• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Comcast (Xfinity)

IPv6
5
9
715
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    CarAnalogy
    last edited by Jul 4, 2024, 12:58 AM

    I've searched but I've never seen this laid out clearly.

    I have a brand new installation with no default settings changed. Fully up to date. Static IPv4 on WAN, DHCP6, works fine on WAN.

    Default LAN settings unchanged, set to track interface WAN, DHCP6 on, etc.

    WAN gets working IPv6 DHCP address, LAN gets no IPv6 DHCP address. IPv6 tests succeed from firewall.

    I have seen an old post that says the default /64 won't route on Comcast unless the modem is put in full bridge mode. This doesn't seem right.

    Under the DHCP6 server, Spectrum installations show the IPv6 address/64 and everything works fine. Comcast shows 0/64 as the WAN IPv6 address, even though it has a working IPv6 address.

    So here's the part where it's laid out clearly: This is only with Comcast (Xfinity). Spectrum routes a /64 just fine. All default settings. Is this just a Comcast thing? I don't understand what the difference is.

    In 2024 this cannot still be a problem with a default configuration on Comcast, can it?

    Has anyone else experienced this with Comcast (Xfinity)?

    pfSense+ 24.3, Netgate hardware.

    1 Reply Last reply Reply Quote 0
    • C
      CarAnalogy
      last edited by Jul 4, 2024, 1:13 AM

      Couple quick clarifications:

      Comcast distinguishes between "passthrough" and "bridge" mode.

      To use a static IPv4 address, the modem must be placed in passthrough and not bridge. Apparently only dynamic IP addressing works in bridged mode.

      This is fine for IPv6, but these installations need static IPv4. Do I need to specifically tell Comcast to put IPv6 in passthrough mode as well?

      They have enough trouble with IPv4, that would be a fun conversation.

      Other clarification is that the default configuration I was referring to is with Comcast. I'm not implying that the problem is with pfSense, I'm implying that surely by now Comcast would have a working default IPv6 configuration via DHCP. I know pfSense's default configuration works with other cable ISPs.

      1 Reply Last reply Reply Quote 0
      • J
        JonathanLee
        last edited by Jul 4, 2024, 2:09 AM

        Did you configure your dhcp on pfSense to hand out ipv6 to hosts also?

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • R
          rtorres Rebel Alliance
          last edited by rtorres Jul 4, 2024, 6:36 AM Jul 4, 2024, 6:33 AM

          Are you using xFinity equipment or your own? If you put the xFinity Modem/router in bridge mode, this applies to both IPv4 and IPv6 - I don't think you can bridge one or the other.

          I have both IPv4 and IPv6 working from xFinity.

          I had to get my IPv6 LAN interface to track WAN. Then go into the WAN interface and check 'Don't wait for RA' because xFinity doesn't use PPPoE.
          🔒 Log in to view

          If I didn't check that option, my WAN would get an IPv4 and IPv6 from xFinity but I wouldn't be able to get one for my LAN even though it was set to Track WAN.

          After that I went ahead and enabled the DHCPv6 server and Router Advertisment to 'Managed'.

          🔒 Log in to view

          I checked on a few IPv6 test websites and was confirmed that my pfSense was getting a 'Native' IPv6 from xFinity.

          C S 2 Replies Last reply Jul 4, 2024, 7:48 PM Reply Quote 1
          • J
            JKnott
            last edited by Jul 4, 2024, 1:38 PM

            I'm on Rogers and they use the same equipment as Comcast. I have my modem in bridge mode and everything works fine. I get a /56 prefix which I split into individual /64s. The IPTV boxes are connect via Ethernet, though WiFi should also work,

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • C
              CarAnalogy @rtorres
              last edited by Jul 4, 2024, 7:48 PM

              @rtorres Thank you! That was it!

              I checked the do not wait for RA box and changed RA to managed and right away the LAN got an IPv6 address and IPv6 leases started showing up under the DHCP6 status!

              R 1 Reply Last reply Jul 4, 2024, 7:51 PM Reply Quote 1
              • R
                rtorres Rebel Alliance @CarAnalogy
                last edited by Jul 4, 2024, 7:51 PM

                @CarAnalogy said in Comcast (Xfinity):

                @rtorres Thank you! That was it!

                I checked the do not wait for RA box and changed RA to managed and right away the LAN got an IPv6 address and IPv6 leases started showing up under the DHCP6 status!

                Awesome! After spending lots of time and many reinstalls of pfSense, I learned it was as simple as a check mark! Haha

                Glad you got it going. The only thing that sucks is xFinity only hands out /64.... I wish they did at LEAST /60 so I can get IPv6 for Wireguard...

                Oh well, IPv4 only it is for Wireguard clients! 😛

                1 Reply Last reply Reply Quote 1
                • S
                  SteveITS Galactic Empire @rtorres
                  last edited by Jul 4, 2024, 8:27 PM

                  @rtorres said in Comcast (Xfinity):

                  Then go into the WAN interface and check 'Don't wait for RA'

                  Interesting, on a home or business account? I don't have to check that at my home. Though, notably, I'm using my own cable modem not theirs.

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  R 1 Reply Last reply Jul 4, 2024, 8:34 PM Reply Quote 0
                  • R
                    rtorres Rebel Alliance @SteveITS
                    last edited by Jul 4, 2024, 8:34 PM

                    @SteveITS It's a home account with an owned Netgear Nighthawk CM2000.

                    There were times where it would work AS IS, didn't need to specify the WAN for a /64 and no RA check.

                    But most of the times, I'd have to specify /64 and Don't wait RA checked or else I'd get no IPv6 on LAN.

                    Weird...

                    1 Reply Last reply Reply Quote 0
                    4 out of 9
                    • First post
                      4/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.