Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    BogonIPV6 not loaded with install

    Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
    7 Posts 3 Posters 294 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      louis2
      last edited by

      After a fresh install among other things, the bogon tables should be loaded. That seems to be the case for the ipv4-bogon table but is not the case for the ipv6-table. Be aware of that!

      After a fresh install go to diagnostics => tables => bogonsv6 and update manually. Should be fixed of course.

      Louis

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by kiokoman

        after a fresh install bogons need to be downloaded,
        under System / Advanced / Firewall & NAT
        Immagine.jpg
        as you can see it can take a week, I think the default is a month to download the list the first time
        moreover the time of download is randomly generated

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • L
          louis2
          last edited by

          That is IMHO not OK at all !! ....

          You want to have bogon protection from the moment the FW become active !! So I stay with my option that this is a severe security bug!

          Louis

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Any copy of bogons included in the installer will be out of date by the time it's used. That is unacceptable for those with IPv6 as that list is constantly changing and new deployments could be blocked out of the box.

            The bogons are automatically downloaded at the end of the setup wizard in the GUI that shows up on your first login. If you don't have them, then you skipped the wizard, so didn't technically complete the installation process.

            They can also be updated manually from Diag > Tables. Otherwise they are updated periodically.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • L
              louis2
              last edited by

              @jimp

              IMHO, that is not the correct sequence.

              To start with, I am not installing from scratch. If I have to install pfSence for some reason I use two USB-sticky's.

              • One being the boot disk containing the build I need to install
              • Second an USB-stick with the config which should be used during setup

              In that scenario, the bogonsV6 table is not updated. I did test that a couple of times (and did report about that earlier).

              In my opinion actions like .e.g. updating bogon tables, should start right after each install sequence, independent of the way that sequence is started or what is next.

              Louis

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                You are free to submit a PR that makes the change.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • L
                  louis2
                  last edited by

                  Jim,

                  I will issue that change request tomorrow.

                  Louis

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.