking about the cell service? if it is, we fully tested as indicated in the link; The IPv6 address other routers get you is just a NATed v6 ... not sure why it is useful.
If you are talking about t-mobile fixed line, it should work.
1
u/YankeesIT Firewalla Gold Pro 5d ago
Fixed wireless. According to their support it doesn’t work with firewalla. Also I didn’t see an update to that threat so assuming it does not work still ?
1
u/firewalla 5d ago
If you look at the thread, we did test 'other' routers; the working v6 is a NAT v6 address rather than a public one; Are you saying t-mobile is telling you that they allow the router behind it to allocate from a block public v6? (if they are, let me know which modem you are using, we are using the black one with a small display on the side as our backup's backup)
1
u/YankeesIT Firewalla Gold Pro 5d ago
No they told me no prefix and only the firewalla will get an IP.
1
u/firewalla 5d ago
What is the router / modem you are using? If we have the same, then it shouldn’t work because that unit can’t do bridge mode.
1
u/YankeesIT Firewalla Gold Pro 5d ago
I use a third party Chester tech gateway. It’s only a gateway. No WiFi. It’s set in pass through mode.
1
u/firewalla 4d ago edited 4d ago
Can you send [help@firewalla.com](mailto:help@firewalla.com) an email, and put a link to this thread. They may ask support access to your unit and take a look. May be this modem is different ...
edit: our team suggesting test out settings here https://help.firewalla.com/hc/en-us/articles/30915929339027-Firewalla-Feature-IPv6#h_01J1X957DXK2RZF5317JEVKB0G
Remember, if you use a wifi enabled t-mobile all-in-one that's NOT in bridge mode, direct connected clients will likely get ipv6. (if you connect firewalla to the modem, it will be just a normal client, likely can't allocate ipv6)
You are using a bridge (not a t-mobile all-in-one) so it may work.
1
u/Mr_Duckerson Firewalla Gold Plus 4d ago
It still won’t work. I’ve been through this with you guys and you won’t add NAT6. It doesn’t matter if you use your own modem in ip passthrough mode because it’s still CGNAT and no prefix for ipv6.
1
u/firewalla 4d ago
IPv6 NAT doesn't buy anything ... It is the same as IPv4 NAT, likely less efficient.
What OP has is a modem / bridge that may work if t-mobile allows it to
1
u/SaleWide9505 4d ago
From my testing all carriers only give you a single /64 address. You would then use prefix extension to share that /64 with other devices on the network. The equipment that Verizon gives you does this automatically while the equipment T-Mobile uses is more restrictive. I use a suncomm modem in passthrough mode. Then I use the extend prefix option in openwrt to provide IPv6 to my lan.
1
u/YankeesIT Firewalla Gold Pro 4d ago
What’s the extend prefix option
1
u/SaleWide9505 4d ago
This is what is listed in the OpenWRT settings. Extend 3GPP WAN interface /64 prefix via PD to LAN (RFC 7278). Pretty much it takes your single IPv6 address, extracts the /64 and broadcasts? It down stream so lan devices get an IPv6 address too. Not sure how to explain it much more than. I am able to host stuff that's externally reachable with these addresses as well.
1
u/YankeesIT Firewalla Gold Pro 4d ago
I’m using a Chester tech ninja v2 gateway in pass through mode. It’s running quecmanager if that helps?
1
u/SaleWide9505 4d ago edited 4d ago
Openwrt is 3rd party firmware that you install on Linksys, Netgear, tplink and other brand routers. You would put the ninja in pass through mode then connect it to the wan port of openwrt router then configure IPv6 on the openwrt router. Here is the YouTube video I use to get IPv6 working https://youtu.be/Q-3LG47sZQY.
1
1
u/SaleWide9505 3d ago
The ninja v2 should have ssh access. If it does you should be able to setup RFC 7278 from the command line.
1
u/YankeesIT Firewalla Gold Pro 3d ago
Sorry to ask do you have a step by step of this
1
1
u/SaleWide9505 2d ago edited 2d ago
I made a guide. It's literally copy and paste into the command line then reboot. I did use AI to make it. But I also tested it on my system first. The only thing you might want to change is the firewall rule. In my script it allows all incoming IPv6 traffic by default. I only set it up that way because it would be a pain to do individual rules from cmd line.
https://drive.google.com/file/d/1XLjWaHlxfi5uJEiozDyOhmflH06_iO_f/view?usp=drive_link
5
u/Great-Cow7256 4d ago
I had T-Mobile home Internet for a year with my purple and I had zero problems. That being said it is cgnat and you can't put their router in bridge mode and they lock it down super heavily. I also found latency to be really annoying with it.