<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>The Wombelix Post - Network</title><link href="https://dominik.wombacher.cc/" rel="alternate"/><link href="/feeds/tag_network.atom.xml" rel="self"/><id>https://dominik.wombacher.cc/</id><updated>2022-01-15T00:00:00+01:00</updated><entry><title>Hurricane Electric IPv6 Certification - Sage level reached</title><link href="https://dominik.wombacher.cc/posts/hurricane_electric_ipv6_certification_sage_level_reached.html" rel="alternate"/><published>2022-01-15T00:00:00+01:00</published><updated>2022-01-15T00:00:00+01:00</updated><author><name>Dominik Wombacher</name></author><id>tag:dominik.wombacher.cc,2022-01-15:/posts/hurricane_electric_ipv6_certification_sage_level_reached.html</id><summary type="html">&lt;!-- SPDX-FileCopyrightText: 2023 Dominik Wombacher &lt;dominik@wombacher.cc&gt; --&gt;
&lt;!--  --&gt;
&lt;!-- SPDX-License-Identifier: CC-BY-SA-4.0 --&gt;
&lt;p&gt;IPv6 connectivity is quite important for me, fortunately IPv6 is a first class citizen for my ISP
(Deutsche Glasfaser) and was also available with my previous one (1&amp;amp;1).
So  ... &lt;a class="read-more" href="/posts/hurricane_electric_ipv6_certification_sage_level_reached.html"&gt; [read more]&lt;/a&gt;&lt;/p&gt;</summary><content type="html">&lt;!-- SPDX-FileCopyrightText: 2023 Dominik Wombacher &lt;dominik@wombacher.cc&gt; --&gt;
&lt;!--  --&gt;
&lt;!-- SPDX-License-Identifier: CC-BY-SA-4.0 --&gt;
&lt;p&gt;IPv6 connectivity is quite important for me, fortunately IPv6 is a first class citizen for my ISP
(Deutsche Glasfaser) and was also available with my previous one (1&amp;amp;1).
So I didn't have to use a Tunnel Broker at home yet to get IPv6 up and running but if I had to,
I would go with Hurricane Eletric and their (free) &lt;a class="reference external" href="https://www.tunnelbroker.net"&gt;Tunnelbroker&lt;/a&gt; Service.&lt;/p&gt;
&lt;p&gt;HE also offer a &lt;a class="reference external" href="https://ipv6.he.net/certification/"&gt;IPv6 Certification&lt;/a&gt;, to test your theoretical
as well as practical knowledge and verify that you are actually using IPv6 at home, your website, mail server and DNS.&lt;/p&gt;
&lt;p&gt;There are seven Certification Level:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;NewB: Read the primer, be able to answer some quick and easy questions.&lt;/li&gt;
&lt;li&gt;Explorer: Verify that you can access an IPv6 website (ours!)&lt;/li&gt;
&lt;li&gt;Enthusiast: Verify that you have an IPv6 capable web server that we can connect to and fetch information from. This should be entered as a FQDN and not an IPv6 address.&lt;/li&gt;
&lt;li&gt;Administrator: Verify that you have a working IPv6 capable MTA by sending you an email only over IPv6.&lt;/li&gt;
&lt;li&gt;Professional: Verify that your MTA has working reverse DNS (ex: dig mx $domain +short ; dig aaaa $mx +short ; dig -x $mxAAAA +short)&lt;/li&gt;
&lt;li&gt;Guru: Verify that the authoritative NS for your domain have AAAA records, and respond to queries for the domain (ex: step 1 is dig ns $domain ; dig aaaa $ns | step 2 is dig aaaa $domain &amp;#64;$nsAAAA)&lt;/li&gt;
&lt;li&gt;Sage: Check to see if your domain's authoritative NS have IPv6 glue with their listed TLD servers. Meaning the TLD server can directly answer for the host record (ex: dig +trace ns $domain to get the TLD server list then dig aaaa $ns &amp;#64;TLD for the glue).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Source: &lt;a class="reference external" href="https://forums.he.net/index.php?topic=304.0"&gt;https://forums.he.net/index.php?topic=304.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;They provide a lot of additional &lt;a class="reference external" href="https://ipv6.he.net/presentations.php"&gt;learning material&lt;/a&gt;
and have a still quite active &lt;a class="reference external" href="https://forums.he.net/index.php?board=11.0"&gt;community&lt;/a&gt; as well.&lt;/p&gt;
&lt;p&gt;Sages also get a &lt;a class="reference external" href="https://forums.he.net/index.php?topic=922.0"&gt;Free IPv6 T-Shirt&lt;/a&gt; upon request,
last batch run was &lt;em&gt;Fri Dec 10 2021&lt;/em&gt;, so let's see when mine will arrive :)&lt;/p&gt;
&lt;p&gt;Hint: Getting Sage Rank is a mandatory requirement to request HE to remove SMTP and IRC Port Filtering
when using their IPv6 Tunnel, to avoid abuse those are blocked by default, see &lt;a class="reference external" href="https://ipv6.he.net/certification/faq.php"&gt;FAQ&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;It Was fun to work through the different level, test my knowledge and validate my IPv6 Setup.
Due to the fact that all my Server already using IPv6, whenever possible IPv6-only, a few in Dual-Stack Mode,
I was able to reach the Sage Level quite fast, no re-configuration of my Services was required to pass all checks.&lt;/p&gt;
&lt;p&gt;Exception was enabling TLS v1.2 on my website, limit to v1.3 only was to strict for he.net
to reach my Server and validate my Domain. Also disabling greylisting for sender &lt;a class="reference external" href="mailto:ipv6&amp;#64;he.net"&gt;ipv6&amp;#64;he.net&lt;/a&gt;
was helpful to speed things up during verification of my mail setup.&lt;/p&gt;
&lt;img src="https://ipv6.he.net/certification/create_badge.php?pass_name=wombelix&amp;amp;badge=3" style="border: 0; width: 229px; height: 137px" alt="IPv6 Certification Badge for wombelix"&gt;&lt;/img&gt;&lt;div class="section" id="certificate"&gt;
&lt;h2&gt;Certificate&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Download&lt;ul&gt;
&lt;li&gt;&lt;a class="reference external" href="/certificates/he.net_ipv6_certification_sage_level_dominik_wombacher.pdf"&gt;Certificate&lt;/a&gt; (PDF, 1.2M)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</content><category term="Certification"/><category term="IPv6"/><category term="Network"/><category term="Administration"/><category term="Certification"/></entry></feed>