diff options
| author | Ahmed Abdelhalim <[email protected]> | 2026-07-08 14:28:33 +0200 |
|---|---|---|
| committer | Ahmed Abdelhalim <[email protected]> | 2026-07-08 16:55:30 +0200 |
| commit | b8f25e9d80c96f7170d51eb5abcd662a66d55317 (patch) | |
| tree | 664374075de9f34ee23ab8f59d50371b4f3522e3 /host_vars/pve.local.yml.example | |
| parent | 663bce95c096ed43dd24674debf4c8df2be1b604 (diff) | |
Route IPv6 through WireGuard VPN via radvd and static gateway
Add radvd to gateway role to advertise Pi as high-preference IPv6
default router using the stable ULA prefix (fd1e:.../64). With
FritzBox also sending RAs, devices end up with ECMP between Pi and
FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local)
as a static route with metric 100 to all managed hosts — beats RA
metric 425, ensuring all IPv6 default traffic goes through Pi.
Fix IPv6 MASQUERADE in gateway-apply-rules:
- Direct mode: add MASQUERADE on end0 (LAN devices use ULA source
addresses not known to FritzBox, so Pi must NAT them)
- FORWARD rules: restrict to RELATED,ESTABLISHED only — previously
the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded
copies, causing duplicate SYNs, conntrack corruption, and RSTs
- MASQUERADE/clear rules: match by interface not by source subnet
(devices may use any source address, not just the ULA prefix)
- VPN mode return traffic: explicitly restrict to wg+→end0 direction
Add network_ipv6_gateway var (optional) to network role NM templates
(ethernet, wifi, bridge) — injects a static IPv6 default route at
metric 100 when set. Add rpi5 static route to FritzBox link-local so
Pi keeps IPv6 after FritzBox RA is disabled.
Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents
Ansible from hanging on mDNS returning multiple IPv6 addresses.
Update gateway and pihole READMEs with two-step IPv6 setup process.
Co-Authored-By: Claude.ai
Diffstat (limited to 'host_vars/pve.local.yml.example')
| -rw-r--r-- | host_vars/pve.local.yml.example | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/host_vars/pve.local.yml.example b/host_vars/pve.local.yml.example index 0a4a5ceb..88a60b5a 100644 --- a/host_vars/pve.local.yml.example +++ b/host_vars/pve.local.yml.example @@ -1,8 +1,13 @@ --- +# Disable wifi connection on PVE, it's connected with LAN +network_wifi_ssid: "" +network_wifi_pass: "" network_ipv4_address: "10.0.0.253" network_ipv4_gateway: "10.0.0.254" network_ipv4_dns: "10.0.0.254" network_bridge_interface: "eth0" +# Discover network_ipv6_gateway with: ip -6 route show default | grep ra (run on any device before disabling router RA) +# network_ipv6_gateway: "fe80::0000:1111:2222:3333" pve_admin_user: "admin" pve_admin_password: "changeme" |
