Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 not passing despite rules

    Scheduled Pinned Locked Moved IPv6
    8 Posts 3 Posters 870 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SpaceBass
      last edited by

      hey folks
      After the upgrade to 23.05 I've got some IPv6 issues. My hosts and my pfsense interfaces still get IPv6 IPs from my ISP.

      But traffic isn't passing at all. My top rule on LAN is an any/any for IPV6.

      alt text

      Any troubleshooting tips or tricks?

      1 Reply Last reply Reply Quote 0
      • S
        s0m3f00l
        last edited by

        Check

        System / Routing / Gateways

        Mine was set to Automatic after Upgrade:

        system/routing/gateways

        It should be set to the WANV6 TUNNEL interface:

        system/routing/gatewayscorrected

        S 1 Reply Last reply Reply Quote 0
        • S
          SpaceBass @s0m3f00l
          last edited by

          @s0m3f00l
          Thanks for the reply and suggestion.
          I've tried both automatic and an explicate setting - no joy with either :/

          I can resolve IPv6 IPs, and I can ping6 across local subnets. I just can't get traffic to egress.

          S 1 Reply Last reply Reply Quote 0
          • S
            s0m3f00l @SpaceBass
            last edited by

            @SpaceBass Check the routing tables. Is there a default route?

            S 1 Reply Last reply Reply Quote 0
            • S
              SpaceBass @s0m3f00l
              last edited by

              @s0m3f00l I get a little out of my depth with IPv6 routes...
              the default route is a local link: fe80::8271:1f0f:fcc1:5100

              I've noticed that I can pass IPv6 traffic across subnets (through pfSense), but I cannot reach the firewall itself via IPv6, it behaves just like trying to ping6 an external address.... the name resolves correctly, the firewall rule log shows a pass, but traffic doesnt move.

              S S 2 Replies Last reply Reply Quote 0
              • S
                s0m3f00l @SpaceBass
                last edited by s0m3f00l

                @SpaceBass I mean it sounds like your default GW for IPv6 is busted. Go to your PFSENSE console or VTY. netstat -rn should show a default route to the next hop. IDK what your setup is but it should be pointing to a 2001. For example my address points to Server IPv6 Address(GIF tunnel remote address if you used the netgate guide) of my HURRICANE ELECTRIC tunnel 2001*::-1

                Does that make sense? If it isn't pointing at that address I would solve for why I lost my default ipv6 gw, not my FW rules.

                1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @SpaceBass
                  last edited by

                  @SpaceBass Do you have two WANs? There is thread https://forum.netgate.com/topic/180377/23-05-update-ipv6-rip

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SpaceBass @SteveITS
                    last edited by

                    @SteveITS said in IPv6 not passing despite rules:

                    Do you have two WANs

                    bingo!
                    Just disabled WAN2 for testing, IPv6 works immediately.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.