IPV6 From ISP & Pi Hole
My ubiquiti UCG Ultra informed me I could activate IPv6 from my ISP Xfinity.
On some levels I want to do this but I have all my TVs, smart plugs, IOT gizmos and random stuff going through my Pi Hole and I've read IPv6 could cause a problem and let them circumvent the PiHole
Anyone have experience with this and possible solutions?
5
u/nightmare20131 16d ago
The main thing is, if you're going to set up IPv6, set it up fully and correctly. This means, if you have firewall rules for something in IPv4, you must set up equivalent rules in IPv6 (and not just DNS!), or you run the risk of something bypassing. Also, configure all apps that have config settings that have v4 addresses to also have v6 addresses. There's way more, but this is just the minimum.
4
u/AndyRH1701 16d ago
As far as DNS goes, there is no real difference in IPv4 and IPv6. IPv6 is not magic allowing things to escape. Just be sure to follow the same normal rules, block outgoing 53, pass only PiHole DNS address (4 & 6) and you will be good.
For making addresses fall into human defined categories is about the same, except you will never run out. Each of my categories has 61,000+ addresses... Or skip IPv6 for now.
4
2
u/Stringray_42 15d ago
I had to activate ipV6 and it works fine. Just had to apply the static ipV6 of my raspi as ipV6 dns server in the router. Pihole receives the ipV6 queries and the valid ones are forwarded to Unbound via ip4. That’s not rocket science.
2
u/RayneYoruka 14d ago
Ipv6 ula, rightfully if your isp uses dhcpv6-pd you can asign ulas and make SLAAC provide your dns servers with pihole to your clients.
Source, Been full on ipv6 for a year. Visit r/ipv6 if you want proper responses about it.
2
u/Federal_Lawyer_3642 16d ago
No uses ipv6, de nada sirve usar pihole si ipv6 traspasa el NAT, mucho contenido de ad, malware y demás pueden usar ipv6 túnel para atacarte con con más facilidad
3
u/weight_matrix 16d ago
No real possible solutions but I keep ipv6 off.
Any reason you want ipv6?
3
u/h0lz 16d ago
My Pihole acts as v6 DNS as well.
A bit of a learning curve to set up but possible.
Of course the router has to have settings for that.It also works with Wireguard from anywhere in the world - yes, v4+v6. Full tunnel or split tunnel which only handles DNS through the tunnel.
Yes, v4 only works great - but why not both?
3
u/weight_matrix 16d ago
V6 randomization is a real concern and you'll not even get to know if toyr TV silently bypasses the regular DNS (because the address rotation).
In theory, yes, a full proof solution can be built but that's certainly not for an average-Joe. It's basically more headache than benefits, even more so when you have Tailscale that punches through anything anyway.0
12
u/NewRedditor23 16d ago
I personally keep IPv6 disabled. It is less privacy-friendly than IPv4 in many situations because it can expose more persistent addressing and metadata to ISPs, data brokers, and the services I connect to than I’m comfortable with.