Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 all working except Internet

    Scheduled Pinned Locked Moved IPv6
    13 Posts 4 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • awebsterA
      awebster
      last edited by

      What about pinging from WAN interface?

      Diagnostics -> Ping

      Host : 2001:4860:4860::8888
      IP Protocol : IPv6
      Select Source Address : WAN

      –A.

      1 Reply Last reply Reply Quote 0
      • M
        mtist_alby
        last edited by

        No connectivity.

        pfsense_ping.GIF
        pfsense_ping.GIF_thumb

        1 Reply Last reply Reply Quote 0
        • M
          mtist_alby
          last edited by

          I have issues with the gateway. Not sure how this works but I am confident "Pending" is not good. When I restart the apinger service I get the screenshot error in the logs. Anybody have any idea what this is?

          pfsense_gateways.GIF
          pfsense_gateways.GIF_thumb
          pfsense_logs.GIF
          pfsense_logs.GIF_thumb

          1 Reply Last reply Reply Quote 0
          • H
            hda
            last edited by

            ISP connect routing issues ?
            How are you instructed by ISP to connect for IPv6 ?
            Post screen [Interfaces: WAN], verified with them ?

            1 Reply Last reply Reply Quote 0
            • M
              mtist_alby
              last edited by

              Connecting native IPv6. No tunneling, etc. The ISP is 2607:fc00:f000:b000::1 and our pfsense is 2607:fc00:f000:b000::2. We can ping that ISP address from our LAN and the pfsense. We cannot ping anything else on IPv6 Internet. It's almost like pfsense does not know where to send IPv6 since the gateway is "pending" in previous relply. Tests from the internet coming in can ping 2607:fc00:f000:b000::1 but not 2607:fc00:f000:b000::2. We just bought the pfSense SG-2440.

              I also posted LAN interface which is different subnet.

              pfsense_WAN.GIF
              pfsense_WAN.GIF_thumb
              pfsense_LAN.GIF
              pfsense_LAN.GIF_thumb

              1 Reply Last reply Reply Quote 0
              • awebsterA
                awebster
                last edited by

                Try unchecking block bogon networks, maybe your IPv6 prefix is in the bogon list.

                Otherwise, if it still doesn't work there might be a routing problem at the ISP.

                –A.

                1 Reply Last reply Reply Quote 0
                • M
                  mtist_alby
                  last edited by

                  It's not bogon networks and it''s not the ISP. It is the Pfsense firewall. I can ping from internet test sites to the ISP but not the firewall WAN interface. And yes, I have completely dropped the firewall via rules to allow any any ipv6 on the WAN interface. Internally, we can ping the ISP from the LAN. That proves they have a route to us because WAN interface is 2607:fc00:f000:b000::/64 and LAN is 2607:fc00:e001::/64. Look at the pics I sent. Why is the WAN interface "PENDING"?  PFsense is dropping the packets since traceroute do not go beyond it. The hit the Link-local address and stop.

                  1 Reply Last reply Reply Quote 0
                  • D
                    David_W
                    last edited by

                    @mtist_alby:

                    It's not bogon networks and it''s not the ISP. It is the Pfsense firewall. I can ping from internet test sites to the ISP but not the firewall WAN interface. And yes, I have completely dropped the firewall via rules to allow any any ipv6 on the WAN interface. Internally, we can ping the ISP from the LAN. That proves they have a route to us because WAN interface is 2607:fc00:f000:b000::/64 and LAN is 2607:fc00:e001::/64. Look at the pics I sent. Why is the WAN interface "PENDING"?  PFsense is dropping the packets since traceroute do not go beyond it. The hit the Link-local address and stop.

                    Just because there's routing to and from 2607:fc00:e001::/64 (or even /48 - that prefix suggests you might have the entire /48 delegated to you) doesn't mean there's routing to and from 2607:fc00:f000:b000::/64.

                    Some ISPs - mine is one of them - statically allocate IPv6 prefixes but require you to establish leases using DHCPv6 and DHCP-PD before they install the routes to use those prefixes.

                    I would try to ping6 2607:fc00:f000:b000::2 from the the Internet using one of the many sites offering ping6 and traceroute6 facilities. Packet capture the traffic on WAN interface using pfSense's built in packet capture features or the mirroring feature of a managed switch. Mirroring on a switch gives you greater flexibility and more assurance that anything that is supposedly being sent has actually been sent.

                    Does your packet capture show any incoming ICMPv6 traffic? Do you see any replies?

                    I would also endorse awebster's suggestion to uncheck the bogon filter on your WAN interface for now. Whilst your WAN interface block doesn't appear in the bogon filter, it is always best to turn off features that might result in dropped traffic whilst debugging a problem.

                    1 Reply Last reply Reply Quote 0
                    • M
                      mtist_alby
                      last edited by

                      Fixed it. Told all in the first post I am newb with pfsense. On the gateway address I had it as 2607:fc00:f000:b000::1/64. When I changed it to 2607:fc00:f000:b000::1 it went from "pending" to "online".  Thanks for the help.  :)

                      1 Reply Last reply Reply Quote 0
                      • awebsterA
                        awebster
                        last edited by

                        Glad you found it.  Probably would have needed to see the System: Gateways: Edit gateway page to have spotted that.

                        –A.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.