Commit 299807

2025-02-11 09:20:32 Samuli Seppänen: Add IPv6 article
/dev/null .. Pages/IPv6.md
@@ 0,0 1,102 @@
+ # IPv6 in OpenVPN
+
+ This page describes IPv6 support in OpenVPN.
+
+ ## Overview
+
+ Starting officially in the 2.3.0 release, OpenVPN supports IPv6 inside the tunnel, and can optionally be configured with IPv6 as a transport protocol for the tunneled data. There were some unofficial developer patches for the 2.2.x series that added partial IPv6 support (Debian in particular chose to integrate these patches into some of their builds.)
+
+ ## Providing IPv6 outside the tunnel
+
+ To connect to your server over ipv6 (ipv6 transport) use this on both sides:
+
+ ```
+ proto udp6
+ ```
+
+ ## Providing IPv6 inside the tunnel
+
+ This section walks through providing IPv6 connectivity inside the tunnel; this will discuss a routed setup; a bridged (dev tap) setup is not recommended in general, and users doing so are presumably advanced enough to know what they're doing.
+
+ ### Requirements
+
+ A few things must be met in order to use IPv6:
+
+ - An existing and functional OpenVPN configuration (use the official howto if you don't yet have this.)
+ - Both client and server must support IPv6; most modern systems these-days include this support already
+
+ Additionally:
+
+ - **Recommended** A routed IPv6 network block that will reach the host configured as the OpenVPN server
+ - alternatively, check section "Splitting a single routable IPv6 netblock" below
+
+ ### Details: IPv6 routed block
+
+ In a routed setup, you **must** use a unique routed network range, just like when routing with IPv4. Most ISPs should have a facility to obtain a routed block on request. It is recommended to use a /64 for your OpenVPN subnet.
+
+ Assuming the OpenVPN server has:
+ - IPv6 IP of `2001:db8:0:abc::100/64` on its LAN interface
+ - Routed block: `2001:db8:0:123::/64`
+
+ ### Additional OpenVPN config
+
+ #### Config stanza using the helper
+
+ Add the following to a functioning OpenVPN config:
+
+ ```
+ server-ipv6 2001:db8:0:123::/64
+ ```
+
+ #### Config stanza with expanded directives
+
+ Add the following to a functioning OpenVPN config:
+
+ ```
+ tun-ipv6
+ push tun-ipv6
+ ifconfig-ipv6 2001:db8:0:123::1 2001:db8:0:123::2
+ ```
+
+ ### Pushing IPv6 routes
+
+ Pushing routes over the tunnel works much like in IPv4:
+
+ ```
+ push "route-ipv6 2001:db8:0:abc::/64"
+ push "route-ipv6 2000::/3"
+ ```
+
+ ## Splitting a single routable IPv6 netblock
+
+ Typically /64 IPv6 netblocks are assigned, leaving a large address space.
+
+ ### Split netblock configuration
+
+ Assume the original IPv6 netblock on your OpenVPN server is `2001:db8:0:123::/64`.
+
+ 1. Check your NIC uses no addresses in the upper /65 block.
+ 2. Re-assign the new restricted netblock – lower part.
+ 3. Assign the higher part of the restricted netblock to OpenVPN.
+ 4. Restart the VPN.
+
+ ## Client issues
+
+ ### Android 4.4.x
+
+ Android 4.4.x has a known bug related to the tun0 interface which affects IPv6 connectivity.
+
+ - [Issue 63349: IPv6Droid does not work on Android 4.4 / 4.4.1](https://code.google.com/p/android/issues/detail?id=63349)
+ - [Issue 62714: VPN issues on KitKat (version 4.4)](https://code.google.com/p/android/issues/detail?id=62714)
+
+ ### iOS 9
+
+ iOS 9 broke redirect-gateway if used with IPv6 tunnels and no IPv4 traffic goes inside the tunnel. To workaround, use:
+
+ ```
+ redirect-gateway ipv6
+ ```
+
+ This option works only on Android and iOS OpenVPN Connect clients (OpenVPN 3) and OpenVPN 2.4 (development version) and has no effect for OpenVPN 2.3.
+
+ - [Connect on iOS 9: IPv4 routing doesn't work with dual-stack](http://community.openvpn.net/openvpn/ticket/614)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9