• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Access webGui via double stack

Scheduled Pinned Locked Moved IPv6
12 Posts 4 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    empbilly
    last edited by May 25, 2016, 2:18 PM

    Hello guys,

    It's possible to access the pfsense webgui via double stack (ipv4 and ipv6)?

    https://eliasmoraispereira.wordpress.com/

    1 Reply Last reply Reply Quote 0
    • K
      kpa
      last edited by May 25, 2016, 3:00 PM

      Why do you think it wouldn't be possible? IPv6 is just addresses and routes just like IPv4 is when it comes to connectivity.

      1 Reply Last reply Reply Quote 0
      • E
        empbilly
        last edited by May 25, 2016, 4:20 PM

        @kpa:

        Why do you think it wouldn't be possible? IPv6 is just addresses and routes just like IPv4 is when it comes to connectivity.

        Ok. How I config this?

        https://eliasmoraispereira.wordpress.com/

        1 Reply Last reply Reply Quote 0
        • K
          kpa
          last edited by May 25, 2016, 5:27 PM

          You need to have DNS configured so that it returns both A and AAAA records for the name you have chosen for the firewall, let's say firewall.example.tld. A record(s) for the IPv4 address(es) and AAAA records for the IPv6 address(es). For local access you can do that in the DNS resolver with host overrides, otherwise in the authoritative name server for your domain.

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by May 25, 2016, 9:04 PM May 25, 2016, 8:56 PM

            Or just go to your ipv6 address directly.

            Your client does have to have a working ipv6 connection, etc.

            Or sure names work as well, if you setup a AAAA for pfsense to resolve too.  See 2nd attachment via name and using ipv6.

            webguiviaipv6.png
            webguiviaipv6.png_thumb
            vianameipv6.png
            vianameipv6.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • E
              empbilly
              last edited by May 27, 2016, 12:55 AM

              @johnpoz:

              Or just go to your ipv6 address directly.

              Your client does have to have a working ipv6 connection, etc.

              Or sure names work as well, if you setup a AAAA for pfsense to resolve too.  See 2nd attachment via name and using ipv6.

              johnpoz,

              what firewall configuration you did?

              https://eliasmoraispereira.wordpress.com/

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by May 27, 2016, 3:58 AM

                What do you mean what firewall config?

                My lan rules are default any any.. I see no reason to filter MY access.  Now my other networks are very restricted from my lan and other segment.  But there is a antilock out rule anyway.

                What rules do you have?  Did you disable the antilock out?  This allows access to pfsense both ipv4 and ipv6

                antilockrule.png
                antilockrule.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by May 27, 2016, 4:47 AM

                  Your pfsense IPV6 address is most probably a public address.

                  So, if you have allowed access throught the firewall, it will be accessible via the internet from anywhere in the world and by anyone without any port forwarding required.

                  Keep that in mind.

                  Now that thats out of the way, I access mine like this (the numbers here are replaced but the form is correct)

                  https://[2001:111:e111:1::1]/

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by May 27, 2016, 12:25 PM

                    ^ very true.  But out of the box all wan inbound be it ipv4 or ipv6 is blocked.  You would of had to allow such access by creating a rule.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • E
                      empbilly
                      last edited by May 27, 2016, 2:27 PM

                      Guys,

                      My firewall no have access from outside. Only for me. ;D

                      My DNS server have both v4 (A) and v6 (AAAA) entries.

                      Did you disable the antilock out?  This allows access to pfsense both ipv4 and ipv6

                      He was disabled. Now, it's working. It needed only a access rule any to vlan300 address.

                      https://eliasmoraispereira.wordpress.com/

                      1 Reply Last reply Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator
                        last edited by May 27, 2016, 5:00 PM

                        That is a pretty OPEN rule ;)  If your wanting to lock down access to the gui.. And only access it from a specific vlan great.  But that that seems pretty wide if you ask me ;)

                        Glad you got it sorted.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • E
                          empbilly
                          last edited by May 27, 2016, 8:43 PM

                          @johnpoz:

                          That is a pretty OPEN rule ;)  If your wanting to lock down access to the gui.. And only access it from a specific vlan great.  But that that seems pretty wide if you ask me ;)

                          Glad you got it sorted.

                          yea..I will configure a rule according to the link below. :D
                          https://doc.pfsense.org/index.php/Restrict_access_to_management_interface

                          Thanks!!!

                          https://eliasmoraispereira.wordpress.com/

                          1 Reply Last reply Reply Quote 0
                          1 out of 12
                          • First post
                            1/12
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received