Disable IPv4 on Airtel XStream Zyxel Modem/Router

Messages
3
Location
Gurgaon
ISP
Airtel XStream
Hi,

First time poster here, looking for some advice.

I have Airtel XStream broadband in the NCR region. I have the ZyXEL PMG5617 router which has been crippled by Airtel in all sorts of ways.

I have 3 questions:
1. Is it possible to set my WAN as IPv6 only, WITH IPv6 DNS?

2. Is it possible for me to use only IPv6 in my LAN for my devices at home - phone, computers, TVs etc. while I continue to have a IPv4 WAN? So that I can use the IPv6 DNS settings from there?

3. When I try to set the "DNS Query Mode" in my IPv6 LAN settings to IPv6 first or IPv6 only - it keeps reverting back to IPv4 only. Is this a bug or are there other settings that are causing some kind of override here?

What I'm essentially trying to do is set a IPv6 DNS for my router so that all traffic goes to a particular DNS server. If there is another way to do for instance DoH or DNS over TSL that would solve my problem as well.



Thanks in advance! 🙂
 
Last edited:
the ipv6 addresses are given out by airtel, each of the ipv6 address you get is public facing, you can block ipv6 traffic from going to the internet using firewall rules (not sure if this is supported by the ZyXEL router) but I don't see any point in doing so.

the ipv4 addresses are NATed, this means that IP is given out by your router using a DHCP Server.

What I'm essentially trying to do is set a IPv6 DNS for my router so that all traffic goes to a particular DNS server. If there is another way to do for instance DoH or DNS over TSL that would solve my problem as well.

The thing is you don't need IPv6 DNS to resolve IPv6 domains, you can try it in Windows, run "nslookup ipv6.google.com 1.1.1.1"

1.1.1.1 despite being an IPv4 DNS Server returns the AAAA (IPv6) IP addresses.

If you want to force all the DNS traffic from your LAN through a particular server you'll need to port forward port 53 to the DNS Server. I do not think this is possible with Zyxel. What you can do is get a router like Archer C6 and run OpenWRT on it, it allows for complex rules so you can force all port 53 traffic through your own DNS Server/Forwarder (this can be PiHole, Unbound, AdGuard Home etc).
 
Thank you for your response. I don't think you understand my problem. I'll try to explain it in more detail.

Very simply I want to use a IPv6 DNS for my router so that I can connect to an ad blocking DNS server. The ad blocking server supports IPv4, DoH etc. as well. The problem with IPv4 is that my public IP address changes everytime the router restarts so I have to manually link it everytime that happens and that's a pain.

I want to do it at the router lever so that I don't have to manage it per device. Using DDNS is not feasible since No-IP etc. cannot get the router's public IP.

So the only feasible solution in my limited knowledge is somehow to force the Airtel router to only use IPv6 DNS. I don't want to invest in a new GPON modem/router to solve my problem.

Anybody with knowledge of Airtel XStream ZyXEL routers? Because the routers have been crippled by Airtel....
 
Talking about manual linking, each IPv6 Client trying to access your (ad-blocking) DNS service will all have a different public IPv6 on their headers and these are deemed to change frequently regardless of reboots as long as you're using Stateless DHCP. I am not sure how you will be able to work around that, even if you solve your initial requirement.
Second, there are quite limited services you will be able to access if you completely turn off IPV4, especially banking and government websites.
Some old App APIs still rely on IPv4 mapping.

If, as you have mentioned, the OS of the router has been crippled by Airtel then there is not much you can do in terms of user-modification except as JB suggested working it out with OpenWrt. Your need for DoH/TLS can be done using this.
 
Last edited:
Talking about manual linking, each IPv6 Client trying to access your (ad-blocking) DNS service will all have a different public IPv6 on their headers and these are deemed to change frequently regardless

Since the IPv6 DNS I will be using is unique to me the client IPs won't matter. That's what makes that system great. As long as all my router traffic goes to my unique DNS it will all be protected by my unique ad/traffic rules.

Second, there are quite limited services you will be able to access if you completely turn off IPV4, especially banking and government websites.
Some old App APIs still rely on IPv4 mapping.

If I turn of IPv4 for my LAN (not WAN) and point to an IPv6 DNS will I not be able to access IPv4 websites? I cannot imagine that's correct because I can use the IPv6 DNS on a Windows client for instance and access everything on the web. But as I said I don't want to manage it on a per device basis so I'm looking for something to work straight off the router.
 
If I turn of IPv4 for my LAN (not WAN) and point to an IPv6 DNS will I not be able to access IPv4 websites?

the LAN contains all the devices on your network, without IPv4 your devices wont get an IPv4 Local Address (the local address is translated by the router so you can access the IPv4 internet). You will only be able to access IPv6 Sites.
 



Top