• Is it possible to not resolve ipv6 certain dns domains?

    9
    0 Votes
    9 Posts
    971 Views
    -flo- 0-
    @Gertjan This does it! Thank you all, you are may today's champions!
  • AT&T IPv6 stopped working after Arris NVG589 update?

    8
    0 Votes
    8 Posts
    1k Views
    M
    I ultimately suspected as much myself, which is also why I haven't taken any further action yet. It's now a question of when I feel like sitting on the phone with AT&T support for however long it takes to convince them to send me a new gateway and then taking the time to configure one from scratch to my liking. It seems like the final outcome is, like @ronv42 said, that the NVG589 is just far too obsolete at this point, and the solution is to replace it.
  • IPv6 NDP Incomplete

    2
    0 Votes
    2 Posts
    370 Views
    GertjanG
    @smaxwell2 said in IPv6 NDP Incomplete: So pretty sure my issue lies within my Windows configuration, though I stand to be corrected. Your 'Windows' devices are like mine : you never changed anything in the 'Network' setup of your devices. They came with DHCPv4 and DHCPv6 client activated. There is/was never a need to change anything. @smaxwell2 said in IPv6 NDP Incomplete: My ISP provides me IPv6 on the WAN and delegated me a /56 I have my LAN configured within pfSense to "Track Interface" (WAN Like me. I assigned prefix ID '0' ion the LAN interface : [image: 1728377088687-2754f99d-c6dc-4ac1-9a8d-69be1d3187d6-image.png] And .... I've set up the DHCPv6 server - like the DHCPv4, for my LAN : [image: 1728377167446-2207d61e-7010-4f74-b7f2-54116f2f5571-image.png] and since I did this (years ago), all my LAN device that are IPv6 capable receive a IPv6 Lease in the ::2 to ::86 range. Because I'm old and stupid, I also gave most of all my device a DHCPv6 Static DUID Lease. This means that all my device always get the same IPv6 GUA. C:\Users\Gauche>nslookup diskstation2 Serveur : pfSense.bhf.tld Address: 2a01:cb19:907:xxxx:yyyy:77ff:fe29:392c Nom : diskstation2.brit-hotel-fumel.net Addresses: 2a01:cb19:907:xxxx::c2 192.168.1.33 I actually never (had to) looked at the NDP table page I can see on the DHCP Logs page that IPv4 and IPv6 are getting renewed : [image: 1728377300422-a167e7a1-58a5-47ea-85d7-c3179191b4d5-image.png] Btw : I use ISC, not Kea.
  • BTnet IPv6 Configuration

    16
    0 Votes
    16 Posts
    4k Views
    T
    @JKnott said in BTnet IPv6 Configuration: How does your ISP provide IPv6? Most use DHCPv6-PD, which provides your LAN prefix. The provide a /56. This gives 256 /64 subnets. The first /64 is setup on the router with router announcements. So for a single vlan with no firewall, you can just connect to the router. Then the whole /56 (minus the first /64) is routed to the ::5 address of the first /64. So if you need a firewall, fancier routing or have multiple vlans, then you just need to put a router on the ::5 at add other /64 to interfaces as you like. DHCPv6 PD is the modern way to do this - you do a DHCP request for a whole /64 subnet to use. This is cool, but not supported by my ISP (a BT or BTNet leased line). The static route way is totally find for my needs.
  • Is this how prefixes work?

    11
    0 Votes
    11 Posts
    1k Views
    JKnottJ
    @smk Here are a couple of other points: A WAN interface doesn't actually need a public address. With IPv6, routing is often done with the link local address. That /128 prefix length means there's no actual subnet there. That address is nothing more than a label for your router.
  • Trying to set up ipv6 with only a /64 range

    5
    0 Votes
    5 Posts
    698 Views
    GertjanG
    @johnpoz Somewhat thought that I already made some publicity for he.net here .. but it was somewhere else.
  • IPv6 Multi-LAN Problem

    7
    0 Votes
    7 Posts
    763 Views
    GertjanG
    @bmeeks @bmeeks said in IPv6 Multi-LAN Problem: My ISP moved me behind CGNAT That, NAT, shouldn't break the tunnel to the HE pop, but he.net has a condition : your 'WAN IPv4' as seen by them must answer to ICMP (ping). And yous doesn't .... so it's game over for you. For me, he.net isn't possible anymore for another reason : my new "state of the art newest ISP router" that has an ONT integrated for the fiber access can't handle the '6in4' protocol (41), so pfSense can't connect to the he.net pop server 6in4 isn't ICMP (1), isn't TCP (6), isn't UDP (17), neither GRE (4) but something else. So, I contacted them. This took me weeks to get in contact with someone who could actually understand my question. They : We've dropped protocol 41 support on our newest models because ... here it comes .... We, Orange, in France (10+ million subscribers) are now proposing IPv4 and IPv6. Me : Yeah, right, but your IPv6 for my usage is broken !? They : You have a static IPv4 and your IPv6 works, I can see that from here. Me : Yeah, sure, but as the (my) subscription implies : I'm using the Pro subscription as I'm a company, I would like to actually use the /56 as advertised. Your router, needed to connect to the Orange fiber, only has one (1) LAN, and I have a company with several LAN's - not just one. They : Wow, what ? Multiple LANs ? But that's not supported. Me : I have that covered : I chained on to a pfSense router, and it wants prefixes - your (my) prefixes. They [10+ minutes on hold, waiting while listing Cherry FM] : Right, there is a issue that only one prefix gets announced by our router. Me : Then why announcing /56 as only one /64 works ? Then they told me to do what others already do : "ditch our ISP router, use an FTP RJ45 to Fiber plug", as my 4100 supports such a connection, create some serious DHCP 4 and 6 options and behold, now I can tap into the full IPv6 /56 advertised. Champagne ! Of course, I'll loose all the ISP "TV" facilities and/or phone support (one phone line, but who cares, we have 6 lines on a PABX), I don't need these. So, I - and many, many other, are waiting for the router update that delivers us the needed IPv6 support. edit : let it be known : In France, ISP Orange : less people then you have fingers on your hand know that there is more then "UDP" and "TCP" ....
  • Verizon FiOS and IPv6 for pfSense 2.7.2

    3
    1 Votes
    3 Posts
    706 Views
    R
    I could tell my routing tables were screwed up, but I didn't really know why. After a while, I stumbled on the System/Routing/Gateways settings and noticed the "Default gateway IPv6" was set to "none." After setting it to WAN_DHCP6, it started working. I'm not sure how that got screwed up, given that my clients were working before.
  • IPv6 subnet lan vs wan

    9
    0 Votes
    9 Posts
    884 Views
    E
    @JKnott said in IPv6 subnet lan vs wan: Another issue might be how he's connected. Correct. And also it is an issue what device manage the connection between pfsense and ISP. A device in modem mode or one in router mode. A device in router mode must also support the prefix delegation to devices in its subnet. Not all do provide that. For example the Draytek Vigor 167 provide router mode and modem mode. But the router mode does not support prefix delegation to devices in the subnet. So for prefix delegation the Vigor 167 needs to be in modem mode then the pfsense will manage the prefix delegation, or it wont work.
  • SLAAC versus DHCPv6

    40
    1 Votes
    40 Posts
    11k Views
    the otherT
    @JKnott I cannot answer your question "why?"... :) But I can report that here in Germany ISPs I know do that as well. Maybe not every 24 hours, but often enough that using those prefixes breaks everything after a change. So: don't know why they still do it (I guess it's just another dumb implementation of v6 as seen so often), but they do it anyways.... That's why I use those global prefixes that change thanx to my German ISP as well as my "own"(not changing) unique locals....for rules and such. It's depressing but that how some big players really make it tedious to use v6 in my opinion...
  • Static IPv6 on WAN+LAN with /63 ISP - LAN to WAN not working

    6
    0 Votes
    6 Posts
    492 Views
    JKnottJ
    @snipleeagle8 As I mentioned, it normally happens with SLAAC in the router advertisements. I have never used DHCPv6 on the LAN side, but I expect it would be the same. Are you using SLAAC or DHCPv6? Can you do a packet capture, filtering on ICMPv6, and post the capture file here?
  • How to revoke per SLAAC distributed prefixes

    2
    0 Votes
    2 Posts
    348 Views
    JKnottJ
    @Jung-Fernmelder What you can do is use Unique Local Addresses, in addition to global addresses. You then use the local DNS to point to the ULA address, rather than GUA.
  • 0 Votes
    2 Posts
    325 Views
    JKnottJ
    @tuanson84uk Are those clients Android devices? They don't work with DHCPv6. Any reason you need it? I've been running IPv6 on my home network for over 14 years and have never needed it.
  • Force RA to send different IPv6 gateway.

    8
    0 Votes
    8 Posts
    654 Views
    JKnottJ
    @DataIdeas-Josh said in Force RA to send different IPv6 gateway.: Is there a way to force the RA to send a different IPv6 rather than the pfsense's routers IP? It's supposed to use it's own address. I'm not quite sure what you're trying to do, but you can have multiple gateways on a LAN and give them a priority, up to 3 of them. You can set priority on the Router Advertisement page.
  • php crash report ipv6 pfblocker

    6
    0 Votes
    6 Posts
    510 Views
    M
    Hi, I was seeing the same error, mostly with this IP list: https://api.gcore.com/cdn/public-ip-list Since ASN are currently not resolved and for reliability, I'm loading the lists from an internal repo anyway and tried my best to remove or reformat "problematic" IPs - without success. Then I had a closer look at /usr/local/share/pear/Net/IPv6.php and compared it to the public source. It seems that, at least in my case with pfBlocker 3.2.0_8 on CE 2.7.2, the file is missing an old fix for this problem: https://github.com/pear/Net_IPv6/commit/70080426d3ac9da4908f9277824694e5eda68985 After changing line 684 from $fill = str_repeat(':0:', 6-$c2-$c1); to $fill = str_repeat(':0:', max(1, 6-$c2-$c1));, the error is gone.
  • WAN with /64 Delegation

    33
    0 Votes
    33 Posts
    3k Views
    Bob.DigB
    @JKnott said in WAN with /64 Delegation: BTW, I've had the same prefix for around 5.5 years. I have the same prefix since my parents met.
  • IPv6 tunnel broker websites showing in German

    5
    0 Votes
    5 Posts
    408 Views
    GertjanG
    @Bob-Dig said in IPv6 tunnel broker websites showing in German: french guy Who ? There are some here.
  • 0 Votes
    1 Posts
    150 Views
    No one has replied
  • 0 Votes
    15 Posts
    1k Views
    D
    I am not sure why everything is working, but it's working. Perhaps my configuration will be of assistance in the future.
  • Services / Router Advertisement - DHCPv6 server - strange behavior

    8
    0 Votes
    8 Posts
    792 Views
    E
    @JKnott said in Services / Router Advertisement - DHCPv6 server - strange behavior: Thanks to some genius at Google, Android does not support DHCPv6 Same genius at Google for its Chrome OS ;-) Does also not fully support RFC 3315 See: https://en.wikipedia.org/wiki/Comparison_of_IPv6_support_in_operating_systems
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.