• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[solved] IPv6 Traffic not routed via IPsec

Scheduled Pinned Locked Moved IPsec
2 Posts 1 Posters 623 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    b_chris
    last edited by b_chris Dec 26, 2022, 10:44 AM Dec 26, 2022, 10:28 AM

    Hi,
    I'd like to test to handout IPv6 GUAs to my IPSec clients. Therefore I configured IPsec to use also an IPv6 address pool (xxxx:xxxx:xxxx:xx80::/64 is currently not in use of cause):
    Bildschirm­foto 2022-12-26 um 11.17.06.png
    (currently I have a dynamic changing prefix, but that's another topic, see other post). This works. My clients get an IPv6 GUA, that looks just fine and also in the pfSense GUI I can see the expected information:
    Bildschirm­foto 2022-12-26 um 11.18.00.png
    The strange thing is: I can't reach anything via this address. Of cause the firewall rules do allow traffic to my home net and also to the internet. But on the client I'm always running into timeouts when using IPv6 (ping6, ssh, ...).
    I also included a "catch all" firewall rule in the IPSec tab at the end to reject and log everything, that wasn't allowed. I don't see any log entries in the firewall log.
    This leads me to the conclusion, that pfSense probably doesn't know, how to route die IPv6 IPsec traffic?!? What am I missing?

    I also added IPv6 support to OpenVPN. This works just fine without any additional configuration.

    Thanks

    B 1 Reply Last reply Dec 26, 2022, 10:43 AM Reply Quote 0
    • B
      b_chris @b_chris
      last edited by Dec 26, 2022, 10:43 AM

      Ok, I was stupid.
      My Phase2 was not configured correctly.
      "Local Network" was set to ::/128 when it should have been ::/0

      It's now working

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received