Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    add Enabling IPv6 Source Address Validation support

    Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
    3 Posts 2 Posters 919 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • yon 0Y
      yon 0
      last edited by

      i have no find about this how do it Enabling IPv6 Source Address Validation support in pfsense system?

      After testing, I am still vulnerable to false ip attacks. And received notification of security breach email.

      from them sent mail. https://imaal.byu.edu/dsav/faq.html

      only see this

      Anti-spoofing Rules
      pfSense uses the antispoof feature in pf to block spoofed traffic. This provides Unicast Reverse Path Forwarding (uRPF) functionality as defined in RFC 3704. The firewall checks each packet against its routing table, and if a connection attempt comes from a source IP address on an interface where the firewall knows that network does not reside, it is dropped. For example, a packet coming in WAN with a source IP address of an internal network is dropped. Anything initiated on the internal network with a source IP address that does not reside on the internal network is dropped.
      
      1 Reply Last reply Reply Quote 0
      • viktor_gV
        viktor_g Netgate
        last edited by

        Please create a feature request https://docs.netgate.com/pfsense/en/latest/development/feature-requests.html

        see pf.conf(4):

        Addresses can be specified in CIDR notation (matching netblocks),
        	   as symbolic host names, interface names or interface	group names,
        	   or as any of	the following keywords:
        
        	   any		   Any address.
        	   no-route	   Any address which is	not currently routable.
        	   urpf-failed	   Any source address that fails a unicast reverse
        			   path	forwarding (URPF) check, i.e. packets coming
        			   in on an interface other than that which holds the
        			   route back to the packet's source address.
        	   <table>	   Any address that matches the	given table.
        
        yon 0Y 1 Reply Last reply Reply Quote 0
        • yon 0Y
          yon 0 @viktor_g
          last edited by

          @viktor_g

          i done it. https://redmine.pfsense.org/issues/11369

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.