• If cable HE reboots dhcpc6 dies on the WAN and doesnt restart (2.3.1)

    5
    0 Votes
    5 Posts
    1k Views
    johnpozJ

    I run same 2.3.1-p5 amd64 and HE tunnel is stable as you could ever want.  Only times there are issues with it is when there are issues with my actual ISP connection.

    What tunnel endpoint are you using?  I use the one in Chicago, they have many many other locations.  They have a status page you can look to find the status of any of the tunnels locations.

    https://tunnelbroker.net/status.php

    Lets see your tunnel quality vs your isp quality..

    tunnel.jpg
    tunnel.jpg_thumb
    wan.jpg
    wan.jpg_thumb

  • Firewall rules for individual hosts with PD

    5
    0 Votes
    5 Posts
    1k Views
    JKnottJ

    It would be nice if pfSense would support filtering based on MAC address, as some other firewalls do.

  • Prefix delegation doesn't get requested

    5
    0 Votes
    5 Posts
    2k Views
    D

    Turned out I had some typos in my dhcpv6 config after all the testing I'd done. Now starting dhcp6c manually works and ipv6 is up.

  • IPv4 Address Mapped on Same Interface

    3
    0 Votes
    3 Posts
    935 Views
    MikeV7896M

    Except that that IPv6 address isn't really an IPv6 address… it's intended to be a way to access or reference an IPv4 host using an IPv6 address (also acceptable would be ::ffff:c0a8:201, if you want the real IPv6 look). A little more depth from a post in the Hurricane Electric forums...

    [It] is an "IPv4-Mapped IPv6 Address".  It's another transition thing that is used to represent v4 addresses in a v6.  It's mainly used as an OS API thing to allow applications to do IPv4 via the IPv6 networking APIs (sockets, etc).  That way, when you write an application and want to do both IPv6 and IPv4, you can use the same calls and structures, etc, for both IPv6 and IPv4.  Without such a mechanism, an application such as a web server would have to reserve a socket and do a separate listen on both an IPv4 and IPv6 socket, manage them separately, etc.  With this mechanism, the application need only do a listen using the IPv6 API, and it can accept both IPv4 and IPv6 connections through the same API.  Doing a TCP connect also works similarly.  If the destination address in the sockaddr structure is a mapped address, it'll go through the IPv4 stack, otherwise it'll use the IPv6 stack.

    Reference: https://forums.he.net/index.php?topic=635.msg2820#msg2820

    So I would expect that using that IPv6 address would create a conflict, if not cause other issues.

    Additional reference:
    RFC 4291, Section 2.5.5.2 - IPv6 Addressing Architecture, IPv4-Mapped IPv6 Address

  • Small feature request for 2.3.X

    6
    0 Votes
    6 Posts
    2k Views
    M

    Thanks Chris.
    I saw you also coded other values to bumb up so that is that and it works fantastic now.
    I wish you good luck in your future career mate!

  • Subnet vs prefix

    15
    0 Votes
    15 Posts
    8k Views
    C

    On networks with end user devices, yes, it would be a bad practice to use anything other than a /64.

  • Can't get PD /56 to work

    12
    0 Votes
    12 Posts
    4k Views
    B

    @sheptard:

    I just updated to 2.3.2-DEVELOPMENT which included a update to dhcp6 and seems things are working better. my internal clients have valid ipv6 addresses and ipv6 dns works just fine.

    However I can't get any ipv6 traffic to leave my lan, but ipv6 connectivity works just fine on the router.

    I just installed the DEV version and for me there was no difference. I configured the prefix and other settings as before. I had to manually start dhcp6c as above. After that, everything was the same as it was with the other version. The dhcp6 gateway status is "pending", but ipv6 is working.

  • DHCPv6 Leases status incorrect

    3
    0 Votes
    3 Posts
    1k Views
    H

    Jimp,

    Many thanks for your reply. The static IP address client (::210) is in the NDP Table but I am not sure if the client is talking to pfSense. Please see the attached NDP Table.

    Thanks again for your reply!

    Untitled.jpg
    Untitled.jpg_thumb

  • Documentation or help? V6 Subnets routing / CARP

    4
    0 Votes
    4 Posts
    1k Views
    B

    Ok … almost that way ..

    I got a /64 and a /48 from HuricaneElektric
    The /64 is no between the first PFSense and the CARP-Cluster
    The /48 is routed to the vIP of the CARP-Clusters WAN-vIP

    the first /64 out of the /48 is for the LAN now.
    RA is set to unmanaged for LAN-IPv6

    Some stuff with default-GW and firewall arround ... Now it works really fine!

  • Trouble with multi-LAN, single-WAN setup

    2
    0 Votes
    2 Posts
    983 Views
    T

    Worked it out, just needed to get my upstream provider to add static routes for those internal LANs to his upstream router.

    2222:fc00:0:123::10:21c/64 via 2222:fc00:0:21::10:21c
    2222:fc00:0:127::10:21c/64 via 2222:fc00:0:21::10:21c

  • 6rd Tunnel with AT&T Uverse IPv6

    21
    0 Votes
    21 Posts
    14k Views
    M

    LOL I was actually just reading through that same post. Seems pretty interesting. I have the old version of the Netgear switch theyre talking about. It has since died. Wonder if I can RMA it! :P Otherwise, I need to pick up a new switch anyway.

  • Ipv6 "Track Interface" causes IPv4 to go down

    1
    0 Votes
    1 Posts
    772 Views
    No one has replied
  • [Solved] Can't use uppercase ipv6 address in interface gui

    2
    0 Votes
    2 Posts
    685 Views
    C

    ipv6 must be in lowercase

    https://tools.ietf.org/html/rfc5952#section-4.3

    https://forum.pfsense.org/index.php?topic=114173.msg634799#msg634799

  • Unable to set IPV6 DHCP range

    6
    0 Votes
    6 Posts
    2k Views
    K

    Basically - yes.

    I assign a /64 for each VPN instance, each "LAN" etc etc.

    As to what you set as the range, it depends completely on what you were assigned by HE.

    Also, you have to set up the firewall to use IPV6 at all and you have to secure it.

  • Possible bug in 2.3.1 with IPv6?

    13
    0 Votes
    13 Posts
    3k Views
    S

    I guess this errormessage is also intressting:

    From systemlog: /rc.newwanipv6: The command '/usr/local/sbin/dhcpd -user dhcpd -group _dhcp -chroot /var/dhcpd -cf /etc/dhcpd.conf -pf /var/run/dhcpd.pid re2_vlan1 re2_vlan2 re2_vlan3' returned exit code '1', the output was 'Internet Systems Consortium DHCP Server 4.3.3-P1 Copyright 2004-2016 Internet Systems Consortium. All rights reserved. For info, please visit https://www.isc.org/software/dhcp/ Config file: /etc/dhcpd.conf Database file: /var/db/dhcpd.leases PID file: /var/run/dhcpd.pid Wrote 15 leases to leases file. Listening on BPF/re2_vlan3/00:0d:b9:33:95:42/192.168.3.0/24 Sending on BPF/re2_vlan3/00:0d:b9:33:95:42/192.168.3.0/24 Listening on BPF/re2_vlan2/00:0d:b9:33:95:42/192.168.2.0/24 Sending on BPF/re2_vlan2/00:0d:b9:33:95:42/192.168.2.0/24 Listening on BPF/re2_vlan1/00:0d:b9:33:95:42/192.168.1.0/24 Sending on BPF/re2_vlan1/00:0d:b9:33:95:42/192.168.1.0/24 Can't bind to dhcp address: Address already in use Please make sure there is no other dhcp server running and that t

    Command executed via ssh: [2.3.1-RELEASE][root@pfSense.localdomain]/root: /usr/local/sbin/dhcpd -user dhcpd -group _dhcp -chroot /var/dhcpd -cf /etc/dhcpd.conf -pf /var/run/dhcpd.pid re2_vlan1 re2_vlan2 re2_vlan3
    Internet Systems Consortium DHCP Server 4.3.3-P1
    Copyright 2004-2016 Internet Systems Consortium.
    All rights reserved.
    For info, please visit https://www.isc.org/software/dhcp/
    Config file: /etc/dhcpd.conf
    Database file: /var/db/dhcpd.leases
    PID file: /var/run/dhcpd.pid
    Wrote 15 leases to leases file.
    Listening on BPF/re2_vlan3/00:0d:b9:33:95:42/192.168.3.0/24
    Sending on  BPF/re2_vlan3/00:0d:b9:33:95:42/192.168.3.0/24
    Listening on BPF/re2_vlan2/00:0d:b9:33:95:42/192.168.2.0/24
    Sending on  BPF/re2_vlan2/00:0d:b9:33:95:42/192.168.2.0/24
    Listening on BPF/re2_vlan1/00:0d:b9:33:95:42/192.168.1.0/24
    Sending on  BPF/re2_vlan1/00:0d:b9:33:95:42/192.168.1.0/24
    Can't bind to dhcp address: Address already in use
    Please make sure there is no other dhcp server
    running and that there's no entry for dhcp or
    bootp in /etc/inetd.conf.  Also make sure you
    are not running HP JetAdmin software, which
    includes a bootp server.

    If you think you have received this message due to a bug rather
    than a configuration issue please read the section on submitting
    bugs on either our web page at www.isc.org or in the README file
    before submitting a bug.  These pages explain the proper
    process and the information we find helpful for debugging..

    exiting.

  • Unable to enter IPv6 address in NPT rules on firewall_nat_npt_edit.php

    5
    0 Votes
    5 Posts
    1k Views
    N

    For improved usability I would suggest noting that either in the description or error message that pops up.

  • Block SSH on link-local ipv6 address

    8
    0 Votes
    8 Posts
    2k Views
    Y

    Alright, that makes sense. Thanks for the help.

  • Can ipv6 virtual server point at ipv4 pool elements?

    7
    0 Votes
    7 Posts
    1k Views
    C

    @hcoin:

    Re #2…. The firm but gentle encouragement I give along these lines has the same result the cashier at the grocery store gives when I explain "But I contribute to open source software, do I still have to pay?"

    Not an apt comparison at all. If you're paying someone for connectivity and they aren't routing you an IPv6 block for use internally, they aren't providing what you're paying for.

  • [SOLVED] radvd on vlan prefix size -1, no ipv6 working

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • ICMPv6 flooding the pfSense firewall logs

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S

    Got it. I have the same question opened in the Firewall section of the forum, but … could I ask you what steps should I take to disable logging for the default rules related to IPv6?

    Thank you for your help.

    This problem is solved now, please see this here:
    https://forum.pfsense.org/index.php?topic=113582.0

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.