Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing brakes if IPv6 is activated on the WAN interface

    Scheduled Pinned Locked Moved IPv6
    15 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      m0nKeY @SteveITS
      last edited by

      @m0nkey

      Since your ISP is providing dual stack, configure for both IPv4 and IPv6.

      One of the settings is:
      Use IPv4 connectivity as parent interface - Request a IPv6 prefix/information through the IPv4 connectivity link

      I will definitely try this, if I have later problems with the IPv6 connection. But as @steveits said, my IPv4 routing should still work and I have to take care of this issue first. One step after another. ๐Ÿ˜„

      @m0nkey *breaks :)

      On Interfaces/LAN how is "IPv6 Configuration Type" set?

      I would not expect enabling IPv6 would break IPv4 connectivity. As in pinging fails by IP (e.g. 8.8.4.4)? As opposed to DNS returning an IPv6 address?

      "brakes"... ๐Ÿ˜ฐ Oh my gosh, what did I write. And I actually had a
      thought "this sounds weird" or should I say "this sounds wired". ๐Ÿ˜† Is it possible for me to correct it?

      The "IPv6 Configuration Type" is set to DHCP6.

      In some cases ping works and in some not. I did some tests:

      Ping "google.de" from LAN with IPv4 -> Does not work
      Ping "8.8.8.8" from LAN with IPv4 -> Works
      Ping "google.de" from WAN with IPv4 -> Does not work
      Ping "8.8.8.8" from WAN with IPv4 -> Works
      Ping "google.de" from LAN with IPv6 -> Works
      Ping "2a02:908:400:c::1bf9" from LAN with IPv6 -> Works
      Ping "google.de" from WAN with IPv6 -> Works
      Ping "2a02:908:400:c::1bf9" from WAN with IPv6 -> Works
      

      This looks like my issue is related to DNS, but I don't know what to change and where to look.

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @m0nKeY
        last edited by

        @m0nkey Click the 3 dots in the lower right of your post and see if it lets you edit it.

        I agree from your tests it looks like pinging IPv4 addresses works and DNS does not. Which seems odd. Is google.de not resolving over IPv4? What are your DNS Resolver settings?

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        M 1 Reply Last reply Reply Quote 0
        • M
          m0nKeY @SteveITS
          last edited by

          @steveits said in Routing brakes if IPv6 is activated on the WAN interface:

          @m0nkey Click the 3 dots in the lower right of your post and see if it lets you edit it.

          This seems only possible in the first 3600 seconds after creation of a thread, but thank. I guess, I have to live with the shame. ๐Ÿ˜„

          I agree from your tests it looks like pinging IPv4 addresses works and DNS does not. Which seems odd. Is google.de not resolving over IPv4?

          It seems so. An recommendation for additional tests here? Should I try to reach a webpage via IP instead of name?

          What are your DNS Resolver settings?

          Here are my settings:

          20220613_DNS_Resolver_Settings_0.png 20220613_DNS_Resolver_Settings_1.png20220613_DNS_Resolver_Settings_2.png20220613_DNS_Resolver_Settings_3.png20220613_DNS_Resolver_Settings_4.png20220613_DNS_Resolver_Settings_5.png20220613_DNS_Resolver_Settings_6.png

          1 Reply Last reply Reply Quote 0
          • M
            m0nKeY
            last edited by

            Is there anyone, who is able to help me with my issue? ๐Ÿ˜ข

            H 1 Reply Last reply Reply Quote 0
            • H
              heper @m0nKeY
              last edited by

              @m0nkey is there a reason you enabled forwarding mode?

              M 1 Reply Last reply Reply Quote 0
              • M
                m0nKeY @heper
                last edited by

                @heper I'm not sure anymore. I guess I had activated it because I was experimenting with certificate offloading for my sub-services.

                But basically, I don't know. Should I try to deactivate it?

                H 1 Reply Last reply Reply Quote 0
                • H
                  heper @m0nKeY
                  last edited by heper

                  @m0nkey i don't know. maybe the upstream dns servers you use for forwarding are causing issues somehow?

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    m0nKeY @heper
                    last edited by

                    @heper Deactivated the option, but it issue still consists and nothing changes.

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      SteveITS Galactic Empire @m0nKeY
                      last edited by

                      @m0nkey You might try unchecking:
                      Use SSL/TLS for outgoing DNS Queries to Forwarding Servers
                      DNSSEC data is required for trust-anchored zones.

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote ๐Ÿ‘ helpful posts!

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        m0nKeY @SteveITS
                        last edited by

                        @steveits Thx, unchecked them, but it does not solve my problem. ๐Ÿ˜Ÿ

                        Bob.DigB 1 Reply Last reply Reply Quote 0
                        • Bob.DigB
                          Bob.Dig LAYER 8 @m0nKeY
                          last edited by Bob.Dig

                          @m0nkey Start a new thread in the German sub-forum and don't do anything s... special like:
                          "I wanted to start with configuring the WAN interface for IPv6 only at first".
                          Load the pfSense default setting first and maybe then someone is able to help you. If you have a full dual stack there shouldn't be a problem at all.

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            m0nKeY @Bob.Dig
                            last edited by

                            @bob-dig Thank you, but why the German sub-forum? ๐Ÿค”

                            In the end, I will have to try what you suggested. I was hoping to get to know, how to analyse such issues, to learn something and solve future problems by myself.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.