<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[WAN Firewall Rules for IPv6]]></title><description><![CDATA[<p dir="auto">I've been running pfSense since v2.4, and am now up to v2.7.  I just enabled enabled IPv6 for the first time, and I've been having problems with intermittent IPv6 connections.  (Rogers)</p>
<p dir="auto">At this point I only want IPv6 on one VLAN.</p>
<p dir="auto">Should I have any special ICMP rules on either the WAN or the VLAN interface?  I thought that I read somewhere that the lasted version of pfSense add some rules when the interfaces are created, but this doesn't happen when an older configuration is modified.</p>
]]></description><link>https://forum.netgate.com/topic/181955/wan-firewall-rules-for-ipv6</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 17:51:15 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/181955.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 03 Aug 2023 09:03:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to WAN Firewall Rules for IPv6 on Sat, 05 Aug 2023 19:34:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guardian">@<bdi>guardian</bdi></a> said in <a href="/post/1119027">WAN Firewall Rules for IPv6</a>:</p>
<blockquote>
<p dir="auto">Will IPv6 go through a bridge the same way as IPv4?</p>
</blockquote>
<p dir="auto">Yep, as will IPX, NetBIOS, SNA, DECNet, etc..</p>
]]></description><link>https://forum.netgate.com/post/1119079</link><guid isPermaLink="true">https://forum.netgate.com/post/1119079</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Sat, 05 Aug 2023 19:34:25 GMT</pubDate></item><item><title><![CDATA[Reply to WAN Firewall Rules for IPv6 on Sat, 05 Aug 2023 19:33:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guardian">@<bdi>guardian</bdi></a> said in <a href="/post/1119027">WAN Firewall Rules for IPv6</a>:</p>
<blockquote>
<p dir="auto">It seems like the problem is that my DHCP6 isn't passing along the DNS server address.</p>
</blockquote>
<p dir="auto">Is there some reason you're using DHCP6?  NormallySLAAC is fine and there's a setting to enable RDNSS.  Also, thanks to some genius at Google, Android devices don't support DHCP6.</p>
]]></description><link>https://forum.netgate.com/post/1119078</link><guid isPermaLink="true">https://forum.netgate.com/post/1119078</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Sat, 05 Aug 2023 19:33:19 GMT</pubDate></item><item><title><![CDATA[Reply to WAN Firewall Rules for IPv6 on Sat, 05 Aug 2023 05:58:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>, <a class="plugin-mentions-user plugin-mentions-a" href="/user/jknott">@<bdi>JKnott</bdi></a> Thanks guys I really appreciate the support as I'm really struggling with this IPv6 stuff.</p>
<p dir="auto">It seems like the problem is that my DHCP6 isn't passing along the DNS server address.</p>
<p dir="auto">Here is how I have the interface set up:<br />
<img src="/assets/uploads/files/1691212601782-10fed511-bc95-4cc3-921f-3393929e32d0-image.png" alt="10fed511-bc95-4cc3-921f-3393929e32d0-image.png" class=" img-fluid img-markdown" /><br />
and the DHCPv6 Server tab looks like this (nothing in the area below what is shown)<br />
<img src="/assets/uploads/files/1691213190713-5bc10657-00c6-473a-8646-69ec1689069e-image.png" alt="5bc10657-00c6-473a-8646-69ec1689069e-image.png" class=" img-fluid img-markdown" /><br />
I have this connected to through an SG300 switch as an untagged access port which connects to a linux laptop.  The laptop has the wired interface connected with both IPV4/6 set to automatic.<br />
DNS4 got picked up correctly (I force all DNS to go through pfSense}, but the only way I could get IPv6 going was to manually code a DNSv6 server address on the laptop.  Since my endgame is to supply IPv6 for a TV box with limited configurablilty I pretty sure I need to get DHCPv6 passing along a DNSv6 server address. (<a class="plugin-mentions-user plugin-mentions-a" href="/user/jknott">@<bdi>JKnott</bdi></a> do you know if am I mistaken on this?)</p>
<p dir="auto">What I also find interesting is that the interface has 2 gua (both in the delegated prefix).  In the NDP Table, one address has a lease, and the other is permanent.  The permanent address has exactly the same bottom 3 hextets as all the other interfaces, but the 4th hextet is different.  What is going on here?  Also given that I have set IPv6 to configuration None, why do all the other interfaces have an IPv6 address in the NDP Table?  Is this going to cause problems?</p>
<p dir="auto">Will IPv6 go through a bridge the same way as IPv4?  My current IPv4 setup has a couple of VLANs that are trunked to a Tomato router, and I have the ports on the router switch bridged to pick up the VLANs and just pass them to the ports.  Devices get their IP address/DNS directly from pfSense, so the router just acts like a combination managed switch/access point.   Will IPv6 act the same way?  (I'm sure my ignorance is really showing at this point - so any suggestions as to what to google or a reference to read would be much appreciated.)</p>
]]></description><link>https://forum.netgate.com/post/1119027</link><guid isPermaLink="true">https://forum.netgate.com/post/1119027</guid><dc:creator><![CDATA[guardian]]></dc:creator><pubDate>Sat, 05 Aug 2023 05:58:37 GMT</pubDate></item><item><title><![CDATA[Reply to WAN Firewall Rules for IPv6 on Thu, 03 Aug 2023 13:00:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guardian">@<bdi>guardian</bdi></a> said in <a href="/post/1118771">WAN Firewall Rules for IPv6</a>:</p>
<blockquote>
<p dir="auto">the lasted version of pfSense add some rules when the interfaces are created</p>
</blockquote>
<p dir="auto">Pfsense AFAIK has always added the required IPv6 icmpv6 rules needed for ipv6 to function -  been using pfsense since really the get go of pfsense.  And don't recall ever having to add any special rules to get Ipv6 to work.</p>
<p dir="auto">As to when they get enabled, I would think that would only happen when you enable IPv6 on the interface.. You could always check to see what "hidden" rules are on your interfaces.</p>
<p dir="auto"><a href="https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html</a></p>
]]></description><link>https://forum.netgate.com/post/1118797</link><guid isPermaLink="true">https://forum.netgate.com/post/1118797</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 03 Aug 2023 13:00:36 GMT</pubDate></item><item><title><![CDATA[Reply to WAN Firewall Rules for IPv6 on Thu, 03 Aug 2023 12:36:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guardian">@<bdi>guardian</bdi></a></p>
<p dir="auto">I'm not aware of any special rules, however if you don't want IPv6 on an interface, don't enable it there.</p>
]]></description><link>https://forum.netgate.com/post/1118791</link><guid isPermaLink="true">https://forum.netgate.com/post/1118791</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Thu, 03 Aug 2023 12:36:43 GMT</pubDate></item></channel></rss>