<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Rin&apos;s Blog</title><description>A personal journal of everyday discoveries, things learned, and moments worth keeping. A little space to think, slowly.</description><link>https://iqwq.com/</link><language>en</language><item><title>Using NDP Responder to Get IPv6 Subnet Devices Online on a Dedicated Server</title><link>https://iqwq.com/en/posts/blog/ndp-responder-for-ipv6-subnet/</link><guid isPermaLink="true">https://iqwq.com/en/posts/blog/ndp-responder-for-ipv6-subnet/</guid><description>Preface When running independent servers (such as Hetzner, OVH), we often run into a pain point: the data center only gives you a /64 or /56 IPv6 block, but th…</description><pubDate>Sat, 26 Sep 2026 08:00:00 GMT</pubDate><content:encoded>&lt;h3&gt;Preface&lt;/h3&gt;
&lt;p&gt;When running independent servers (such as Hetzner, OVH), we often run into a pain point: the data center only gives you a &lt;code&gt;/64&lt;/code&gt; or &lt;code&gt;/56&lt;/code&gt; IPv6 block, but the gateway strictly binds to a physical MAC address. If you want to spin up sub-machines (LXC/KVM) inside the host machine, the IPv6 packets sent from the sub-machines&apos; virtual MAC will be dropped directly by the gateway.&lt;/p&gt;
&lt;p&gt;Today, through &lt;strong&gt;NDP Responder (NDP Proxy)&lt;/strong&gt; technology, we&apos;ll manually implement an industrial-grade solution that lets subnet devices &quot;disguise&quot; themselves for internet access.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;I. Core Principle: Why Do We Need an NDP Proxy?&lt;/h3&gt;
&lt;p&gt;In IPv4, we&apos;re used to using NAT. But in the world of IPv6, we advocate for end-to-end communication.
Normally, when an external gateway looks for a certain IPv6 address, it sends a &lt;strong&gt;Neighbor Solicitation&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Problem:&lt;/strong&gt; The virtual machines inside the host machine aren&apos;t directly connected to the data center switch, so they can&apos;t receive this request; even if they did receive it, their reply (containing the virtual MAC) would be intercepted by the data center switch&apos;s firewall.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Solution:&lt;/strong&gt; We run a proxy program on the host machine. It listens on the physical network card, and when it discovers someone asking about a virtual machine&apos;s IP, it preemptively answers: &quot;This IP is with me, please send the packet to my physical MAC.&quot; After the host machine receives the packet, it forwards it to the virtual machine according to the internal routing table.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h3&gt;II. Environment Preparation&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Host Machine:&lt;/strong&gt; Debian/Ubuntu (this example uses a Proxmox environment)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tool:&lt;/strong&gt; &lt;code&gt;ndpresponder&lt;/code&gt; (a lightweight tool written in Go, which fits your learning direction perfectly)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Network Topology:&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Physical network card: &lt;code&gt;ens3&lt;/code&gt; (connected to the external network)&lt;/li&gt;
&lt;li&gt;Virtual bridge: &lt;code&gt;vmbr1&lt;/code&gt; (connected to internal containers)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h3&gt;III. Detailed Steps&lt;/h3&gt;
&lt;h4&gt;1. Enable Kernel Forwarding&lt;/h4&gt;
&lt;p&gt;First, the Linux kernel must be allowed to let IPv6 packets &quot;travel&quot; between different network cards.
Modify &lt;code&gt;/etc/sysctl.conf&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# Enable IPv6 forwarding on all interfaces
net.ipv6.conf.all.forwarding=1
# Allow receiving router advertisements
net.ipv6.conf.ens3.accept_ra=2
# Enable NDP proxy support
net.ipv6.conf.all.proxy_ndp=1

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Run &lt;code&gt;sysctl -p&lt;/code&gt; to apply.&lt;/p&gt;
&lt;h4&gt;2. Configure Network Interfaces (&lt;code&gt;/etc/network/interfaces&lt;/code&gt;)&lt;/h4&gt;
&lt;p&gt;We need to define two &quot;pools,&quot; one external and one internal.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# External main bridge
auto vmbr0
iface vmbr0 inet6 static
    address 2a01:4f8:xxx:113a/80  # Your main IP
    gateway fe80::1               # Data center gateway

# Internal subnet bridge (for virtual machines)
auto vmbr1
iface vmbr1 inet6 static
    address 2a01:4f8:xxx:10e0::1/96
    bridge-ports none
    bridge-stp off

&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;3. Deploy NDP Responder&lt;/h4&gt;
&lt;p&gt;We&apos;ll run the program in a Systemd daemon.
Create the file &lt;code&gt;/etc/systemd/system/ndpresponder.service&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;[Unit]
Description=NDP Responder for LXC Subnet
After=network.target

[Service]
# -i: the external interface to listen on
# -n: the internal subnet to proxy
ExecStart=/usr/sbin/ndpresponder -i vmbr0 -n 2a01:4f8:xxx:10e0::/96
Restart=always

[Install]
WantedBy=multi-user.target

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Start the service: &lt;code&gt;systemctl enable --now ndpresponder&lt;/code&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;IV. Verification and Debugging&lt;/h3&gt;
&lt;p&gt;As developers, we must learn to read logs. Observe &lt;code&gt;journalctl -u ndpresponder -f&lt;/code&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Found Gateway:&lt;/strong&gt; Found the data center gateway...
&lt;strong&gt;RESPOND:&lt;/strong&gt; who-has &lt;code&gt;...:10e0:1010:3&lt;/code&gt; tell &lt;code&gt;fe80::...&lt;/code&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When you see the word &lt;code&gt;RESPOND&lt;/code&gt;, it means the host machine has successfully &quot;impersonated&quot; the virtual machine and completed the neighbor discovery handshake.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;V. Architectural Reflection (Student Perspective)&lt;/h3&gt;
&lt;p&gt;From the perspective of &lt;strong&gt;Go language development&lt;/strong&gt;, what inspiration does this technology bring us?&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Decoupling:&lt;/strong&gt; NDP Proxy essentially acts as a transparent adapter between the link layer (L2) and the network layer (L3).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Concurrency Model:&lt;/strong&gt; Tools like &lt;code&gt;ndpresponder&lt;/code&gt; typically use Go&apos;s &lt;code&gt;pcap&lt;/code&gt; library or raw sockets to listen to traffic. This requires extremely high processing efficiency and is an excellent case for learning how Go handles high-performance network streams.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Industrial Standards:&lt;/strong&gt; This configuration pattern (Map First, Code Follows) conforms to the IEP collaboration protocol we discussed earlier—first plan the network topology (Map), then proceed with service deployment (Code).&lt;/li&gt;
&lt;/ol&gt;
&lt;hr /&gt;
&lt;h3&gt;Conclusion&lt;/h3&gt;
&lt;p&gt;IPv6 is no longer a mysterious black box. By understanding the NDP protocol and manually configuring the proxy, we have not only solved the data center internet access problem, but also gained a deeper understanding of the routing essence of the modern internet.&lt;/p&gt;
</content:encoded></item><item><title>Pixiv Illustration 01</title><link>https://iqwq.com/en/posts/pixiv-illustration-01/</link><guid isPermaLink="true">https://iqwq.com/en/posts/pixiv-illustration-01/</guid><description>Pixiv illustration.</description><pubDate>Fri, 25 Sep 2026 08:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Pixiv illustration.&lt;/p&gt;
</content:encoded></item><item><title>Pixiv Illustration 02</title><link>https://iqwq.com/en/posts/pixiv-illustration-02/</link><guid isPermaLink="true">https://iqwq.com/en/posts/pixiv-illustration-02/</guid><description>Pixiv illustration.</description><pubDate>Fri, 25 Sep 2026 08:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Pixiv illustration.&lt;/p&gt;
</content:encoded></item><item><title>Pixiv Illustration 03</title><link>https://iqwq.com/en/posts/pixiv-illustration-03/</link><guid isPermaLink="true">https://iqwq.com/en/posts/pixiv-illustration-03/</guid><description>Pixiv illustration.</description><pubDate>Fri, 25 Sep 2026 08:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Pixiv illustration.&lt;/p&gt;
</content:encoded></item><item><title>Pixiv Illustration 04</title><link>https://iqwq.com/en/posts/pixiv-illustration-04/</link><guid isPermaLink="true">https://iqwq.com/en/posts/pixiv-illustration-04/</guid><description>Pixiv illustration.</description><pubDate>Fri, 25 Sep 2026 08:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Pixiv illustration.&lt;/p&gt;
</content:encoded></item></channel></rss>