<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://docs.opennet-initiative.de/index.php?action=history&amp;feed=atom&amp;title=Benutzer%3ALeo%2Ftayga</id>
	<title>Benutzer:Leo/tayga - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://docs.opennet-initiative.de/index.php?action=history&amp;feed=atom&amp;title=Benutzer%3ALeo%2Ftayga"/>
	<link rel="alternate" type="text/html" href="https://docs.opennet-initiative.de/index.php?title=Benutzer:Leo/tayga&amp;action=history"/>
	<updated>2026-10-07T08:57:10Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Opennet</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://docs.opennet-initiative.de/index.php?title=Benutzer:Leo/tayga&amp;diff=36328&amp;oldid=prev</id>
		<title>Leo: Die Seite wurde neu angelegt: „==Beispiel für NAT64 tayga Installation auf Server gai==  root@gai:~/tayga# cat README.md   &lt;nowiki&gt; see /etc/tayga.conf  Before starting the TAYGA daemon, th…“</title>
		<link rel="alternate" type="text/html" href="https://docs.opennet-initiative.de/index.php?title=Benutzer:Leo/tayga&amp;diff=36328&amp;oldid=prev"/>
		<updated>2020-11-01T20:53:45Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „==Beispiel für NAT64 tayga Installation auf Server gai==  root@gai:~/tayga# cat README.md   &amp;lt;nowiki&amp;gt; see /etc/tayga.conf  Before starting the TAYGA daemon, th…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Beispiel für NAT64 tayga Installation auf Server gai==&lt;br /&gt;
&lt;br /&gt;
root@gai:~/tayga# cat README.md &lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
see /etc/tayga.conf&lt;br /&gt;
&lt;br /&gt;
Before starting the TAYGA daemon, the routing setup on your system will need&lt;br /&gt;
to be changed to send IPv4 and IPv6 packets to TAYGA.  First create the TUN&lt;br /&gt;
network interface:&lt;br /&gt;
&lt;br /&gt;
  # tayga --mktun&lt;br /&gt;
&lt;br /&gt;
If TAYGA prints any errors, you will need to fix your config file before&lt;br /&gt;
continuing.  Otherwise, the new nat64 interface can be configured and the&lt;br /&gt;
proper routes can be added to your system:&lt;br /&gt;
&lt;br /&gt;
   ip link set nat64 up&lt;br /&gt;
   ip addr add 2a0a:4580:1010:2002::1 dev nat64  # replace with your router&amp;#039;s address&lt;br /&gt;
   ip addr add 10.253.0.1 dev nat64    # replace with your router&amp;#039;s address&lt;br /&gt;
   ip route add 2a0a:4580:1010:2002::/96 dev nat64  # from tayga.conf&lt;br /&gt;
   ip route add 10.253.0.0/24 dev nat64      # from tayga.conf&lt;br /&gt;
&lt;br /&gt;
Firewalling your NAT64 prefix from outside access is highly recommended:&lt;br /&gt;
&lt;br /&gt;
  # ip6tables -A FORWARD -s 2001:db8:1::/48 -d 2001:db8:1:ffff::/96 -j ACCEPT&lt;br /&gt;
  # ip6tables -A FORWARD -d 2001:db8:1:ffff::/96 -j DROP&lt;br /&gt;
&lt;br /&gt;
At this point, you may start the tayga process:&lt;br /&gt;
&lt;br /&gt;
  # tayga&lt;br /&gt;
&lt;br /&gt;
Check your system log (/var/log/syslog or /var/log/messages) for status&lt;br /&gt;
information.&lt;br /&gt;
&lt;br /&gt;
If you are having difficulty configuring TAYGA, use the -d option to run the&lt;br /&gt;
tayga process in the foreground and send all log messages to stdout:&lt;br /&gt;
&lt;br /&gt;
  # tayga -d&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
cat 330_ugw-nat64-native-on-gai.inc &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
#todo: test whether the br-.... interface name change in the meantime&lt;br /&gt;
&lt;br /&gt;
@def $IF_ONI_NAT64 = nat64;&lt;br /&gt;
@def $IF_WAN = eth0;&lt;br /&gt;
@def $IF_BABEL_MESH = babel-vpn;&lt;br /&gt;
&lt;br /&gt;
domain (ip ip6) table filter {&lt;br /&gt;
	chain service-input {&lt;br /&gt;
		# erlaube input weil NAT64 Adressbereich geroutet wird&lt;br /&gt;
		interface $IF_ONI_NAT64 ACCEPT;&lt;br /&gt;
	}&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
domain (ip ip6) chain FORWARD outerface $IF_WAN {&lt;br /&gt;
	# erlaube Internet Traffic&lt;br /&gt;
	interface $IF_ONI_NAT64 ACCEPT;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
domain (ip6) chain FORWARD interface $IF_ONI_NAT64 {&lt;br /&gt;
	# erlaube NAT64 Traffic, welcher ueber docker host geroutet wird. Deshalb in und out gleiches Interface.&lt;br /&gt;
	outerface $IF_ONI_NAT64 ACCEPT;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
#dns64&lt;br /&gt;
#TODO: auf Ziel IP + Port beschraenken&lt;br /&gt;
domain ip6 chain FORWARD interface $IF_BABEL_MESH {&lt;br /&gt;
	# erlaube mesh Zugriff auf DNS64&lt;br /&gt;
	outerface $IF_ONI_NAT64 ACCEPT;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
domain ip table nat {&lt;br /&gt;
        chain POSTROUTING {&lt;br /&gt;
		outerface $IF_WAN saddr (10.254.0.0/16) MASQUERADE;&lt;br /&gt;
	}&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;/div&gt;</summary>
		<author><name>Leo</name></author>
	</entry>
</feed>