Skip to content

Routing IPv6 to Your LAN

Your tunnel includes a dedicated IPv6 range (264 addresses). Unlike IPv4 — where you have a handful of addresses and need NAT to share them — IPv6 gives you far more addresses than you’ll ever use, so you can assign a real, public IPv6 address to every device on your network and route them all over the tunnel. No NAT, no port forwarding.

When you enable IPv6, your WireGuard config gets an address like:

[Interface]
Address = 134.49.198.10/32, 2604:5c00:34:1000::1/64
...
AllowedIPs = 0.0.0.0/0, ::/0

The /64 means the entire range is routed to your WireGuard host. Your host holds ::1, and every other address in the range is available for your LAN. To hand those addresses out, you announce the range to your network and let your devices auto-configure — exactly how a normal IPv6-capable ISP works, except the range is yours and static.

On the WireGuard host, enable IPv6 forwarding so it will route between the tunnel and your LAN:

Terminal window
sysctl -w net.ipv6.conf.all.forwarding=1

(Persist it in /etc/sysctl.conf or /etc/sysctl.d/.)

Point your devices at a sub-range of your /64 on your LAN interface. There are two common tools — you can use either:

Most setups just need radvd (source). Advertise the prefix and clients configure themselves:

/etc/radvd.conf
interface eth0 {
AdvSendAdvert on;
prefix 2604:5c00:34:1000::/64 {
AdvOnLink on;
AdvAutonomous on;
};
};

Use the same range that’s routed to your host. Clients on eth0 will pick up addresses within it automatically.

If you want to hand out specific addresses instead of letting devices self-assign, use a DHCPv6 server — dnsmasq or ISC’s Kea (docs) — configured to lease from a sub-range of your /64.

Once the range is announced, your LAN devices get public IPv6 addresses and reach the internet — and are reachable — over the tunnel with your dedicated addresses.

Because these are real public addresses (not behind NAT), your devices are directly reachable over IPv6. By forwarding this range to your LAN, your WireGuard host is now acting as a router for your network, so it’s where you enforce inbound policy: configure its firewall (ip6tables / nftables) to allow only the inbound IPv6 traffic you intend to expose.