Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suddenly, trouble with HE Net tunnel IPv6 traffic

    Scheduled Pinned Locked Moved IPv6
    12 Posts 4 Posters 743 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TasMot
      last edited by

      IPv6

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @TasMot
        last edited by

        @TasMot

        My crystal ball in on the fritz again, so you'll have to provide some info.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • T
          TasMot
          last edited by

          Dag nabbit, I hate when that happens. It would have been much easier on me if it was still working. (thanks for reminding me that I didn't go back and fill it in after I submitted without any details, my fuzzy brain couldn't figure out how to work the "tags" box).

          So I've been using a Hurricane Electric IPv6 tunnel for the last 5 to 6 years. All of a sudden, my IPv6 traffic is being blocked and slowing down the response time on the entire network.
          This is what is showing up on the dashboard:
          955b9a75-ce76-411b-a451-3b7e4caaa02d-image.png

          This makes it look like traffic is getting out but is unable to return;
          ca54547b-0122-4d04-b95d-55e962b60463-image.png

          Again, this has been working for 5 to 6 years. I am in the process of trying to move to a newer 64bit box because the 32bit version is no longer being updated. In any case, the tunnel is established, as the graph shows, traffic is getting out, but not in. Since somebody will tell me to do this, here it is, checked:
          fd899b3d-09d2-4558-ab3d-dd3d468c4a5d-image.png

          What concerns me is that when it is unchecked, the rules look like this:

          723f9dff-68cf-4c6a-aab2-df51c320a987-image.png.

          Then, when I check the box and save the rules look like this:

          1c7d732f-4500-4dd3-9a38-635756861e51-image.png.

          There are still two rules at the top that say to block all IPv6 traffic.

          How do I get rid of them, they are not rules I put in. Thanks for any help.

          Tom

          1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan
            last edited by

            It happens that one of these shows 'red' : https://tunnelbroker.net/status.php
            Which means : down or heavy load.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            T 1 Reply Last reply Reply Quote 0
            • T
              TasMot @Gertjan
              last edited by

              @Gertjan It shows down all the time now on my end, but the link you posted shows that it should be up. Tom

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan
                last edited by

                You checked https://forums.he.net/ ? Use this one if you suspect a problem with IPv6 from he.net, they are quiet reactive.

                Can you ping / reach the Tunnel Endpoints Server IPv4 Address ?
                Same thing for Tunnel Endpoints Server IPv6 Address ?

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • kiokomanK
                  kiokoman LAYER 8
                  last edited by kiokoman

                  can you show us a screenshot of your rules?
                  can you ping your GIF ipv4 Remote Address ?
                  can the GIF ipv4 remote address ping you ?

                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @kiokoman
                    last edited by Gertjan

                    @kiokoman said in Suddenly, trouble with HE Net tunnel IPv6 traffic:

                    can the GIF ipv4 remote address ping you ?

                    @TasMot To test this : connect to your tunnel.he.net settings. Wipe the (your WAN !) Client IPv4 Address - and re enter it.
                    If it's accepted, your WAN IP is replying to ping and accepted.

                    For myself, never had issues with this - my WAN - IP, and I'm using non static WAN IP's, so I use some DDNS solution proposed by pfSense to update it.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • kiokomanK
                      kiokoman LAYER 8
                      last edited by

                      @TasMot did you solve the problem? i had the same problem yesterday after moving my pfsense to another machine, i spent hours to figure out what the problem was but i was unable to find anything, so i decided to go to bed and when i woke up the problem was gone by itself 🤔

                      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                      Please do not use chat/PM to ask for help
                      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                      1 Reply Last reply Reply Quote 0
                      • T
                        TasMot
                        last edited by

                        I have not gotten it solved yet. Life keeps getting in the way of working on this (it is a home system not a work system). So, I have not made any progress on it. I have rebooted several times and no-joy yet. Thanks, eventually, I will get a chance to supply some of the info requested in the other posts.

                        1 Reply Last reply Reply Quote 0
                        • T
                          TasMot
                          last edited by

                          OK, I thought it was because on the computer I was using I switched it to IPv4 only that things seemed to be working better. However; that wasn't it. I looked at the firewall again to try to decide on a course of action, and surprise, surprise it's working. I have no clue what changed. At this point, my only guess is something at he.net or verizon changed.

                          Thanks for all the help,
                          Tom

                          1 Reply Last reply Reply Quote 0
                          • kiokomanK
                            kiokoman LAYER 8
                            last edited by kiokoman

                            eh i wonder if he.net do some kind of check on the hardware used and it need time to sync after a change, mac address or fingerprint or something 🤔

                            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                            Please do not use chat/PM to ask for help
                            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.