Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    lan clients periodically drop ipv6 connectivity

    Scheduled Pinned Locked Moved IPv6
    11 Posts 3 Posters 1.3k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      gambit100
      last edited by

      Lan clients appear to lose IPV6 connection after a day or two. Packet capture shows the ping going out the wan but no response is received. General IPV6 connectivity works fine prior to this and no longer works after I verify the ping responses stop.

      • I'using SLAAC for lan IP addresses
      • my ISP provdes a /64 prefix
      • as far as i can tell, the client ipv6 network information seems ok (e.g. addresses, gateways, etc.)
      • the client ipv6 network information is the same before and after this occurs
      • when a lan client stops working, the other lan clients continue to work until they also stop working somtime later
      • when the lan clients lose wan ipv6 access, they still retain ipv6 access on the lan (i.e. they can ping each other using ipv6 addresses)

      I thought maybe the leases were expiring and the renewed leases were perhaps not being correctly renewed but the RA timeout settings use the default values and seem much shorter than the failure times I'm seeing.

      Any ideas on what is happening or how to further diagnose this?

      G JKnottJ 2 Replies Last reply Reply Quote 0
      • G Offline
        gambit100 @gambit100
        last edited by

        I forgot to mention that if I go to Status/Interfaces on the wan interface and click "Release Wan" with "Relinquish Lease" checked and then renew the lease, the clients are once again able to reach ipv6 wan destinations.

        Bob.DigB 1 Reply Last reply Reply Quote 0
        • Bob.DigB Offline
          Bob.Dig LAYER 8 @gambit100
          last edited by

          @gambit100 That is somewhat normal with dynamic IPv6. Name your ISP and country, maybe someone can give more advise.

          G 1 Reply Last reply Reply Quote 0
          • G Offline
            gambit100 @Bob.Dig
            last edited by

            @Bob.Dig Sorry, I should have mentioned this is for Spectrum ISP in the USA

            1 Reply Last reply Reply Quote 0
            • JKnottJ Offline
              JKnott @gambit100
              last edited by

              @gambit100

              Since you're using SLAAC, there should be periodic router advertisements, that provide the IP address etc.. Do you see those? Also, there are no leases with SLAAC. That's a DHCP thing.

              You can see the RAs with Wireshark on a client. You can also use Packet Capture on pfSense, but Wireshark is better.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              G 1 Reply Last reply Reply Quote 0
              • G Offline
                gambit100 @JKnott
                last edited by

                @JKnott I see ICMPv6 traffic on both the lan and wan. I'm not a SLACC or RA pro. I've attached a file with a packet capture on the wan (adding it as text gets flagged as spam by akismet for some reason].ICMPv6.txt

                JKnottJ 1 Reply Last reply Reply Quote 0
                • JKnottJ Offline
                  JKnott @gambit100
                  last edited by

                  @gambit100

                  That file is really not usefull, as it doesn't show the contents.

                  I ran Wireshark, filtering on ICMP6. Here's a list of the packets received, with the RA in the top row:

                  17d2a377-a2cc-4179-aa71-f0ba19566d2d-image.png

                  Here is the contents of that frame, showing the relevant info. Several items can be expanded further:

                  826054d0-050a-4992-890f-b88e7057c4e5-image.png

                  This is the sort of thing you need to understand network problems. You can use Packet Capture, in pfSense, but I find Wireshark is much better. Even if you capture with Packet Capture, you're still better off examining the capture with Wireshark.

                  Now, if you look at the options, you'll see things like assigned addresses and DNS.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  1 Reply Last reply Reply Quote 0
                  • G Offline
                    gambit100
                    last edited by

                    Sorry about the delay...spectrum was having trouble keeping the network up in this area.

                    Here is the summary of messages when I connect a client to the LAN
                    2868a039-938f-4f89-92c1-f740c2ca628a-Summary.png
                    After the client connects, it appears to have the correct network info but can't reach any Ipv6 sites. I then bring the router's WAN interface down and then back up. The client is now able to reach ipv6 sites.
                    360def69-eca2-40d9-b1ff-bae7444d5e1c-client.jpg
                    The contents of some of the messages are below.
                    5f2e3887-bc75-4d43-ac82-9be5a3d38468-100-MLR.png
                    a6a6ff34-1607-49ee-9cb6-520abf3d2a28-101 RS.png
                    3b965758-a6e8-4458-9a80-4054a962a6ea-102 NS.png
                    2eb77f10-f024-4c77-ac8d-2b2e91a16737-104 MLR.png
                    58133235-b272-4fa6-9c10-11aab94c6e01-105 NA.png
                    44c97159-5a49-4517-8362-058e6b365bd6-109 MLR.png
                    1003542a-6e6f-422e-b354-371129c1457d-110 NS.png

                    1 Reply Last reply Reply Quote 0
                    • JKnottJ Offline
                      JKnott
                      last edited by

                      Please do a capture of ICMP6, with at least one router advertisement. Then post the capture file, not just it's contents.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      G 1 Reply Last reply Reply Quote 0
                      • G Offline
                        gambit100 @JKnott
                        last edited by

                        @JKnott attached is a packet capture from pfsense on the WAN which includes a RA at record #231. I've also included a wireshark capture on the LAN for the same time period (approximately).
                        This capture is over the time frame where I bring an android client back on the LAN (WIFI). Before and after the capture period, the client has lost IPV6 connectivity but has IPV4 connectivity before I took it off the LAN and also once brought back on the LAN. The client had IPV6 connectivity a few hours before this but lost that connectivity sometime between that check and a few hours later when I checked again.
                        Client IPV6:
                        fe80::20e0:1065:c8e0:d799
                        2603:9001:7c00:253d:90d9:29d8:f822:ed20
                        2603:9001:7c00:253d:9c7a:de1f:50ee:52e8

                        packetcapture LAN.pcapng packetcapture WAN.pcap

                        G 1 Reply Last reply Reply Quote 0
                        • G Offline
                          gambit100 @gambit100
                          last edited by

                          @JKnott here is another wireshark capture on the LAN that has RA packets from the pfsense router: packetcapture LAN with RA.pcapng

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.