• static IPv6 stuck in DAD after upgrade to 2.5.1

    3
    0 Votes
    3 Posts
    516 Views
    A

    Nope. Solution for tonight is just disable IPv6 completely and live in IPv4 land. Thankfully this is a small network, I can reboot (or release/renew, or disconnect/reconnect) everything pretty quickly.

    I'll try non-VLAN, non-LAG ports tomorrow.

  • How do I block IPv6 connectivity to certain websites

    3
    0 Votes
    3 Posts
    547 Views
    GertjanG

    Many years ago, ther were question like this https://forum.netgate.com/topic/118566/netflix-and-he-net-tunnel-fixed-using-unbound-python-module?_=1622934995649

    These days, the package pfBlockerNG can work with lists of AAAA domain names, that can be blocked (no AAAA returned on a DNS request) so the A record gets used == IPv4.

  • Wireless clients lose ipv6 gateway

    30
    0 Votes
    30 Posts
    7k Views
    M

    For my site the issue has been resolved now. Been running smoothly for more than a week after increasing Router Lifetime in services_router_advertisements.php?if=lan

  • No IPv6 address from router in LAN interface

    15
    0 Votes
    15 Posts
    1k Views
    Bob.DigB

    @jknott It is a router for around 100 bucks. It only has one switch and one guest network, so the rest will get passed on I guess.

  • Comcast IPv6 works for 1-2 days, then stops routing

    26
    0 Votes
    26 Posts
    2k Views
    JKnottJ

    @sts-134

    You allow only what you want to. In this case, I didn't want to block anything. On the other hand, my guest WiFi VLAN is configured to allow only pinging the interface or going out to the Internet.

    c703fd7b-51cd-4e17-8cd4-8bd8d81345ed-image.png

  • Ipv6 pending gateway

    2
    0 Votes
    2 Posts
    382 Views
    No one has replied
  • 0 Votes
    4 Posts
    807 Views
    D

    @gertjan

    I feel a bit silly. I missed the step on assigning an address to LAN first.

    Thank you the detailed explanation.

    Lesson learned is do not attempt IPv6 when tired.

  • 0 Votes
    24 Posts
    5k Views
    JKnottJ

    @ddbnj

    Then I can only assume you didn't reboot pfsense. That's pretty much necessary to get the full sequence. Otherwise, you only get renewals.

  • 0 Votes
    4 Posts
    1k Views
    JKnottJ

    @spacey

    SLAAC is the normal way to configure IPv6.

    Look on Services > DHCPv6 Server & RA > LAN > Router Advertisements. If you have things configured correctly, a prefix will be automatically provided and the suffix is provided by the device.

  • IPv6 assigned through openvpn

    4
    0 Votes
    4 Posts
    646 Views
    JKnottJ

    @ofloo

    Sorry, I have never used TAP, but I can see problems in trying to bridge between networks.

  • Trouble configuring IPv6

    28
    0 Votes
    28 Posts
    3k Views
    JKnottJ

    @wineguy

    Yeah, using a sniffer is a good idea. When I had the problem with my ISP, I made a data tap with a managed switch.

  • Comcast IPv6 Problem: Works for 1-2 days, then stops

    2
    0 Votes
    2 Posts
    265 Views
    No one has replied
  • WAN DHCP6 gets addresses, but no connectivity

    16
    0 Votes
    16 Posts
    2k Views
    J

    @tzvia said in WAN DHCP6 gets addresses, but no connectivity:

    @jackthesmack said in WAN DHCP6 gets addresses, but no connectivity:

    @tzvia said in WAN DHCP6 gets addresses, but no connectivity:

    @jackthesmack Do IPV6 IPs show in your INTERFACES on the dashboard now, because your post showing your INTERFACES only lists IPV4 addresses.

    No they don't, despite the IPv6 addresses showing in the Status / Interfaces page.

    In your screenshot I only see the link local and gateway which looks to be an FE80. I don't see an IPV6 address assigned, that's why I am asking. You would think that if your router was getting functional IPV6 from the ISP and was set correctly and was assigned, you would have IPs assigned from the ISP, not just a link local address.
    a9377e67-27bf-48f5-ab46-0a18e80ca677-image.png

    Well this seems like an ISP issue now, because I plugged in my PC directly into the modem and now IPV6 doesn't work anymore.

    6735661e-e88a-408a-a8ab-d548b473e5b3-image.png

    03291491-d272-465a-abe3-3935b888ecd4-image.png

  • pFsense IPv6 gateways

    1
    0 Votes
    1 Posts
    394 Views
    No one has replied
  • [Solved] Unable to ping pfSense's LAN interface on IPv6

    16
    0 Votes
    16 Posts
    9k Views
    S

    @tomsparklabs said in [Solved] Unable to ping pfSense's LAN interface on IPv6:

    rebooted the router

    Hmm, thanks from the future...I set up an HE tunnel tonight and though the router could get out over IPv6, and PCs got IPv6 addresses, I found the PCs could not ping the router, dig to pfSense DNS over IPv6 to the LAN IPv6 was blocked by the default block firewall rule despite already having a LAN IPv6 to any rule, and new rules I added for DNS.

    Restarting pfSense (2.5.1) got IPv6 working fine from the PCs.

    Oddly https://test-ipv6.com/ worked...I guess over IPv4? But it showed IPv6 working, 10/10.

  • [solved] RA Subnets

    37
    0 Votes
    37 Posts
    5k Views
    JKnottJ

    @bob-dig

    I agree it should be easier to find. As for the name alias, that was even the case with IPv4, before there was IPv6. I assume it's because you have more than one address an interface can use, which is not typical. Also, with IPv6, you have not just mulitple addresses, you have multiple prefixes. Even if you don't have an alias, with SLAAC you can have up to 8 addresses, then there's link local too. By the time you've added a 2nd prefix, you're up to 17 addresses on a single interface.

  • IPv6 Router behind router

    68
    1 Votes
    68 Posts
    16k Views
    A

    I can use the IPV6 that are assigned on the USG DHCP to address computers from the internet. It just won't say "Internet" on Network and Sharing Center, or pass any IPv6 tests.

    Ping (as well as traceroutes) from local computers to google.com are fine even though it says "No Internet Access".

    The traceroutes go from the USG to the pfSense LAN IPv6 out to the internet, even though I have the link-local gateway address of Cox specified in the next-hop on the USG.

  • 0 Votes
    2 Posts
    552 Views
    lohphatL

    I found the problem.

    I had IPv6 enabled in pfBLocker-devel 3.0.16 DNSBL:

    IPv6 DNSBL
    Enable Enable DNSBL for IPv6 DNS Resolution filtering. Default IPv6 Webserver address [ ::10.10.10.1 ] and ports [80/443]

    radvd was choking on the ::10.10.10.1 RDNSS line of the config file.

  • Persistently Change RADVD AdvLinkMTU?

    5
    0 Votes
    5 Posts
    2k Views
    D

    Just in case someone finds this hack useful, the following is the patch I used on 2.5.0. It will only do what is intended (hardcode advertised MTU to 1480) if "Use same settings as DHCPv6 server" is unchecked under the Router Advertisements configuration settings.

    src/etc/inc/services.inc | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/etc/inc/services.inc b/src/etc/inc/services.inc index a3203aaaf7..1c63272ca1 100644 --- a/src/etc/inc/services.inc +++ b/src/etc/inc/services.inc @@ -130,7 +130,8 @@ function services_radvd_configure($blacklist = array()) { $radvdconf .= "\tAdvDefaultLifetime {$dhcpv6ifconf['raadvdefaultlifetime']};\n"; } - $mtu = get_interface_mtu($realif); + /*$mtu = get_interface_mtu($realif);*/ + $mtu = 1480; if (is_numeric($mtu)) { $radvdconf .= "\tAdvLinkMTU {$mtu};\n"; } else {
  • IPv6 No Gateway after 2.5 upgrade

    97
    2 Votes
    97 Posts
    30k Views
    yon 0Y

    https://redmine.pfsense.org/issues/11800

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.