I asked starlink to see if any issue on their side and apprently not; here is their answer:
We use CGNAT, so incoming ports are not available. However, we do not block any outbound ports, except for SMTP port 25 to prevent the spread of spam and SMB port 445 to prevent the spread of malware. Our router does not have administrative functions for port forwarding. However, you can use a third-party device. You have an IPv6 address, but it’s your responsibility to set it up on your end. We are unable to provide guidance. We will be closing this support request for the time being and we encourage you to contact us in a new support ticket with any other issues or questions.
So I setup on my end WG server on spitz AX
I just cannot get my WG client to connect to my WG server
I tried every ipv6 I could find but in theory it should be the interface wan ip
this impossibility to establish a simple handshake and the DDNS not reporting the correct ipv6 address makes me think there is a bug on GL side.
Can I get an answer from GL staff please
Yes I can ping wan ipv6 address from my client but only if I disable VPN client on the spitz. Is this normal ? I should be able to have WG client and server running at the same time right ?
Still no handshake using wan ip endpoint and dns provided but the spitz configuration and mtu 1420.
So after more digging because I found the last starlink reply quite cryptic reading again I asked clearly multiple times and turns out starlink blocks EVERY incoming ports both on ipv4 AND ipv6 so game over using ipv6… only my pi will save me eventually… I guess this is why nothing is working even DDNS. All that so they can sell horribly expensive plans…
Sorry for wasting your time…
Elon Musk blows
if it does not need any open port then somehow it does not register the correct address as I have shown before… so I maintain something is off there.
Please GL dual VPN on spitz; just to get the finger to elon and cgnat
There’s a couple of different ways to update your ddns against a IP checking website (eg: https://checkipv4.dedyn.io/ ) but yeah… none of it matters in this particular CGNAT chaos.