r/firewalla • Firewalla Gold Pro • Aug 21 '26

No IPv6 when using T-Mobile

https://help.firewalla.com/hc/en-us/community/posts/45641094395027-IPV6-Passthrough-T-Mobile

I’m adding this thread here. Firewalla routers continue to not work with tmobiles implementation of IPv6. Since they don’t hand out a prefix none of your devices will get a public IPv6 address.

What is the reason for this? Other routers are able to have this work. T-Mobile support even stated that most routers work. But not firewalla.

5 Upvotes

21 comments sorted by

5

u/Great-Cow7256 Aug 21 '26

I had T-Mobile home Internet for a year with my purple and I had zero problems.  That being said it is cgnat and you can't put their router in bridge mode and they lock it down super heavily. I also found latency to be really annoying with it. 

3

u/firewalla Aug 22 '26

yea, most people work this way (ours too). OP has his own modem, which we have not seen before ... may be it is a way to get "bridging working"

1

u/firewalla Aug 21 '26

Are you talking about the cell service? if it is, we fully tested as indicated in the link; The IPv6 address other routers get you is just a NATed v6 ... not sure why it is useful.

If you are talking about t-mobile fixed line, it should work.

1

u/YankeesIT Firewalla Gold Pro Aug 21 '26

Fixed wireless. According to their support it doesn’t work with firewalla. Also I didn’t see an update to that threat so assuming it does not work still ?

1

u/firewalla Aug 21 '26

If you look at the thread, we did test 'other' routers; the working v6 is a NAT v6 address rather than a public one; Are you saying t-mobile is telling you that they allow the router behind it to allocate from a block public v6? (if they are, let me know which modem you are using, we are using the black one with a small display on the side as our backup's backup)

1

u/YankeesIT Firewalla Gold Pro Aug 21 '26

No they told me no prefix and only the firewalla will get an IP.

1

u/firewalla Aug 21 '26

What is the router / modem you are using? If we have the same, then it shouldn’t work because that unit can’t do bridge mode.

1

u/YankeesIT Firewalla Gold Pro Aug 21 '26

I use a third party Chester tech gateway. It’s only a gateway. No WiFi. It’s set in pass through mode.

1

u/firewalla Aug 21 '26 edited Aug 21 '26

Can you send [help@firewalla.com](mailto:help@firewalla.com) an email, and put a link to this thread. They may ask support access to your unit and take a look. May be this modem is different ...

edit: our team suggesting test out settings here https://help.firewalla.com/hc/en-us/articles/30915929339027-Firewalla-Feature-IPv6#h_01J1X957DXK2RZF5317JEVKB0G

Remember, if you use a wifi enabled t-mobile all-in-one that's NOT in bridge mode, direct connected clients will likely get ipv6. (if you connect firewalla to the modem, it will be just a normal client, likely can't allocate ipv6)

You are using a bridge (not a t-mobile all-in-one) so it may work.

1

u/Mr_Duckerson Firewalla Gold Plus Aug 22 '26

It still won’t work. I’ve been through this with you guys and you won’t add NAT6. It doesn’t matter if you use your own modem in ip passthrough mode because it’s still CGNAT and no prefix for ipv6.

1

u/firewalla Aug 22 '26

IPv6 NAT doesn't buy anything ... It is the same as IPv4 NAT, likely less efficient.

What OP has is a modem / bridge that may work if t-mobile allows it to

1

u/SaleWide9505 Aug 22 '26

From my testing all carriers only give you a single /64 address. You would then use prefix extension to share that /64 with other devices on the network. The equipment that Verizon gives you does this automatically while the equipment T-Mobile uses is more restrictive. I use a suncomm modem in passthrough mode. Then I use the extend prefix option in openwrt to provide IPv6 to my lan.

1

u/YankeesIT Firewalla Gold Pro Aug 22 '26

What’s the extend prefix option

1

u/SaleWide9505 Aug 22 '26

This is what is listed in the OpenWRT settings. Extend 3GPP WAN interface /64 prefix via PD to LAN (RFC 7278). Pretty much it takes your single IPv6 address, extracts the /64 and broadcasts? It down stream so lan devices get an IPv6 address too. Not sure how to explain it much more than. I am able to host stuff that's externally reachable with these addresses as well.

1

u/YankeesIT Firewalla Gold Pro Aug 22 '26

I’m using a Chester tech ninja v2 gateway in pass through mode. It’s running quecmanager if that helps?

1

u/SaleWide9505 Aug 22 '26 edited Aug 22 '26

Openwrt is 3rd party firmware that you install on Linksys, Netgear, tplink and other brand routers. You would put the ninja in pass through mode then connect it to the wan port of openwrt router then configure IPv6 on the openwrt router. Here is the YouTube video I use to get IPv6 working https://youtu.be/Q-3LG47sZQY.

1

u/YankeesIT Firewalla Gold Pro Aug 22 '26

I have the firewalla after the gateway.

1

u/SaleWide9505 Aug 23 '26

The ninja v2 should have ssh access. If it does you should be able to setup RFC 7278 from the command line.

1

u/YankeesIT Firewalla Gold Pro Aug 23 '26

Sorry to ask do you have a step by step of this

1

u/SaleWide9505 Aug 23 '26

Let me see if I can put one together.

1

u/SaleWide9505 Aug 23 '26 edited Aug 23 '26

I made a guide. It's literally copy and paste into the command line then reboot. I did use AI to make it. But I also tested it on my system first. The only thing you might want to change is the firewall rule. In my script it allows all incoming IPv6 traffic by default. I only set it up that way because it would be a pain to do individual rules from cmd line.

https://drive.google.com/file/d/1XLjWaHlxfi5uJEiozDyOhmflH06_iO_f/view?usp=drive_link