NATted static IP and regularly changing IPv6 DP

fibrewhat

New Member
Joined
Oct 5, 2023
Messages
6
Reaction score
1
In short, is it actually literally impossible to have a stable IPv6 PD and a non-NAT static IP with Openserve?

There's a bit of a preamble for this. I have recently had tremendous trouble with Vumatel in my area, where the service would go down for hours, almost weekly. Frustrated with this, I started down the path of migrating to Openserve.

First I clarified with the Afrihost sales team, in advance of making an order, whether:
- I could have a publically addressable static IPv4, no CGNAT, nothing like that, just like I had before.
- Whether I could have both lines active at once for a changeover period, so as to have no downtime.
- Whether I would still have IPv6. (Which, btw, a huge shoutout here to Afrihost for being proactive with rolling out support for this. Thank you!)

All of which were confirmed by sales. Satisfied, I proceeded with the order. After some time and some back and forth because of an address miscommunication between Afrihost and Openserve, my new line is installed. It works great so far, and is more stable (though with slightly higher latency) than the Vumatel line before it. So I proceed down the path of making sure I have the features I was expecting.

And almost none of them were as promised.

Unlike with the previous Vumatel line, my IPv6 PD is not stable and changes seemingly every two days. Even worse, the IPv4 static address is now behind a NAT, making it almost entirely useless for my purposes. For example, all the incoming IP whitelisting I used to do is impossible because source addresses are now obscured behind the NAT. My router now doesn't know its actual external address at all, but is given one (seemingly at random) in 10.0.0.0/8. And the DP changing regularly makes practically using v6 for devices behind my router for anything extremely frustrating.

Dealing with Afrihost email support over this issue has been extremely painful. After much back and forth I have still not gotten anyone at support to acknowledge the existence of the NAT, only ever responding with repeated claims that I have a static IP address. I haven't even attempted to speak to them about the changing IPv6 prefix, because I'm still waiting for them to tell me whether it's expected that my static IP is still behind a NAT.

Is what I want not possible? All of this worked fine on Vumatel. And if not, why did sales not tell me this when I asked?
 
Last edited:
In short, is it actually literally impossible to have a stable IPv6 PD and a non-NAT static IP with Openserve?

There's a bit of a preamble for this. I have recently had tremendous trouble with Vumatel in my area, where the service would go down for hours, almost weekly. Frustrated with this, I started down the path of migrating to Openserve.

First I clarified with the Afrihost sales team, in advance of making an order, whether:
- I could have a publically addressable static IPv4, no CGNAT, nothing like that, just like I had before.
- Whether I could have both lines active at once for a changeover period, so as to have no downtime.
- Whether I would still have IPv6. (Which, btw, a huge shoutout here to Afrihost for being proactive with rolling out support for this. Thank you!)

All of which were confirmed by sales. Satisfied, I proceeded with the order. After some time and some back and forth because of an address miscommunication between Afrihost and Openserve, my new line is installed. It works great so far, and is more stable (though with slightly higher latency) than the Vumatel line before it. So I proceed down the path of making sure I have the features I was expecting.

And almost none of them were as promised.

Unlike with the previous Vumatel line, my IPv6 PD is not stable and changes seemingly every two days. Even worse, the IPv4 static address is now behind a NAT, making it almost entirely useless for my purposes. For example, all the incoming IP whitelisting I used to do is impossible because source addresses are now obscured behind the NAT. My router now doesn't know its actual external address at all, but is given one (seemingly at random) in 10.0.0.0/8. And the DP changing regularly makes practically using v6 for devices behind my router for anything extremely frustrating.

Dealing with Afrihost email support over this issue has been extremely painful. After much back and forth I have still not gotten anyone at support to acknowledge the existence of the NAT, only ever responding with repeated claims that I have a static IP address. I haven't even attempted to speak to them about the changing IPv6 prefix, because I'm still waiting for them to tell me whether it's expected that my static IP is still behind a NAT.

Is what I want not possible? All of this worked fine on Vumatel. And if not, why did sales not tell me this when I asked?

@Afrigirl
@AfriNatic
 
In short, is it actually literally impossible to have a stable IPv6 PD and a non-NAT static IP with Openserve?

There's a bit of a preamble for this. I have recently had tremendous trouble with Vumatel in my area, where the service would go down for hours, almost weekly. Frustrated with this, I started down the path of migrating to Openserve.

First I clarified with the Afrihost sales team, in advance of making an order, whether:
- I could have a publically addressable static IPv4, no CGNAT, nothing like that, just like I had before.
- Whether I could have both lines active at once for a changeover period, so as to have no downtime.
- Whether I would still have IPv6. (Which, btw, a huge shoutout here to Afrihost for being proactive with rolling out support for this. Thank you!)

All of which were confirmed by sales. Satisfied, I proceeded with the order. After some time and some back and forth because of an address miscommunication between Afrihost and Openserve, my new line is installed. It works great so far, and is more stable (though with slightly higher latency) than the Vumatel line before it. So I proceed down the path of making sure I have the features I was expecting.

And almost none of them were as promised.

Unlike with the previous Vumatel line, my IPv6 PD is not stable and changes seemingly every two days. Even worse, the IPv4 static address is now behind a NAT, making it almost entirely useless for my purposes. For example, all the incoming IP whitelisting I used to do is impossible because source addresses are now obscured behind the NAT. My router now doesn't know its actual external address at all, but is given one (seemingly at random) in 10.0.0.0/8. And the DP changing regularly makes practically using v6 for devices behind my router for anything extremely frustrating.

Dealing with Afrihost email support over this issue has been extremely painful. After much back and forth I have still not gotten anyone at support to acknowledge the existence of the NAT, only ever responding with repeated claims that I have a static IP address. I haven't even attempted to speak to them about the changing IPv6 prefix, because I'm still waiting for them to tell me whether it's expected that my static IP is still behind a NAT.

Is what I want not possible? All of this worked fine on Vumatel. And if not, why did sales not tell me this when I asked?
Hello.
I am sorry on your experience with the Sales Team, they should have confirmed with the Fibre Technical Team.

With Openserve we assigned a NAT static IP address.

The IP is static which means the public facing IP will never change. The natted IP address assigned on the WAN port will change and will be in the 10. range. Each time your router dials a pppoe connection this 10. IP will change but the public IP will be static. We forward all traffic from the 169. static public IP to whatever natted 10.
You won't get the static 169. IP on the wan port.
 
Hello.
I am sorry on your experience with the Sales Team, they should have confirmed with the Fibre Technical Team.

With Openserve we assigned a NAT static IP address.

The IP is static which means the public facing IP will never change. The natted IP address assigned on the WAN port will change and will be in the 10. range. Each time your router dials a pppoe connection this 10. IP will change but the public IP will be static. We forward all traffic from the 169. static public IP to whatever natted 10.
You won't get the static 169. IP on the wan port.
So no direct route inward to the client from the web?
 
In short, is it actually literally impossible to have a stable IPv6 PD and a non-NAT static IP with Openserve?

There's a bit of a preamble for this. I have recently had tremendous trouble with Vumatel in my area, where the service would go down for hours, almost weekly. Frustrated with this, I started down the path of migrating to Openserve.

First I clarified with the Afrihost sales team, in advance of making an order, whether:
- I could have a publically addressable static IPv4, no CGNAT, nothing like that, just like I had before.
- Whether I could have both lines active at once for a changeover period, so as to have no downtime.
- Whether I would still have IPv6. (Which, btw, a huge shoutout here to Afrihost for being proactive with rolling out support for this. Thank you!)

All of which were confirmed by sales. Satisfied, I proceeded with the order. After some time and some back and forth because of an address miscommunication between Afrihost and Openserve, my new line is installed. It works great so far, and is more stable (though with slightly higher latency) than the Vumatel line before it. So I proceed down the path of making sure I have the features I was expecting.

And almost none of them were as promised.

Unlike with the previous Vumatel line, my IPv6 PD is not stable and changes seemingly every two days. Even worse, the IPv4 static address is now behind a NAT, making it almost entirely useless for my purposes. For example, all the incoming IP whitelisting I used to do is impossible because source addresses are now obscured behind the NAT. My router now doesn't know its actual external address at all, but is given one (seemingly at random) in 10.0.0.0/8. And the DP changing regularly makes practically using v6 for devices behind my router for anything extremely frustrating.

Dealing with Afrihost email support over this issue has been extremely painful. After much back and forth I have still not gotten anyone at support to acknowledge the existence of the NAT, only ever responding with repeated claims that I have a static IP address. I haven't even attempted to speak to them about the changing IPv6 prefix, because I'm still waiting for them to tell me whether it's expected that my static IP is still behind a NAT.

Is what I want not possible? All of this worked fine on Vumatel. And if not, why did sales not tell me this when I asked?
Hi. You can try the following with the apps you are hosting, instead of binding the address to a static IP, put an asterisk so it can listen to any network.
 
So there's no way to have a static IPv4 without NAT? Without being able to see the incoming source IPs I have to expose my network to the entire internet, now being unable to ip whitelist incoming traffic for services I share with my friends and family. This makes the the static IP somewhat next to useless, and I'd actually be better off with a non-NATted dynamic IP instead and DDNS.

And what about the changing v6 prefix?
 
So there's no way to have a static IPv4 without NAT? Without being able to see the incoming source IPs I have to expose my network to the entire internet, now being unable to ip whitelist incoming traffic for services I share with my friends and family. This makes the the static IP somewhat next to useless, and I'd actually be better off with a non-NATted dynamic IP instead and DDNS.

And what about the changing v6 prefix?

I’m not understanding how your Static IP (outgoing) relates to traffic that is incoming?

Your friends and family would still have the very same Source IP’s. You being NAT’d on your outgoing connection will not change that in any way.

Your whitelist has no reason to change because of this configuration. The source IP’s are the source IP’s.
 
All incoming IPs appear to be my static IP. I cannot whitelist because the source IPs are rewritten. This is what SNAT does.
 
Okay, so after a weekend, Fibre Support still insists that there is no NAT. It seems like not having one is probably not possible, and, judging from the silence here, neither is a stable v6 prefix. The latter thing honestly is somewhat extraordinary, considering it rather defeats the purpose of offering v6 in the first place.

I have to say, I've been an Afrihost customer for more than 12 years at this point, and have always been happy with them, but dealing with fibre support in particular, in the past 2-3 years, has become extraordinarily frustrating. So frustrating that I felt the need for the first time to come here to seek help; it always seemed like (from the outside at least) the support reps here on MyBB are always better, judging by their responses in other contexts.

Afrihost Hosting support is and always has been excellent (they've resolved bugs in their clientzone and DNS editor for me within 8 hours!), and the lovely Sales team is friendly and helpful. But it truly seems like fibre support has become increasingly poor. It is very disappointing to have to roll the dice every time I contact them in the hopes that I actually get a helpful and informed response.
 
Okay, so after a weekend, Fibre Support still insists that there is no NAT. It seems like not having one is probably not possible, and, judging from the silence here, neither is a stable v6 prefix. The latter thing honestly is somewhat extraordinary, considering it rather defeats the purpose of offering v6 in the first place.

I have to say, I've been an Afrihost customer for more than 12 years at this point, and have always been happy with them, but dealing with fibre support in particular, in the past 2-3 years, has become extraordinarily frustrating. So frustrating that I felt the need for the first time to come here to seek help; it always seemed like (from the outside at least) the support reps here on MyBB are always better, judging by their responses in other contexts.

Afrihost Hosting support is and always has been excellent (they've resolved bugs in their clientzone and DNS editor for me within 8 hours!), and the lovely Sales team is friendly and helpful. But it truly seems like fibre support has become increasingly poor. It is very disappointing to have to roll the dice every time I contact them in the hopes that I actually get a helpful and informed response.
Please share your email address via PM, so we can have a look.
 
So just for posterity, and in case someone else comes across this thread with a similar problem to me, an update:

This issue could not be resolved. I reverted back to a dynamic (non NAT) IPv4 (at least it doesn't cost anything). Afrihost cannot give you a static IPv4 without NAT on Openserve. I will settle for dynamic DNS under one of my domains, which should be fine for my purposes anyway.

The IPv6 prefix also couldn't be made static, however @Afrigirl has assured me that this feature is on the roadmap and coming 'in the near future'. Hopefully this will come soon!
 
So just for posterity, and in case someone else comes across this thread with a similar problem to me, an update:

This issue could not be resolved. I reverted back to a dynamic (non NAT) IPv4 (at least it doesn't cost anything). Afrihost cannot give you a static IPv4 without NAT on Openserve. I will settle for dynamic DNS under one of my domains, which should be fine for my purposes anyway.

The IPv6 prefix also couldn't be made static, however @Afrigirl has assured me that this feature is on the roadmap and coming 'in the near future'. Hopefully this will come soon!

Hi

With the dynamic IP we have built-in DDNS that you can make use of. fiberusername.ip.afrihost.co.za which will point and update to your current IP. You can find your username in ClientZone and it's the name before @afrihost.co.za

If you have your own domain name hosted with us or anywhere else create a cname record and add fiberusername.ip.afrihost.co.za to the cname record to have a custom DDNS name. If you want to protect it even further you can use Clourflare and proxy it through Cloudflare.
 
With the dynamic IP we have built-in DDNS that you can make use of. fiberusername.ip.afrihost.co.za which will point and update to your current IP. You can find your username in ClientZone and it's the name before @afrihost.co.za
Thank you, that's good to know!
 
Top
Sign up to the MyBroadband newsletter
X