HST.🇫🇷.◕‿◕.ST 1/128

Linux Debian Hostinger KVM for connection testing ASN 47583 in Paris (FR), France (UTC+2).

🍋‍🟩 Network IPv4 + IPv6


IPv6 GUA Network : 2a02:4780:28::/48
IPv6 GUA Network range : 2a02:4780:0028:0000:0000:0000:0000:0000-2a02:4780:0028:ffff:ffff:ffff:ffff:ffff

hst.fr.◕‿◕.st

IPv4 Public address : 147.79.115.130/32 - FQDN : hst.🇫🇷.◕‿◕.st.

IPv6 GUA : 2a02:4780:28:5295::1/128 - FQDN : hst.🇫🇷.◕‿◕.st.
IPv6 GUA Network range : 2a02:4780:0028:5295:0000:0000:0000:0000-2a02:4780:0028:5295:0000:0000:0000:0001

Hostinger assigns me an IPv6 address of type IPv6::/64 ; however, I only have access to a single IPv6::/128 address. I asked customer support if it was possible to have the entire IPv6::/64 block - The answer is no (at least for the KVM8 servers - AMD EPYC 9354P 32-Core Processor - 8 cores, 32GB of DDR ECC, 350GB hard drive).

Will I be their main node « 1 » of the IPv6::/64 « 95:: » multicast block, or will I have the entire block ? I don't quite understand.

IPv6 SLA : fec5::1/120 - FQDN : 🌓.🇫🇷.ip❤10.ws.
IPv6 SLA Network range : fec5:0000:0000:0000:0000:0000:0000:0000-fec5:0000:0000:0000:0000:0000:0000:00ff

/ infos /

Ethernet interfaces :

⛔🔜 root@hst-fr:~ # lshw -C network
  *-network
       description: Ethernet controller
       product: Virtio network device
       vendor: Red Hat, Inc.
       physical id: 12
       bus info: pci@0000:00:12.0
       version: 00
       width: 64 bits
       clock: 33MHz
       capabilities: msix bus_master cap_list rom
       configuration: driver=virtio-pci latency=0
       resources: iomemory:e080-e07f irq:10 ioport:f080(size=64) memory:fea42000-fea42fff memory:e0800008000-e080000bfff memory:fea00000-fea3ffff
     *-virtio2
          description: Ethernet interface
          physical id: 0
          bus info: virtio@2
          logical name: eth0
          serial: a4:e8:d4:b5:94:55
          capabilities: ethernet physical
          configuration: autonegotiation=off broadcast=yes driver=virtio_net driverversion=1.0.0 ip=147.79.115.130 link=yes multicast=yes

Configuration Network :

⛔🔜 root@hst-fr:~ # ip address show
1: lo:  mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute
       valid_lft forever preferred_lft forever
2: eth0:  mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether a4:e8:d4:b5:94:55 brd ff:ff:ff:ff:ff:ff
    altname enp0s18
    altname enxa4e8d4b59455
    inet 147.79.115.130/24 brd 147.79.115.255 scope global eth0
       valid_lft forever preferred_lft forever
    inet6 2a02:4780:28:5295::1/48 scope global deprecated
       valid_lft forever preferred_lft 0sec
    inet6 fec5::1/120 scope site
       valid_lft forever preferred_lft forever
    inet6 fe80::a6e8:d4ff:feb5:9455/64 scope link proto kernel_ll
       valid_lft forever preferred_lft forever
3: lxcbr0:  mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 10:66:6a:00:00:00 brd ff:ff:ff:ff:ff:ff
    inet 10.0.3.1/24 brd 10.0.3.255 scope global lxcbr0
       valid_lft forever preferred_lft forever
    inet6 fc42:5009:ba4b:5ab0::1/64 scope global
       valid_lft forever preferred_lft forever
    inet6 fe80::1266:6aff:fe00:0/64 scope link proto kernel_ll
       valid_lft forever preferred_lft forever
4: incusbr0:  mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 10:66:6a:56:26:85 brd ff:ff:ff:ff:ff:ff
    inet 10.175.0.254/24 brd 10.175.0.255 scope global incusbr0
       valid_lft forever preferred_lft forever
    inet6 fc00:4780:28:5295::fd/112 scope global
       valid_lft forever preferred_lft forever
    inet6 fe80::1266:6aff:fe56:2685/64 scope link proto kernel_ll
       valid_lft forever preferred_lft forever
6: vethbf8a9344@if5:  mtu 1500 qdisc noqueue master incusbr0 state UP group default qlen 1000
    link/ether 1e:7d:d6:1a:57:f2 brd ff:ff:ff:ff:ff:ff link-netnsid 1
8: vethc0aa0584@if7:  mtu 1500 qdisc noqueue master incusbr0 state UP group default qlen 1000
    link/ether 32:d5:16:cf:49:0e brd ff:ff:ff:ff:ff:ff link-netnsid 0
10: vethrqqdBu@if2:  mtu 1500 qdisc noqueue master lxcbr0 state UP group default qlen 1000
    link/ether fe:64:3b:40:c4:d4 brd ff:ff:ff:ff:ff:ff link-netnsid 3
⛔🔜 root@hst-fr:~ # ip -4 route show
default via 147.79.115.254 dev eth0 proto static
10.0.3.0/24 dev lxcbr0 proto kernel scope link src 10.0.3.1
10.175.0.0/24 dev incusbr0 proto kernel scope link src 10.175.0.254
147.79.115.0/24 dev eth0 proto kernel scope link src 147.79.115.130
⛔🔜 root@hst-fr:~ # ip -6 route show
2a02:4780:28::/48 dev eth0 proto kernel metric 256 pref medium
fc00:4780:28:5295::/112 dev incusbr0 proto kernel metric 256 pref medium
fc42:5009:ba4b:5ab0::/64 dev lxcbr0 proto kernel metric 256 pref medium
fe80::/64 dev eth0 proto kernel metric 256 pref medium
fe80::/64 dev incusbr0 proto kernel metric 256 pref medium
fe80::/64 dev lxcbr0 proto kernel metric 256 pref medium
fec5::/120 dev eth0 proto kernel metric 256 pref medium
default via 2a02:4780:28::1 dev eth0 proto static metric 1024 pref medium

Configuration SLA strongSwan :

⛔🔜 root@hst-fr:~ # swanctl -v
strongSwan swanctl 6.0.3
⛔🔜 root@hst-fr:~ # swanctl --list-conns
hst_fr-ca: IKEv2, no reauthentication, rekeying every 14400s, dpd delay 60s
  local:  %any[500]
  remote: 158.69.126.137[500]
  local public key authentication:
    id: hst.fr.lab3w.com
    certs: C=FR, O=LAB3W, CN=hst.fr.lab3w.com
  remote public key authentication:
    id: srv.ca.lab3w.com
    certs: srv.ca.lab3w.com
  hst_fr-ca: TUNNEL, rekeying every 5400s or 500000000 bytes or 1000000 packets, dpd action is none
    local:  fec5::/120 fc00:4780:28:5295::/64 fc00::10:0:3:0/112
    remote: fec0::/16 fc00:5300:60:9389::/64 fec1::/16 fc01::192:168:0:0/104 fc01::172:16:0:0/104 fc01::10:0:0:0/80 fec2::/120 fc00:41d0:801:2000::/64 fec3::/120 fc00:41d0:701:1100::/64 fec4::/120 fc00:1f00:8100:400::/64
⛔🔜 root@hst-fr:~ # swanctl --stats
uptime: 19 days, since Jul 09 16:43:40 2026
worker threads: 16 total, 11 idle, working: 4/0/1/0
job queues: 0/0/0/0
jobs scheduled: 3
IKE_SAs: 1 total, 0 half-open
mallinfo: sbrk 4448256, mmap 0, used 3407920, free 1040336
loaded plugins: charon random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pgp dnskey sshkey pem openssl pkcs8 xcbc cmac kdf ml drbg attr kernel-netlink resolve socket-default vici updown eap-identity eap-md5 eap-mschapv2 eap-dynamic eap-radius eap-tls eap-ttls eap-peap eap-tnc xauth-eap tnc-tnccs dhcp whitelist certexpire radattr addrblock unity counters
⛔🔜 root@hst-fr:~ # swanctl --list-sas
hst_fr-ca: #190, ESTABLISHED, IKEv2, b0b847af4e16ab36_i 43829c2d07cc7e26_r*
  local  'hst.fr.lab3w.com' @ 147.79.115.130[4500]
  remote 'srv.ca.lab3w.com' @ 158.69.126.137[4500]
  AES_GCM_16-256/PRF_HMAC_SHA2_384/CURVE_25519/KE1_ML_KEM_512/KE2_ML_KEM_768/KE3_ML_KEM_1024
  established 11011s ago, rekeying in 2209s
  hst_fr-ca: #347, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256/CURVE_25519/KE1_ML_KEM_512/KE2_ML_KEM_768/KE3_ML_KEM_1024
    installed 2219s ago, rekeying in 2968s, expires in 3722s
    in  c66a8e24, 21731453 bytes, 44030 packets,     0s ago
    out cc011508, 4361727 bytes, 44675 packets,     0s ago
    local  fc00::10:0:3:0/112 fc00:4780:28:5295::/64 fec5::/120
    remote fc00:1f00:8100:400::/64 fc00:41d0:701:1100::/64 fc00:41d0:801:2000::/64 fc00:5300:60:9389::/64 fc01::10:100:0:0/88 fc01::172:16:0:0/104 fc01::192:168:0:0/104 fec0::/16 fec1::/16 fec2::/120 fec3::/120 fec4::/120
⛔🔜 root@hst-fr:~ # ip -6 route show table 220
fc00:1f00:8100:400::/64 dev eth0 proto static src fec5::1 metric 1024 pref medium
fc00:41d0:701:1100::/64 dev eth0 proto static src fec5::1 metric 1024 pref medium
fc00:41d0:801:2000::/64 dev eth0 proto static src fec5::1 metric 1024 pref medium
fc00:5300:60:9389::/64 dev eth0 proto static src fec5::1 metric 1024 pref medium
fc01::10:100:0:0/88 dev eth0 proto static src fec5::1 metric 1024 pref medium
fc01::172:16:0:0/104 dev eth0 proto static src fec5::1 metric 1024 pref medium
fc01::192:168:0:0/104 dev eth0 proto static src fec5::1 metric 1024 pref medium
fec0::/16 dev eth0 proto static src fec5::1 metric 1024 pref medium
fec1::/16 dev eth0 proto static src fec5::1 metric 1024 pref medium
fec2::/120 dev eth0 proto static src fec5::1 metric 1024 pref medium
fec3::/120 dev eth0 proto static src fec5::1 metric 1024 pref medium
fec4::/120 dev eth0 proto static src fec5::1 metric 1024 pref medium
⛔🔜 root@hst-fr:~ # traceroute6 fc00:5300:60:9389:15:1:a:10
traceroute to fc00:5300:60:9389:15:1:a:10 (fc00:5300:60:9389:15:1:a:10), 30 hops max, 80 byte packets
 1  fec0::1 (fec0::1)  84.070 ms  84.486 ms  84.450 ms
 2  fc00:5300:60:9389:15:1:0:1 (fc00:5300:60:9389:15:1:0:1)  84.275 ms  84.101 ms  84.060 ms
 3  fc00:5300:60:9389:15:1:a:10 (fc00:5300:60:9389:15:1:a:10)  83.906 ms  83.595 ms  84.346 ms
⛔🔜 root@hst-fr:~ # traceroute6 fc01::10:116:42:10
traceroute to fc01::10:116:42:10 (fc01::10:116:42:10), 30 hops max, 80 byte packets
 1  fec0::1 (fec0::1)  87.532 ms  87.295 ms  86.938 ms
 2  fec1::1 (fec1::1)  181.693 ms  181.492 ms  181.182 ms
 3  fc01::10:106:0:252 (fc01::10:106:0:252)  181.129 ms  181.100 ms  182.079 ms
 4  fc01::10:116:0:1 (fc01::10:116:0:1)  182.053 ms  182.026 ms  182.356 ms
 5  fc01::10:116:42:10 (fc01::10:116:42:10)  182.301 ms  182.268 ms  183.810 ms
⛔🔜 root@hst-fr:~ # traceroute6 fc00:41d0:801:2000::1
traceroute to fc00:41d0:801:2000::1 (fc00:41d0:801:2000::1), 30 hops max, 80 byte packets
 1  fec0::1 (fec0::1)  84.342 ms  85.799 ms  85.142 ms
 2  fec2::1 (fec2::1)  161.548 ms  161.519 ms  161.491 ms
 3  fec2::1 (fec2::1)  3210.982 ms !H  3210.955 ms !H  3210.927 ms !H
⛔🔜 root@hst-fr:~ # traceroute6 fc00:41d0:701:1100::1
traceroute to fc00:41d0:701:1100::1 (fc00:41d0:701:1100::1), 30 hops max, 80 byte packets
 1  fec0::1 (fec0::1)  83.485 ms  83.377 ms  83.610 ms
 *  * * *
 *  * * * * * * * * * * * * * * * * * * * * * * * 
30  * * *

⛔🔜 root@hst-fr:~ # mtr -rwzc 1 -T -P 53 fc01::10:106:0:252
Start: 2026-07-29T13:47:33+0200
HOST: hst-fr                      Loss%   Snt   Last   Avg  Best  Wrst StDev
  1. AS???    fec0::1              0.0%     1   83.7  83.7  83.7  83.7   0.0
  2. AS???    fec1::1              0.0%     1  181.6 181.6 181.6 181.6   0.0
  3. AS???    fc01::10:106:0:252   0.0%     1  181.2 181.2 181.2 181.2   0.0

Not to joke, because you never know with all this information, I'm adding the files /.well-known/security.txt to the default WebServers directory ; hoping you're not too mean.


IPv4/IPv6 FrontEnd Web Services with France IP address :


🔥 My Firewall ICMPv6 - IPv6 Netfilter GNU/Linux : https://howto.zw3b.fr/linux/securite/comment-faire-un-reseau-ipv6-firewall-icmpv6 (Translate Page).
🔑 How to configure strongSwan v6 Post-Quantum Cryptography NIST compliant #2731 : https://github.com/strongswan/strongswan/discussions/2731
🌐 Create your network map with GestióIP IPv4/IPv6 subnet calculator : http://www.gestioip.net/cgi-bin/subnet_calculator.cgi
🖧 The IPv6 ULA (Unique Local Address) network configuration from my home to the servers ; shown in the image : https://howto.zw3b.fr/pub/vpn/strongSwan-v6.0/network_map-ipv10.jpg

❗NETDOC.net : Iptables Tutorial 1.2.2, Maquettage et autohébergement : le VPN IPSec BEET avec strongSwan

Read the INFOS.txt file in my StrongSwan 6.0.1 Configuration files n°7 ; there is some nice information - I like my "traceroute" tests from home (gate-fr / command-traceroute6.txt). It's tempting.


ZW3B.FR IP❤10.WS