SRV.🇫🇷.◕‿◕.ST 1AB3::1/70

Dedicated Linux Debian Proxmox VM Server with connection ASN 3215 Orange S.A. in Valdeblore (FR), France (UTC+1) for Load-balancing Virtual Machine Services.

Network IPv4 + IPv6


IPv4 Public address : 109.210.49.186/32

IPv6 GUA Network : 2a01:cb1d:6aa:b400::/56
IPv6 GUA Network range : 2a01:cb1d:6aa:b400:0000:0000:0000:0000-2a01:cb1d:813:4aff:ffff:ffff:ffff:ffff

srv.fr.◕‿◕.st

IPv6 GUA Network : 2a01:cb1d:6aa:b400:1800::/70
IPv6 GUA Network range : 2a01:cb1d:6aa:b400:1800:0000:0000:0000-2a01:cb1d:6aa:b400:1bff:ffff:ffff:ffff

I assign an IPv6 address of type IPv6::/70 on the main block of my Orange_FR internet connection for my server at home (Intel(R) Core(TM) i9-9900K CPU @ 3.60GHz - 16 cores, 64GB non-ECC DDR, 2x 1TB hard drives + system).

/ infos /

Ethernet interfaces :

root@srv-fr:~ # lshw -C network
  *-network
       description: Ethernet interface
       produit: 82599ES 10-Gigabit SFI/SFP+ Network Connection
       fabriquant: Intel Corporation
       identifiant matériel: 0
       information bus: pci@0000:01:00.0
       nom logique: enp1s0
       version: 01
       numéro de série: 00:1b:21:bc:c7:0e
       taille: 10Gbit/s
       capacité: 10Gbit/s
       bits: 64 bits
       horloge: 33MHz
       fonctionnalités: pm msi msix pciexpress vpd bus_master cap_list rom ethernet physical fibre 10000bt-fd
       configuration: autonegotiation=off broadcast=yes driver=ixgbe driverversion=6.8.12-8-pve duplex=full firmware=0x00012b2c latency=0 link=yes multicast=yes port=fibre speed=10Gbit/s
       ressources: irq:16 mémoire:51400000-5147ffff portE/S:3000(taille=32) mémoire:51500000-51503fff mémoire:51480000-514fffff mémoire:51504000-51603fff mémoire:51604000-51703fff
root@srv-fr:~ # brctl show
bridge name     bridge id               STP enabled     interfaces
gatebr0         8000.001b21bcc70e       no              enp1s0
vmbr0           8000.16faeaefe802       yes             tap100i0
vmbr1           8000.9e76818e82ad       yes             tap101i0
vmbr2           8000.b20d242ccc3b       yes             tap102i0


Representation WAN :

⛔🔜 root@srv-fr:~ # dig -x fec0:1:2:3::1 @dns.google

; <<>> DiG 9.18.49-1~deb12u1-Debian <<>> -x fec0:1:2:3::1 @dns.google
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 21640
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.3.0.0.0.2.0.0.0.1.0.0.0.0.c.e.f.ip6.arpa. IN PTR

;; AUTHORITY SECTION:
ip6.arpa.               1525    IN      SOA     b.ip6-servers.arpa. nstld.iana.org. 2026022547 1800 900 604800 3600

;; Query time: 19 msec
;; SERVER: 2001:4860:4860::8844#53(dns.google) (UDP)
;; WHEN: Wed Jul 29 16:04:40 CEST 2026
;; MSG SIZE  rcvd: 165

I manage my ULA (fc00::/7) and SLA (fec0::/10) IPv6 networks using my reverse DNS.

⛔🔜 root@srv-fr:~ # dig -x fec0:1:2:3::1 @2a01:cb1d:6aa:b400:1ab3::1

; <<>> DiG 9.18.49-1~deb12u1-Debian <<>> -x fec0:1:2:3::1 @2a01:cb1d:6aa:b400:1ab3::1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 47087
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 9bba4a529c696814010000006a6a08a7a6142ffaa81c277f (good)
;; QUESTION SECTION:
;1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.3.0.0.0.2.0.0.0.1.0.0.0.0.c.e.f.ip6.arpa. IN PTR

;; AUTHORITY SECTION:
c.e.f.ip6.arpa.         60      IN      SOA     srv.🇫🇷.◕‿◕.st. 👮.🇫🇷.◕‿◕.st. 2025110501 20 5 420 60

;; Query time: 0 msec
;; SERVER: 2a01:cb1d:6aa:b400:1ab3::1#53(2a01:cb1d:6aa:b400:1ab3::1) (UDP)
;; WHEN: Wed Jul 29 16:05:27 CEST 2026
;; MSG SIZE  rcvd: 218
⛔🔜 root@srv-fr:~ # dig -x fc00:1:2:3::1 @2a01:cb1d:6aa:b400:1ab3::1

; <<>> DiG 9.18.49-1~deb12u1-Debian <<>> -x fc00:1:2:3::1 @2a01:cb1d:6aa:b400:1ab3::1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 31320
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: b68d8f56d590f630010000006a6a08c935b774cc4a046315 (good)
;; QUESTION SECTION:
;1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.3.0.0.0.2.0.0.0.1.0.0.0.0.0.c.f.ip6.arpa. IN PTR

;; AUTHORITY SECTION:
c.f.ip6.arpa.           60      IN      SOA     srv.🇫🇷.◕‿◕.st. 👮.🇫🇷.◕‿◕.st. 2025101803 20 5 420 60

;; Query time: 0 msec
;; SERVER: 2a01:cb1d:6aa:b400:1ab3::1#53(2a01:cb1d:6aa:b400:1ab3::1) (UDP)
;; WHEN: Wed Jul 29 16:06:01 CEST 2026
;; MSG SIZE  rcvd: 216

Delegation of a second reverse DNS for the various buildings (racks, networks, machines, workers) - enabling them to configure and manage their IPv6 addresses according to their specific infrastructure :

; TEST ;

; -------------------------------
; Delegation reverse IPv6::/56

; fc00::10:0:0:0/56
; 0.0.0.0.0.0.0.0.0.0.0.0.c.f.ip6.arpa.     IN      NS      xn--53h.xn--ch9h.srv.xn--j77hya.xn--hwgz2tba.st.

; -------------------------------
; Delegation reverse IPv6::/64

; fc00::10:0:0:0/64
; 0.0.0.0.0.0.0.0.0.0.0.0.0.0.c.f.ip6.arpa.     IN      NS      xn--53h.xn--ch9h.srv.xn--j77hya.xn--hwgz2tba.st.

; -------------------------------
; Delegation reverse IPv6::/80

; fc00::10:0:0:0/80
; 0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.c.f.ip6.arpa.	IN      NS      xn--53h.xn--ch9h.srv.xn--j77hya.xn--hwgz2tba.st.

; -------------------------------
; Delegation reverse IPv6::/96

; fc00::10:0:0:0/96
; 0.0.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.c.f.ip6.arpa.     IN      NS      xn--53h.xn--ch9h.srv.xn--j77hya.xn--hwgz2tba.st.

; -------------------------------
; Delegation reverse IPv6::/104

; fc01::10:106:0:0/104
; 0.0.6.1.1.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.1.0.c.f.ip6.arpa.     IN      NS      xn--53h.xn--ch9h.srv.xn--j77hya.xn--hwgz2tba.st.

; -------------------------------
; Delegation reverse IPv6::/112

; fc01::10:116:42:0/112
2.4.0.0.6.1.1.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.1.0.c.f.ip6.arpa.     IN      NS      xn--53h.xn--ch9h.srv.xn--j77hya.xn--hwgz2tba.st. ; ☕.🟨.srv.🇫🇷.◕‿◕.st - fc01::10:116:0:1

; fc01::10:126:42:0/112
2.4.0.0.6.2.1.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.1.0.c.f.ip6.arpa.     IN      NS      xn--53h.xn--9g9h.srv.xn--j77hya.xn--hwgz2tba.st. . ; ☕.🟦.srv.🇫🇷.◕‿◕.st. - fc01::10:126:0:1

Not to joke, because you never know with all this information, I'm adding the files /.well-known/security.txt to the default WebServers directory ; hoping you're not too mean.


IPv4/IPv6 FrontEnd Web Services with French IP address :


TODO : Installing an Active Directory (currently it's just the Samba service) - Introduction : AD integration on Ubuntu Server.


🔥 My Firewall ICMPv6 - IPv6 Netfilter GNU/Linux : https://howto.zw3b.fr/linux/securite/comment-faire-un-reseau-ipv6-firewall-icmpv6 (Translate Page).
🔑 How to configure strongSwan v6 Post-Quantum Cryptography NIST compliant #2731 : https://github.com/strongswan/strongswan/discussions/2731
🌐 Create your network map with GestióIP IPv4/IPv6 subnet calculator : http://www.gestioip.net/cgi-bin/subnet_calculator.cgi
🖧 The IPv6 ULA (Unique Local Address) network configuration from my home to the servers ; shown in the image : https://howto.zw3b.fr/pub/vpn/strongSwan-v6.0/network_map-ipv10.jpg

❗NETDOC.net : Iptables Tutorial 1.2.2, Maquettage et autohébergement : le VPN IPSec BEET avec strongSwan

Read the INFOS.txt file in my StrongSwan 6.0.1 Configuration files n°7 ; there is some nice information - I like my "traceroute" tests from home (gate-fr / command-traceroute6.txt). It's tempting.


ZW3B.FR IP❤10.WS