I’ve been setting up my first nas and set up DNS routing from my router to adguard home, which then routes traffic to nginx-proxy-manager, which then routes to the docker container for the intended service. I’ve spent days pulling my hair out, trying to figure out what the issue was - why all my services behind NPM were periodically unreachable on my browser. after a wifi reset on my laptop they’d come back online, but why? today I found out that although my router correctly had the DHCP setting correctly set up to route IPv4 traffic to adguard, there was a separate section in the router settings that handles IPv6 settings, and that this was set up to look for my ISP’s assigned DNS provider. Just posting on the off chance anyone finds this helpful or entertaining. I am extremely tired (I have a 3 month old baby) so please bare with the poor formatting of the post!
Hey, congrats on your first NAS! I also struggled a lot at the beginning, but once you figure out some stuff at least you achieve an stable-ish baseline. And congrats on the baby too, good luck trying to manage both ;)
NAS is way easier. Working with a baby you are testing in prod all the time. Congrats on both!
Thanks! 🥰
Thanks team! 😁❤️
I disabled ipv6 across the board. I don’t want my internal devices to be individually routable from the outside. I don’t have a million devices. It’s complexity I don’t want.
Is there anything I’m missing?
Do you not run a firewall? Because your concerns are 100% fixed with a statefull firewall.
I think I worded this poorly. My point about being individually routable is that, that’s the only benefit IPv6 seems to have. Unless I’m missing something.
Well…
Ipv6 is needed for peer to peer networks, easier for vpn and full mndgoru if you want to have a vps…
With it, you can avoid Cgnats and home Nats and usually it is faster and more reliable than ipv4.
So, see it for yourself…
NAT is not a security feature. This is a poor recommendation. Just because something has a globally-routable address does not make it accessible from anywhere.
I didn’t say it was a security feature. But I also don’t really want my ISP knowing how many devices are in my house.
Depending on how your ISP is doing IPv6, the typical way would just route the entire prefix to your router, and the ISP would not know how many addresses are used, in the sense that there is no table (no neighbor discovery is needed). If your ISP is keeping data of flows from your prefix then it could start counting unique addresses, but there isn’t really good a reason to and it wouldn’t be accurate. Some devices pull and use more than one address, and quiet devices might not get picked up by flows which are typically sampled at a ratio.