Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Openvpn and virgin media v6

    Scheduled Pinned Locked Moved OpenVPN
    13 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      This is version 6 of the IPTV box not an IPv6 question I assume?

      What rules are you using on LAN exactly? Guess work otherwise.

      What error does it show?

      Steve

      1 Reply Last reply Reply Quote 0
      • T Offline
        techy82
        last edited by

        Hi

        Yes it is a cable tv box but it uses the network now instead of the old type with a cable modem built in

        I have a lan rule set as shown, I can use on demand services but for some reason it doesn't download the EPG and reports that it cannot connect? no error is shown on the cable tv box apart from the negotiation error, i have ran the dns test on the cable tv box and that works fine.

        Thanks very much

        ![image test.JPG_thumb](/public/imported_attachments/1/image test.JPG_thumb)
        ![image test.JPG](/public/imported_attachments/1/image test.JPG)

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          Is it using IPv6?

          Try checking the state table for all states from 192.168.0.211. Make sure they are all via WAN and are NAT'd correctly.

          That box streams live TV also? Does it require multicast or a specific VLAN or even 802.1p tags? This could be far more complex than just passing traffic through the firewall.

          Steve

          1 Reply Last reply Reply Quote 0
          • T Offline
            techy82
            last edited by

            it is ipv4

            Thanks i'll check the state table

            The box is for live tv but it does this via coax, it uses the network for youtube, epg, on demand etc

            I have my ps4 setup in the same way, so I wasnt sure if there server trys to connect back to the box

            Thanks again

            1 Reply Last reply Reply Quote 0
            • T Offline
              techy82
              last edited by

              I have had a look at the state table

              and on the lan interface it is showing the ip going straight out to the correct destination

              there is another wan entry showing my openvpn ip going out to the correct destination

              both entries show the same sized packets and bytes?

              Thanks

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                If you are policy routing the traffic then you must have the OpenVPN interface assigned and if that traffic were going over the VPN you would see an outbound state on the OpenVPN interface.

                I expect to see a state on the LAN from your v6box to the public IP and another state on the WAN showing the same traffic but NAT'd to the WAN address for each outbound connection.

                That must be working to some extent to allow on demand services.

                Steve

                1 Reply Last reply Reply Quote 0
                • T Offline
                  techy82
                  last edited by

                  it is really strange, everything works fine on it apart from the negotiation bit, which looks to download the epg every few weeks, could the virgin server be trying to get access back to the box and is being blocked for some reason?

                  it is setup the same way as my ps4 bypass, which works fine

                  Thanks again!

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    It could be though that seems odd if it is.

                    You'd have to try and catch it doing it to find out what's happening. Or find some other useful person who's already done it.  ;)
                    If you can trigger it try catching the states or logging everything it opens with a specific firewall rule. Or run a packet capture filtered for it.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • T Offline
                      techy82
                      last edited by

                      Has anyone else got a virgin media v6 box and a similar issue?

                      I have ran packet monitoring and can't see anything that stands out, if I disable open vpn it works fine but it's a pain every week, it only seems to effect downloading the epg

                      On demand services work fine

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator
                        last edited by

                        You could try reversing your policy routing rules.

                        Add a rule that policy routes everything you need to via the OpenVPN and leaves everything else to go straight to WAN.

                        The only reasonable explanation here is that the EPG is reaching out and being routed via the VPN currently where it cannot reach the server.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          techy82
                          last edited by

                          Thanks I'll give that a go, as it does seem strange how it's only effecting the epg, thanks very much!

                          1 Reply Last reply Reply Quote 0
                          • C Offline
                            conor
                            last edited by

                            @techy82

                            That LAN rule you show a snip of, is there anything above that? If it works with the openvpn off then it really looks like an incorrect rule.

                            200+ pfSense installs - best firewall ever.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.