Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 and IPSec VPN

    Scheduled Pinned Locked Moved IPv6
    8 Posts 4 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sjdurand
      last edited by

      Hi,

      I have 2 pfsense firewalls.

      Both pfsense firewalls have an ipv4 site to site to each other. All traffic works.

      I have added an IPv6 HE Tunnel to each of the pfsense firewalls. IPv6 traffic works fine. When i add some rules i can get from site A to B via ipv6 and everything works.

      If i create an IPv6 IPSec VPN tunnel between Site A and B (and allow all IPv6 traffic between A and B). The tunnel will work but not for all traffic. I can use ping/traceroute/smtp for example but i cannot use SMB.

      Somebody got some tips?

      Running on 2.1.2-RELEASE

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        It could be an issue with packet fragmentation/MTU.

        Try setting MSS Clamping for VPNs on System > Advanced, Misc tab

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • S
          sjdurand
          last edited by

          I did change the MTU to 1320 and still have the problem.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            On both sides?

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • S
              sjdurand
              last edited by

              Changed it at both sides

              1 Reply Last reply Reply Quote 0
              • M
                mix_room
                last edited by

                I just wan't to mention that I have the same problem.

                Traffic works fine without the IPSec tunnel, but as soon as it comes up, connectivity disappears.

                I am running 2.1.3-RELEASE on one end, and 2.1-RELEASE on the other.
                Native IPv6 on both ends, no HE-tunnels or such.

                1 Reply Last reply Reply Quote 0
                • Z
                  Zeon
                  last edited by

                  +1 here. 7 PFsense routers running IPv6 and IPSEC. Ping etc. works so you think its working fine but MySQL over port 3306 is facing timeouts, active directory replication doesn't work etc.

                  1 Reply Last reply Reply Quote 0
                  • M
                    mix_room
                    last edited by

                    I set the MSS to 1000, and then it started working.
                    No idea why it has to be so low, and it could probably be a bit higher, but I haven't been bothered to check.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.