Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 Not able to ping WAN to LAN

    Scheduled Pinned Locked Moved IPv6
    14 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      And what are the rules on your wan.. Do allow ipv6 through to this clients IP

      Out of the box pfsense is not going to allow anything into wan… So no you would not be able to ping through to ipv6 unless you allow it.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • M
        manishchawla2017
        last edited by

        WAN Also IPv6 any is allowed
        I am not able to send any packet from LAN to WAN
        Nor WAN to LAN on IPv6

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Can your client ping your lan ipv6 IP?  Your going to need to post up your rules for your lan and your wan if you want someone to help you point out what your doing wrong.

          Out of the box lan allows any any ipv6 on lan… So if your client is getting a vlan ipv6 on your lan segment it should be able to ping your lan ipv6 and your wan ipv6.

          From the outside.. Nobody would be able to ping your wan ipv6 or your clients behind it on your lan unless you allow for it.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott
            last edited by

            What does netstat -r show for the default route on IPv6?  It should be a link local address, as that's what IPv6 normally uses for routing.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • M
              manishchawla2017
              last edited by

              I am able to ping following from my machine

              1. LAN gateway ie LAN port of Pfsense
              2. WAN Port of pfsense from LAN
              3. WAN port of pfsense from Internet

              I am not able to ping

              1. anything other than WAN port  such as 2001:4860:4860::8888 ( Google DNS is not ping)
              2. I am not able to ping my LAN port from Internet
                even though policy is IPv6 any to any
              1 Reply Last reply Reply Quote 0
              • M
                manishchawla2017
                last edited by

                ubuntu@ipv6testBed:~$ ip -6  route show
                2001:df7:7640:bc4a::/64 dev ens18  proto ra  metric 100  pref medium
                fe80::/64 dev ens18  proto kernel  metric 256  pref medium
                default via fe80::21a:64ff:fe78:e820 dev ens18  proto static  metric 100  pref medium

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  What policy?? Post up your rules..  Both lan and wan

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • M
                    manishchawla2017
                    last edited by

                    1. Yes my Client is able to ping both LAN port of pfsense and WAN port of pfsense but nothing beyond it
                    2. If i login to pfsense, I am able to ping anything on Ipv6 from pfsense shell

                    @johnpoz:

                    Can your client ping your lan ipv6 IP?  Your going to need to post up your rules for your lan and your wan if you want someone to help you point out what your doing wrong.

                    Out of the box lan allows any any ipv6 on lan… So if your client is getting a vlan ipv6 on your lan segment it should be able to ping your lan ipv6 and your wan ipv6.

                    From the outside.. Nobody would be able to ping your wan ipv6 or your clients behind it on your lan unless you allow for it.

                    1 Reply Last reply Reply Quote 0
                    • M
                      manishchawla2017
                      last edited by

                      @johnpoz:

                      What policy?? Post up your rules..  Both lan and wan

                      ![Screen Shot 2018-05-04 at 8.19.25 PM.png](/public/imported_attachments/1/Screen Shot 2018-05-04 at 8.19.25 PM.png)
                      ![Screen Shot 2018-05-04 at 8.19.25 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2018-05-04 at 8.19.25 PM.png_thumb)
                      ![Screen Shot 2018-05-04 at 8.18.55 PM.png](/public/imported_attachments/1/Screen Shot 2018-05-04 at 8.18.55 PM.png)
                      ![Screen Shot 2018-05-04 at 8.18.55 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2018-05-04 at 8.18.55 PM.png_thumb)

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        where did you come up with those addresses.  I don't show any AS number for your wan IP

                        No AS number was found for 2001:df7:7640:a000::6
                        No AS number was found for 2001:df7:7640:bc4a::1

                        You can not just make numbers up?  And use them…

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • M
                          manishchawla2017
                          last edited by

                          Don't worry I have changed my IP while posting query for security reasons, my actual ip is routable and has a very clear route-object

                          @johnpoz:

                          where did you come up with those addresses.  I don't show any AS number for your wan IP

                          No AS number was found for 2001:df7:7640:a000::6
                          No AS number was found for 2001:df7:7640:bc4a::1

                          You can not just make numbers up?  And use them…

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Well impossible to help you without being able to see if traffic gets to your wan or not, etc.  In a traceroute.

                            PM me your actual IPs

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • M
                              manishchawla2017
                              last edited by

                              It is reaching upto my WAN port of Pfsense
                              I am not authorized to share IP details

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.