Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. pfSense® Software
    3. IPv6
    Log in to post
    • Newest to Oldest
    • Oldest to Newest
    • Most Posts
    • Most Votes
    • Most Views
    • R

      No global address on LAN using Track Interface behind ISP router

      • • RoyceTheBiker
      10
      0
      Votes
      10
      Posts
      507
      Views

      JKnottJ

      @roycethebiker

      Did you select 56 for the prefix size?

    • D

      Lost ipv6 connectivity on TrueNAS Core after upgrade from 22.01 to 22.05

      • • dualmoo
      3
      0
      Votes
      3
      Posts
      554
      Views

      D

      Looks like a bug has been filed by the dev team.

    • L

      Issue configuring IPv6 with ULA, but works fine with Track Interface.

      • • lamboalpha
      36
      0
      Votes
      36
      Posts
      1021
      Views

      L

      It is set on for me per my above post. But, I am on 2.6.0 (which is 22.2 config rev).

    • S

      Static IPv6 addresses (last 64bits) with dynamic ISP prefix /56

      • • SirSilentBob
      8
      0
      Votes
      8
      Posts
      567
      Views

      JKnottJ

      @pfadmin

      Assuming you want access from elsewhere, how would that help? You still have to allow the outside world to know what the address is.

    • J

      No RA on WAN and ISP brushes me off stating its my FW config that is at fault.....

      • • jagdtigger
      24
      0
      Votes
      24
      Posts
      939
      Views

      JKnottJ

      @jagdtigger

      You said an ordinary computer doesn't work. Try complaining about and see what they say. I know it can sometimes be difficult to get through support.

    • G

      Setting up ULA and GUA addresses

      • • gwabber
      22
      0
      Votes
      22
      Posts
      733
      Views

      G

      @jknott works like a charm now! thanks!

    • A

      Cosmote FTTH connection ipv6 issue

      • • AlexanderK
      1
      0
      Votes
      1
      Posts
      250
      Views

      No one has replied

    • D

      Site to Site ipv6 best practice GUA vs ULA

      • • ddbnj
      6
      0
      Votes
      6
      Posts
      426
      Views

      JKnottJ

      @ddbnj said in Site to Site ipv6 best practice GUA vs ULA:

      I'm still using IPv4 tunnels but am transmitting IPv6 packets across.

      I do the same. I don't run the tunnel over IPv6 due to DNS issues. My IPv4 address is an alias that points to the ISP provided host name. Using the alias prevents the DNS server from returning the IPv6 address, which is a regular AAAA record. However, pfSense is configured to allow either IPv4 or IPv6.

    • J

      xfinity/comcast ipv6 issue

      • • jcp
      16
      0
      Votes
      16
      Posts
      581
      Views

      JKnottJ

      @jarhead said in xfinity/comcast ipv6 issue:

      But the CGNAT issue I agree with and is valid. Other than that, no reason for IPv6.

      When NAT first came out, it broke FTP clients.
      It breaks VoIP and some games, requiring STUN to get around it.
      It breaks IPSec authentication headers.
      It adds work load to routers.
      IPv6 provides far more than enough addresses.
      IPv6 adds security features.
      IPv6 improves router performance.
      Etc..

    • D

      Best practices for local name resolution

      • • ddbnj
      12
      0
      Votes
      12
      Posts
      500
      Views

      D

      @jknott

      The packet capture via mac address is a good idea. If I decide to create an IPv6 table for my local devices, I'll use it.

      Regarding routing, I realized that I have to add a route for ULA devices if I don't create an address for the interface itself. It's for devices on a different VLAN to reach ULA devices (admin to IOT).

      Anyway, thanks for your insights. Learning and deploying IPv6 has been pretty time consuming, I got to catch up with my real life!

      Thanks,

      Devan

    • M

      Routing IPv6 and Prefix Delegation

      • • mloiterman
      13
      0
      Votes
      13
      Posts
      780
      Views

      DerelictD

      @mloiterman Make a /128 Virtual IP address on your WAN in on of the /64s you want to route downstream. Make a WAN rule passing ICMP6 to that address. Ping it from the outside. Until that works you're not going to be able to route it downstream.

      pfSense is doing what it's supposed to be doing with the /64s on a tracked inside interface. That doesn't mean it's a new delegation. Just that dhcpd is adding that prefix to that interface from the delegation.

      Go to System > Advanced, Networking and enable the debug on dhcp6c. Then edit/save WAN. Then go to Status > System Logs, DHCP and filter on Process: dhcp6c. See what is there. That should show you the prefix that was assigned.

    • A

      Bug - Router Advertisements Server is active by default on internal LAN Interface – Multiple Errors like – Renaming of LAN Interface or setting up OpenVPN Server runs into an error regarding IPv6 Configuration

      • • albgen
      1
      0
      Votes
      1
      Posts
      217
      Views

      No one has replied

    • F

      Help needed geting fresh install playing nice with IPV6

      • • ftarz
      23
      0
      Votes
      23
      Posts
      747
      Views

      F

      2c9312f5-1be0-42f0-82b9-37c99c93416b-image.png

      I only keep zipping files since this webpage doesn't accept my native uploads. The screenshots have to be less than 2MB or they get rejected. The only way I could get the screenshot that small was to make it a PDF file which isn't accepted. Saving it as a .BMP or .JPG the file was just over 2MB and wasn't accepted.

      Frank

    • A

      VIP address in NDP table on secondary node

      • • arfid
      1
      0
      Votes
      1
      Posts
      214
      Views

      No one has replied

    • NightlySharkN

      Could this be a bug? Radvd cannot start.

      2.6.0 ipv6 virtualization configuration radvd • • NightlyShark
      2
      0
      Votes
      2
      Posts
      433
      Views

      NightlySharkN

      So, I found a GUI "bug". I had correctly set the prefix ID's in the "Tracked Interface" for each VLAN, but at the RA page, I mistakenly reinserted the prefix ID in the fields that are for static (full, not delegated) prefixes. Removed the static prefixes and everything now works. GUI should not let you enter static prefixes on a tracked interface, aside from fc00 or fd. And if it does, it should check if they are correct. One of the prefixes was ::1/64.

    • N

      No IPv6 traffic (Init7)

      • • noviceiii
      23
      0
      Votes
      23
      Posts
      1195
      Views

      JKnottJ

      @noviceiii

      Here's an example of what I'm looking for in the captures. This is just part of one packet of 8.

      5494ae04-4151-4fb1-a332-0dd7a0ea02a9-image.png

    • C

      Is it me or verizon?

      • • Cyth
      29
      0
      Votes
      29
      Posts
      864
      Views

      B

      @cyth I did a clean installation of pFSense out of the box provided IPV6, without changing any settings. Looks like they just started rolling dual stack so it will be some issues until they figure it out and finish the implementation. So far my pFSense is working, no issues with internet IPV6 traffic. From Verizon Automatic provide to pFSense address size.

      Then I upgraded to pFSense plus, no issues working our of the box.

      I spend a lot of time tried to figure it out, and looks like all this time was Verizon implementation issues.

      I found out I started getting IPV6 because, some of my devices stop working, the reason was because those devices tried to communicate only using IPV6, they were giving priority over IPv4.

    • S

      IPv6 works fine to internet from pfsense, but not from LAN devices.

      • • S_D
      11
      0
      Votes
      11
      Posts
      816
      Views

      JKnottJ

      @zennb1

      Clients rely on router advertisements to learn the LAN prefix and they append the suffix to it. Run Packet Capture, filtering on icmpv6, to see if you have them. You could also run Wireshark on a computer to do the same thing.

    • V

      Wan uses wrong IPv6 address

      • • vsey
      8
      0
      Votes
      8
      Posts
      434
      Views

      V

      @mikev7896 My problem is that my ISP sends multiple /64 IP prefixes with its RAs although DHCPV6 is used
      Pfsense than takes these Prefixes and configures multiple wan addresses. The problem is now that not all of these addresses work
      My idea was then to switch off the Address Auto configuration on WAN, but I don't know exactly how I can do that

    • B

      Firewall rules for IPV6 track interface.

      • • bassopt
      19
      0
      Votes
      19
      Posts
      646
      Views

      the otherT

      @steveits
      Hey there and thanks for your reply.
      That is what I thought.
      So, there must have been some rule responsible for this issue. Since the Screenshots of wan and lan did not show any such rule, I figured there must have been other rules...
      Just uninstalling pfblockerng solving the problem seems strange otherwise.
      Just trying to understand this issue.

    • ?

      IPv6 WAN Gateway monitoring reports 100% packet loss

      • • A Former User
      36
      0
      Votes
      36
      Posts
      2158
      Views

      ?

      @vortex21

      Hi, I reconfigured my network yesterday to eliminate the pfSense WAN connection being on a VLAN on the external network port. The WAN interface is now the physical interface card my problem of IPv6 WAN Gateway monitoring reporting 100% loss no longer occurs.
      So it appears the problem was related to the use of a VLAN.

    • P

      "Reuse" the same LLA IPv6 Address for VLAN VIPs?

      • • phongn
      1
      0
      Votes
      1
      Posts
      216
      Views

      No one has replied

    • P

      Add ULA DNS address to DHCPv6/RA *and* the dynamic GUA address?

      • • phongn
      9
      0
      Votes
      9
      Posts
      455
      Views

      P

      Oof, maybe I am just an idiot. I finally looked at /var/etc/radvd.conf:

      interface igc0 { AdvSendAdvert on; MinRtrAdvInterval 200; MaxRtrAdvInterval 600; AdvDefaultLifetime 1800; AdvLinkMTU 1500; AdvDefaultPreference medium; AdvManagedFlag on; AdvOtherConfigFlag on; prefix [COMCAST-PREFIX]::/64 { DeprecatePrefix on; AdvOnLink on; AdvAutonomous on; AdvValidLifetime 86400; AdvPreferredLifetime 14400; }; prefix fd0f:f5b9:d3f9:3068::/64 { DeprecatePrefix on; AdvOnLink on; AdvAutonomous on; }; route ::/0 { AdvRoutePreference medium; RemoveRoute on; }; RDNSS fd0f:f5b9:d3f9:3068::1 { AdvRDNSSLifetime 1800; }; DNSSL [DOMAIN] { AdvDNSSLLifetime 1800; };

      Sorry for wasting your time! It looks like pfsense's configuration "does the right thing" in radvd.

    • M

      [bug] Not showing what it's supposed to

      • • mencargo
      3
      0
      Votes
      3
      Posts
      279
      Views

      M

      @jimp I get it, sorry for the misunderstanding

    • D

      IPv6/DHCP6 Permission Denied

      • • dvonhand
      12
      0
      Votes
      12
      Posts
      570
      Views

      JKnottJ

      @dvonhand

      Once again, you need packet captures, to see what's happening.

    • B

      IPv6 RA Question

      • • behemyth
      3
      0
      Votes
      3
      Posts
      439
      Views

      B

      @jknott

      Yeah after doing a bunch of research and reading some IPv6 RFC's I decided to just use unmanaged. Everything is working good and I got to turn off the DHCPv6 server. One less thing I have to deal with.

    • Bob.DigB

      After IPv6 prefix change no IPv6 connectivity on Windows host

      • • Bob.Dig
      2
      0
      Votes
      2
      Posts
      338
      Views

      Bob.DigB

      @bob-dig said in After IPv6 prefix change no IPv6 connectivity on Windows host:

      Maybe the default lease times for IPv6 should be drastically shortened on any interface which uses "track".

      Another way to tackle that would be to use NPt I guess. So it would be great for that, if pfSense allows to use Track Interface in the NPt options directly instead of only using it for "physical" interfaces.

      Capture.PNG

    • D

      No IPv6 WAN connectivity on pfSense box itself -- LAN works fine.

      • • displaced
      11
      0
      Votes
      11
      Posts
      491
      Views

      JKnottJ

      @skilledinept

      If you want to connect to the firewall with a VPN, etc., you can use another interface address, such as the LAN.

      Perhaps if you mentioned your ISP, someone else might be able to help.

    • O

      How to configure DHCPv6 server for downstream routing?

      • • oliver.netgate
      2
      0
      Votes
      2
      Posts
      397
      Views

      O

      Update: I did some more reading on these forums and found this discussion from a few months ago that contained the solution.

      I need to specify the whole prefix delegation range allocated to me by the ISP:
      screenshot_dhcpv6_working.png

      As far as I know it's not possible to automatically update this prefix delegation range if the ISP decides to change it; I'll have to update it manually if that ever happens. Please correct me if this statement is wrong...

      Consider this question answered. Will leave the post up in the hopes that it will serve as a template / tutorial for others trying to do the same thing in the future.

    • I

      Multiwan v6

      • • ikkuranus
      5
      0
      Votes
      5
      Posts
      430
      Views

      I

      @jknott I didn't upgrade because of the issues with intel nics and the at&t fiber bypass on 2.6.x
      Apparently, fixed drivers aren't going to be provided till 2.7 so I'm holding off till then. Having my primary connection working is more important then having the latest version.

    • D

      Some websites do not access (PPPoE + IPv6 | Vivo Fibra Brasil)

      • • DaviCavalheiro
      2
      0
      Votes
      2
      Posts
      325
      Views

      JKnottJ

      If some sites work, but others don't, it's not likely a pfSense issue. What comes to mind is the site has an IPv6 address, but it's not working properly. However, in that case, it should time out and switch to IPv4.

      Can you do a packet capture of what happens when those sites fail?

    • junicastJ

      IPv6 issues after reinstallation

      • • junicast
      3
      0
      Votes
      3
      Posts
      579
      Views

      junicastJ

      @junicast
      To whom it may concern.

      We just migrated to different hardware and the original problem with reloading firewall rules is now resolved big relief.
      Actually it happened again. I suspect the Intel X170 are just bad and the update to pfSense 2.6 triggers this problem.

      Jun 30 10:24:05 fw3-rx kernel: ixl0: Interface stopped DISTRIBUTING, possible flapping

      The other problem persists. Neighbor discovery fails and the reason is that the primary firewall uses its Global Unicast address in the source field instead of the Link Local address. That was not the reason. We observed other occurences of NDP using UGA as source and those worked.

      At first I though some NAT rules might be the reason for that but after deactivation the problem persists.

      I checked that all interfaces have a Link Local address assigned so that also isn't the reason.

      Does someone have an idea under what circumstances this might happen?

      Edit:
      We contacted Netgate about it. They think this might be an actual FreeBSD bug. They do now have a solution, yet.

      d97a8679-c393-4c06-ad30-bbd11056ccf7-image.png

    • C

      NDP table not showing Hostname

      • • cjbujold
      12
      0
      Votes
      12
      Posts
      628
      Views

      NogBadTheBadN

      @jimp Working fine here too 👍

    • H

      IPv6 Bug ::1 notation do not work

      • • hsv
      13
      0
      Votes
      13
      Posts
      497
      Views

      Bob.DigB

      @hsv I noticed problems with IPv6 too, but for me these are not general but individual to an interface. For example, because mine is virtual and I deleted a "faulty" interface, added a new one and problem was gone (new MAC address etc.). So maybe try this four your installation too, if you can.

    • J

      How to correctly setup static IPv6?

      • • jbattermann
      6
      0
      Votes
      6
      Posts
      395
      Views

      NogBadTheBadN

      @jbattermann I used :1::1/64 as the gateway address and the following in the RA section as I have Apple devices :-

      Screenshot 2022-06-24 at 20.00.36.png

    • A

      IPv6 PPPoE Telmex/Telnor WAN Interface Configuration (Continued...)

      telnor telmex ipv6 bridge pppoe • • abcdefabcdef
      1
      0
      Votes
      1
      Posts
      293
      Views

      No one has replied

    • ?

      Hundreds of ipv6 rule errors appearing in dashboard –- brings down the WAN

      • • A Former User
      13
      0
      Votes
      13
      Posts
      2427
      Views

      luckman212L

      When this used to be a problem for me, I added the 192.168.100.x IP to the dhcp ignorelist so pfSense would not accept it when offered by the ISP CPE. This definitely helped.

    • A

      fe80::1:1 as static route for ipv6 track interface LAN? also LAN link-local no response?

      • • AveryFreeman
      9
      0
      Votes
      9
      Posts
      921
      Views

      JKnottJ

      @jknott said in fe80::1:1 as static route for ipv6 track interface LAN? also LAN link-local no response?:

      There are 256 possible prefixes within that /48. You use the other prefixes for other interfaces.

      My mistake. That should be 65536, not 256. Better have another beer. 😉

    • M

      Routing brakes if IPv6 is activated on the WAN interface

      • • m0nKeY
      15
      0
      Votes
      15
      Posts
      660
      Views

      M

      @bob-dig Thank you, but why the German sub-forum? 🤔

      In the end, I will have to try what you suggested. I was hoping to get to know, how to analyse such issues, to learn something and solve future problems by myself.

    • luckman212L

      rtsold not running, IPv6 WAN (DHCP) keeps losing connectivity

      • • luckman212
      8
      0
      Votes
      8
      Posts
      598
      Views

      luckman212L

      I just pushed an update to my PR #4595 that attempts to mitigate this issue. Testers wanted!