Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Static IPv6 on WAN+LAN with /63 ISP - LAN to WAN not working

    Scheduled Pinned Locked Moved IPv6
    6 Posts 2 Posters 430 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      snipleeagle8
      last edited by snipleeagle8

      Hello all,

      I am not able to access WAN from LAN with my /63 assignment from ISP. I can ping the GW from WAN, but not LAN.

      Assignment:

      Network:    2606:1420:500:4::1/63
      GW:         2606:1420:500:4::1
      WAN:        2606:1420:500:4::2/64
      LAN:        2606:1420:500:5::1/64
      

      My pfsense settings:

      WAN: 
      - Static IPv6: 2606:1420:500:4::2/64
      - Gateway:     2606:1420:500:4::1
      
      LAN:
      - Static IPv6: 2606:1420:500:5::1/64
      - Gateway:     None
      

      I have the following:

      • DHCPv6 and RA working fine. I get IP assignments in my LAN subnet: 2606:1420:500:5::1/64.
      • I can ping and access all LAN machine to machine IPv6.
      • I can ping WAN IP (2606:1420:500:4::2) from LAN
      • I can ssh into pfsense and ping external IP such as cloudflare (2606:4700:4700::1111) as well as ping the Gateway (2606:1420:500:4::1).

      I cannot:

      • I cannot ping GW IP (2606:1420:500:4::1) from LAN
      • I cannot access any IP outside on the internet such as cloudflare

      Firewall rules and other settings:

      • Allow IPv6 LAN subnet to any is set as default by pfsense (same as IPv4)
      • I have set Allow IPv6 checkbox in Advanced Settings > General.
      • Default Ipv6 Gateway in System > Routes is set to WANGWv6 which is 2606:1420:500:4::1. It's not set to automatic.

      For some reason LAN traffic is not going through the gateway at all. Any ideas?

      JKnottJ 2 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @snipleeagle8
        last edited by

        @snipleeagle8 said in Static IPv6 on WAN+LAN with /63 ISP - LAN to WAN not working:

        GW: 2606:1420:500:4::1

        Normally, the link local address is used for the gateway. What does your ISP say to use? Did you manually configure that? It normally gets populated automagically by DHCPv6.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        S 1 Reply Last reply Reply Quote 0
        • S
          snipleeagle8 @JKnott
          last edited by

          @JKnott ISP just gave me static IPv6 allocation and configuration including the gateway. There is no DHCP on WAN side.

          1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @snipleeagle8
            last edited by

            @snipleeagle8 said in Static IPv6 on WAN+LAN with /63 ISP - LAN to WAN not working:

            Gateway: None

            That might have something to do with it.
            The devices on your LAN also need a gateway, typically the pfSense box link local address. This is normally provided by SLAAC or DHCPv6. How is your system configured.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            S 1 Reply Last reply Reply Quote 0
            • S
              snipleeagle8 @JKnott
              last edited by

              @JKnott Interesting. How do I set that?

              This is my current LAN setting: f9b48688-e252-4565-acbf-bea6be203c03-CleanShot 2024-09-03 at 12.55.51@2x.png /Users/neil/Library/Mobile Documents/com~apple~CloudDocs/Screenshots/CleanShot 2024-09-03 at 12.55.51@2x.png

              I can click add gateway, but not sure where to find the local link address:

              39390114-7c44-483b-ac62-552dbc81920c-CleanShot 2024-09-03 at 12.56.40@2x.png /Users/neil/Library/Mobile Documents/com~apple~CloudDocs/Screenshots/CleanShot 2024-09-03 at 12.56.40@2x.png

              JKnottJ 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @snipleeagle8
                last edited by

                @snipleeagle8

                As I mentioned, it normally happens with SLAAC in the router advertisements. I have never used DHCPv6 on the LAN side, but I expect it would be the same. Are you using SLAAC or DHCPv6?

                Can you do a packet capture, filtering on ICMPv6, and post the capture file here?

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.