consider a user vlan or even a dmz. you don’t want thost hosts to be reachable from the public network.
we’re not talking about ip4 <> ip6 translators here.
instead, we’re doing simple dual-stack, however there’s a catch:
we do not want our internal network to be routable.
we want to take advantage of the implicit protections offered by legacy NAT setup, while allowing outbound ipv6 connections (SNAT) to go through and eventually precise inbound connections to be defined (DNAT). in short, we want similar NAT setup for ip6 as we have for ip4.
workstation kvm host
┌─────────────┐
│ │
│ kvmbr0 │
192.168.122.1/24 guest1 (bookworm1)
baaf::baaf:1/112 ┌─────────────┐
│ ┬─────────────────┤ eth0 │
└─────────────┘ 192.168.122.21/24 guest2 (bookworm2-internal)
baaf::baaf:21/112 ┬──────────────┐
│ │ │ │
│ eth1 ┼────────────────┤ eth0 │
└─────────────┘ │ 10.0.0.22/24 │
10.0.0.21/24 │ fc00::beef:22/112
fc00::beef:21/112 │ │
└──────────────┘
this is a PoC on a KVM host, therefore you can consider this address range as perimeter network (front-facing and public)
192.168.122.1/24
as well as this one we’ve added manually for this PoC but is supposedly a globally routed ipv6 address
baaf::baaf:1/112
assuming ip4 /24 internal network
this section is only about being able to easily identify an ipv4 address out of an ipv4 address.
we would like to keep the same suffix on a given host,
for both ip4 and ip6, for example here 22
192.168.122.22 fc00::beef:22
this can be achieved with both ip6 netmasks /120 (exact match)
and /112 (twice the ip space).
it’s your choice which netmask dual-stack host mapping strategy you want.
in this guide we went for /112
on the kvm station
stop and disable the default bridge
virsh net-destroy default virsh net-autostart default --disable
build-up a better front-facing bridge instead
brctl addbr kvmbr0 ifconfig kvmbr0 192.168.122.1/24 up ip addr add baaf::baaf:1/112 dev kvmbr0
also build-up an internal bridge for guest1 and guest2 to communicate
brctl addbr dummybr0 ifconfig dummybr0 up
then point to those for guest1 (two interfaces)
<interface type='bridge'> <source bridge='kvmbr0'/> <model type='virtio'/> </interface> <interface type='bridge'> <source bridge='dummybr0'/> <model type='virtio'/> </interface>
and guest2
<interface type='bridge'> <source bridge='dummybr0'/> <model type='virtio'/> </interface>
on guest1 (two interfaces)
vi /etc/network/interfaces
see interfaces.nat4466.bookworm1
on guest2
vi /etc/network/interfaces
see interfaces.nat4466.bookworm2-internal
HERE DISABLE RAD
enable routing
vi /etc/sysctl.conf net.ipv4.conf.all.arp_filter = 1 net.ipv4.conf.default.arp_filter = 1 net.ipv4.ip_forward = 1 net.ipv6.conf.all.forwarding = 1 sysctp -p
proceed with nat4466
mv -i /etc/nftables.conf /etc/nftables.conf.dist chmod -x /etc/nftables.conf.dist vi /etc/nftables.conf
systemctl start nftables systemctl enable nftables
check snat works
from guest2
ping -c3 192.168.122.1 ping -c3 baaf::baaf:1
check dnat works
from kvm host
ssh -p 2222 192.168.122.21 -l root ssh -p 2222 baaf::baaf:21 -l root