• Welcome to Hurricane Electric's IPv6 Tunnel Broker Forums.

News:

Welcome to Hurricane Electric's Tunnelbroker.net forums!

Main Menu

Recent posts

#1
Questions & Answers / unblock port 25
Last post by himanshu77 - September 16, 2026, 09:06:50 PM
how to unblock port 25 in ipv6 in tunnelbroker
#2
General Discussion / Support with Sage level
Last post by IHesslegrave - September 14, 2026, 11:58:27 AM
I am currently trying to complete the sage level, I believe I have added my nameserver and glue record correctly (see first image), and it seems to send it correctly in the additional information (second image) but the certification says the delegation chain isn't complete. Please can I have some support?
Thanks, Isaac
#3
Questions & Answers / Re: YouTube previews in Signal...
Last post by pdesveaux - August 28, 2026, 07:14:23 PM
I experience the same so just block AAAA DNS records for YouTube on my Pi-Hole setup with the following regex entries:
(\.|^)youtube\.com$;querytype=AAAA
(\.|^)youtu\.be$;querytype=AAAA

Not the best solution, but it works.
#4
Questions & Answers / YouTube previews in Signal don...
Last post by mlindgren - August 28, 2026, 02:23:56 PM
When I'm using my HE /48 and I copy and paste a link into the signal messenger app, I'm unable to render previews.  Similarly when I'm on reddit and there is an embedded YouTube link, I am usually unable to play it and have to click around to find the actual URL and paste it into a new browser window.  If I disable tunnel broker and use IPv4 or my 6rd prefix, everything works great again.  I'm assuming this is something on Google's side and figured there wasn't much we could do about it, but figured I'd ask.
#5
Questions & Answers / Re: Dealing CGNAT to using Tun...
Last post by brianjmurrell - August 18, 2026, 03:22:38 PM
So, I just moved to a location where I am forced behind CGNAT.  I was so bummed to learn that 6-in-4 (which is what HE.net Tunnelbroker is) can't work with CGNAT.

But due to having CGNAT whereas my previous provider gave me my own IP address, and I ran services (mail, web, Nextcloud, etc.) for family and friends on that IP address I decided to go down the route of getting a (free) Oracle Cloud VPS so that I could have an IPv4 address that I could forward connections from over WireGuard to my homelab server (i.e. the server that used to have it's own IPv4 address).

Well, in all honesty I had the Oracle VPS for a longer time as my external domain's nameserver.  But now it was going to come in handy to forward IPv4 connections to my homelab (which is now behind CGNAT) to.

It did occur to me that I could also run HE.net's Tunnelbroker on that Oracle VPS host and delegate and route (real routing, no NAT!!) an IPv6 subnet to my homelab also over that WireGuard connection.  But I was dreading adding yet another latency in the form of my_homelab->Oracle_VPS->HE.net_PoP.

But boy was I ever happy to discover that my Oracle VPS must be hosted in the same facility as my HE.net PoP since the latency from that VPS host to the HE.net PoP was sub-millisecond.  So in the end even though I was adding my Oracle VPS into the path, the latency was the same as when I had an IPv4 address on my homelab and used HE.net Tunnelbroker from there.

SO the moral of the story is to find a VPS, hopefully at the free tier (you don't need much to simply run HE.net and WireGuard) that is in the same facility as your nearest HE.net PoP to avoid adding another latency to your connection.

As an aside, as much of an abomination as CGNAT is, what is even worse is ISPs that use it for IPv4 and don't also deploy GUA IPv6 along side it.
#6
Questions & Answers / Unoptimal route between a VPS ...
Last post by m1doroshin - August 17, 2026, 03:32:32 PM
I have a VPS in Amsterdam, and tunnelbroker.net tunnel with server in Amsterdam.

Traceroute shows pakcets going from Amsterdam through Copenhagen and Stockholm and then back to Amsterdam when running MTR from my home router to the VPS. Traceroute in the other direction shows a much more optimal path. This adds about 20ms of unnecessary latency.

Is there any way to fix this? Should i report it to HE and my VPS provider?

my VPS ip is 2a0d:8480:3:234e:: (AS216071)
tunnelbroker.net server ip is 2001:470:1f14:450::1

MTR from tunnel to VPS:


MTR from VPS to tunnel:

#7
General Questions & Suggestions / Re: Do RFC8482 HINFO records b...
Last post by aphor - August 17, 2026, 02:57:57 PM
Today, just for fun, I tried adding the domain again, and it worked. If anyone at HE did any remediation, thank you very much.
#8
General Questions & Suggestions / Do RFC8482 HINFO records break...
Last post by aphor - August 13, 2026, 03:28:48 PM
I need to add a domain delegated from another domain, but this domain has a HINFO record which blocks "ANY" record lookups from returning NS records that delegate the domain. Running dig with `+trace` follows the NS records and looking up the NS records with `dig -t NS` also works, but I get a zone validation error message in the web UI claiming the NS records to ns?.he.net are not there.

If the validation script is using `dig -t any` under the hood, can we please modernize to be RFC8482 friendly and do `dig -t NS` instead?
#9
Help :<

My file is up and responding over IPv6: https://www.maxrdz.com/av7p7o8h.txt
#10
I lately moved to BT as a broadband provider who also provide IPV6.  I intended to continue with my IPV6 tunnel, but as far as I could find out BT's smarthub 2 blocks IPV6 tunnel traffic.

Does anybody know if that is correct ?

The ISP router of my previous provider which did not supply IPV6 had no issue with tunnel traffic.

Thank you
Markus