Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 'single host' rule selects a /32

    Scheduled Pinned Locked Moved IPv6
    5 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hikingpete
      last edited by

      I'm setting up a rule to allow outside traffic to pass through to a single internal IPv6 address on a handful of ports. When setting up the destination match for the rule, 'Single host or alias' selects and locks '/32' as the CIDR prefix length. In case the problem isn't clear already, allow me to elaborate—to specify a single host on IPv6 needs a CIDR prefix of /128. A /32 will select everything routed to me and more.
      ![pfsense issue.png](/public/imported_attachments/1/pfsense issue.png)
      ![pfsense issue.png_thumb](/public/imported_attachments/1/pfsense issue.png_thumb)

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Try setting it as a Network with a /128

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          That appears to be purely cosmetic. Continue creating the rule. Even if you submit at that point with the /32 showing the correct host rule is created.

          For me when I move on to the destination address that /32 is hidden again.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • H
            hikingpete
            last edited by

            Switching to 'Network' and back to 'Single host or alias' did indeed clear the prefix length. I'm going to operate under the assumption that it's cosmetic, as you suggest Derelict. Thank you both.

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              Thanks for pointing it out:

              https://redmine.pfsense.org/issues/7625

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.