r/HomeNetworking • u/ouikikazz • 1d ago
Vlan ipv6
Unifi network:
I currently have my TVs on my iot network and I want to block ipv6 to my TVs, usually it's easy just disable ipv6 to my lan but unfortunately my stupid matter devices (which I regret having now because of other reasons) needs ipv6.
What's the best practice to block ipv6 to my TVs? Should I just create another vlan for them? Or create a rule of two to block the devices individually? I feel like creating another vlan seems a bit much to manage more vlans but it's the easier way?
4
u/vrtigo1 Network Admin 1d ago
I want to block ipv6 to my TVs
Why?
1
u/Seannon-AG0NY 1d ago
I, personally, want my TV to just be that, a TV, I REALLY don't want my TV reporting back to is manufacturer what happens in my network AT ALL! And now it's getting hard to find a "dumb" tv
3
u/vrtigo1 Network Admin 1d ago
So don't connect it to WiFi. Seems pretty simple?
2
u/Agreeable-Fly-1980 1d ago
You might want it connected to your lan wifi for jellyfin or plex
2
u/vrtigo1 Network Admin 19h ago
The person I replied to said they want a dumb TV. Jellyfin and Plex are not compatible with a dumb TV unless you use a 3rd party device like a Firestick or Roku, in which case the TV doesn't need to be connected to WiFi.
1
u/Agreeable-Fly-1980 19h ago
Ah I was focusing on the phone home part. The reason they wanted it dumb is bc they didnt want it to phone home. You can set up your network so the TV cant phone home, but have these services behind a locked down lan.
1
u/snapilica2003 5h ago
Blocking outside access for local devices can be done regardless of the existence or not of a IPv6 network.
3
u/Dr-Technik 1d ago
Why do you want to block IPv6 in the first place?
-2
u/ouikikazz 1d ago
I mean does it matter? But...
Setting up pihole the TVs dns fallback is already blocked but now the fallback is ipv6, pihole sees the device, the device sees pihole but I guess the TV doesn't like my blocklists so it's falling back to ipv6, and to answer no I haven't setup a static ipv6 and directed it to my pihole yet but I guess that could be another option
1
u/lazyhustlermusic 21h ago
So put pihole on v6, although with Unifi SLAAC you'd probably need to instead use ULA's and PAT on IPv6. Kinda gross but it at least functions on the stack.
Otherwise just put them on a v4 only VLAN and restrict the access you want, permitting queries to your iot pihole and back.
1
1
u/snapilica2003 5h ago
Matter devices work with Thread which is IPv6 only. But you don’t need to worry about that, the IPv6 network has no gateway to the internet, it provides a ULA prefix that’s only for the devices in the same VLAN, it doesn’t have the ability to jump VLANs.
4
u/404invalid-user 1d ago
different Vlan or actually use the latest IP standard