Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
Buying anything on Amazon? Please use the Geekzone Amazon aff link.




4 posts

Wannabe Geek


Topic # 112958 29-Dec-2012 14:12 Send private message

Has anyone had any success setting up 6to4 from a home Xtra broadband connection?

I've been playing around with Linux & Mac boxes (behind NAT) and a Cisco router (which is assigned the public IPv4 addr) and a dual-stacked (telehoused outside Xtra's nw) Linux box but all my testing seems to suggest that Xtra are filtering protocol 41 - even though my traceroute attempts with raw GRE also fail but which I know to work because of the functioning VPN using it.

I can ping 192.88.99.1 (and traceroutes appear to go to .au...) from home (...traceroute from my colo'd box reaches fx.net.nz in Wgtn) and I've even tried using my colo'd box as a relay but the IPv4 traffic doesn't seem to make it there.

The one thing that would give me certainty which I can't do is put a Linux box in the place of the Cisco router to see if any proto 41 traffic makes to the the public IPv4 address but then if they are filtering this outbound traffic then it's unlikely inbound would get through.

Any ideas/knowledge on this subject please?

Filter this topic showing only the reply marked as answer Create new topic
3047 posts

Uber Geek
+1 received by user: 223

Trusted
Subscriber

  Reply # 738329 29-Dec-2012 14:35 Send private message

Try to connect your computer directly onto the public IPv4 address (ie maybe get a bridging modem and connect the PPP session from your computer). I suspect one of your devices is filtering it out - GRE doesn't do well with NAT.





319 posts

Ultimate Geek
+1 received by user: 47


  Reply # 738346 29-Dec-2012 15:08 Send private message

I have a working 6to4 setup on Xtra, so it does work. An ACL on the Cisco will tell you if you are getting packets.

Does the Cisco support ipv6? That might be an easier way to go.

1871 posts

Uber Geek
+1 received by user: 400

Trusted
Spark NZ

  Reply # 738523 30-Dec-2012 10:41 Send private message

I can say uncategorically that Telecom doesn't filter any traffic apart from TCP port 25 (SMTP) to stop computers infected with viruses sending bulkloads of spam.  You can opt out of that filter by contacting the broadband helpdesk.

So I suspect it's something wrong with your configuration... And as others said can't you configure the 6to4 tunnel on your router?  As long as you have new enough IOS then you should be away.  I configured a 6to4 on a old Cisco 1721... Just needed enough ram and new enough IOS.




I work for Spark, but as always my views are my own.



4 posts

Wannabe Geek


Reply # 738824 31-Dec-2012 11:01 Send private message

Thanks guys (why doesn't this site email me to say someone replied like fb does?! - I only read your replies because I came here to post an update.)

I managed to get it going (sometimes it pays to sleep on a problem huh), some weirdness with using traceroute -P 41 going on I suspect, _and_ some weirdness pinging/tracerouting from the Cisco itself (an 877 w/ current 12.4/15.x so yes it supports IPv6 & 6to4, duh) - ping & traceroute are only working to/from the inside nw, I cannot use any of the router's 6to4 addresses as an endpoint to ping from outside.

It's also working flawlessly with my GRE multipoint VPN (I was concerned that I'd have to drop this to make 6to4 work due to a comment in some Cisco docs).
(I don't know why someone suggested GRE has issues with NAT, I can PPTP through it just fine, unless your foreign endpoint is handing out addresses in the same range as your internal subnet - that's not good, tried changing your internal nw range?).

Very pleased, just a shame my nearest relay is in Aussie.


3047 posts

Uber Geek
+1 received by user: 223

Trusted
Subscriber

  Reply # 738827 31-Dec-2012 11:11 Send private message

When will Telecom be offering native IPv6?





2799 posts

Uber Geek
+1 received by user: 458


  Reply # 738853 31-Dec-2012 13:12 Send private message

Jamey: Thanks guys (why doesn't this site email me to say someone replied like fb does?! - I only read your replies because I came here to post an update.)



It does if you want it to. This can be configured globally in your profile, for just one topic, there is a check box right next to the "Post Reply" button.

Filter this topic showing only the reply marked as answer Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





Trending now »

Hot discussions in our forums right now:

Police Camera Van Disguise
Created by Reanalyse, last reply by oxnsox on 19-Dec-2014 21:59 (26 replies)
Pages... 2


Has Spark (Telecom) locked their iphone 6 ?
Created by anewguy2014, last reply by michaelmurfy on 17-Dec-2014 14:32 (25 replies)
Pages... 2


forgot how to unlock a car door
Created by joker97, last reply by joker97 on 19-Dec-2014 19:10 (49 replies)
Pages... 2 3 4


In defence of cats
Created by Rikkitic, last reply by DarthKermit on 17-Dec-2014 15:40 (68 replies)
Pages... 3 4 5


Slaughter of Innocents
Created by networkn, last reply by networkn on 19-Dec-2014 17:46 (64 replies)
Pages... 3 4 5


Lightbox launches on PlayStation 4
Created by freitasm, last reply by sultanoswing on 19-Dec-2014 20:56 (39 replies)
Pages... 2 3


How is iParcel these days?
Created by peejayw, last reply by surfisup1000 on 18-Dec-2014 21:45 (19 replies)
Pages... 2


Spray Foam Insulation
Created by AACTech, last reply by timbosan on 19-Dec-2014 16:58 (36 replies)
Pages... 2 3



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.