Cool... now, what do I need to do to configure say OpnSense to give out my internal IPv4/6 addresses that way... and then what pain do I need to go through to secure my internal devices from externally oriented connection attempts?
The former is somewhat serious a question... I want some devices statically assigned and others dynamically, and I'd love to have them match, so where desired I can directly route to/from external over IPv6.
The problem with ipc6 is that transparent v4 support
My ISP gives me an ipv6 range of 2001:abc:ab23:: (well something very similar) routed down the pppoe tunnel (which autoestablishes ipv6 with a /128 IP, just like my ipv4 establishes with a /32)
I thus have my ipv6 vlan 2301 as 2001:abc:ab23:2301::/64
The router is at 2001:abc:ab23:2301:: (which is 2001:abc:ab23:2301:0:0:0:0)
My DNS server on that vlan is statically configured as 2001:abc:ab23:2301::53
My phone when I connect gets a slacc address 2001:abc:ab23:2301:so.me:thi.ng
I can't reach my DNS server from the outside world on 2001:abc:ab23:2301::53 because my firewall blocks it, but if I did allow it t would route through just fine
Remember none of this works with v4 though, you'd have to configure your router to do nat46 and nat64. I've never used such a router, but looks like its supported
My backup router is ipv4 only, so when 192.168.231.0/24 gets routed out my main ISP as normal, it's hidden behind an IP like 81.187.123.45. If I route traffic out of my backup 5g ISP it gets hidden behind that (it actually gets src-natted to a 10.x range, as it's a 4g ISP, it gets converted to a real public IP later)
My 4g doesn't support ipv6, and ipv6 is just a toy, but I expect I would use nat66 to map
2001:abc:ab23:2301::53
behind whatever IP range I was given for the backup route. I've not looked into nat66.
The other aspect is changing ISP. I don't plan on doing that, and ipv6 is only a toy protocol, hence I can just use my global address range. I could however use fd00:2301::53 for my internal DNS server (equivalent of 192.168.231.53) and nat66 it at the boundary, hiding fd00:2301:: behind 2001:abc:ab23:2301::
As the hide address is a /64 there's no need for port mapping, my traffic would emerge from 2001:abc:ab23:2301::53
ipv6 proponents talk about advertising half a dozen IPs to your end devices and renumbering them all dynamically and using mdns instead of static IPs. And they wonder why people thing ipv6 is crap.
The former is somewhat serious a question... I want some devices statically assigned and others dynamically, and I'd love to have them match, so where desired I can directly route to/from external over IPv6.