• 0 Votes
    7 Posts
    775 Views
    I
    ehhh, so I made the config change and it worked fine, but some time after I made the change (maybe an hour?) my pfSense system crashed and rebooted with a kernel panic/page fault :-/ (haven't had that happen on me ... ever I think? and I've been a longtime user) Basically I just set my manual Outbound NAT rules to IPv4 only, and only applicable to one of my internal subnets and everything seemed fine until it suddenly crashed. I did check the General and System logs and nothing useful or noteworthy was found there. Maybe the attached debug files are useful to somebody, though (I censored my info) info.0 textdump.tar.0
  • NPt should allow to use a dynamic delegated prefix as source too

    4
    0 Votes
    4 Posts
    610 Views
    M
    @bob-dig You're right on this, I don't use two GUA prefixes simultaneously pointing to the same internal ULA prefix, only as failover from one to the other if either ISP gets disconnected, as this is fairly common here. As far as I've tested, this works correctly if the primary ISP fails with pfSense changing the default GW to the next one in its Gateway Group after dpinger detects the failure of the previous one. You have to take care to arrange NPt rules in the same order (from top to bottom) as the matching GW's (1 to n), otherwise it won't work. It even fails back correctly when the previous ISP comes back online.
  • Feature request to assigng multiple IA-PD via IAID to track interfaces

    1
    0 Votes
    1 Posts
    260 Views
    No one has replied
  • Ipv6 showing pending on gateway

    12
    1 Votes
    12 Posts
    2k Views
    T
    Also just read some of this: No IPv6 after upgrade to 23.01. You did mention you upgraded... I am on 2.6 still.
  • IPv6 not assigning to LAN device - ISP Hyperoptic UK

    26
    0 Votes
    26 Posts
    5k Views
    D
    Thanks for all the input; I think I'm nearly there but it is still not routing any traffic over IPv6. I set up as above, including the virtual IP as a3sx, and finally the WAN_DHCP6 has come up and is green (it wouldn't without the virtual IP). Amazing, never worked before. I took the address from configuring 'none' on WAN ip6 and seeing the loopback address after reboot (where does this come from??) it starts fe80:: My devices on the LAN are getting IP6 addresses and I can see leases on 'DHCPv6 Leases' status screen. My devices are getting IPv6 addresses starting with 2002:89dc... etc, could this be based on my delegated prefix? (Where do I see the prefix I got?) Yet when I open browser and do an IPv6 test all IPv6 tests fail. If I ping 'google.com' over ipv6 on diagnostics on the webUI it fails as well. Feels like it's close but there is still something wrong. Pfsense+ 23.01 If somebody would be able to look at my screenshare I'd send them money for a beer in the pub! thanks B
  • IPv6 route exclusions in OpenVPN

    1
    0 Votes
    1 Posts
    249 Views
    No one has replied
  • Best "IPv6 full-tunnel (with exceptions)" strategy

    1
    0 Votes
    1 Posts
    263 Views
    No one has replied
  • HE.net GIF requires disabling Outer Source Filtering?

    4
    0 Votes
    4 Posts
    642 Views
    S
    Appears the problem was related to a secondary WAN interface we have configured in the firewall. As soon as that WAN interface was disabled, the GIF tunnel would work without the filtering disabled. When the secondary WAN interface was enabled again, the tunnel still worked, so probably some messed up routing.
  • HE tunnel broken after 23.01

    he.net tunnelbroker error gif
    6
    0 Votes
    6 Posts
    1k Views
    J
    @steveits OK, thanks. If I can ever get registered on Redmine, I'll file a bug report.
  • guest vlan with ipv6

    6
    0 Votes
    6 Posts
    788 Views
    JKnottJ
    @gwabber No, you route the traffic, just as you do with your default gateway.
  • win11 no DHCPv6 adress

    Moved
    13
    0 Votes
    13 Posts
    4k Views
    GertjanG
    @r4ptor Your win dhcpdv6 client is working : [image: 1677233457673-467e835f-706e-4d56-9b18-38360a17e76c-image.png]
  • WireGuard automatically initiate using IPv6, but need IPv4

    1
    0 Votes
    1 Posts
    589 Views
    No one has replied
  • Poor IPv6 performance through HAProxy

    1
    0 Votes
    1 Posts
    637 Views
    No one has replied
  • neighbor discover proxy

    8
    0 Votes
    8 Posts
    1k Views
    NightlySharkN
    @tanya-0 I believe those decisions are made either from a performance standpoint (must be cheaper resource-wise to not having to handle network prefixes greater than half the address), a security standpoint (most pfsense subsystems, which are dependent on the specific implementation of the BSD kernel would IM ignorant O have to be re-written to change the long-standing in-code "assumptions" about the IPv6 netstack, which would introduce bugs and vulnerabilities that would take a lot of revisions to be ironed out and would reduce customer trust in the product) and a demand standpoint (not many of us, either pros like you, or enthusiasts like me) ask for that specific thing (I think).
  • Incorrect radvd config after updating to 23.01

    2
    3 Votes
    2 Posts
    622 Views
    R
    Thanks for the hint. Maybe it could be related to my Post here
  • Upgraded to 23.01 release no IPV6

    14
    0 Votes
    14 Posts
    2k Views
    maverickwsM
    @defunct78 unfortunately that is not my issue. I have a IPv6 Gateway Group selected the same as before.
  • NPt Why can I not open ports?

    8
    0 Votes
    8 Posts
    991 Views
    Bob.DigB
    Thinking about it, it makes sense, that it is only working for the first entry because no router will make many connections from one. So to get this working better it would need a dialog like for port forwarding where the router can be instructed what to do for what port.
  • RIPE Probe Disconnect every 24-ish hours IPv6 only

    2
    0 Votes
    2 Posts
    538 Views
    L
    @lurick Seems to have been an issue with the probe I have. I setup a VM version of the probe on the same network as the physical probe, no issues after 48 hours and counting.
  • [solved] NPt doesn't let me do that, why?

    9
    0 Votes
    9 Posts
    1k Views
    JKnottJ
    @bob-dig said in [solved] NPt doesn't let me do that, why?: I don't immediately update my DDNS-records. Are you talking about internal or external DNS? If internal, ULA is all you need for static addresses.
  • DHCPv6 address ignored on WAN

    3
    0 Votes
    3 Posts
    574 Views
    keyserK
    @bob-dig This is in Denmark, and the ISP is called Kviknet. I know My used settings at this time works with kviknet in other parts of the country (i have a friend using pfsense with kviknet), and more than One OPNsense uses them as Well. So what things could influence this and cause My dhcp6c Client to behave so irradically?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.