Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ipv6 vlan leak

    General pfSense Questions
    4
    8
    765
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      anyn12
      last edited by

      Hoping someone can give me a pointer on troubleshooting: I have 4 vlans on igb0, vlan1 thru vlan4. Vlans 1-4 each get different ipv6 /64 adresses through track interface. Igb0 itself has no ipv6 connectivity (ipv6 is set to none on interface settings). But, somehow, igb0 clients get ipv6 adresses from vlan1 by slaac.

      Does anyone know why this is happening or how to fix?

      johnpozJ JKnottJ 2 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @anyn12
        last edited by

        @anyn12 do you actually have vlan1 with an ID of 1?

        This is the native vlan on pretty much every switch on the planet. And would normally be an untagged.

        If interface igb0 has no IPv6 what IP is being handed out? The one you have on vlan 1?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        A 1 Reply Last reply Reply Quote 0
        • A
          anyn12 @johnpoz
          last edited by anyn12

          @johnpoz igb0 has a static ipv4 address.

          Yes vlan1 has id 1.

          I know it is an odd choice, really just a workaround so that I can track interfaces for multiwan ipv6 NPt. Igb0 doesn't go to a switch - it goes straight to the IPMI port on my pfsense box. The vlans themselves have no clients.

          Is the fix simply changing vlan1 to something else like vlan10?

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @anyn12
            last edited by johnpoz

            @anyn12 I would never in a million years use the actual ID of 1 set on a vlan. This is default untagged vlan.

            Without some more details of exactly how everything is connected, and where the client is exactly that is getting the IPv6 you don't want it to get.

            But yeah I would change the actual ID on a vlan your using to something other than 1.

            A common practice is to use the vlan ID that somehow ties with your IP scheme.. If your using /24 vlans, use like the 3rd octet as the ID for example. But I would stay away from setting an actual tag of 1..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            A 1 Reply Last reply Reply Quote 0
            • A
              anyn12 @johnpoz
              last edited by

              @johnpoz ok yes sounds like I made a really dumb mistake. Thank you for helping me fix this so quickly!

              1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @anyn12
                last edited by

                @anyn12

                Any chance you have a TP-Link switch? Some models don't handle VLANs properly.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                A 1 Reply Last reply Reply Quote 0
                • A
                  anyn12 @JKnott
                  last edited by

                  @jknott no I don't have tplink, but I have a good feeling changing the ID will fix my problem, thank you for the pointer on not using id1.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Yup. Using VLAN1 bad! 😉

                    https://docs.netgate.com/pfsense/en/latest/vlan/security.html#using-the-default-vlan-1

                    Steve

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.