Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense 2.4.4p3 - IPv6 on bridged interfaces not working...

    Scheduled Pinned Locked Moved IPv6
    20 Posts 4 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tomeq82
      last edited by

      fix is old, but without it, there is no link-local addresses for interfaces on the bridge.... and nothing will virtually work at all in that kind o setup.

      Comparing your screens, this is exactly the same setup. Just keep in mind that my "primary" interface LAN has all IP information needed, while LAN2 and LAN3 are bound with LAN as BRIDGE0 (pure L2 bridge, no L3 config)

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by kiokoman

        ah i understand
        i was checking the process
        dhcp is launched like this

        /usr/local/sbin/dhcpd -6 -user dhcpd -group _dhcp -chroot /var/dhcpd -cf /etc/dhcpdv6.conf -pf /var/run/dhcpdv6.pid ix0 ix0.30 ix0.20 ix0.100 igb1
        

        my guess is that it's not serving your LAN2 / LAN3 but only LAN even if it's set as a L2
        but than again.. if it was that, you should have problem even with ipv4 ....
        let's see what we can find out until someone come to the rescue

        did you try any packet capture ?

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8
          last edited by

          advanced configuration of the bridge
          Immagine.jpg

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          T 1 Reply Last reply Reply Quote 0
          • T
            tomeq82 @kiokoman
            last edited by

            @kiokoman it is set, but it doesn't do anything than set the flag "auto linklocal" (patch to make link local address is STILL needed!)

            1 Reply Last reply Reply Quote 0
            • kiokomanK
              kiokoman LAYER 8
              last edited by

              i'm replicating your config on my virtual machine, i have the same behavior.
              ipv4 work on all interface, ipv6 only on LAN

              ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
              Please do not use chat/PM to ask for help
              we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
              Don't forget to Upvote with the 👍 button for any post you find to be helpful.

              1 Reply Last reply Reply Quote 0
              • kiokomanK
                kiokoman LAYER 8
                last edited by kiokoman

                i get an adress if i configure a /64 but dhcpv6 still not working idk if it's a bug or what

                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                Please do not use chat/PM to ask for help
                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                T 1 Reply Last reply Reply Quote 0
                • T
                  tomeq82 @kiokoman
                  last edited by

                  @kiokoman exactly. Only slac works and only for /64 prefixes (which is obvious) DHCPv6 works only on first interface of the bridge

                  1 Reply Last reply Reply Quote 0
                  • kiokomanK
                    kiokoman LAYER 8
                    last edited by

                    i can't find a way out ...
                    what i found with packet capture is that there is no answer from dhcp
                    from console i use struss against the running dhcp. it see request coming from dhclient -4 but it see nothing coming from dhclient -6

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    T 1 Reply Last reply Reply Quote 0
                    • T
                      tomeq82 @kiokoman
                      last edited by

                      @kiokoman when you assign shorter network for each one of the interfaces from the bridge it will work. But will work randomly. This is apparently a bug but...

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Interfaces get a /64. Anything else is nonsense.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • kiokomanK
                          kiokoman LAYER 8
                          last edited by

                          yes, well i was testing with prefix set to /64 for the interface but i don't understand why dhcpv6 is unreacheable

                          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                          Please do not use chat/PM to ask for help
                          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                          1 Reply Last reply Reply Quote 0
                          • T
                            tomeq82
                            last edited by

                            Yes, despite the prefix set (/64 or any else) DHCPv6 doesn't work over bundled interfaces. It should normally as it does for DHCPv4. I have floating rule allowing all traffic in the lan area so it is no issue either here...

                            BTW, shorter prefixes are used widely in the enterprises, this is not nonsense.

                            JKnottJ 1 Reply Last reply Reply Quote 0
                            • JKnottJ
                              JKnott @tomeq82
                              last edited by

                              @tomeq82 said in pfsense 2.4.4p3 - IPv6 on bridged interfaces not working...:

                              BTW, shorter prefixes are used widely in the enterprises, this is not nonsense.

                              Not on the LAN, where /64 must be used. The shorter prefixes are split by routers, eventually winding up at /64s. For example, I get a /56 from my ISP, which I can split up into 256 /64s. I could, if needed, spit it into other prefixes, for routing elsewhere, before getting to the /64s.

                              PfSense running on Qotom mini PC
                              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                              UniFi AC-Lite access point

                              I haven't lost my mind. It's around here...somewhere...

                              T 1 Reply Last reply Reply Quote 0
                              • T
                                tomeq82 @JKnott
                                last edited by

                                @JKnott Correct, nevertheless - in this scenario it doesn't really matter. /64 is not hard limit in any kind (only if you use SLAAC it is "must")

                                JKnottJ DerelictD 2 Replies Last reply Reply Quote 0
                                • JKnottJ
                                  JKnott @tomeq82
                                  last edited by

                                  @tomeq82 said in pfsense 2.4.4p3 - IPv6 on bridged interfaces not working...:

                                  @JKnott Correct, nevertheless - in this scenario it doesn't really matter. /64 is not hard limit in any kind (only if you use SLAAC it is "must")

                                  From RFC4291

                                  " For all unicast addresses, except those that start with the binary
                                  value 000, Interface IDs are required to be 64 bits long and to be
                                  constructed in Modified EUI-64 format."

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  1 Reply Last reply Reply Quote 1
                                  • DerelictD
                                    Derelict LAYER 8 Netgate @tomeq82
                                    last edited by

                                    @tomeq82 well aware that interfaces may be set to prefixes longer than /64 in certain router-to-router links, etc. That is not what is being discussed here. Interfaces with hosts on them need to be /64.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 1
                                    • N netblues referenced this topic on
                                    • N netblues referenced this topic on
                                    • N netblues referenced this topic on
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.