• Dashboard cpu update 10 seconds just hangs

    Locked
    33
    0 Votes
    33 Posts
    20k Views
    johnpozJ
    Joe_cowboy I want to thank you for your fixes!!!!  And hopefully see more of your contributions, sounds like your part of the team now if your code has been merged into the master branch?? I am quite sure there is quite bit of clean up that could use your scrutiny. So you mention bind – I would be very interested in anything you could do to implement bind into pfsense..  I do like unbound and the work being done in that direction...  Its a great product for most scenarios where pfsense would be used..  But then again I would much rather run a full bind product for my dns where I have full control and can have duplication of dns services where one box is master and another slave, etc. I keep wanting to move to the full bind running on my pfsense - but since its not actually a package its kind of a road block... I have munin running giving me stats on my unbound running on pfsense - it would be sweet as hell to see full bind as an option with stats in an rrd, etc.. Is that somthing your interested in doing???  I would sign up for sure as your #1 beta tester ;)
  • Country IP Blocks IPv6 ACLs

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    C
    moved this over to the IPv6 board where it may get more attention from those of us who use v6. One thing with IPv6, it reduces the usefulness of country-restricting. It's easy to get free IPv6 space in many different countries from a number of different tunneling providers. Though not that country restrictions ever stopped any targeted attack, one can just as easily own something in another country on v4 and route through it. It's great for blocking various abuse, but not targeted attacks, and v6 lowers the barrier for bypassing such measures. Are you also doing v6 bogons? Same as my comments on the v4 bogons thread for that, we're fully dual stack with AAAA's for all our A's in our primary datacenter (95% of what we host). I would be willing to at least toss in a block rule right above our default deny to see what it would have blocked that we're blocking anyway, as an initial test. We're also using Cymru's list for v6 bogons, auto-updated far more frequently than we've needed to update v4 (including 6+ years ago when there actually was a changing Cymru v4 bogons list).
  • Welcome to the IPv6 board

    Locked
    5
    0 Votes
    5 Posts
    26k Views
    D
    Although Hurricane Electric have free resolvers available for IPv6, these are often slow and returning results in seconds instead of milliseconds. Google now has IPv6 DNS servers available too. 2001:4860:4860::8844 and 2001:4860:4860::8888 http://code.google.com/intl/nl/speed/public-dns/docs/using.html OpenDNS does have resolvers available too: 2620:0:ccc::2 2620:0:ccd::2 But these are as of january 4th 2012 not running the full service including malware filtering. http://www.opendns.com/ipv6/
  • No bogonsv6 in tables?

    Locked
    13
    0 Votes
    13 Posts
    7k Views
    I
    Thanks jimp for fixing that! It is strange since my crontab has the rc.update_bogons.sh running once a day, …although each time the rc.update_bogons.sh script is run, it has the initial sleep plus each section has an additional relaunch and sleep in it for a total of 4 relaunch and 5 sleeps if it has major problems... Such as if the WAN interface is down, or some other problem such as md5 (weird i know). maybe an exit 1 should be called after the first relaunch so that it doesn't relaunch up to 4 times/script and start a relaunch cascade!
  • Static ipv6 and ipv6 neighbour

    Locked
    11
    0 Votes
    11 Posts
    8k Views
    D
    Reading your diagram that the isp gave you, it looks like a normal static ipv6 configuration. Basically you configure the ::2 of the /126 prefix on the pfSense wan interface. You then create a gateway to the ::1 address of the /126 subnet. Normally the isp router will reply for ndp requests for this address. You can configure the 1st /64 prefix on the lan interface. Your isp will just forward the /64 networks to the ::2 address of your /126 subnet. This really is a basic static config as long as both the isp and pfsense reply to ndp requests. Which i think they will. If you have any questions or want me to review your configuration i can verify it remotely.
  • Router Advertisement

    Locked
    9
    0 Votes
    9 Posts
    15k Views
    D
    there is a bug in the current ra config mode where it does not set the right mode. That is still open for fixing. The IAID will have to be saved into the config.xml to make sure it persists, not sure why it needs another file unless the clients needs to have it that way. Also, I will likely pull the wide client and move to the ISC dhcp6 client at some point. Atleast before 2.1 is released. That client supports configuring a "pretty" ipv6 address on a prefix delegated. e.g. <prefix>::1 It's not that dhcp6 server is not a priority, but I'd rather get cascading prefix delegation working.</prefix>
  • DUID/IAID and other DHCPv6 notes

    Locked
    3
    0 Votes
    3 Posts
    12k Views
    M
    Yes, please add the IAID field and I'll be glad to do the testing.  As I say, I'm currently testing against an MS DHCPv6 server and I think there is an inherent incompatibility between the two distributions which may or may not have to do with the server receiving FQDN and vendor class options from the client.  I'm using Wireshark to sniff and I know the Solicit message is being sent.  I've already tested the DUID and IAID functionality with FreeBSD clients and I know those fields are showing up in the right places in the Solicit.  But the MS server does not Advertise in response.  At least, no Advertise shows up in Wireshark as it does when Solicited from a Windows client.  Strangely, though, the DHCP statistics displayed by the MS server always show an equal number of Solicits and Advertises.  The log file generated by the MS server only shows incoming messages (Solicits and Requests), which is equally bizarre.  Sounds like a firewall issue, right?  I disabled it on both machines with the same results.  I have to admit, I'm stumped for now.  If anybody has any ideas, please let me know.  I had hoped to rule out the FQDN-and/or-vendor-class issue by spoofing a Microsoft vendor code and sending the correct FQDN.  I think the ISC client does have this functionality, but then I can't use pfSense as the firewall, which is a deal-breaker.
  • L2TP IPSec VPN client behind pfsense 2.1 not working?

    Locked
    5
    0 Votes
    5 Posts
    9k Views
    johnpozJ
    I think your confusing my setup with running l2tp ipsec on pfsense? As I thought I clearly stated this is not have anything to do with pfsense acting as any part of the l2tp ipsec connection, not a client not server.  The l2tp server is not setup or on or enabled at all. This is a client behind pfsense connecting to a server on the public internet outside pfsense. If I enabled, ie uncheck pfscrub then it works.. If I disable pfscrub then it hangs.  It use to work just fine with pfscrub disabled - but now it is not. It is currently working, I don't have any issues with pfscrub being enabled.
  • I´m having prb with getting dhcpv6 addresses when i reconnect

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    ?
    Problem seems to be with the "managed" option, if u run "unmanaged" it works every time i reconnect, just not with "managed" anyone else noticed this? /f
  • Router Advertisement Option doesn't take

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D
    must have the bits set wrong, I'll look into it.
  • Error when setting DNS Servers

    Locked
    10
    0 Votes
    10 Posts
    7k Views
    K
    Same error with the new build. If I edit the restore file with 2 ipv6 dns server, both are configured in pfsense after the restore. But Package and Update management doesn't work. Unable to communicate with www.pfsense.com. Please verify DNS and interface configuration, and that pfSense has functional Internet connectivity. DNS Lookup with the both IPv6 DNS Server works fine. Diagnostic -> DNS Lookup pfsense.com = 69.64.6.21 2a01:4f8:120:5121:6::53 6 msec 2001:4d88:1ffc:409:1::53 8 msec Any Idears ? Thx Greetings
  • Unbound on 2.1-AMD64 broken

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    D
    Unbound integration into 2.1 is a ongoing project.
  • 0 Votes
    5 Posts
    7k Views
    F
    Hello databeestje: When I performed the resync the first time, my shell session got "terminated" (got kicked back to local prompt) and I had to login again so I thought the router had rebooted.  I resynched it just a moment ago and rebooted it again after my session got terminated and it looks like everything's working.  I can access ipv6.google.com and a test site so all appears well now. Thank you for your assistance. FIRESTORM_v1 Note to newbies:  If you're planning on implementing IPv6, it's best to use a v6/v4 dual-homed network.  Running IPV6-only will leave you with very little to do on the Internet.  (example:  www.v6.facebook.com only works halfway.  Facebook's fault. :P )
  • Error in latest sync?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    D
    Without the rtadvd the router will not announce itself. I have made a number of changes that could have caused it. Investigating.
  • UI recommendation for WAN/LAN interface config

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D
    Are you referring to the dhcpv6 server here? For the server part you can already choose. For the wan slaac is not supported currently since it does not work for a router.
  • He.net dynamic dns issue

    Locked
    12
    0 Votes
    12 Posts
    10k Views
    P
    Ah, thanks jimp! I was using the userid from the other method instead of my username. Works now.
  • IPv6 tunnel not coming up

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    G
    OK. So I solved this by deleting my tunnel and assignment with the tunnel broker. I then created a new tunnel and routed assignments, and replaced those in my non-working configuration and they worked. I have to surmise it was something at the other end (tunnelbroker). ipv6 gateway came right up, once I changed the ipv6 assignment for LAN/DHCP and refreshed, it all worked.
  • DHCP-PD available

    Locked
    17
    0 Votes
    17 Posts
    15k Views
    D
    I've managed to fix his installation and committed a few patches to the repo. The biggest issue is that the bogonsv6 table might be lagging on your installation, although we update that table very frequently at files.pfsense.org it might still be out of date. If you do run into issues with the dhcp6 client not aquiring a address and the dhcp6 requests ending up in the firewall logs as [fe80::something]:547 or [fe80::something]:546 it is probably hitting the bogons filter. After disabling the bogons on the WAN interface it succesfully acquired a DHCP-PD prefix for the LAN.
  • [2.1] RRD Graphs for default interfaces broken

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    D
    you gitsynced but did not perform a config upgrade. Please reboot and it should upgrade your configuration and thus your rrd files.
  • Comcast rolling out IPv6 – Finally!

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    their reasoning is that the amount of directly connected users is not trivial. So this should be a fairly harmless afair. Also, if the DHCP6 client is activated on the WAN interface pfSense will pick a DHCP6 address but there will be no prefix delegated when requested from the DHCP6 server. In the near future you can request a prefix delegation from the DHCP6 server and that should provide you with a routed subnet for the LAN. From my understanding from talking to Comcast they want to have generic devices from Netgear and D-link that work with DHCP-PD. They are not going the route that Ziggo in .nl is with the UBEE modems/routers/wifi gateways.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.