Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Update from 2.2.3 to 2.3.1 blocks access to many websites, but not all

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    11 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Amuzed2pieces
      last edited by

      So my DHCP Server on pfSense is handing out IPV 6 DHCP addresses, but its not set this way to do so. I have checked my other servers and none of them are running DHCP to create a conflict.  How do I ensure DHCP on pfSense is only handing out Ipv4 addresses, when all the check boxes are correctly marked?

      1 Reply Last reply Reply Quote 0
      • A Offline
        Amuzed2pieces
        last edited by

        As a temp solution, I enabled the IPV 6 Pass ALL rule, however, the Firewall is still blocking most Ipv6 outbound traffic.  How do I get this rule to stick?

        1 Reply Last reply Reply Quote 0
        • A Offline
          Amuzed2pieces
          last edited by

          I have through my network and logfiles in some increased detail.  there is nothing in my network of computers configured incorrectly.  pfSense is translating outgoing Ipv4 requests into IPv6 requests.  The universal Allow All outgoing IPv6 rule is not working, as are many other rules using any "all" field.  Outgoing requests are being blocked that should not be.  The only rules that are working are rules specific to each machine and destination.  I was able to get some connection to some sites, but only by adding quick rules for every single outgoing page request.

          I had of course previously turned off all unnecessary services, and restarted the box.  And went through the settings with a fine tooth comb.

          I will have to come back in and work at night to reinstall pfSense 2.2.3 tonight unless someone suggests a version that is better.

          1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan
            last edited by

            @Amuzed2pieces:

            So my DHCP Server on pfSense is handing out IPV 6 DHCP addresses, but its not set this way to do so. ….

            You are aware of the fact that a IPv4 DHCP server doesn't know anything about IPv6 addresses ?
            The IPv6 server is another service (Services >> DHCPv6 Server & RA >> LAN >> DHCPv6 Server), not enabled by default.

            On what interface did you :

            As a temp solution, I enabled the IPV 6 Pass ALL rule
            

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • J Offline
              JorgeOliveira
              last edited by

              I wonder… Is your WAN IPv6 ready (ISP supports it) ?

              On Windows, Internet Explorer will timeout badly if a site has IPv6 support (Ex: Google, Facebook...) and you don't.

              AFAIK, browsers like Google Chrome or Mozilla Firefox will fallback automatically to IPv4 after 1 second, when IPv6 does not respond in that time frame.

              The "fix" would be, on pfSense, disabling (setting to 'None') the IPv6 configuration on WAN and LAN interfaces.

              Regards,
              Jorge M. Oliveira

              My views have absolutely no warranty express or implied. Always do your own research.

              1 Reply Last reply Reply Quote 0
              • S Offline
                spittlbm
                last edited by

                Similar issue reported here

                https://forum.pfsense.org/index.php?topic=112286.0

                1 Reply Last reply Reply Quote 0
                • A Offline
                  Amuzed2pieces
                  last edited by

                  yes, that is what makes it so mystifying

                  @Gertjan:

                  @Amuzed2pieces:

                  So my DHCP Server on pfSense is handing out IPV 6 DHCP addresses, but its not set this way to do so. ….

                  You are aware of the fact that a IPv4 DHCP server doesn't know anything about IPv6 addresses ?
                  The IPv6 server is another service (Services >> DHCPv6 Server & RA >> LAN >> DHCPv6 Server), not enabled by default.

                  On what interface did you :

                  As a temp solution, I enabled the IPV 6 Pass ALL rule
                  
                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    Amuzed2pieces
                    last edited by

                    it is set to "none" already, I verified thinking the very same thing.

                    @JorgeOliveira:

                    I wonder… Is your WAN IPv6 ready (ISP supports it) ?

                    On Windows, Internet Explorer will timeout badly if a site has IPv6 support (Ex: Google, Facebook...) and you don't.

                    AFAIK, browsers like Google Chrome or Mozilla Firefox will fallback automatically to IPv4 after 1 second, when IPv6 does not respond in that time frame.

                    The "fix" would be, on pfSense, disabling (setting to 'None') the IPv6 configuration on WAN and LAN interfaces.

                    Regards,
                    Jorge M. Oliveira

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      Amuzed2pieces
                      last edited by

                      thanks, yes, it seems to be the same issue.  I did have squid running prior to update, but disabling squid doesn't seem to resolve it.

                      @spittlbm:

                      Similar issue reported here

                      https://forum.pfsense.org/index.php?topic=112286.0

                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        spittlbm
                        last edited by

                        Try uninstalling Squid and reinstalling it.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.