211
for example to bind multiple Internet IP addresses to SX-GATE and then use firewall
rules to redirect connections to different internal addresses. However you may also add
addresses of different networks if multiple IP subnets share the same physical Ethernet.
DS-Lite Address-Family-Transition-Router (AFTR)
In dual stack light Internet links IPv4 packets are tunneled via IPv6. The tunnel endpoint
on the provider side is a special router. It its address isn't advertised with DHCP you
can enter the address here.
IPv6 address
Enter an IPv6 address for this interface. If the address is based on a delegated prefix,
please add an entry of type "IPv6 address" in menu "Definitions > IP objects" which
refers to the prefix.
IPv6 prefix length
The IPv6 prefix length is the equivalent to IPv4 netmasks. The typical prefix length ist
64.
With prefix lengths greater than 64 some IPv6 features like
e.g. SLAAC no longer work. Use large prefixes only when you
understand the implications.
IPv6 default gateway
If a router is attached to the current interface which provides Internet connectivity, you
can enter its IP address here.
You can either enter a global address or a link local address
(fe80:...).
IPv6 privacy extension (RFC3041)
A dynamic IPv6 address derived with SLAAC is based on the hardware address of the
network card. So it can be tracked worldwide easily. Enable this option and SX-GATE
will add a temporary random address which is preferred.
IPv6 prefix delegation
Enable this option to ask your provider for an additional IPv6 network prefix, which is
then made available for internal networks by SX-GATE.
As soon as SX-GATE receives such a prefix, an entry is created in menu "Definitions >
IP objects" which will be named after the interface (e.g. "ipv6_prefix_eth1" for "eth1").
Subdivide the prefix by adding entries of type "IPv6 prefix" or "IPv6 address" and make