I’ve been setting up my first nas and set up DNS routing from my router to adguard home, which then routes traffic to nginx-proxy-manager, which then routes to the docker container for the intended service. I’ve spent days pulling my hair out, trying to figure out what the issue was - why all my services behind NPM were periodically unreachable on my browser. after a wifi reset on my laptop they’d come back online, but why? today I found out that although my router correctly had the DHCP setting correctly set up to route IPv4 traffic to adguard, there was a separate section in the router settings that handles IPv6 settings, and that this was set up to look for my ISP’s assigned DNS provider. Just posting on the off chance anyone finds this helpful or entertaining. I am extremely tired (I have a 3 month old baby) so please bare with the poor formatting of the post!

  • surewhynotlem@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    7
    ·
    7 hours ago

    I disabled ipv6 across the board. I don’t want my internal devices to be individually routable from the outside. I don’t have a million devices. It’s complexity I don’t want.

    Is there anything I’m missing?

    • 4am@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      3
      ·
      2 hours ago

      NAT is not a security feature. This is a poor recommendation. Just because something has a globally-routable address does not make it accessible from anywhere.

      • surewhynotlem@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        46 minutes ago

        I didn’t say it was a security feature. But I also don’t really want my ISP knowing how many devices are in my house.

    • slazer2au@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      2
      ·
      7 hours ago

      Do you not run a firewall? Because your concerns are 100% fixed with a statefull firewall.

      • surewhynotlem@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        45 minutes ago

        I think I worded this poorly. My point about being individually routable is that, that’s the only benefit IPv6 seems to have. Unless I’m missing something.

      • Onomatopoeia@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        5
        ·
        5 hours ago

        Or, just completely bypass any config by simply not using IP6 for an environment where it offers no advantage

    • thelittleblackbird@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      2
      ·
      7 hours ago

      Well…

      Ipv6 is needed for peer to peer networks, easier for vpn and full mndgoru if you want to have a vps…

      With it, you can avoid Cgnats and home Nats and usually it is faster and more reliable than ipv4.

      So, see it for yourself…

      • HelloRoot@lemy.lol
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        4 hours ago

        Every time I try to use Ipv6, I run into dozens of weird issues and bugs and my selfhosted stuff becomes unusable/unreliable.

        I don’t know where the issue exactly lies in the chain of networking, but it sure is annoying as a motherfucker to debug. As far as I can tell none of my stuff is the problem and the issue lies either with my ISP or VPS provider.

        For now, I removed the AAAA entries and suddenly everything works without any hiccups. Wake me up when those issues are solved… maybe in 10 or 20 years…

        • thelittleblackbird@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          2 hours ago

          Don’t know what to say,

          I maintain a double stack since 5 years and apart of some small nuisance I never had a real problem.

          Ipv6 has been with us for more than 20 years, and It is true that to have that fine grain control in ipv6 you will need to go to a prosumer devices, but those are not that expensive and if you have a home lab you should check on them anyway…

          Things are mature despite your bad experiences