Routing IPv6 to Your LAN
Your tunnel includes a dedicated IPv6 range (264 addresses). Unlike IPv4 — where you have a handful of addresses and need NAT to share them — IPv6 gives you far more addresses than you’ll ever use, so you can assign a real, public IPv6 address to every device on your network and route them all over the tunnel. No NAT, no port forwarding.
How it works
Section titled “How it works”When you enable IPv6, your WireGuard config gets an address like:
[Interface]Address = 134.49.198.10/32, 2604:5c00:34:1000::1/64...AllowedIPs = 0.0.0.0/0, ::/0The /64 means the entire range is routed to your WireGuard host. Your host holds ::1, and every other address in the range is available for your LAN. To hand those addresses out, you announce the range to your network and let your devices auto-configure — exactly how a normal IPv6-capable ISP works, except the range is yours and static.
Enable forwarding
Section titled “Enable forwarding”On the WireGuard host, enable IPv6 forwarding so it will route between the tunnel and your LAN:
sysctl -w net.ipv6.conf.all.forwarding=1(Persist it in /etc/sysctl.conf or /etc/sysctl.d/.)
Announce the range to your LAN
Section titled “Announce the range to your LAN”Point your devices at a sub-range of your /64 on your LAN interface. There are two common tools — you can use either:
radvd (SLAAC — devices self-assign)
Section titled “radvd (SLAAC — devices self-assign)”Most setups just need radvd (source). Advertise the prefix and clients configure themselves:
interface eth0 { AdvSendAdvert on; prefix 2604:5c00:34:1000::/64 { AdvOnLink on; AdvAutonomous on; };};Use the same range that’s routed to your host. Clients on eth0 will pick up addresses within it automatically.
DHCPv6 (assigned addresses)
Section titled “DHCPv6 (assigned addresses)”If you want to hand out specific addresses instead of letting devices self-assign, use a DHCPv6 server — dnsmasq or ISC’s Kea (docs) — configured to lease from a sub-range of your /64.
That’s it
Section titled “That’s it”Once the range is announced, your LAN devices get public IPv6 addresses and reach the internet — and are reachable — over the tunnel with your dedicated addresses.
Firewall note
Section titled “Firewall note”Because these are real public addresses (not behind NAT), your devices are directly reachable over IPv6. By forwarding this range to your LAN, your WireGuard host is now acting as a router for your network, so it’s where you enforce inbound policy: configure its firewall (ip6tables / nftables) to allow only the inbound IPv6 traffic you intend to expose.