Em 26-06-2015 16:44, Christian Weisgerber escreveu:
Well, you can add an IPv6 address for each internal host to the
external interface of your firewall, use private addresses on the
internal network, and then use pf's binat to map between the two.
This will preserve port numbers, although it may not be enough for
nasty protocols like SIP.
I know I could use NAT. But, I really think it's almost an abomination
to use it, when you have native IPv6 support. I'll contact my ISP to see
if they can change my CPE mode of operation or, at least, allow me to
configure it. In the meantime, I'll go with a bridge firewall. It seems
like the most hassle free way to go. Perhaps I'll hack some NDP proxy.
But I need IPv6 connectivity, and I need it now.
Cheers,
Giancarlo Razzolini