• IPv6 and AON (Manual Outbound NAT)?

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    M

    Hi doktornotor,

    I have to use AON for my StrongVPN connection. Regardless, this is a moot thread. I'll update our other thread with why.

  • Radvd.conf empty

    7
    0 Votes
    7 Posts
    2k Views
    S

    I'm having a similar issue on the current 2.1 RELEASE.  I set my lan interface as static IPv6, fe80::1/64 and when I bring up the DHCPv6/RA page it is completely blank.  Am I configuring this wrong?  I'm use DHCPv6 on my Comcast interface and it gets an IP just fine.  Just not sure how to get IP's out to my clients with radvd going.

    EDIT:  I got this going.  I switched to using track interface on the LAN and  DHCP6 with /64 prefix delegation request  on the Comcast WAN and everything came up.

  • Gmail and smtp over IPv6 FYI

    4
    0 Votes
    4 Posts
    2k Views
    johnpozJ

    SPF is not the same as a PTR, and how would that solve your problem when you just stated that gmail doesn't accept email from servers that don't have PTR.

    "FYI - google won't accept email via smtp over IPv6 if you don't have a reverse DNS v6 record for your mailserver's v6 address."

    You stated that spf is not sufficient - now your saying it is?

    "Having a valid SPF record with IPv6 included isn't sufficient."
    "I managed to work around it by updating my SPF record to specifically include a v6 address."

    If your isp supplies you with a /64 then they should provide the the ability to update your own ptr.  Hurricane electric allows for this with the /48 or /64s they give you for free.

    Who is your isp?

  • Apple TV and iPad AirPlay on Same SubNet not Working

    2
    0 Votes
    2 Posts
    3k Views
    C

    Hi I have been doing lots of tests and the problem is solved.

    1. if you are in different subnets then activate System > Advanced > Networking: Allow IPv6. After that enable proper Firewall rules to allow traffic.

    2. If you are in the same subnet pFsense does not interfere with AirPlay. In my case the problem was my WiFi Router that didn’t hade enable the IPv6 traffic for internal network.

    Sergio Handal.

  • Ipv6 address problem

    4
    0 Votes
    4 Posts
    2k Views
    V

    Ok i guess ill give more info to see troubleshoot the problem. My setup is re0 is my local lan ethernet and re1 is my connection to my adsl modem.
    I use PPPoE  on my wan(re1) interface. From what i managed to check so far is that instead of checking pppoe0 interface for my ipv6 address it checks re1.
    Maybe i understood wrong when i was selecting re1 as my wan interface? Should i have checked pppoe0? But its not created till i logging thru pppoe so it cant be.
    Maybe my set up is not supported for ipv6? And my re1 should have access to ipv6? i.e. I turn my modem back again to a router, it gets an ipv6 address and re1 gets an ipv6 address and everything works?

  • Cannot save settings if I use a ipv6 connection through WAN access

    8
    0 Votes
    8 Posts
    2k Views
    jimpJ

    I access firewalls frequently over IPv6 by hostname (Firefox won't connect to an SSL-enabled IPv6 host by IP address… it's been that way for years and they need to fix that already) and have had no issues.

    Do you have the same issue accessing by IPv6 on the LAN? Or just WAN?

    I can access a VM here by IP in Chrome over IPv6 and it was OK.

    If it was a general POSTing issue, you wouldn't be able to login.

    Are you sure you didn't login with an account that you gave the "deny config write" permission to?

  • Proper way to setup Router-Advertisements with DHCPv6?

    2
    0 Votes
    2 Posts
    1k Views
    D

    Well, managed or assisted, depending on what you need. (E.g., the Bitten Fruit™ machines still use radvd for the privacy IPv6 addresses even with DHCPv6, IIRC.)

  • Question static NPD Table

    5
    0 Votes
    5 Posts
    2k Views
    B

    Okay thank you.

  • 6rd and Centurylink

    2
    0 Votes
    2 Posts
    2k Views
    S

    Hi Maurice,

    As far as I can tell 6RD is still (still!) broken…..at least I haven't seen a build come through in the last 8 months that works with Charter.

    Here's the link to the ticket I opened back when I first noticed that something had changed and the builds were no longer working with 6RD:

    http://redmine.pfsense.org/issues/2882

    The last answer i got from the devs was that "I have only seen that on misconfigurations of pfSense" but I have no idea where that misconfiguration might be and have not gotten any hints as to where to look.

    -Will

  • Sorry, where exactly do I find this option…

    2
    0 Votes
    2 Posts
    1k Views
    C

    That text shouldn't have been there, it's a copy/paste from the v4 page. I removed it from the page. That option isn't applicable with prefix delegation, should be no need nor desire for it.

  • 6RD not working

    29
    0 Votes
    29 Posts
    15k Views
    S

    Hi podilarius,

    Updating to the latest (Fri. 8/16) build has allowed my WAN interface to once again get an ipv6 address.

    6RD still doesn't function, sorry to say.

    -Will

  • Native /64 and pfSense as VM in proxmox

    4
    0 Votes
    4 Posts
    5k Views
    Z

    @athurdent:

    I think you would need an extra /64 (or bigger) IPv6 subnet routed to your WAN IPv6 IP by your provider. You should use the /64 only as transport net between your VM and the provider router. You can use that extra /64 net on the LAN side for DHCP then.

    He is indeed correct. You need a subnet routed to an address in your linking subnet. Typically here in New Zealand we are given a /64 or /112 linking subnet between our router and the ISP. The ISP then tells us what /48 or /56 subnet they will route us and to which IP address in the linking range. We then set the PFsense WAN to that address and it works great.

  • IPv6 - Open Firewall… despite some rules, it cannot be closed...?!

    7
    0 Votes
    7 Posts
    4k Views
    4

    @athurdent:

    As far as I know, German T-Com's IPv6 capable lines are dual-stack, not 6to4. I think the OP means IA-PD. Here's a link to the other topic regarding his setup:
    http://forum.pfsense.org/index.php/topic,65123.0.html

    Right, but that is another access I use.  German Telekom does not equip every access with dual stack, the older ones are only IPv6 by 6to4.

    Cheers,

    4920441

  • ICMPv6 on tunnel interface gets blocked regardless of firewall rules

    10
    0 Votes
    10 Posts
    3k Views
    D

    Goes nowhere. From my POV, blocking ICMP is a pretty useless and as far as IPv6 goes, also completely broken idea. So, we'll agree to disagree.

  • Question regarding NPT

    7
    0 Votes
    7 Posts
    4k Views
    I

    I talked to CMB a few weeks ago and he probably will consider NAT66…
    There really are use cases for NAT66. As i told earlier especiallay if you have to use ISP hardware that cannot be changed, doesn't get reconfigured, too small delegated prefix etc...

    Thanks for the bridging Firewall info, that could be of help. Didn't think of that :-)

    Allthough NAT is bad in general it wouldn't be too hard to implement it in pfSense; PF supports NAT66 and it would only require small change to the GUI.

    There has been even code for the pfSense GUI

    https://github.com/pfsense/pfsense/pull/427   <- even discussed on the forum here…

  • Problems setting up native IPv6 on German Provider QSC

    4
    0 Votes
    4 Posts
    2k Views
    F

    We are in talks with QSC. They will setup correct Prefix Delegation, so that we hopefully have autoconfiguration pwith pfsense.

  • V6 troubles

    4
    0 Votes
    4 Posts
    4k Views
    D

    +1 on that, need a tunnel iface for that with WAN as parent, not ethernet. The howto should get you started pretty quickly.

  • IPv6 only for DMZ0 and DMZ1

    5
    0 Votes
    5 Posts
    2k Views
    T

    IPV6LAN
    Use the HE client IPv6 address as the interface IPv6 address

    IPV6DMZ
    You’re going to type your HE client IPv6 address into the IPv6 address box.

    And if not what kind of IPv6 adrdress I should use :) instead of the one in the manual?

    Kind regards
    Simon

  • Ipv6 2.1-RC0 (i386)

    6
    0 Votes
    6 Posts
    3k Views
    D

    I don't use snort for anything; not worth the myriad of false positives.

  • IPv6 Problem

    2
    0 Votes
    2 Posts
    1k Views
    D

    No, you don't need any second range from another tunnel broker. Please, read the howto more carefully, it works perfectly fine.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.