Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem Loading web pages with ipv6

    Scheduled Pinned Locked Moved IPv6
    15 Posts 5 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @unemployed_ghost
      last edited by

      @unemployed_ghost said in Problem Loading web pages with ipv6:

      P.S. I have those packages at pfsense (snort, pfblockerng)
      P.S.2 I have the DNS resolver works as a resolver. ( i tried with as forwarder, even disabled,)(tried different dns servers, at pfsense or directly to clients) ---> no change :(

      The DNS Resolver should be set up as and kept as a resolver. Actually, the settings were ok when you installed pfSense from scratch. These are proven to work well.

      Not related to your question, but pfblockerng-devel needs the Resolver to work as a resolver.

      General advise : packages like snort and pfblockerng-devel should be activated only when IPv4 and IPv6 works well.

      You do have a firewall rule on each LAN interface that let's pass IPv6 traffic - and ICMPv6 traffic ?
      The default rule on the LAN interface will d the job just fine. To be copied to the other OPTx interfaces = your other LAN type interfaces.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 0
      • U
        unemployed_ghost
        last edited by

        thanks for your answer.

        yes i have a proper rule (Allow ipv4+6 on each lan, protocol ANY port ANY)

        The DNS resolver works as it was by default.( i just made changes to test and reverted them)

        Web sites resolving to ipv6 address just web pages not loading to web browsers :(

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan
          last edited by

          You're using PPOE.
          The word 'MTU' means something to you ?
          Try lowering it - there are ping tests that show you when packets are fragmented (MTU to big) and when you lower the MTU, you'll hit a moment when they stop being fragmented. That will be your perfect WAN MTU setting.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • U
            unemployed_ghost
            last edited by

            I have an MTU of 1492 as my ISP suggests.

            1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @unemployed_ghost
              last edited by

              @unemployed_ghost

              Try something basic. Can you ping the the IPv6 sites? It could be your ISP has a problem, even though you have valid addresses. I ran into that a couple of years ago. Regardless, a browser should try IPv6 first and then IPv4 if it fails. Is that happening?

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              • U
                unemployed_ghost
                last edited by

                i can ping the ipv6 sites.
                browsers not reverting to ipv4 if ipv6 fails not know why. (how to check this?)

                1 Reply Last reply Reply Quote 0
                • kiokomanK
                  kiokoman LAYER 8
                  last edited by

                  and what website did you trying to access for example?

                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                  1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad
                    last edited by

                    what does this show:-

                    https://ipv6-test.com

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan
                      last edited by

                      A browser should :

                      150f3567-a68d-48a8-a5b7-e59f072e5145-image.png

                      Use IPv6 (if it is available** on the device)
                      and if no answer, it should fall back to IPv4 (if available ;) )

                      available means : it should have some sort of IPv6 starting with ff.... or 20..... and it has probably multiple IPv6. Execute "ipconfig /all" or ifconfig on your device to check.
                      It should know about a IPv6 capable gateway, which should point to pfSense - and a DNS (also a the LAN IPv6 of pfSense)
                      Or : if you have a mouse :

                      7bd8f6c3-3a41-4d3e-8357-392c64e32181-image.png

                      and you can check the status also over there which shows everything.
                      All this to check if your device is all set up.

                      On the pfSense side :

                      c0c5781d-e75a-4e8f-b6d5-4515ef095fe5-image.png

                      As I have a IPv4 (only) WAN and a 'special' interface that gives me IPv6, as my ISP doesn't know what IPv6 is ....

                      Another test :
                      http://test-ipv6.com/

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      U 1 Reply Last reply Reply Quote 0
                      • U
                        unemployed_ghost
                        last edited by unemployed_ghost

                        it cant even load ipv6-test.com if idont close ipv6 from lan settings and use ipv4

                        the site keeps loading on browser forever (no error no anything)
                        @NogBadTheBad said in Problem Loading web pages with ipv6:

                        what does this show:-

                        https://ipv6-test.com

                        1 Reply Last reply Reply Quote 0
                        • U
                          unemployed_ghost @Gertjan
                          last edited by

                          @Gertjan

                          test-ipv6.com
                          shows my ipv4 and ipv6 ip
                          and score 10/10

                          1 Reply Last reply Reply Quote 0
                          • U
                            unemployed_ghost
                            last edited by unemployed_ghost

                            suddenly i can open webpages with ipv6 but not all of them
                            i tested disabling ipv4 on my client (pc) network card and leave only ipv6

                            i.e. ipv6-test.com not opening
                            the netgate forum opens fine
                            some other local forum page not opening
                            ipv6.google.com opens
                            youtube opens
                            google.com opens

                            Any clue what is going on?

                            no logs at the firewall
                            i can only see the ip:53 request and the reply after that no logs

                            1 Reply Last reply Reply Quote 0
                            • kiokomanK
                              kiokoman LAYER 8
                              last edited by kiokoman

                              if it is pppoe
                              go to the interface and set MSS to 1452, test and see if it's better.
                              eventually lower the value to 1440

                              ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                              Please do not use chat/PM to ask for help
                              we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                              Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                              1 Reply Last reply Reply Quote 0
                              • U
                                unemployed_ghost
                                last edited by

                                After another call to my ISP the problem finally solved!!!
                                There was nothing from my side!

                                Thank you all for your support.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.