My ISP doesn't yet support IPV6. Using XGS87, v 18.5. I have not enabled anything IPV6 yet, but obviously almost all devices are using it internally.
1. In poking through IPV6-related pages in the GUI I can see in Network > Neighbor > IPV6 Cache, I see 60+ link-local entries of which about half show the WAN port (Port 2 in my case) as their Interface. These devices have MAC addresses that I don't recognize as my devices but I guess it's possible they're devices I'm not aware of on my network and for whatever reason they are associated with the WAN rather than their internal zone. Should I be seeing apparently external ipv6 (and and associated MAC) addresses as neighbors? (I realize this has to do with what my ISP is doing upstream of me, though again I'd mention that they don't currently support ipv6 for customers, so I'm suspicious of them having a lot of ipv6-using devices of their own that are directly visible to my XGS.)
2. It seems like there are at least 4 methods my ISP could use to roll out IPV6 to the XGS87. The current SFOS 18.5 allows for a manual entry, and also for DHCPv6. There is apparently a different DHCP-based mechanism (DHCP-PD) that SFOS doesn't currently support. And it seems like there another option as well. Have you found any concise clear descriptions of these mechanisms and can you say which ones Sophos currently supports or is expected to support soon?
3. It seems like internally, regardless of the option the ISP chooses (from question #2), I just have to turn on the IPV6 RA on the XGS and that will let all the local devices know what to do. Is it pretty much that simple? (It seems like DHCPv6 is also available for the internal networks, but that seems like overkill for a home office network.)
4. DDNS currently supports either ipv4 or ipv6. Is this a Sophos limitation or do places like Google not support it?
5. How might one create rules that apply to individual devices? The mechanisms I see would be either clienteles users or Mac-address-based host names? Not sure if a clienteles user supports multiple IP (v6) addresses though. I believe that since most of my rules are zone-based they should work regardless of ipv6 addresses changing. Right? So it's just the couple of device-specific rules that need to be considered?
Thanks!``
This thread was automatically locked due to age.