Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    only ICMP protocol works !!!

    Scheduled Pinned Locked Moved IPv6
    19 Posts 5 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott @tchello
      last edited by

      @tchello said in only ICMP protocol works !!!:

      My WAN Static: 2001:XXXX:XXXX:9f00::2/56 - Pfsense

      If they provide a WAN address, it normally has a /128 prefix length. You would also have a /64 on a link local address. You'd use the /56 to request the prefix size, if that's what the ISP provides.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      T 2 Replies Last reply Reply Quote 0
      • T
        tchello @johnpoz
        last edited by

        @johnpoz
        Thank you John

        They gave it to me like this:

        The block was configured and the ping is ok. Please validate with the client by providing them with the configured IPs as below.

        ipv6 from 2001:xxxx:xxxx:9F00::2/56
        IPv6 gateway 2001:xxxx:xxxx:9F00::1
        ipv6 dns server 2804:7F4:2002:1005::98
        ipv6 dns server 2804:7F4:2002:1005::99”

        So am I wrong in the configuration?

        Sorry, I'm not experienced in setting IPv6 statically.

        johnpozJ 1 Reply Last reply Reply Quote 0
        • T
          tchello @JKnott
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • T
            tchello @JKnott
            last edited by

            @JKnott

            This is what the provider gave me

            The following is the return:
            “The block has been configured and the ping is ok. Please validate with the client by providing them with the configured IPs as below.

            ipv6 from 2001:xxxx:xxxx:9F00::2/56
            IPv6 gateway 2001:xxxx:xxxx:9F00::1
            ipv6 dns server 2804:7F4:2002:1005::98
            ipv6 dns server 2804:7F4:2002:1005::99”

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @tchello
              last edited by johnpoz

              @tchello yeah that is not right at all.. That is fine if they gave you a /56 that they route to you.. But there would be transit network.. You might sometimes see the first prefix out of the /56 as the transit.

              Try setting that first prefix as /64 and then use the next prefix of /64 on your lan.

              So your lan side interface would be 2001:xxxx:xxxx:9f01::1/64

              That info is pretty bad.. Which is typical of ISP that really have no business doing IPv6 because they have no real clue how to do it ;)

              edit:
              You asked for a /56 I take it and that is the info you got. Which would work if all your devices were directly connected, but still wrong because you wouldn't use a /56 in that scenario. But some level 1 guy plugged the ticket into some ip allocation form and that is what it spit out..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              T 1 Reply Last reply Reply Quote 0
              • T
                tchello @johnpoz
                last edited by

                @johnpoz
                Ok John, I will todo tomorrow, I talk to u

                Thank a lot

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @tchello
                  last edited by

                  @tchello not saying that will work.. But I have seen this method used before.. Its not really a good way to do it, but maybe it will work for you.. Good luck, let us know.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  T 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @tchello
                    last edited by

                    @tchello said in only ICMP protocol works !!!:

                    My WAN Static: 2001:XXXX:XXXX:9f00::2/56 - Pfsense
                    My GW Static :2001:XXXX:XXXX:9f00::1/56 - Pfsense

                    WAN IPv6 ....:2 and gateway ...:1 Humm, is this a huricane IPv6 tunnel setup ?

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • T
                      tchello @johnpoz
                      last edited by

                      @johnpoz Good day
                      I did this setup
                      WAN: 2001:XXXX:XXXX:9F00::2 /64
                      LAN : 2001:XXXX:XXXX:9F01:f0ca:4 /64

                      ping OK!
                      any protocol outside this -> failed

                      If this setup is what you told me, then the fault is with the provider. I'm trying to contact them.

                      Thanks a lot brow

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @tchello
                        last edited by

                        @tchello yeah like I said it could work that way.. But then again not sure what they are thinking with just giving you that info.. It is not how you would allow a user to use a /56 behind a router. Their info would be for if that /56 was directly attached, and not behind a router. Which you would never do - because its pointless to be honest.. If your only going to directly attach to the isp, a /64 is more than you would ever need.. And you using a /56 over a /64 gets you nothing. It defeats the whole point of /56 that you could break up into multiple /64s

                        To be honest since your isp seems clueless, would be just a use a tunnel from HE - they will give you a /48 that never changes, and even allow you to create PTRs for the space - something I highly doubt your isp would allow you to do.

                        Are they charging you for this /56?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        T 1 Reply Last reply Reply Quote 0
                        • T
                          tchello @johnpoz
                          last edited by

                          @johnpoz

                          Are they charging you for this /56?
                          I'm client for them, have a LP dedicated a far long time. Then now I need it Ipv6 for many cameras that I cant access because the provider only give me cgnat ip . Then I asked about ipv6 to him. Give me without charge.

                          Here in Brazil is known Vivo
                          Captura de tela de 2025-05-28 09-47-10.png

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @tchello
                            last edited by

                            @tchello What I can tell you is the info they gave you will not work.. They have given you a /56 that is directly attached to them - not routed to you that you can use on prefixes behind a router.

                            And directly attaching a /56 is borked.. They need to route the /56 to you - so that you can then break up that /56s to use on your networks behind pfsense.

                            There needs to be a transit network to route to you - be it a /64 or a /128 or even just link-local.. But you can not put a /56 on an interface and expect it to work.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            T 1 Reply Last reply Reply Quote 0
                            • T
                              tchello @johnpoz
                              last edited by

                              @johnpoz
                              Dear John As I suspected, the error was with the provider, after my request they solved the IPv6 problem. I am very grateful to you for your support.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.