• 0 Votes
    60 Posts
    24k Views
    bearhntrB
    @bmeeks said in Why do I have to 'Track Interface' on LAN to WAN for IPv6 to work?: The correct way to handle this is to use a separate sub-domain for your internal AD setup. Something like mydomain.com for the public IP domain name and internal.mydomain.com for the Windows AD network in RFC1918 space. That can work. A quick Google search will lead you to a Microsoft best practices and how-to article on this configuration. I highly recommend you restructure you AD configuration to match what is described at this older Microsoft link here: https://social.technet.microsoft.com/wiki/contents/articles/34981.active-directory-best-practices-for-internal-domain-and-network-names.aspx. And here is a slightly newer document showing the same thing: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc772970(v=ws.10). Thanks for the links - one of them I had looked already (as a Google search pointed to it). My public domain name has a - {dash} in it, and apparently my old ass NAS does not like that. I have tried and tried to get it to recognize the domain-name that I first setup as ad.{mypublicdomain} - even a chat session with them for over an hour (nothing worked - they plan no updates to it. It also only does CIFSv1/SMBv1 - FTP (no sFTP) and NFS (but only to Linux boxes) - and some form of iSCSI. I have over 6TB of files and stuff on there, and they "SEAGATE" is not even willing to 'help' me with another NAS to replace it. One of my IT buddies said I should use {mypublicdomain}.loc for my AD/DS...but still going to resolve the - {dash} in there unless I remove it completely. I have considered creating (renaming my public-facing-domain) as only HomeAssistant uses it (well their app on my phone and the ALEXA and GOOGLE links do too). My older post you referenced was assuming the network was IPv4 only with no IPv6 in use. You want to use IPv6, but your ISP is not guaranteeing you a static assignment (they use prefix delegation which means the IPv6 space might change unexpectedly). That's going to be an issue unless you use both ULA and GUA IPv6 addresses. My post also assumed that your Active Directory domain was never going to be accessed from outside. Sounds like that is not what you intend as you mentioned somewhere up above about using some type of home automation with LDAP authentication I believe (unless I'm confusing this thread with another one). Pretty much what I am going to. Every guide that I have read says not to DISABLE the IPv6 on a DC. I am going to leave it at its default settings and let pfSense take care of it. Same for DHCPv4 - going to only do DNS on AD/DS and I am guessing that pfSense is RESOLVER with the FORWARDING option turned on. I would also need a Domain Override setup to point to AD/DS name and IPv4 address as well. Still trying to grasp the REV LOOKUP (setup in pfSense) thing and the HOST OVERRIDE too. The LDAP stuff that I want to do is not really for Home Automation, per se. I do have HomeAssisitant - what I want to do is sign-ins to the various parts with LDAP credentials so that I do not have to keep up with (currently 22) separate login accounts. All of that stuff is 'inside' my pfSense Firewall - only Alexa and Google can access from outside and their app. I got that working, and hoping that I do not have to go through that again. WHEW!!!
  • chrome://net-internals/dns#dns ???

    IPv6 dns resolver dns resolution chromium ipv6
    3
    0 Votes
    3 Posts
    2k Views
    JonathanLeeJ
    @johnpoz I mostly do, except some university classes require we use it. [image: 1688851689003-r.png]
  • 0 Votes
    7 Posts
    2k Views
    GertjanG
    @jbannister SLAAC .... NPT .... Never used these, as they are 'not needed' ( ? ) I followed the pfsense documentation as mentioned above, and was a happy IPv6 user for many years. I advise you to validate the pfsense documentation. There is no SLAAC, even as it promises beautiful things. No NPT. This boils down to : set up a DHCPv6 server on every LAN - with a pool, so you can static DHCP map, as the old DHCPv4 days, your devices. I'm saying this with any in depth knowledge, but : as soon as I read NPT, there are issues .... so, it must be a complex thing. And I tend to keep things "simple", especially my Ethernet networks and everything that is related to it.
  • 0 Votes
    5 Posts
    1k Views
    JKnottJ
    @johnpoz I'm only using 5 of my 256 /64s. However, I think people have learned a lot of bad habits, with having to conserve IPv4 address space. The only place where a smaller prefix makes sense is with a point to point link, where a /127 is all you need.
  • 1 Votes
    4 Posts
    1k Views
    A
    Thanks @jimp for the fix. I've re-tested with 23.01.b.20221221.1946 snapshot and the issue seems to be resolved.
  • Outbound NAT not work if pppoe have been used in WAN

    NAT nat ipv6
    3
    0 Votes
    3 Posts
    1k Views
    A
    solved by add a WAN_IGB0 interface and use it in NAT Outbound. [image: 1670056555355-9b2fcfee-c934-445d-b725-d7da11b2337f-image-resized.png] [image: 1670056599435-66f43f6c-9d85-4177-a228-fc0e29157020-image-resized.png] [image: 1670056514929-784a3a56-3edb-423f-a98d-d4694c7c0e68-image-resized.png]
  • Randomly losing IPv6 DHCP-PD from ISP

    IPv6 ipv6 dchpv6
    1
    1 Votes
    1 Posts
    572 Views
    No one has replied
  • Ipv6 configured but unable to ping internet

    IPv6 ipv6 ovh wan
    20
    0 Votes
    20 Posts
    5k Views
    S
    @lolo54000 said in Ipv6 configured but unable to ping internet: In my ovh account i have 6 physical server and each have it's own ipv4 and it's own ipv6 /64 ipv6 To have a router in front, you would need: an IPv6 for the router WAN an IPv4 for the router WAN OVH to route your other IP addresses to those IPs your servers to use your router LAN IPv4/IPv6 as their gateway It sounds like they are simply not set up to handle a router, like you're asking for.
  • Getting IPv6 SLAAC to work in my network

    IPv6 ipv6 slaac gua ula stateless
    31
    0 Votes
    31 Posts
    6k Views
    I
    @mariog Thanks for the link. I'll keep an eye on this.
  • 0 Votes
    2 Posts
    1k Views
    NightlySharkN
    So, I found a GUI "bug". I had correctly set the prefix ID's in the "Tracked Interface" for each VLAN, but at the RA page, I mistakenly reinserted the prefix ID in the fields that are for static (full, not delegated) prefixes. Removed the static prefixes and everything now works. GUI should not let you enter static prefixes on a tracked interface, aside from fc00 or fd. And if it does, it should check if they are correct. One of the prefixes was ::1/64.
  • LWLcom DSL IPv6 über DHCP kein renewal

    Deutsch ipv6
    2
    0 Votes
    2 Posts
    985 Views
    JeGrJ
    @unbekannt3 said in LWLcom DSL IPv6 über DHCP kein renewal: Die Sense bekommt eine Adresse aus einem /64er Subnetz am WAN Interface zugewiesen und darauf dann mein /60er Subnetz geroutet, beides mit einer lifetime von 300. Warum? 300er Lifetime hört sich für mich nach Quatsch an und viel zu kurz. Wenn ich da auf bspw. einer Fritzbox nachsehe, was da das Default Verhalten ist bei DHCP6 dann sehe ich da Zeiten in der Größenordnung 48h als Lease Time runtertickern. Zumindest wesentlich mehr als 300s. Das hört sich da schon entweder nach einer seltsamen/falschen Konfiguration an oder dass der ISP da Murks macht. Da würde ich nochmal beim ISP selbst versuchen jemand technischeren an die Strippe zu bekommen, denn das klingt nicht gerade sinnvoll. Cheers \jens
  • 0 Votes
    1 Posts
    726 Views
    No one has replied
  • usb iphone ipv6 WAN dhcp6

    Routing and Multi WAN usbconfig ipv6 dhcp6 interface
    1
    0 Votes
    1 Posts
    801 Views
    No one has replied
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • BT Business FTTP IPv6 help

    IPv6 bt business ipv6 fttp pfsense
    12
    0 Votes
    12 Posts
    3k Views
    F
    @dwren78 Hmmm this is frustrating, could you describe what is happening in more detail? I am confused why it works when you have the Smarthub ahead of the pfsense router. I am not familiar with configuring the smart hub as a bridge, so where is the pppoe authentication done, in the smarthub or pfsense? Are you getting a v4 address? Is the v6 interface up? Are you getting a link-local v6 address? Dumb question, but I am going to ask it anyway, are you using your bt business pppoe username/password? cheers F
  • IPv6 Gateway monitoring broken in 2.6.0?

    IPv6 ipv6 dpinger gateways
    21
    0 Votes
    21 Posts
    5k Views
    JKnottJ
    @kimble said in IPv6 Gateway monitoring broken in 2.6.0?: Maybe it's clever enough to bind to a LAN address in that instance? I've no idea. You have to specify a source address by using the -S option in ping. I just did it, using my LAN global address.
  • All IPv6 Home Network

    Official Netgate® Hardware macos duid dhcp ipv6
    14
    0 Votes
    14 Posts
    3k Views
    NogBadTheBadN
    @quasaur said in All IPv6 Home Network: Enjoying my SG-1100. I wish to switch everything to IPv6 using each host’s MAC as the last three segments of the interface ID. Unfortunately, it appears that pfSense requires the DUID of a DHCP client to assign it a static address, and no one on the planet seems to know how to get that from a MacBook running Monterey…not even Apple! PLEASE HELP! [image: 1645127681956-screenshot-2022-02-17-at-19.49.55.png] Run the following from the terminal:- sudo plutil -p /var/db/dhcpclient/DUID_IA.plist andyk@mac-pro ~ % sudo plutil -p /var/db/dhcpclient/DUID_IA.plist { "DUID" => {length = 14, bytes = 0x000100012743ca95003ee1c1af07} "HostUUID" => {length = 16, bytes = 0x8d4aa329f7175da2ac8fc3e713f04f63} "IAIDList" => [ 0 => "en0" 1 => "en1" 2 => "en2" ] } andyk@mac-pro ~ %
  • IPv6 list generated IPv4 rule

    pfBlockerNG pfblockerng ipv6
    5
    0 Votes
    5 Posts
    1k Views
    J
    @rvjr said in IPv6 list generated IPv4 rule: ok, that's weird. No I'm using the standard pfBlockerNG 2.1.4_26 on pfSense 21.05.2-RELEASE. I'll try switching the list action and see if that makes any difference. Your problem is that you are using an old unsupported version of pfBlockerNG. The maintainer of pfBlockerNG, @BBcan177, does not recommend the use of that old version. The -devel version has been in use for 2 to 3 years now and is very stable and the only version currently being updated. Make sure that the box is checked to save your current settings and then uninstall your current version of pfBlockerNG 2.1.4.26 and then install the -devel version 3.1.0_1. This should take care of the issues you are seeing, if not, post back to the forum and someone will help you.
  • Weird dpinger and IPv6 issue?

    IPv6 dpinger ipv6 dpinger issues packetloss
    28
    0 Votes
    28 Posts
    5k Views
    JKnottJ
    @pfsensation Yep, it's green and showing online.
  • Ipv6 adresses from the same home?

    IPv6 ipv6 routing
    11
    0 Votes
    11 Posts
    2k Views
    T
    Thank you all for your answers and discussion. Unfortunately it’s a “real problem”. There is a person who I trusted before but this person is now in suspicion for a bad deed. While changing my passwords (way too late I did that) I saw a log in to my personal account that was definitely not made by myself. It’s possible that that person had an auto login but I also had the hunch this person spied my personal mailbox (which is of great concern because I was in touch with official entities). Well I think the chance is quite low I forgot to logout somewhere and that that device has the same /56 prefix as that person. So I can just hope that was an auto login or that person did not found anything. Thank you all.