Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    BT Full Fibre only partially functioning via pfSense Router

    Scheduled Pinned Locked Moved General pfSense Questions
    27 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      That's fine. How do you have the WAN and LAN configured for IPv6 though?

      It's probably at least mostly corret since it has pulled a prefix and is using it on the LAN.

      Go to Diag Ping in pfSense and try to ping out using IPv6 there. Does that work? If not what error is shown?

      1 Reply Last reply Reply Quote 1
      • brookheatherB
        brookheather @MattDownes89
        last edited by

        @MattDownes89 I have my IPv6 Prefix ID set to 1 and you need to set the Prefix Delegation Size to 64 (and select Enable DHCPv6 server on LAN interface). You shouldn't need to change any other options though personally I set the IPv6 DHCP address pool range from ::d:1 to ::d:ffff so it's obvious that the IPv6 address comes from the DHCPv6 server.

        M 1 Reply Last reply Reply Quote 1
        • M
          MattDownes89 @brookheather
          last edited by

          OK, so here's the WAN Settings:

          41d838c0-68d1-4097-a841-8fe6a405d81c-image.png
          7907cef4-fd93-4bba-8e20-710cff1912cc-image.png

          And the LAN Settings:

          dd01bdae-c1b6-419b-bb46-8442e97541c2-image.png
          14ac47f2-39a1-4d26-b073-0db2ef44dfbd-image.png

          And then the DHCPv6 Settings:

          f19d9d99-4c24-409e-be2f-b1f4b3db64a5-image.png
          027ed63d-1b6c-4e2d-a8de-dcefaa3839a2-image.png

          I have no doubt I am missing something simple somewhere, I think I have probably caused myself more issues by trying to update what I had rather than starting fresh with the new ISP.

          @stephenw10 Not sure what address to Ping to test? But if I ping the ISPs IPv6 address that's successful so it's getting that far!

          stephenw10S 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator @MattDownes89
            last edited by

            You should be able to set the WAN to pull a /56 prefix so you can have addresses on more than one internal interface.

            But if you can ping a v6 address from pfSense itself this is almost certainly an issue with assigning v6 addresses to the clients.

            Can we assume that your LAN side clients are not getting an IPv6 address at all currently?

            M 1 Reply Last reply Reply Quote 1
            • F
              ficti0n851
              last edited by ficti0n851

              Hi, not sure if you managed to get much further but heres what I got for LAN:

              lan-1.png
              lan-2.png

              This is for WAN:

              wan-1.png
              wan-2.png
              wan-3.png

              This is Router Advertisement as I dont use DHCPv6:

              ra-1.png
              ra-2.png

              PS, I noticed your DHCPv6 is allocating a /56, I only allocate /64, maybe that doesnt help.

              PPS, make sure you refresh your clients NIC to get new addresses.

              fic.

              1 Reply Last reply Reply Quote 1
              • M
                MattDownes89 @stephenw10
                last edited by MattDownes89

                @stephenw10 I have set to /56 as suggested.

                I think it is an issue on the LAN side - if I do an 'ipconfig /all' I can see my Laptop has picked up an IPv6 Address and if I look at DHCPv6 Leases I can see it in there as the only IPv6 Device on the list, but it just shows as idle/offline whereas in the normal DHCP list for IPv4 I can see all the devices on my network and the vast majority have a green tick and say they're online.

                0029a919-47a1-4e5a-912e-452301ce1fe9-image.png

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Hmm, what pfSense version is that?

                  That client still has the IPV6 address.

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    MattDownes89 @stephenw10
                    last edited by

                    @stephenw10 looks like I'm up to date:

                    e5882611-bd4b-476e-bd44-237436354907-image.png

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      You are not. Probably wouldn't make any difference for this but you should upgrade anyway. Try running at the command line : certctl rehash

                      Then recheck. You should see 2.7.2 available.

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        MattDownes89 @stephenw10
                        last edited by

                        @stephenw10 - that did it, will update and see if anything changes!

                        M 1 Reply Last reply Reply Quote 1
                        • M
                          MattDownes89 @MattDownes89
                          last edited by

                          OK, I am now on 2.7.2, looks subtly different and a few more devices seem to have got IPv6 Addresses but all showing as Offline in the list:

                          1aa93857-6387-43f9-9e78-f195123055a3-image.png

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Hmm, those devices are actually present in the ARP table?

                            Are they all Windows clients?

                            M 1 Reply Last reply Reply Quote 0
                            • M
                              MattDownes89 @stephenw10
                              last edited by

                              @stephenw10 so the bottom one in that screenshot was my Win11 Laptop I am on now, not sure what devices the other two were, however, this morning I have a different IPv6 Address if I do IP Config on here and it's not showing up in the leases - my laptop is showing the correct IPv4 & IPv6 addresses for pfSense as the DNS Servers.

                              If I do arp - a on the pfSense box it doesn't show any IPv6 addresses but I do see the IPv4 for my laptop in the list.

                              I don't know if any of that helps?

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                They won't show in the ARP table that only ever shows v4 addresses. But do those clients show there at all?

                                Check Diag > NDP Table to see the current v6 devices.

                                M 1 Reply Last reply Reply Quote 0
                                • M
                                  MattDownes89 @stephenw10
                                  last edited by

                                  @stephenw10 yes, my laptop is in the ARP Table with it's IPv4 IP.

                                  NDP Table doesn't show the IPv6 address that my laptop is showing under IP Config.

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Hmm, how are the clients configured for IPv6?

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.