Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPV6 OpenVPN

    Scheduled Pinned Locked Moved OpenVPN
    18 Posts 4 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott
      last edited by

      Do you also use Rogers for Internet?  They also provide IPv6 there, so maybe enabling it is the way to go.

      One curious thing I noticed was they used 464XLAT, with a 194.0.0.x address for IPv4 over IPv6, but with the Google Pixel 2 I bought recently, the IPv4 address is in  the 25.112.12.x range, so I'm not sure if they're using 464XLAT or NAT with this phone.  In the settings, the current APN is Rogers Internet ltemobile.apn, though Rogers Tethering ltedata.apn is available.  No idea what the difference is.  My old phone, a Nexus 5, also uses ltemobile.apn.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • X
        xman111
        last edited by

        I will have a look at the TCP.  I do not think my ISP supports IPv6.  I am on Rogers for cellular but Shaw for home internet.

        I was hoping it would be a quick fix.  John, you helped me setup my home network and it is working GREAT.  It is a little complicated with about 6 VLAN's and VPN client and server, i really don't want to mess it up.  I really was hoping I could just tick a button on the Openvpn client export or something along those lines.

        Sorry, I forgot to add.. I can connect to my home network with the IPv6, it says connect success, I just cannot do anything..

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          So when you connect on your phone it shows you a ipv6 address for the server..  See example of my phone connected via tmobile..

          As you see it gives an IPv6 address for the server which is not mine… Owned by tmobile
          https://whois.arin.net/rest/net/NET6-2607-7700-1

          I can ping into my network when connected to the vpn.. Without any problems.

          ipv6vpn.png
          ipv6vpn.png_thumb

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • X
            xman111
            last edited by

            no doesn't show Ipv6 server. I know that when following a tutorial of setting up AirVPN with pfsense, one of the steps was to disable Ipv6 within pfsense. maybe I should at least start by enabling it.

            I do have a tunnel with HE but have not set it up. Do I need the tunnel up and running to vpn into my home network with Ipv6?

            1 Reply Last reply Reply Quote 0
            • X
              xman111
              last edited by

              i got the tunnel up and running and it looks like when i connect i get a ipv6 ip.  I wasn't sure how to setup the ipv6 dhcp server.  Also, i still can't do anything once connected but it looks like i am heading the right way.

              Screenshot.png
              Screenshot.png_thumb

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                There is a big difference between talking ipv6 in the tunnel and to ipv6 clients on the other end of the tunnel and using ipv6 as the method of connecting to the server and routing ipv4 through the tunnel, etc..

                Lets forget the whole ipv6 for a bit - you say you connect via IPv4… when your phone is set for ipv6 and ipv4.. But nothing works???  But your server shows you connected.. But you can not ping anything?  What exactly is not working.. Can you ping the end of the tunnel, can you ping pfsense interface on lan side?

                But you say if you set your phone to ipv4 only it works??  What is working exactly?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • X
                  xman111
                  last edited by

                  Hey John, when i set my phone to IPV4/IPV6, i can connect to my home network but some things do not work.

                  When I use OpenVPN for android:

                  -I cannot log into PFsense
                  -I cannot view my cameras
                  -I can browse the internet

                  When I use OpenVPN Connect:

                  -I cannot log into PFsense
                  -I cannot view my cameras
                  -I cannot  browse the internet

                  When I set the phone to IPV4 only, i can do everything.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    When you say you browse the internet you sure your going over the vpn to do that?

                    What specific client are you using - What does your routing table look like on your device when you get connected?  The openvpn connect client has been updated recently and they had some growing pains, etc.

                    I show the current version as 1.2.6

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • X
                      xman111
                      last edited by

                      John,

                      I am not 100% sure I am going over the VPN.  I just assumed because if I turn it off, it works, turn it on and it doesn't work.  I am trying both OpenVPN for Android and OpenVPN Connect.  I just downloaded OpenVPN Connect for Android and it shows 1.1.27.

                      I will have to try to figure out the routing table on the phone, never done that before.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        hurricane electric app will show you that.. give me a sec and take a picture of mine

                        edit… So take a look at your connection info in your vpn app should see what is being handed out.  And the Hurricane electric app can show you the routes going down your tunnel, etc.

                        links to the apps here
                        https://networktools.he.net/

                        ![2018-01-24 15-03-10-1.png](/public/imported_attachments/1/2018-01-24 15-03-10-1.png)
                        ![2018-01-24 15-03-10-1.png_thumb](/public/imported_attachments/1/2018-01-24 15-03-10-1.png_thumb)
                        ![2018-01-24 15-05-41-1.png](/public/imported_attachments/1/2018-01-24 15-05-41-1.png)
                        ![2018-01-24 15-05-41-1.png_thumb](/public/imported_attachments/1/2018-01-24 15-05-41-1.png_thumb)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • X
                          xman111
                          last edited by

                          hey John, on the HE app, what menu is the routes under for you to get that second screen shot, i tried all of them and couldn't find it.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            The one that says routing table - scroll down the menu..

                            ![2018-01-24 16-16-43-1.png](/public/imported_attachments/1/2018-01-24 16-16-43-1.png)
                            ![2018-01-24 16-16-43-1.png_thumb](/public/imported_attachments/1/2018-01-24 16-16-43-1.png_thumb)

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 0
                            • X
                              xman111
                              last edited by

                              hey John, scrolled down the list but mine looks a little different than yours, just installed from google play store.  One thing though I got the tunnel up on pfsense and when i go to test ipv6, everything comes back a check..  Still trying to get the phone working though.

                              Screenshot_20180126-115706.png
                              Screenshot_20180126-115706.png_thumb

                              1 Reply Last reply Reply Quote 0
                              • X
                                xman111
                                last edited by

                                and when i connect, sometimes it looks like the first screenshot, sometimes the second.  Looks like ipv4 sometimes and ipv6 the other. I have no idea what's going on :)

                                Screenshot_20180126-120518.png
                                Screenshot_20180126-120518.png_thumb
                                Screenshot_20180126-120505.png
                                Screenshot_20180126-120505.png_thumb

                                1 Reply Last reply Reply Quote 0
                                • X
                                  xman111
                                  last edited by

                                  anyone have any ideas?

                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    trumee
                                    last edited by

                                    @johnpoz:

                                    T-mobile went ipv6 only on their cells awhile back.. And there was a bit of a learning curve for their gateway from ipv6 to ipv4…  For a short time I had enabled a ipv6 instance of vpn so I could get in with my phone..  But they corrected their problem and I can now vpn in via ipv6 phone connection to my IPv4 IP on pfsense.

                                    Please can you elaborate what did you have to do on the pfsense side to get it working with tmobile ipv6. If I use my vpn server the phone shows my vpn ip for IPv4 but shows tmobile ipv6 address. Is it possible to change pfsense vpn server so that it offers ipv6 address too?
                                    What should be the ipv6 server address akin to 10.8.0.4 in IPv4?

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.