Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple IPV6 Tunnels

    Scheduled Pinned Locked Moved IPv6
    32 Posts 5 Posters 15.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mdpugh
      last edited by

      What are your pfSense configurations for all three tunnel interfaces?  Show IPv6 address, IPv6 gateway, IPv4 endpoints, etc.

      1 Reply Last reply Reply Quote 0
      • Y
        yon
        last edited by

        Me too. I have setup Second ipv6 tunnel via Second WAN, but it is show offline.  :(

        If you are interested in free peering for clearnet and dn42,contact me !

        1 Reply Last reply Reply Quote 0
        • Y
          yon
          last edited by

          I find once creat second ipv6 tunnel in interface,then all ipv6 tunnel link will offline.

          If you are interested in free peering for clearnet and dn42,contact me !

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            I've got two tunnels, one on each WAN. Both are online, and thanks to NPt and some gateway groups, I have working IPv6 multi-wan. Not sure why others might be having issues, but the same things apply as usual.

            1. Make sure you have a distinct tunnel endpoint for each tunnel. For example, one to Chicago, one to Dallas, one to NY, etc. Don't use the same HE.net endpoint for more than one.
            2. Make sure all your WANs allow ICMP from the endpoints
            3. Perhaps add a static route to the remote endpoint node to make sure they use the proper WAN

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • Y
              yon
              last edited by

              @jimp:

              I've got two tunnels, one on each WAN. Both are online, and thanks to NPt and some gateway groups, I have working IPv6 multi-wan. Not sure why others might be having issues, but the same things apply as usual.

              1. Make sure you have a distinct tunnel endpoint for each tunnel. For example, one to Chicago, one to Dallas, one to NY, etc. Don't use the same HE.net endpoint for more than one.
              2. Make sure all your WANs allow ICMP from the endpoints
              3. Perhaps add a static route to the remote endpoint node to make sure they use the proper WAN

              I have check its like you said.

              1. I am sure. and success creat tunnel in tunnelbroker.net.

              2. I think should had do allow ICMP from the endpoints. because tunnelbroker.net endpoint has update.

              3. whats add route ?

              20120329043720.jpg
              20120329043720.jpg_thumb

              If you are interested in free peering for clearnet and dn42,contact me !

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                System > Routing, Routes tab. Add a route for the endpoint IP, pick the WAN you have it attached to, save/apply, repeat for the other endpoints.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • Y
                  yon
                  last edited by

                  @jimp:

                  System > Routing, Routes tab. Add a route for the endpoint IP, pick the WAN you have it attached to, save/apply, repeat for the other endpoints.

                  thank you jimp .  :-*  now it seem is online.

                  it is should write in your wiki doc. I have no find about this.

                  then How I do will second ipv6 subnet address add in LAN?  LAN only can an ipv6 address ?

                  If you are interested in free peering for clearnet and dn42,contact me !

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    You don't use both at once on LAN. You just use one on LAN and setup NPt (sort of like 1:1 NAT) for the WAN routed /64's.

                    See my other doc here:
                    http://doc.pfsense.org/index.php/Multi-WAN_for_IPv6

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • Y
                      yon
                      last edited by

                      @jimp:

                      You don't use both at once on LAN. You just use one on LAN and setup NPt (sort of like 1:1 NAT) for the WAN routed /64's.

                      See my other doc here:
                      http://doc.pfsense.org/index.php/Multi-WAN_for_IPv6

                      OK.  I have done. How I know Whether this success ?

                      If you are interested in free peering for clearnet and dn42,contact me !

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        Just an FYI- databeestje committed some code to automatically add static routes for the gif tunnel endpoints so this should be much easier now.

                        And there have been other routing/gateway improvements as well that will make things work smoother.

                        Recently I had an outage that let me test mine more thoroughly from home and it worked rather well. When my primary WAN+Tunnel were down, I was able to get out over my secondary WAN+Tunnel and when I checked, it was using the prefix I specified in NPt. I'd call it a success.

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • D
                          databeestje
                          last edited by

                          Still need to shore up the input validation on the NPt page, maybe reword some of the text.

                          It also needs a single prefix size drop down. The filter rules don't allow specifying differing sizes which causes filter rules.

                          Should be easy, but lacking a dual wan to test. I need to investigate what the cheapest DSL I can get is.

                          1 Reply Last reply Reply Quote 0
                          • Y
                            yon
                            last edited by

                            now I have setup Multi-ipv6 tunnels in adsl.  using config the Static Routes and NTP show all ipv6 tunnels online.

                            but only out visit work, the second ipv6 can't visit from internet. I want to setup multi-ipv6 network, when one ipv6 slow then change use the second ipv6 for my web server etc.

                            I think should allow setup multi ipv6 network address for the same LAN?

                            I can offer login my router account. if your need it.

                            If you are interested in free peering for clearnet and dn42,contact me !

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.