This video demonstrates how to configure IPv6 access for self-hosted services using NginX Proxy Manager on a UniFi router. The process involves enabling IPv6 on the WAN interface with DHCPv6 and appropriate prefix delegation, configuring the LAN interface with SLAAC address assignment, setting up dynamic DNS for IPv4, and creating firewall rules to allow IPv6 traffic directly to the NginX Proxy Manager instance. IPv6 provides a massive address space (16 quintillion addresses per user) compared to IPv4's single WAN address, and while IPv4 users connect through the router's port forwards, IPv6 users connect directly to the proxy manager's IPv6 address, allowing backend services to remain on IPv4 private networks.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Ipv6 & NginX Proxy Manager
Added:Yeah, [music] docker unifi power up the home lab.
Welcome back to the Scottabyte channel and this is Scott. So, I have to tell you over the last three or four days I've been toddling between 6,999 subscribers to 7,000 subscribers. I keep losing two or three and gaining a few more back. So, the thing is 2026 is the year where tech channels really have not done very well. As a matter of fact, mine uh my growth of my channel has absolutely frozen and I've been looking at other tech channels and discovered the same thing. I think in part that this is due to the cost of computers, memory, and storage in 2026.
And I think the other thing is that people don't have time to learn anymore.
With that in mind, hopefully there's a few of you left out there that are still watching my videos. And I thought that I would review something that I have not discussed in a long time. And that is EngineX Proxy Manager and IPv6 on UniFi. And actually, the two of them are going to go together pretty closely as you're going to see in just a minute.
So the real question is why use IP version 6 at all? And part of the reason is because globally we're running out of IPv4 addresses. And I know you've heard that many, many times. In Western Europe and in other parts of the world, IPv6 is pretty much the standard and ISPs are no longer granting people IPv4 when addresses.
And then our cell phones that we use largely use IPv6.
So there's limited public address space.
There's more complexity in using that. I know it doesn't really seem that way, but really it is. And you're going to see that here shortly. And some ISPs and mobile networks prefer IPv6.
And they're getting to the point where IPv4 is going to become a thing of the past. And I know they've talked about that for 20 years now. And there's harder long-term growth for IPv4 when you look at all the opportunities and even that has its shortcomings. And one of the things I can think of right off hand is your ISP gives you one wide area network address for your router.
Whereas with IPv6, your ISP grants you somewhere on the order of 16 quadrillion, quintillion, whatever that number is. It's so big I can't even remember it. And that's the number of addresses that each and every individual user gets. So, the thing about it is when it comes right down to it, ISPs want you to use IPv6 and IPv6 is really great. It's got a massive address space. It's got much better end user reachability and it's got native support in Windows, MacOss, and Linux as well as iOS and Android. So, basically, we have internet clients out there on the wide area network that may be gaining access to your self-hosted services. They do so over IPv4 and they can also do so over IPv6.
In my particular case, I'm going over a UDM Protype device, my UDM Beast. And so it accepts IPv4 and IPv6 if you have it configured. And that's one of the things we're going to learn about today. And then I engineext proxy manager is basically a publicfacing reverse proxy and it can listen for IPv4 and IPv6 traffic. And then I set up my back-end connections via EngineX Proxy Manager so that all of my internal services are actually operating on IPv4 private address space and yet people can connect to my services externally with IPv6.
So you can have a dual stack configuration. That means that you're running IPv4 and IPv6, but you can have your services inside of your network being accessed via IPv4 only if you prefer to do that. Enabling IPv6 is different on any router equipment that you have. And so for the purposes of this video, I'm going to address how it's done in UniFi. So the first step is you want to enable IPv6 on your internet WAN interface. And so that amounts to going to your internet connection on the router itself. And then inside of it, you can click on the WAN interface, your primary WAN interface. And when it comes up, you want to go ahead and set it to DHCP V6.
And then you can pretty much leave everything else the same with the exception of what is called the prefix delegation size. In my particular case, I'm using Comcast Xfinity and they specifically say that their prefix delegation size is 56 bits, whereas on others it may be the full 64 bits. Refer to your ISP's documentation to discern to determine what your prefix delegation size is. And I'm leaving mine at auto DNS server. And the reason for that is because I don't want to run my own IPv6 DNS inside of my network. Once you have IPv6 enabled on your WAN interface, the second step is to go to your primary LAN network and you're going to go to settings and networks. Open your primary LAN and in the IPv6 section, you want to choose prefix delegation for the interface type. You're going to set the prefix delegation interface to your primary because that's where your connections coming from on the WAN. And you can leave your delegation ID on auto. And you're going to choose the client address assignment type of slack which is the stateless address auto configuration and that's what we want.
And then you can disable autoDNS server. So the reason I disable autoDNS server is I've done several videos where I have described my use of Pi Hole. So your local DNS would be your Pi Hole DNS addresses. And so therefore you would add the IPv6 addresses of your Pi holes. In my particular case, I have three Pi holes in there. And so I have given the three addresses that you see here. If you have only one Pi hole, you're going to go ahead and enter its address in this location.
So the gateway can receive the ISP DNS on the WAN while the LAN clients use your Pi Hole DNS over IPv6.
The next step is with your dynamic DNS because most of you probably have a WAN address that changes that is your IPv4 WAN address. So you've probably already done this. I use Cloudflare as my DNS provider and I went out there and created a Cloudflare API token and in that token I gave it the privileges or the permission for read and also for edit. You're going to go ahead and copy that token because it's only going to give it to you one particular point in time. And then secondly, you're going to head over to your UniFi device and you're going to set up the dynamic DNS.
And I'm specifying Cloudflare since that's where my connection is coming from. My host name is the name of my domain, scottabyte.com.
And my zone name I named over there also, scottabyte.com.
And then I pasted in the API token and clicked save. So I put a little note here in the upper right hand corner that says that the IPv4 when a record is updated through Cloudflare's API by Unifi Dynamic DNS. And that's what we've just completed. And that is updating that address for your domain to be the address of the WAN interface on your Ubiquiti router. Notice at the top of the screen here, it says that IPv6 does not useNAT.
And so that's where this green block here becomes pretty significant. It basically says that IPv6 quad A records are not dynamically updated by UniFi. And there's a very good reason for this and that is because rather than being a descriptor for say the WAN interface, it's actually the EngineX proxy manager container itself.
And so that's just a host inside of your UniFi network. So there's no way that the UniFi router has to update that address. A workaround for that might be that if you were to run a DNS client that uses a Cloudflare token like we did above here, it might be able to assign that quad Accordingly.
Most people are assigned a dynamic DNS address for their WAN interface by your internet service provider. And normally that address does not change unless you reboot your cable modem or you reboot your fiber modem or whatever it is that you happen to have that provides connectivity to your internet service provider.
And in addition to that IPv4 when address changing realize that the IPv6 allocation block address can change as well. And so that's why I bring up this issue. In practice, there have been far fewer times when I've seen my IPv6 allocation block address range actually change. So now assuming that all this is set up correctly, your IPv4 users come into your network, they go to your router, they go out to your engine xroxy manager in virtue of an uh port forward and then that goes ahead and heads off to your backend host where you have applications hosted. The IPv6 users from the internet take a similar path. The only real difference is that rather than pointing to the WAN address of your UniFi router, they are pointing to a quad A record, which is the IPv6 address of your EngineX proxy manager instance inside of your network. And so that will point to um EngineX proxy manager just the same because it's just enginex proxy managers um IPv6 address and therefore from then it goes down to the back end which is hosting everything via IPv4.
So obviously to make all of this work, we have to find out what the IPv6 address is on the EngineX proxy manager host. So in order to do that, you can do an if config command and look for device ETH0 or whatever your physical Ethernet adapter is if you're not running inside of a container or a VM. And in my case, it's ETH0.
If you look down this listing, you'll notice that there is the IPv4 address for my EngineX proxy manager, which is 172.16.1.215.
As it turns out, I actually have multiple instances of EngineX Proxy Manager for redundancy, but that's beyond the scope of this particular presentation.
Next, you'll see an I an IPv6 address that will always begin with FE80.
So, FE80 is referred to as a link local address. It exists for all IPv6 host and it will even show up if you do not have IPv6 configured on your network. It's just so that IPv6 on the same LAN can do peer-to-peer communication.
So, what you're really looking for is you're looking for an IPv6 address.
You'll probably have one. I have two.
And it'll be a longer address. And it will look something like this. Uh the shorter address that I have here, you may also have in my particular case this apparently shorter address. And it really isn't shorter. It's just that colon colon means that there happen to be some uh address components here that are all zeros and colon colon is just a shorthand nomenclature in IPv6.
So in my case this second address is actually pointing to a virtual address that points to my two engine x proxy manager instances. But as I said, generally you're going to be looking for the particular address of your one instance. In my case, that ends with 921c.
So you're going to open a shell on your npm host. You run if config. You're going to find that network interface ETH0 as an example. And that's where you're going to find that particular address.
Back on Cloudflare, I have an A record for scottabyte.com which points to the current WAN address on my UDM beast and that address is set for DNS only which means it is not proxied. And then I also have a quad A record on cloudflare that is set to scottabyte.com and it is an IPv6 address but that IPv6 address is the IPv6 address of the engine X proxy manager host and then it is also set to DNS only because you're likely already a self-hoster. You have IPv4 port forwards in UniFi which accept inbound connections to port 443 and port 80 from your UniFi router down to the address of your engine X proxy manager. So we have port forwards that are set in the case of IPv4.
In the case of IPv6, this is a little bit different. So as I had mentioned earlier, IPv6 provides what we call an IPv6 global address. And the reason it's referred to as an IPv6 global address is because anything granted an IPv6 global address has an address out on the internet. And that might make people nervous because you're thinking, "Wow, I don't want people to have access to everything inside my network." Well, realize that your firewall prevents inbound access. So in order to have inbound access to our EngineX proxy manager for IPv6, we do not have network address translation as we do in IPv4.
Instead, we have the ability to open a firewall rule that specifically points directly to our EngineX proxy manager.
So, you're going to go into the UniFi firewall, the zonebased firewall. Now, if you're running the latest version of Ubiquiti software, you're going to create an allow rule. You're going to set the source as external and you're going to set the source as any IPv6 and the destination will be the internal network and then the destination will be the IPv6 global address and that is the address that we found by looking at device ETH0 inside of the engine X proxy manager instance. You're going to set the destination port to 80 and 443 and we're going to set the IP version to IPv6.
And then you can set the log to enabled or disabled. So what that does is that opens your firewall for people trying to access that quad A record for your domain and it will allow them to go directly to that EngineX proxy manager instance via IPv6.
So now that all this is in place, the IPv4 path has not changed. We have an IPv4 user out on the internet. They are going out to Cloudflare DNS to resolve the A record in my case for scottabyte.com.
That gives them an IP address which is the current IP address of the WAN interface on my UniFi router. And that will go ahead and port forward ports 80 and 443 to the address inside of my network that represents my engine xroxy manager. And then my backend host are whatever that they need to be out here.
For example, discussion.scottabyte.com, chat.scottabyte.com, scottabite.com which is my rocket chat server which you should be going to to ask for questions and then for example just plain old scottabyte.com which is my website and others in the case of IPv6 the IPv6 user is going to cloudflare and translating the quad A record that quad A record is an IPv6 address. That IPv6 address represents the address of my EngineX proxy manager host and not my gateway router. And then there is a UniFi firewall which allows access through that address and that address represents the EngineX proxy manager host and it will only allow access for ports 80443.
EngineX proxy manager then uses the reverse proxy request to go to the same services on the back end of the network. And it's notable to point out that I didn't have to change any of my backend services to allow for IPv6 because that's all being handled here on the front end.
So how do we determine that all of this is working? Well, you can use a utility called the domain information groper or dig for short. And if you're using uh iuntu or a debian derived operating system, you can do a pseudoapp install DNS util and as a part of that the dig command will come along. So if I do a dig space at sign 1.1.1.1 which is cloudflare and I say a and say scottabyte.com and I do a plus short it will come back and tell me uh what the address for scottabyte.com is or basically it'll say what does cloudflare think the address for scottabyte.com is. And likewise, we also have a dig command for the quad a record for scottabyte.com.
That will tell you what the address is in both cases and if it is translating.
Secondly, you can test your website reachability.
So you could do something like if you have a website or something you're trying to reach, I don't know your Bit Warden or whatever you want to reach uh that's on the other end of your EngineX proxy manager, you can do a curl-4- capital I and then https colon slash whatever it is. I just have scottabyte.com here because that's my website and it will respond appropriately and is also defined inside of my EngineX proxy manager. And so that should go ahead and respond and tell you it has connectivity. We can do the same curl command with a -6 and it will tell you if that has connectivity as well.
Basically, we're looking for a 200 response which says, "Yay, verily, it has connected."
So, this is testing it probably within your network, but you can go ahead and grab your cell phone and load up some kind of a terminal program, Termix or something, and you can go ahead and issue the same commands from it when your Wi-Fi is off, and you'll be going through the cellular network. And that's how you can determine these things work from outside your network. Either that or call a friend.
And then you can determine whether or not npm is listening simply by doing a u this pseudo uh SS command that I've got here. And what you're looking for is of course your engineext proxy manager is listening on port 80 and 443 for IPv4 and the 0.0.0.0.
zero simply means it accepts connections from anything. And then if the IPv6 is configured, you should have something that looks like these last two entries here. Have you ever heard the saying in teaching where it says tell them what you're going to tell them? Tell them and then tell them what you told them. So that's what I'm doing here. So the IPv4 verification path is basically the client translates an A record that goes to the WAN port of the UniFi router or whatever router and then it goes directly to EngineX proxy manager in virtue of the port forward. In the case of IPv6, you have an IPv6 client. It translates the quad A address. The quad A address is the address of the EngineX proxy manager. And in virtue of that firewall rule that we added, it's able to get there via port 80 or 443 and contact EngineX proxy manager. And it really doesn't matter that the backend services are IPv4 because EngineX proxy manager is accepting IPv6 traffic. I really believe that providing IPv6 access to your self-hosted services in your home lab is an important addition. That being said, realize that Ubiquiti still hasn't worked out the issue of how to handle a changing IPv6 address prefix for its firewall rules.
So until they determine how to do that, you're just going to have to watch for cases where your IPv6 pre-allocation address range changes so that you can go down and make the appropriate changes on your system. Anyway, that's it for today. Please subscribe and like to the channel and don't forget to hit your notification bell and we'll see you next time.
>> [music]
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23