Blame
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 1 | # IPv6 in OpenVPN |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 2 | |
| 3 | This page describes IPv6 support in OpenVPN. |
|||
| 4 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 5 | ## Overview |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 6 | |
| 7 | Starting officially in the 2.3.0 release, OpenVPN supports IPv6 inside the tunnel, and can optionally be configured with IPv6 as a transport protocol for the tunneled data. There were some unofficial developer patches for the 2.2.x series that added partial IPv6 support (Debian in particular chose to integrate these patches into some of their builds.) |
|||
| 8 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 9 | ## Providing IPv6 outside the tunnel |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 10 | |
| 11 | To connect to your server over ipv6 (ipv6 transport) use this on both sides: |
|||
| 12 | ||||
| 13 | ``` |
|||
| 14 | proto udp6 |
|||
| 15 | ``` |
|||
| 16 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 17 | |
| 18 | ## Providing IPv6 inside the tunnel |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 19 | |
| 20 | This section walks through providing IPv6 connectivity inside the tunnel; this will discuss a routed setup; a bridged (dev tap) setup is not recommended in general, and users doing so are presumably advanced enough to know what they're doing. |
|||
| 21 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 22 | ### Requirements |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 23 | |
| 24 | A few things must be met in order to use IPv6: |
|||
| 25 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 26 | * An existing and functional OpenVPN configuration (use the official howto if you don't yet have this.) |
| 27 | * Both client and server must support IPv6; most modern systems these-days include this support already |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 28 | |
| 29 | Additionally: |
|||
| 30 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 31 | * **Recommended** A routed IPv6 network block that will reach the host configured as the OpenVPN server |
| 32 | * alternatively, check section "Splitting a single routable IPv6 netblock" below |
|||
| 33 | ||||
| 34 | ||||
| 35 | ### Details: IPv6 routed block |
|||
| 36 | ||||
| 37 | In a routed setup, you cannot use your on-link network; you **must** use a unique routed network range, just like when routing with IPv4. Most ISPs should have a facility to obtain a routed block on request, or sometimes provided as part of DHCPv6-PD; these concepts are outside the scope of this document. Speak to your ISP or use other IPv6 learning resources for further information. |
|||
| 38 | ||||
| 39 | It is recommended to use a /64 for your OpenVPN subnet. While OpenVPN can happily use smaller networks (such as a /112) this is not compatible with the 2.2.x dev-patches that f.ex Debian uses. Thus a /64 is the preferred choice for an OpenVPN IPv6 allocation. |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 40 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 41 | In this document, we'll assume you have the following from the OpenVPN server's viewpoint: |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 42 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 43 | * The OpenVPN server has an IPv6 IP of 2001:db8:0:abc::100/64 on its LAN interface |
| 44 | * The following block is routed to the OpenVPN server host: 2001:db8:0:123::/64 |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 45 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 46 | ### Additional OpenVPN config |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 47 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 48 | There are 2 ways to add IPv6 addressing and pool options to the server, similar to what OpenVPN supports for IPv4: using a helper-directive, and by expanding the helper-directive. The expansion is required if you do not wish to use the automatic values the helper-directive supplies. Clients who use `--client` or `--pull` will get the `tun-ipv6` directive and addressing from the pool pushed as a result. |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 49 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 50 | #### Config stanza using the helper |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 51 | |
| 52 | Add the following to a functioning OpenVPN config: |
|||
| 53 | ||||
| 54 | ``` |
|||
| 55 | server-ipv6 2001:db8:0:123::/64 |
|||
| 56 | ``` |
|||
| 57 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 58 | #### Config stanza with expanded directives |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 59 | |
| 60 | Add the following to a functioning OpenVPN config: |
|||
| 61 | ||||
| 62 | ``` |
|||
| 63 | tun-ipv6 |
|||
| 64 | push tun-ipv6 |
|||
| 65 | ifconfig-ipv6 2001:db8:0:123::1 2001:db8:0:123::2 |
|||
| 66 | ``` |
|||
| 67 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 68 | Note: the option tun-ipv6 is deprecated and not required anymore since version 2.4 (see DeprecatedOptions). |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 69 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 70 | ### Pushing IPv6 routes |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 71 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 72 | Pushing routes over the tunnel works much like it does in IPv4, but you use `--push "route-ipv6 NETWORK/CIDR"` |
| 73 | ||||
| 74 | Using the addressing examples shown above, if you wanted to expose the server-side network of 2001:db8:0:abc::/64, you could use: |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 75 | ``` |
| 76 | push "route-ipv6 2001:db8:0:abc::/64" |
|||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 77 | ``` |
| 78 | ||||
| 79 | To redirect all Internet-bound traffic, use the current allocated public IP space like this: |
|||
| 80 | ``` |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 81 | push "route-ipv6 2000::/3" |
| 82 | ``` |
|||
| 83 | ||||
| 84 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 85 | ## Splitting a single routable IPv6 netblock |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 86 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 87 | Otherwise, there is a way out. Typically /64 IPv6 netblocks are assigned, leaving a large address space. For an OpenVPN setup, this address space can be broken in 2, /65-prefix parts, the first being assigned to the physical network interface, and the second to the VPN. **Warning** operating netblocks smaller than /64 might break some network features. |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 88 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 89 | **Avoid** this setup if you are using any of: |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 90 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 91 | * SLAAC. If you are using SLAAC and have no way around, ask your ISP for permission to use static address assignment on your VPN server. |
| 92 | * IPv6 Multicast - RFC3306 |
|||
| 93 | * Cryptographically Generated Address - CGA - RFC3972 |
|||
| 94 | * NAT64 - RFC6052 |
|||
| 95 | * IPv6-to-IPv6 Network Prefix Translation - NPTv6 - RFC6296 |
|||
| 96 | * Identifier-Locator Network Protocol - ILNP - RFC6741 |
|||
| 97 | * Multihoming Shim Protocol for IPv6 - shim6 - RFC5533 |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 98 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 99 | See this [Internet Draft](http://tools.ietf.org/html/draft-carpenter-6man-why64-00) for details. |
| 100 | ||||
| 101 | ### Split netblock configuration |
|||
| 102 | ||||
| 103 | Get the original IPv6 netblock on your OpenVPN server; let's assume it's |
|||
| 104 | ``` |
|||
| 105 | 2001:db8:0:123::/64 |
|||
| 106 | ``` |
|||
| 107 | ||||
| 108 | 1. check that your NIC uses no addresses in the upper /65 block (in this case, addresses greater than 2001:db8:0:123:8000::/65). If you do, you can't use this setup until you eliminate those. |
|||
| 109 | 2. re-assign the new restricted netblock – lower part. The command for this depends on your OS. For example, in **FreeBSD**: |
|||
| 110 | ``` |
|||
| 111 | ### check this on your OS! |
|||
| 112 | # ifconfig igb0 inet6 2001:db8:0:123::/64 -alias |
|||
| 113 | # ifconfig igb0 inet6 2001:db8:0:123::/65 |
|||
| 114 | ### |
|||
| 115 | ### re-assign the other aliases previously set under the /64 block |
|||
| 116 | # ifconfig igb0 inet6 2001:db8:0:123::dead/128 alias |
|||
| 117 | # ifconfig igb0 inet6 2001:db8:0:123::ea:beef/128 alias |
|||
| 118 | # ... |
|||
| 119 | ``` |
|||
| 120 | 3. assign the higher part of the restricted netblock to OpenVPN. Add |
|||
| 121 | ``` |
|||
| 122 | # add this line |
|||
| 123 | server-ipv6 2001:db8:0:123:8000::/65 |
|||
| 124 | ``` |
|||
| 125 | 4. restart the VPN |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 126 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 127 | You can do this also if your assigned IPv6 netblock is already shorter than /64, e.g. /112 . Just perform the same steps and compute the base address of the upper subnet: the lower starts with the last bit in the netmask set to 0, the upper starts with it set to 1. |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 128 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 129 | ## Client issues |
| 130 | If you are running **Android** 4.4.x you will encounter a bug related to the tun0 interface. |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 131 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 132 | After setting up the OpenVPN connection you are able to ping6 the Android 4.4.x device from your server, but you cannot ping6 the server or other IPv6 targets from your Android 4.4 device. This bug doesn't occur in Android 4.3 (And earlier?) and occurs in all Android 4.4.x versions including 4.4.2. There is no known workaround for this issue except hoping on a fix in Android 4.4.3. |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 133 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 134 | * [Issue 63349: IPv6Droid does not work on Android 4.4 / 4.4.1](https://code.google.com/p/android/issues/detail?id=63349) |
| 135 | * [Issue 62714: VPN issues on KitKat version 4.4](https://code.google.com/p/android/issues/detail?id=62714) |
|||
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 136 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 137 | **iOS 9** broke redirect-gateway if used with IPv6 tunnels and no IPv4 traffic goes inside the tunnel. To workaround this issue, use: |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 138 | |
| 139 | ``` |
|||
| 140 | redirect-gateway ipv6 |
|||
| 141 | ``` |
|||
| 142 | ||||
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 143 | combined with usual redirect-gateway. This option works only on Android and iOS OpenVPN Connect clients (OpenVPN 3) and OpenVPN 2.4 (development version) and has no effect for OpenVPN 2.3. |
| 299807 | Samuli Seppänen | 2025-02-11 09:20:32 | 144 | |
| 423a3c | Samuli Seppänen | 2025-02-27 09:43:59 | 145 | * [#614 Connect on iOS 9: IPv4 routing doesn't work with dual-stack](http://community.openvpn.net/openvpn/ticket/614) |
