Am 16. April 2017 10:54:51 MESZ schrieb Harald Dunkel <[email protected]>: >Hash: SHA256 > >Hi Florian, > >sorry to say, but you missed the point. The IP address of >*another* host inside my LAN changes, e.g. a mail server, >a http proxy, etc. The interface identifier of each host is >surely stable. The prefix is not. Using the old prefix in >pf.conf these hosts are affected as soon as it expires. > > >Regards >Harri
Aw, crap, right IPv6. Then: Link local addresses. There may be a way for `($IFACE_ext:network) & $IP_mailserver:host` but until someone smarter and more attentive figures this out there are link local addresses. Unless you get a /(>64) from your ISP and hand out a bunch of /64s to your subnets internally in what you call your LAN for simplicity's sake. Regards, Florian

