Skip to content

Commit e5cf450

Browse files
committed
Site updated: 2023-04-06 13:36:15
1 parent 7ae643f commit e5cf450

3 files changed

Lines changed: 5 additions & 5 deletions

File tree

2023/02/22/爱快主路由下IPV6防火墙的最优解/index.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@
5252
<meta property="og:image" content="https://r0yanx.com/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-16-23-16.png">
5353
<meta property="og:image" content="https://r0yanx.com/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-23-20-56-01.png">
5454
<meta property="article:published_time" content="2023-02-22T03:45:23.000Z">
55-
<meta property="article:modified_time" content="2023-04-06T05:31:00.671Z">
55+
<meta property="article:modified_time" content="2023-04-06T05:35:55.268Z">
5656
<meta property="article:author" content="r0yanx">
5757
<meta property="article:tag" content="折腾">
5858
<meta name="twitter:card" content="summary">
@@ -258,7 +258,7 @@ <h1 class="post-title" itemprop="name headline">
258258
<i class="far fa-calendar-check"></i>
259259
</span>
260260
<span class="post-meta-item-text">更新于</span>
261-
<time title="修改时间:2023-04-06 13:31:00" itemprop="dateModified" datetime="2023-04-06T13:31:00+08:00">2023-04-06</time>
261+
<time title="修改时间:2023-04-06 13:35:55" itemprop="dateModified" datetime="2023-04-06T13:35:55+08:00">2023-04-06</time>
262262
</span>
263263
<span class="post-meta-item">
264264
<span class="post-meta-item-icon">
@@ -308,7 +308,7 @@ <h3 id="实践"><a href="#实践" class="headerlink" title="实践"></a>实践</
308308
<p><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-24-08.png"></p>
309309
<p><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-25-30.png"></p>
310310
<p>然后配置vlan101口的ipv6服务。需要确保在ipv6设置中外网接口能获取到公网v6地址,且获取到ipv6前缀,正常桥接光猫并正确拨号后会自动获取到:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-35-41.png"><br>前缀这里需要小于64,否则在openwrt就无法下发ipv6地址:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-36-42.png"></p>
311-
<h4 id="openwrt-ipv6配置"><a href="#openwrt-ipv6配置" class="headerlink" title="openwrt ipv6配置"></a>openwrt ipv6配置</h4><p>接下来配置openwrt,为了方便,我的openwrt配置了2个网口,都是绑定了内网lan口:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-26-51.png"><br>openwrt作为ipv4旁路由,相信大家都会,不细说了,配置好之后可开始配置v6,不配置也行。<br>然后修改wan6配置:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-28-45.png"><br>把协议切换为dhcpv6客户端,如何没有的,请自行查询安装ipv6(主要是ipv6-helper)方法或更换固件:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-30-34.png"><br>不要勾选”使用内置的 IPv6 管理”:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-32-53.png"><br>配置为桥接接口,并连接到vlan101。具体操作是,在自定义接口中输入<code>eth1.101</code>代表连接到<code>eth1</code>网口的<code>VLAN 101</code>::<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-33-27.png"><br>防火墙区域设置为wan:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-34-02.png"></p>
311+
<h4 id="openwrt-ipv6配置"><a href="#openwrt-ipv6配置" class="headerlink" title="openwrt ipv6配置"></a>openwrt ipv6配置</h4><p>接下来配置openwrt,为了方便,我的openwrt配置了2个网口,都是绑定了内网lan口:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-26-51.png"><br>openwrt作为ipv4旁路由,相信大家都会,不细说了,配置好之后可开始配置v6,不配置也行。<br>然后修改wan6配置:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-28-45.png"><br>把协议切换为dhcpv6客户端,如何没有的,请自行查询安装ipv6(主要是ipv6-helper)方法或更换固件:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-30-34.png"><br>不要勾选”使用内置的 IPv6 管理”:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-32-53.png"><br>配置为桥接接口,并连接到vlan101。具体操作是,在<code>自定义接口</code>中输入<code>eth1.101</code>代表连接到<code>eth1</code>网口的<code>VLAN 101</code>::<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-33-27.png"><br>防火墙区域设置为wan:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-34-02.png"></p>
312312
<p>保存后会自动重启接口,此时wan6应该能获取到ipv6地址及pd前缀,正常的话lan口也应该获取到ipv6地址:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-16-01-18.png"></p>
313313
<p>然后配置lan口的dhcpv6服务,内网设备即可获取到ipv6地址:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-23-20-51-01.png"></p>
314314
<p>然而博主的lan口经过多方配置,也无法获取到ipv6地址,内网设备也无法获取到公网的ipv6地址,网上很多教程是改成中继模式的并不符合本人的需求。</p>

index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -396,7 +396,7 @@ <h2 class="post-title" itemprop="name headline">
396396
<i class="far fa-calendar-check"></i>
397397
</span>
398398
<span class="post-meta-item-text">更新于</span>
399-
<time title="修改时间:2023-04-06 13:31:00" itemprop="dateModified" datetime="2023-04-06T13:31:00+08:00">2023-04-06</time>
399+
<time title="修改时间:2023-04-06 13:35:55" itemprop="dateModified" datetime="2023-04-06T13:35:55+08:00">2023-04-06</time>
400400
</span>
401401
<span class="post-meta-item">
402402
<span class="post-meta-item-icon">

search.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2685,7 +2685,7 @@ st->op1->op2->op3->op4->e</textarea><textarea id="flowchart-0-options" style="di
26852685
<p><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-24-08.png"></p>
26862686
<p><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-25-30.png"></p>
26872687
<p>然后配置vlan101口的ipv6服务。需要确保在ipv6设置中外网接口能获取到公网v6地址,且获取到ipv6前缀,正常桥接光猫并正确拨号后会自动获取到:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-35-41.png"><br>前缀这里需要小于64,否则在openwrt就无法下发ipv6地址:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-36-42.png"></p>
2688-
<h4 id="openwrt-ipv6配置"><a href="#openwrt-ipv6配置" class="headerlink" title="openwrt ipv6配置"></a>openwrt ipv6配置</h4><p>接下来配置openwrt,为了方便,我的openwrt配置了2个网口,都是绑定了内网lan口:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-26-51.png"><br>openwrt作为ipv4旁路由,相信大家都会,不细说了,配置好之后可开始配置v6,不配置也行。<br>然后修改wan6配置:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-28-45.png"><br>把协议切换为dhcpv6客户端,如何没有的,请自行查询安装ipv6(主要是ipv6-helper)方法或更换固件:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-30-34.png"><br>不要勾选”使用内置的 IPv6 管理”:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-32-53.png"><br>配置为桥接接口,并连接到vlan101。具体操作是,在自定义接口中输入<code>eth1.101</code>代表连接到<code>eth1</code>网口的<code>VLAN 101</code>::<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-33-27.png"><br>防火墙区域设置为wan:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-34-02.png"></p>
2688+
<h4 id="openwrt-ipv6配置"><a href="#openwrt-ipv6配置" class="headerlink" title="openwrt ipv6配置"></a>openwrt ipv6配置</h4><p>接下来配置openwrt,为了方便,我的openwrt配置了2个网口,都是绑定了内网lan口:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-26-51.png"><br>openwrt作为ipv4旁路由,相信大家都会,不细说了,配置好之后可开始配置v6,不配置也行。<br>然后修改wan6配置:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-28-45.png"><br>把协议切换为dhcpv6客户端,如何没有的,请自行查询安装ipv6(主要是ipv6-helper)方法或更换固件:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-30-34.png"><br>不要勾选”使用内置的 IPv6 管理”:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-32-53.png"><br>配置为桥接接口,并连接到vlan101。具体操作是,在<code>自定义接口</code>中输入<code>eth1.101</code>代表连接到<code>eth1</code>网口的<code>VLAN 101</code>::<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-33-27.png"><br>防火墙区域设置为wan:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-13-34-02.png"></p>
26892689
<p>保存后会自动重启接口,此时wan6应该能获取到ipv6地址及pd前缀,正常的话lan口也应该获取到ipv6地址:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-22-16-01-18.png"></p>
26902690
<p>然后配置lan口的dhcpv6服务,内网设备即可获取到ipv6地址:<br><img data-src="/2023/02/22/%E7%88%B1%E5%BF%AB%E4%B8%BB%E8%B7%AF%E7%94%B1%E4%B8%8BIPV6%E9%98%B2%E7%81%AB%E5%A2%99%E7%9A%84%E6%9C%80%E4%BC%98%E8%A7%A3/2023-02-23-20-51-01.png"></p>
26912691
<p>然而博主的lan口经过多方配置,也无法获取到ipv6地址,内网设备也无法获取到公网的ipv6地址,网上很多教程是改成中继模式的并不符合本人的需求。</p>

0 commit comments

Comments
 (0)