• SIXXS-Aiccu and pfSense

    2
    0 Votes
    2 Posts
    1k Views
    ?
    You have to switch to non aiccu mode.
  • Loss of IPv6 connectivity from LAN to Internet v2.3.1

    12
    0 Votes
    12 Posts
    4k Views
    L
    Hi everyone, just an update regarding this issue.  I posted in a Teksavvy dslreports forum about the issue I'd been having and got some interesting feedback.  They recommended allowing IPv6 ICMP packets to hit the WAN interface of the firewall.  After doing this, my IPv6 connectivity to my LAN has remained constant and is at 5 days straight now vs losing it after 2 days.  So either something has changed on the Teksavvy side to monitor the CPE/FW of their customers to ensure that the DHCP /56 that is handed out is still valid and should stay in their routing tables vs removing it.  Or something on the pfsense configuration changed in that Teksavvy is no longer able to tell whether the FW is alive or not via some kind of ND or whatever.  This started about a year ago so it's not something recent.  Others seem to have experienced similar problems with one person using a cron job to reset the DHCP6 session nightly. I'll post back if things change and I lose connectivity again. LoboTiger
  • Please Help with DHCP6C on native /56

    35
    0 Votes
    35 Posts
    12k Views
    B
    @rancid-lemon: @bimmerdriver: @rancid-lemon: I tried to install patch 3102 for this issue, but I run into a 'this patch can't be applied cleanly' error. Can anyone advise how to install on 2.3.2? PR 3102 hasn't been backported to 2.3.2 (yet, I hope). If you want to run the patches, you need to run the development snapshot. I'm running PRs 3102/1, 3102/2, 3103, 3105, 3106 and 3107 and they are working quite well. The only patches that are specifically for the RA issue are 3102/1 and 3102/2. The rest are for dhcp6. Refer to https://redmine.pfsense.org/issues/5993 and https://github.com/pfsense/pfsense/pulls. The shapshot already has an earlier version of the fix, so it should get a prefix even without the PRs. Understood, thank you for the explanation. I will give the snapshot a go and see how I get on before installing the patches, will keep an eye on this thread too. In case you didn't notice, if you upgrade to the latest 2.3.3 development snapshot, all of the pertinent patches have already been merged.
  • DHCPv6 Reservation - IAID

    2
    1 Votes
    2 Posts
    2k Views
    B
    You're not missing it. It's not supported. I believe it should be, however. If you want to set up a reservation for a host, such as a laptop, with wifi and wired interfaces, it's needed to prevent an address clash.
  • Routing IPv6 space over OpenVPN client

    6
    0 Votes
    6 Posts
    3k Views
    J
    @johnpoz: "the provider actively blocks 6in4 on their RGs" So they are blocking protocol 41?  You ask them this and they gave you reason why?  This is AT&T http://www.dslreports.com/forum/r30137020-AT-T-U-Verse-Protocol-41-IPv6-Net-Neutrality-Complaint-with-FCC What equipment do you have from them? I've got a Pace 5268AC.  Disappointingly, there is native v6 available, but it doesn't support the /60 they hand out when you use it in DMZ+ (with pfSense). I've thought about filing a net neutrality complaint, but I can likely see them citing security issues with allowing 6in4.  Based on my research, they either deny or act confounded when asked (or served).
  • Rogers and changing prefix

    7
    0 Votes
    7 Posts
    2k Views
    JKnottJ
    I called the support line and advised them.  They said IPv6 isn't officially supported yet, so there may still be issues.  They said they'd forward my probelm to the appropriate people.  Hopefully, it's just a teething problem that will be resolved shortly.  At least the person I was talking to knew what the DUID was and what it's supposed to do.
  • Stumped by IPv6 (LAN/WAN)

    21
    0 Votes
    21 Posts
    6k Views
    JKnottJ
    Actually, they are real, public addresses, every one of them.  It's up to your firewall to keep them "private".  Any IPv6 address that starts with a 2 or 3, in the first digit, is a public (global) address.
  • LAN Clients don't get an IPv6 Address

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Pf "skip" rules - where is this in the GUI?

    6
    0 Votes
    6 Posts
    3k Views
    jimpJ
    No. You always want to filter on the interface the traffic enters. You can't manage traffic entering GIF on the LAN tab, a floating rule outbound on LAN maybe, but why would you want to let traffic enter the firewall before blocking it? Block it at the GIF interface. You do have to assign the GIF interface first so it gets its own firewall tab, if you haven't already.
  • DHCPv6 Possible? [SOLVED]

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    M
    Ok, so changing RA to Managed appears to have fixed all my issues.  Marking topic as SOLVED.  Thank you everyone for your help!
  • Fyi: Mediacom & ipv6

    17
    0 Votes
    17 Posts
    7k Views
    H
    So much of the ipV6 talk presupposes subnets smaller than /64 are in the category of 'error' it just never occurred to me an ISP would expect it.
  • IPv6 problem, periodic loss of packets

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • DHCPv6 leases not showing, not getting RAs on pfSense 2.3.2

    2
    0 Votes
    2 Posts
    2k Views
    J
    Hi, It is possible my problem is due to bugs already logged. I checked out https://redmine.pfsense.org/issues/6717 and https://redmine.pfsense.org/issues/6541
  • Ipv6 dual stack Deutsche Telekom VDSL not working

    13
    0 Votes
    13 Posts
    6k Views
    M
    Yes your pfSense get the "Kundennetz/WAN" Subnet on the WAN interface and the "Kundennetz/Lan"/56 on all other interfaces splitted as /64. You configured Track Interface(WAN) on the other Interfaces? And dont forgett to reboot.
  • [solved] IPv6 address lost (not renewed) on cable modem reset

    3
    0 Votes
    3 Posts
    2k Views
    G
    …and based on the cause listed in the previous message, the solution is to go into Interfaces->WAN, scroll down to "DHCP Client Configuration" and add your cable modem's IP address to the "Reject leases from" field. The IP address of the cable modem depends on the specific hardware.  For nearly all Motorola/Arris modems, it'll be "192.168.100.1". You can figure it out if you examine the "dhcp" logs in pfsense after a reboot of the modem.  It'll be the IP address listed as the DHCP server assigning pfSense an IPv4 before the modem is completely rebooted.
  • Router solicitation flood

    3
    0 Votes
    3 Posts
    2k Views
    M
    That sounds plausible but we have "router solicitation" and that article is about "neighbor discovery" Will look deeper into that.
  • DHCP DUID file not preserved across reboots when "Use RAM Disks" is enabled

    12
    0 Votes
    12 Posts
    4k Views
    B
    I contacted the engineer at my ISP for clarification about the "UUID". It was a typo. He said their gateways use LL, but they tested EN and LLT. I think having an option to preserve LLT and enable it to be entered as a configuration parameter would be useful for situations where preservation of prefix is based on consistent DUID.
  • General DHCPv6 to DNS updates

    3
    0 Votes
    3 Posts
    2k Views
    junicastJ
    How do I set this up on the pfsense side? Thank you. Little bit awkward to answer my own question. Here's a short howto for FreeIPA and pfsense: For the specific zone in Freeipa Settings make sure "Dynamic update" is set to: true generate key, me using srvxxx.my.domain dnssec-keygen -a HMAC-MD5 -b 512 -n HOST srvxxx.my.domain Open generate *.private file and copy the Key in the line that starts with Key: 3) On all FreeIPA hosts in replication edit /etc/named.conf by adding include "/etc/named.srvxxx.key"; On all FreeIPA write file /etc/named.srvxxx.key key "srvxxx.my.domain" {       algorithm hmac-md5;       secret "your_key_from_2)"; }; restart ipa via``` ipactl restart You can add this for DHCP server if you like also for DHCPv6 server. Unfortunately the updates are being refused. I think the grant statement is not just right. I'll update this post if I get it resolved.
  • Need help enabling IPv6 w/Android Devices on 2.3.2

    19
    0 Votes
    19 Posts
    7k Views
    C
    I'm guessing that the global address is used because a downstream IPv6 router could pick the RDNSS entry up and re-use it for its own LAN, this won't work if the address is a link-local address because the address wouldn't be reachable outside the original LAN. In my case, I don't have any routers downstream. Thanks, Chris.
  • Globally-scoped unicast address for pfsense WAN

    7
    0 Votes
    7 Posts
    2k Views
    B
    @JKnott: In the case of my ISP (Telus), their edge router does not allocate such an address. Their gateway allocates its global WAN address in prefix+ff/64, using RFC 2464. Are you using both pfSense and their modem in gateway mode?  If so, put the modem in bridge mode and use pfSense for your firewall.  pfSense is expecting to be assigned a prefix.  But the modem, in gateway mode, is taking that prefix.  I'm on Rogers and have a Hitron cable modem.  It's configured in bridge mode and I have a computer running pfSense as my firewall/router. No, that's not what's happening. The modem is in bridged mode. (Actually one port is bridged, not the entire modem.) pfSense is getting its own prefix. It's working perfectly, albeit using the "dhcp before RA" patches. (FYI, I'm running two pfSense VMs on the server, each getting its own prefix.)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.