3
Votes

Block IPv6 traffic for clients configured with VPN access

 
3
Votes

Block IPv6 traffic for clients configured with VPN access

Block IPv6 traffic for clients configured with VPN access
Block IPv6 traffic for clients configured with VPN access
3 weeks ago - last edited 3 weeks ago
Tags: #VPN #IPv6 #Firewall
Model: Archer GE800  
Hardware Version: V1
Firmware Version: 1.1.6 Build 20241120 rel.41416(4555)

I currently have the VPN client configured using OpenVPN. I have my XBOX console enabled for VPN access. Since I also have IPV6 enabled on my router (Internet and LAN) all clients automatically receive an IPv4 and also an IPv6 address. There is no possibility to manually disable IPv6 on my Xbox (option not provided on the device). Therefor all outgoing IPv4 traffic from my Xbox is correctly routed through my VPN connection as intended. However all IPv6 traffic is directly routed to the internet causing VPN leakage. This is undesired and I would expect the router to block IPv6 traffic for clients which have VPN access configured to prevent traffic leakage. At least until your firmware will implement IPv6 support for the VPN client.

 

Is there a way to block IPv6 traffic for VPN access enabled clients (e.g. using the built-in IPv6 firewall)? And if not can you please consider this functionality for a future release since it is a security concern and I need all outgoing traffic to either pass through the configured VPN (IPv4) or be blocked (Ipv6).

#1
Options
4 Reply
Re:Block IPv6 traffic for clients configured with VPN access
2 weeks ago

  @banc 

 

Hello, thank you for posting on the TP-Link community, and we certainly appreciate all your feedback and feature request(s) here.

Currently, The VPN functionality of TP-Link routers does not support IPv6. 

If you want to have a try, we would like to escalate your case to the system engineering team for further investigation. While we don't have any specific details that I can share whether this optimization can come to Archer GE800.

Best regards.

 

 

#2
Options
Re:Block IPv6 traffic for clients configured with VPN access
2 weeks ago

  @Marvin_S thanks for your reply. Yes I am aware that IPv4 isn't yet implemented for the VPN client. This is exactly the reason why clients configured with VPN access should have all IPv6 traffic blocked to prevent VPN leakage until TP Link will add IPv6 support to the VPN client in a later release. 

 

Yes please forward my request to the engineering team since I would consider it a security risk as it stands today.

#3
Options
Re:Block IPv6 traffic for clients configured with VPN access
2 weeks ago

  @banc 

 

Hi, we would like to escalate your case to the support engineers, and they will help follow it up. If you are willing, please check your inbox and respond.   

Best regards.

#4
Options
Re:Block IPv6 traffic for clients configured with VPN access
2 weeks ago

  @Marvin_S yes please go ahead to escalate this request. thank you

 

Marvin_S wrote

  @banc 

 

Hi, we would like to escalate your case to the support engineers, and they will help follow it up. If you are willing, please check your inbox and respond.   

Best regards.

 

#5
Options