• Welcome to Hurricane Electric's IPv6 Tunnel Broker Forums.

Trouble Connecting to Tunnel with Private IP network?

Started by Mikiryu, July 29, 2019, 07:57:32 AM

Previous topic - Next topic

Mikiryu

Hello i've been tryring to connect to the tunnel/IPv6 network using my Mikrotik router with private IP since the Huawei router from ISP (i think) didn't have 6to4 configuration
I've already try to forward using Port Mapping Configuration for Mikrotik private IP in Huawei Router setting but it's still dont work

here my topology
https://imgur.com/A68Lkwc
and Huawei available forward configuration
https://imgur.com/ryJyyB4

please help needed for my thesis

cholzhauer

#1
When you say private IP, you're saying you have an RFC1918 address on your device?

You need to use 6in4, port != protocol

Mikiryu

yes i have a RFC1918 address.
Already set 6to4 configuration on the Mikrotik but still can't connect,
that's why it's must have something to do with the Huawei EchoLife HG8245H router (ISP Router) as the bridge for mikrotik router to connect to internet, so that's why i try to forward the Private ip of the mikrotik router

correct me if i'm wrong

cholzhauer

I am not familiar with that router, so I can't help with specifics.

Is there an HE script that you can apply? They have some for popular routers/OSes

Post the config you have.

snarked

You should try a different router.  Chinese spy hardware is not my first choice.  You should research whether it's DMZ function passes everything or just unknown TCP/UDP ports.

Lastly, for a tunnel here, you need "6in4", not 6to4.

missingusername

Saying this you should stay clear from cisco stuff. Unlike Huawei this is proven (through the Snowden documents) to be spy hardware. Mikrotik os OK so far.

Mikiryu

Quote from: cholzhauer on July 29, 2019, 10:21:42 AM
I am not familiar with that router, so I can't help with specifics.

Is there an HE script that you can apply? They have some for popular routers/OSes

Post the config you have.

I think i just following the config on Example Configurations tabs on the Tunnel Details

https://imgur.com/YSBDdbm

Mikiryu

Quote from: snarked on July 29, 2019, 11:31:11 AM
You should try a different router.  Chinese spy hardware is not my first choice.  You should research whether it's DMZ function passes everything or just unknown TCP/UDP ports.

Lastly, for a tunnel here, you need "6in4", not 6to4.

Sadly i can't change the Huawei router that since it's only router that my ISP giving to us for my house. probably gonna try the DMZ configuration hope it's gonna work

Sorry i didn't know which one is the correct one since the example configuration given from the tunnel is only 6to4
here the configuration
https://imgur.com/YSBDdbm

Mikiryu

Quote from: missingusername on July 29, 2019, 12:45:05 PM
Unlike Huawei this is proven (through the Snowden documents) to be spy hardware. Mikrotik os OK so far.

Didn't know about this, but my ISP only lending this router when we use their service and only this device that can connect to their network

tjeske

You can try DMZ mode. Port forwarding will not work. 6in4 is protocol 41, nothing to do with TCP/UDP and doesn't use ports. Ports are only used by TCP/UDP.

Btw: did you try already if you can ping your public IP address? E.g. use https://www.subnetonline.com/pages/network-tools/online-ping-ipv4.php

Mikiryu

Quote from: tjeske on July 30, 2019, 07:51:25 AM
You can try DMZ mode. Port forwarding will not work. 6in4 is protocol 41, nothing to do with TCP/UDP and doesn't use ports. Ports are only used by TCP/UDP.

Btw: did you try already if you can ping your public IP address? E.g. use https://www.subnetonline.com/pages/network-tools/online-ping-ipv4.php

Already try DMZ mode and change the configuration since I wrongly put my public IP address instead my mikrotik Private address in 6to4 configuration
in my mikrotik terminal I already can ping the Server IPv6 Address, but using the subnetonline I cannot ping my private IP, is it ok?

thank you for the reply

tjeske

What do you mean exactly, you can ping the server IPv6 address? Which IPv6 are you trying to ping exactly?

And no, of course you cannot ping your private IPv4 from subnetonline.com. You need to check if you can ping your public IPv4 (180.246.218.244 in your sketch). I can ping it from here, but I don't know if that is your current public IPv4 address. Check your current public IPv4 by visiting http://ip4.me/.

Edit: maybe you can configure your HG8245H to act as bridge in WAN configuration?

Edit2: Can't you configure IPv6 directly from the HG8245H? Maybe it needs a firmware update, but it should have this option available. Don't know if this supports 6in4 though.