• ipv6 dns opcode: QUERY, status: REFUSED

    10
    0 Votes
    10 Posts
    2k Views
    johnpozJ
    @netgate_etagten said in ipv6 dns opcode: QUERY, status: REFUSED: why dhcp6c needs to reacquire the address. Did you try setting this https://docs.netgate.com/pfsense/en/latest/config/advanced-networking.html#do-not-allow-pd-address-release
  • How to block/allow traffic send FROM one specific IPV6-computer !!??

    12
    0 Votes
    12 Posts
    1k Views
    johnpozJ
    @JKnott https://docs.netgate.com/pfsense/en/latest/firewall/ethernet-rules.html#ethernet-layer-2-rules pfSense Plus software versions 23.05 and later include support for rule-based pass/block filtering of packets based on Ethernet (Layer 2) header attributes. If you want to play with it, get the FREE + home license.. https://shop.netgate.com/products/pfsense-software-subscription [image: 1694203482358-plus2.jpg]
  • Erratic behaviour regarding updating aliases by hostname

    3
    0 Votes
    3 Posts
    391 Views
    Bob.DigB
    @Gertjan Your usecase is "dynamic-DNS". I wish pfSense would let you do what you did but with the DDNS-Clients onboard. My usecase is a host-alias for firewall rules, which can be private IPs for v4. And it has worked in the past, now it only works partially.
  • IPV6 Prefix ID issue after upgrading to 23.05.1

    21
    0 Votes
    21 Posts
    3k Views
    A
    Thanks for all your support guys, but nothing seems to work on my Qotom pfsense box with this release. Did a new install with CE2.7 and there it works fine. As soon as I upgrade to 23.05.1 the IPv6 network doesn't get any IP addresses. Therefor will put by Qotom box on the shelf for now and re-use my Dell R320-II for the time being. Looking forward for an improved pfsense release.
  • NDP Table Timeout

    15
    0 Votes
    15 Posts
    2k Views
    I
    @johnpoz Yup, that seems to fix it. NDP Table loads up on webUI after setting my current GUA PD as local-zone. So yeah, an option to always set the PD as local-zone would be nice...
  • Does anybody use Bell/FibeTV (in Canada) with pfSense

    12
    0 Votes
    12 Posts
    3k Views
    JKnottJ
    @guardian said in Does anybody use Bell/FibeTV (in Canada) with pfSense: My understanding (but am not 100% sure), is that you are not behind NAT Then they will have to provide multiple IPv4 addresses and I doubt they do.
  • How to diagnose IPv6 delegation issues

    9
    0 Votes
    9 Posts
    2k Views
    JKnottJ
    @Gertjan said in How to diagnose IPv6 delegation issues: Putting the ISP router in 'bridge' mode isn't possible anymore in France. Do those routers provide DHCPv6-PD to the customer? That's what pfSense requires to provide IPv6 to the LAN. I'm on Rogers, in Canada, and if I had a fibre connection, I could completely eliminate all their equipment, other than the optical terminal, and install my own router. As I'm on cable, I have to put their modem in bridge mode. Maybe you can do a capture of what's happening on the pfSense WAN port and post it here.
  • Missing Link Local on WAN

    11
    0 Votes
    11 Posts
    1k Views
    Z
    @johnpoz It has a link local now. I don't know why just reassigning the interfaces in the same exact way changed it, but I'm happy with it as long as its working. bce0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 description: WAN options=800bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,LINKSTATE> ether 00:26:b9:8b:fc:4f inet6 fe80::226:b9ff:fe8b:fc4f%bce0 prefixlen 64 scopeid 0x1 inet6 2001:558:6040:52:4d97:8d28:xxxx:xxxx prefixlen 128 inet 73.x.x.x netmask 0xfffffe00 broadcast 255.255.255.255 media: Ethernet autoselect (1000baseT <full-duplex,master>) status: active nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL>
  • 0 Votes
    12 Posts
    960 Views
    bmeeksB
    @JKnott said in ISP offering and testing an IPv6 BETA program, but it's not working and need some ideas: @bmeeks said in ISP offering and testing an IPv6 BETA program, but it's not working and need some ideas: I'm talking about lines #31 and #32 in the top window of the Wireshark display at times 140.049081 and 140.071568. Notice that reply from my ISP side that is sourced from port 547 (which is correct) and destined for port 547 (which is incorrect as I think it should be 546). Note also this says it is a Relay-reply message type. I see that replay reply, which I have never seen before. I have no idea what it's about. Yeah, me neither. I've sent your capture and mine to the consulting engineer for my ISP. I think perhaps setting all this up is new for him as well. Hence the BETA program. So, likely a learning curve for the both of us . Thank you for your input. You validated what I thought I understood. Just wanted another more experienced IPv6 user's view.
  • 0 Votes
    7 Posts
    1k Views
    GertjanG
    @myfamilydeservesbetter said in Editing the PHP SOURCECODE to enable ipv6 ?! // block in log inet6 all ridentifier 1000000105 label "Default deny rule IPv6": I also have a green check mark The green check mark means : this is a pass rule. Bytes "0" means : the rule hasn't matched (yet ) with traffic passed into the interface. Editing the PHP SOURCECODE to enable ipv6 Something really strange is going on.
  • my DHCP6 is up but not detected

    33
    0 Votes
    33 Posts
    3k Views
    S
    @JKnott yea weird. :( I guess we’ll see but everything seems to be okay. I do appreciate your help through this.
  • prefix length should be 64

    53
    0 Votes
    53 Posts
    12k Views
    JKnottJ
    @Bob-Dig Given the pictures are already there, what would it accomplish to provide more? I often post pictures when I think it would help.
  • pFsense not responding to multicast arp whohas

    16
    0 Votes
    16 Posts
    1k Views
    O
    @jimp I understand, that this is the case however I think it's sad that CE is neglected in this way.
  • Help with DS-Lite and AFTR

    1
    0 Votes
    1 Posts
    183 Views
    No one has replied
  • WAN Firewall Rules for IPv6

    6
    0 Votes
    6 Posts
    1k Views
    JKnottJ
    @guardian said in WAN Firewall Rules for IPv6: Will IPv6 go through a bridge the same way as IPv4? Yep, as will IPX, NetBIOS, SNA, DECNet, etc..
  • Linux systemd and Prefix Delegation

    1
    0 Votes
    1 Posts
    517 Views
    No one has replied
  • icmpv6

    3
    0 Votes
    3 Posts
    419 Views
    H
    @Gertjan Yes this would work if I not disable IPv6 in Advanced Settings and then catch the IPv6 with my own rules as you suggest. However, by allowing IPv6 in Advanced Settings, pfSense automatically add rules to allow any icmpv6, because this is needed for ipv6 to work. These rules cannot simply be overruled. It's not a big problem, at least I can control the logs a little better, but at least icmpv6 will be allowed and that is not something I wanted to begin with.
  • Ipv6 not passing route.

    1
    0 Votes
    1 Posts
    315 Views
    No one has replied
  • DHCPv6 PD not installing route after 23.05-RELEASE upgrade

    6
    0 Votes
    6 Posts
    1k Views
    GertjanG
    @asdjklfjkdslfdsaklj said in DHCPv6 PD not installing route after 23.05-RELEASE upgrade: new bug report. That link is also a bug .... I mean : click on it and enjoy. More edits : Since 5 days or so : If the patchs is applied and you "pkg install dhcpleases6" does it work ?
  • Problems using npt in pfsense 2.7

    1
    0 Votes
    1 Posts
    137 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.