<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place.]]></title><description><![CDATA[<p dir="auto">I am trying to get my LAN IPv6 to route properly over my WAN IPv6 and seem to be running into a wall.</p>
<p dir="auto">I can ping IPv6 addresses from the wan interface of the firewall using Diagnostics -&gt; ping but I can do the same with the LAN interface.</p>
<p dir="auto">If this is something obvious I apologies I just can't seem to formulate the right question to find the answer</p>
<p dir="auto">Version info:<br />
PfSense CE 2.7.2</p>
<p dir="auto">ISP info<br />
Rogers (former Shaw)</p>
<p dir="auto">Using DHCPv6 to pull IPv6 successfully<br />
<img src="/assets/uploads/files/1721433194499-f42e9c78-56e9-4710-ac78-6011bec89f4d-image.png" alt="f42e9c78-56e9-4710-ac78-6011bec89f4d-image.png" class=" img-fluid img-markdown" /><br />
With "Request a IPv6 prefix/information through the IPv4 connectivity link" enabled<br />
With "DHCPv6 Prefix Delegation size" set to none</p>
<p dir="auto"><img src="/assets/uploads/files/1721433782525-a6702327-efd9-476f-9c94-b1236a029d63-image.png" alt="a6702327-efd9-476f-9c94-b1236a029d63-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">(I know that Rogers doles out /128 prefix addresses (I can see this using with other client who use FortiGate routers to do IPv6) so I can't specify a proper prefix</p>
<p dir="auto"><img src="/assets/uploads/files/1721433286787-02fbb226-ac90-4bb1-8be5-1e093df8258c-image.png" alt="02fbb226-ac90-4bb1-8be5-1e093df8258c-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">PfSense is coming up with a gateway address from Link-Local (fe80::201:XXXXX:XXXX:8445%vmx0)<br />
<img src="/assets/uploads/files/1721433154595-d647e3fc-5048-4682-90d5-ae1f03749c2f-image.png" alt="d647e3fc-5048-4682-90d5-ae1f03749c2f-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Gateway monitoring says it is up even if I put in a Public IPv6 address to verify with.</p>
<p dir="auto">LAN info<br />
I am using Kea DHCP on the LAN to dole out 2001:XXXX:XXXX:8e01::/64 addresses<br />
Systems are getting addresses properly but when I look at the IPv6 Gateway on my systems they come back with another Link-Local address which I think is weird.  On my Fortinet Clients this would come back as the IPv6 address of the LAN interface.<br />
<img src="/assets/uploads/files/1721433333749-f2dca0ba-794e-430f-9588-062b3dd40625-image.png" alt="f2dca0ba-794e-430f-9588-062b3dd40625-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I can ping other IPv6 addresses on my LAN.<br />
I can ping the IPv6 interface on the firewall.<br />
I can ping the IPv6 address on the WAN</p>
<p dir="auto">I cannot ping any public IPv6 address</p>
<p dir="auto">External hosts can ping my public IPv6 address.</p>
<p dir="auto">I have a IPv6 rule in the firewall for outbound traffic that seems to be working as far as I can tell.  The counter are going up.<br />
<img src="/assets/uploads/files/1721433525131-91c67885-8329-4020-815d-92e38498a7df-image.png" alt="91c67885-8329-4020-815d-92e38498a7df-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">So I don't know where to look next.  This feels like a routing issue with the weird gateway address, but I can't seem to figure out what to do next.</p>
<p dir="auto">UPDATE:  So I turned on logging on the IPv6 rule and it is not recording traffic from the LAN to internet, but to a OpenVPN tunnel I also have on this firewall.  Irritatingly enough traffic works over the VPN just fine, just not from my internal LAN to Internet</p>
]]></description><link>https://forum.netgate.com/topic/189271/so-close-on-ipv6-yet-so-far-away-can-t-get-to-internet-over-ipv6-despite-everything-seeming-to-be-in-place</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Jul 2026 18:23:24 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/189271.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 20 Jul 2024 00:00:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 27 Jul 2024 11:32:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/br8bruno">@<bdi>br8bruno</bdi></a> said in <a href="/post/1178439">So close on IPv6 yet so far away - Can't get to internet over IPv6 despite everything seeming to be in place.</a>:</p>
<blockquote>
<p dir="auto">Not really sure, but I will as the ISP</p>
</blockquote>
<p dir="auto">They will ask you to execute a traceroute to, for example, 8.8.8.8<br />
The second, third, maybe fourth IP listed is theirs - on of their equipment. Pick any of these, as long as they answer to ping.<br />
Further on, you'll will find the main 'highway Internet core routers'.</p>
]]></description><link>https://forum.netgate.com/post/1178443</link><guid isPermaLink="true">https://forum.netgate.com/post/1178443</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Sat, 27 Jul 2024 11:32:22 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 27 Jul 2024 08:42:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a><br />
Thank you for the reply.</p>
<p dir="auto">In the end it was pfBlocker that was causing the problem. I didn't have to change any configuration, since they were not blocking anything. But I turned it off and on... now it all works.</p>
<p dir="auto">I will try and find the correct pings to monitor. Not really sure, but I will as the ISP. Thanks.</p>
]]></description><link>https://forum.netgate.com/post/1178439</link><guid isPermaLink="true">https://forum.netgate.com/post/1178439</guid><dc:creator><![CDATA[br8bruno]]></dc:creator><pubDate>Sat, 27 Jul 2024 08:42:51 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Fri, 26 Jul 2024 10:27:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/br8bruno">@<bdi>br8bruno</bdi></a></p>
<p dir="auto">All screen look, fine to me.<br />
IPv6 uses 'prefixes' for the LANs, your ISP has 00-&gt;ff = 256 available.<br />
Can't see if that worked out fine, as you've hidden them ^^</p>
<p dir="auto">Where I've difference :</p>
<p dir="auto"><img src="/assets/uploads/files/1721989192055-b8e21092-3b9c-4352-a282-3cab2ab29c6f-image.png" alt="b8e21092-3b9c-4352-a282-3cab2ab29c6f-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">where the third gateway is my OpenVPN server, so that's valid.<br />
But my WAN has an Ipv4 and IPv6 mode DHCP.</p>
<p dir="auto">I don't understand your LAN gateway ... neither the 3 ? WAN gateways.</p>
<p dir="auto">You have DHCP for IPv4 and DHCP6 for IPv6 - so the first two are the correct ones.</p>
<p dir="auto">Btw : just for the fun : don't ping 2001:4860:4860::8888 (and 8.8.8.8 and 8.8.4.4) as that's a DNS server IP. Not a ping answering machine.<br />
The day 'they' decide not to answer to a ping because this costs them a lot of bandwidth and bandwith == expensive they will shut down the ping answer. Result : your networks go down.<br />
Solution : ping a nearby ISP-based IPv4 and IPv6 upstream device that answers to ping.<br />
You pay your ISP (right ?) : they are payed to answer to your traffic, your pings so your pfSense can "test" the connection.</p>
<p dir="auto">Image the situation : Google 8.8.8.8 goes down. As a result, half the planet will lose it's Internet connection (as dpinger will detect the ping loss, and continuously restart the WAN interface).<br />
That will be the day I will be ROFL all day long.<br />
It happened : remember Facebook being down all day ?</p>
]]></description><link>https://forum.netgate.com/post/1178338</link><guid isPermaLink="true">https://forum.netgate.com/post/1178338</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Fri, 26 Jul 2024 10:27:46 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Mon, 22 Jul 2024 06:33:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a></p>
<p dir="auto">So you are aware I am running windows Domain controllers at this site.  I modified them as required for the Prefix provided by the earlier steps.</p>
<p dir="auto">DNS is working just fine<br />
<img src="/assets/uploads/files/1721629887133-b3ae29cc-b71f-4263-846f-dbdd8e8cfe06-image.png" alt="b3ae29cc-b71f-4263-846f-dbdd8e8cfe06-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Back here I left myself some IP's for use on static devices</p>
<p dir="auto"><img src="/assets/uploads/files/1721629940230-b43d4eed-7768-4b21-8a0d-305c08acc3b7-image.png" alt="b43d4eed-7768-4b21-8a0d-305c08acc3b7-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">And I'm using this IPv6 address as the gateway address on the statically assigned systems<br />
<img src="/assets/uploads/files/1721630003138-677ade63-ac9c-4491-800c-2e71c42e1a99-image.png" alt="677ade63-ac9c-4491-800c-2e71c42e1a99-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1177920</link><guid isPermaLink="true">https://forum.netgate.com/post/1177920</guid><dc:creator><![CDATA[MerikFyndhorn]]></dc:creator><pubDate>Mon, 22 Jul 2024 06:33:56 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Mon, 22 Jul 2024 05:54:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/merikfyndhorn">@<bdi>MerikFyndhorn</bdi></a></p>
<p dir="auto">Delete these two hardcoded DNS entries :</p>
<p dir="auto"><img src="/assets/uploads/files/1721627587464-ee617ff0-3d5a-4fe4-867f-2edfd548a0d9-image.png" alt="ee617ff0-3d5a-4fe4-867f-2edfd548a0d9-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">you don't need them.<br />
And the day your ISP decides to give you another prefix, you've broken DNS ...</p>
]]></description><link>https://forum.netgate.com/post/1177915</link><guid isPermaLink="true">https://forum.netgate.com/post/1177915</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 22 Jul 2024 05:54:17 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sun, 21 Jul 2024 02:48:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jknott">@<bdi>JKnott</bdi></a><br />
I guess I will have to adapt to the new way of things.:</p>
<p dir="auto">Thanks for all your help!</p>
]]></description><link>https://forum.netgate.com/post/1177852</link><guid isPermaLink="true">https://forum.netgate.com/post/1177852</guid><dc:creator><![CDATA[MerikFyndhorn]]></dc:creator><pubDate>Sun, 21 Jul 2024 02:48:51 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 20 Jul 2024 23:43:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/merikfyndhorn">@<bdi>MerikFyndhorn</bdi></a></p>
<p dir="auto">Change the DHCPv6 delegation size to 56 or whatever your ISP provides.  With 64 you'll only get a single /64.  I just realized 64 was from back in the days when Rogers only offered a single /64.  Now they provide a /56.  I have corrected that link.</p>
<blockquote>
<p dir="auto">Eventually I do get a LAN IPv6 address to show, but as expected it is a address of external origin.<br />
Since I think the ISP is providing me the range?</p>
<p dir="auto">Is the take away from this? You can't run a different internal range for IPv6 than the external range or you can't route on PfSense? That seems wrong.... :(</p>
</blockquote>
<p dir="auto">Yes, you will get public IP addresses, which is what the Internet gods intended, before NAT messed things up.</p>
]]></description><link>https://forum.netgate.com/post/1177846</link><guid isPermaLink="true">https://forum.netgate.com/post/1177846</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Sat, 20 Jul 2024 23:43:49 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 20 Jul 2024 22:56:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jonathanlee">@<bdi>JonathanLee</bdi></a></p>
<p dir="auto">Yes indeed.    The setting changes recommended by <a class="plugin-mentions-user plugin-mentions-a" href="/user/jknott">@<bdi>JKnott</bdi></a> did work, I'm just pouting about having the IPv6 range dictated inside my network, but I can get over that.</p>
<p dir="auto">DHCPv6<br />
<img src="/assets/uploads/files/1721515743723-0ba28542-38ea-479b-968a-9f7cd45de4ae-image.png" alt="0ba28542-38ea-479b-968a-9f7cd45de4ae-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Router Advertisement<br />
<img src="/assets/uploads/files/1721515796212-814551ca-8832-4b2b-90e3-548b0c9018f8-image.png" alt="814551ca-8832-4b2b-90e3-548b0c9018f8-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">DNS<br />
<img src="/assets/uploads/files/1721515823787-7e362625-9eb3-4126-981f-db1a47dd4d66-image.png" alt="7e362625-9eb3-4126-981f-db1a47dd4d66-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Yes on LAN IPv6<br />
<img src="/assets/uploads/files/1721515927636-c1f038a1-8d10-4f6e-b7d3-e3fdca0d2e1e-image.png" alt="c1f038a1-8d10-4f6e-b7d3-e3fdca0d2e1e-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Also IPv6 is not turned off on the firewall<br />
<img src="/assets/uploads/files/1721516070055-13194c11-e06b-475c-a8f9-e6b144da1838-image.png" alt="13194c11-e06b-475c-a8f9-e6b144da1838-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1177844</link><guid isPermaLink="true">https://forum.netgate.com/post/1177844</guid><dc:creator><![CDATA[MerikFyndhorn]]></dc:creator><pubDate>Sat, 20 Jul 2024 22:56:26 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 20 Jul 2024 22:48:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jknott">@<bdi>JKnott</bdi></a><br />
Changes made to WAN as per your recommendation<br />
<img src="/assets/uploads/files/1721511223655-965bea2f-ffe8-455c-adad-89c7f79a6b75-image.png" alt="965bea2f-ffe8-455c-adad-89c7f79a6b75-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I am still getting the same IPv6 address as before.</p>
<p dir="auto">Changes made to LAN as per your recommendation<br />
<img src="/assets/uploads/files/1721511402695-8f2929bf-ac52-4dab-8c14-40245f34bc45-image.png" alt="8f2929bf-ac52-4dab-8c14-40245f34bc45-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Eventually I do get a LAN IPv6 address to show, but as expected it is a address of external origin.<br />
Since I think the ISP is providing me the range?</p>
<p dir="auto">Is the take away from this?  You can't run a different internal range for IPv6 than the external range or you can't route on PfSense?   That seems wrong.... :(</p>
<p dir="auto">Worse yet is the results when I test the implementation.<br />
https://www.whatismyip.com/ give me my devices IPv6 not the external IPv6 of my firewall.</p>
<p dir="auto">Feels like I'm hanging my bum out on the internet for all to see rather than directing them to the firewall, but maybe I'm just been sensitive.</p>
]]></description><link>https://forum.netgate.com/post/1177842</link><guid isPermaLink="true">https://forum.netgate.com/post/1177842</guid><dc:creator><![CDATA[MerikFyndhorn]]></dc:creator><pubDate>Sat, 20 Jul 2024 22:48:02 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 20 Jul 2024 17:41:16 GMT]]></title><description><![CDATA[<p dir="auto">Have you enabled dhcp IPv6 and router advertising? Do your DNS server list contain some IPv6 servers to resolve with? Does your LAN have IPv6 also assigned to it?</p>
]]></description><link>https://forum.netgate.com/post/1177818</link><guid isPermaLink="true">https://forum.netgate.com/post/1177818</guid><dc:creator><![CDATA[JonathanLee]]></dc:creator><pubDate>Sat, 20 Jul 2024 17:41:16 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 20 Jul 2024 11:10:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/merikfyndhorn">@<bdi>MerikFyndhorn</bdi></a></p>
<p dir="auto">Here's <a href="https://forum.netgate.com/topic/106885/rogers-pfsense-configuration?_=1702908820440">Rogers pfSense configuration</a>.  How does it compare with what you have?</p>
]]></description><link>https://forum.netgate.com/post/1177796</link><guid isPermaLink="true">https://forum.netgate.com/post/1177796</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Sat, 20 Jul 2024 11:10:45 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 20 Jul 2024 02:51:51 GMT]]></title><description><![CDATA[<p dir="auto">The modem is definitely in Bridge Mode</p>
<p dir="auto">I operate with a static IPv4 assigned by my ISP.</p>
<p dir="auto">Rogers does not provide static IPv6 address, as as I mentioned earlier I am getting an IPv6 address successfully using DHCPv6.</p>
<p dir="auto">When I switch to SLAAC I get no IPv6</p>
]]></description><link>https://forum.netgate.com/post/1177781</link><guid isPermaLink="true">https://forum.netgate.com/post/1177781</guid><dc:creator><![CDATA[MerikFyndhorn]]></dc:creator><pubDate>Sat, 20 Jul 2024 02:51:51 GMT</pubDate></item><item><title><![CDATA[Reply to So close on IPv6 yet so far away - Can&#x27;t get to internet over IPv6 despite everything seeming to be in place. on Sat, 20 Jul 2024 02:21:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/merikfyndhorn">@<bdi>MerikFyndhorn</bdi></a></p>
<p dir="auto">Is your modem in bridge mode?  That's what you need for pfSense to handle IPv6 properly.  I don't know what modem you have, but with Rogers modems it's trivial to switch to bridge mode.  As soon as you login to the modem, the button is right in front of you.</p>
<p dir="auto">BTW, unless you have a specific need for DHCP, you're better off using SLAAC, as thanks to some genius at Google, Android devices won't work with DHCPv6.</p>
]]></description><link>https://forum.netgate.com/post/1177779</link><guid isPermaLink="true">https://forum.netgate.com/post/1177779</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Sat, 20 Jul 2024 02:21:23 GMT</pubDate></item></channel></rss>