Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    IPv6 Gateway problems on 25.11

    Scheduled Pinned Locked Moved IPv6
    19 Posts 5 Posters 561 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      gseidler
      last edited by

      Hi there!

      I've been trying to configure IPv6 on my router since my ISP put me on CGNAT recently and I've been having some problems with the router's internal communication to the internet. My devices connected to the router seem to work just fine with IPv6 but internal functions like updating packages seem to have a problem whenever my IPv6 Gateway is online. If I disable the IPv6 Gateway they work again.

      Gateways
      Screenshot 2025-12-15 at 15.36.10.png

      Problems with the IPv6 Gateway Enabled
      Screenshot 2025-12-15 at 15.33.34.png

      Screenshot 2025-12-15 at 15.34.50.png

      Screenshot 2025-12-15 at 15.39.04.png

      With the IPv6 Gateway Disabled things work again
      Screenshot 2025-12-15 at 15.37.48.png

      Here's my Dashboard:
      Status: Dashboard - pfsense.cdm.lan.jpg

      My IPv6 config:
      I'd appreciate some help with this one and if you need more info, let me know.

      1 Reply Last reply Reply Quote 0
      • G Offline
        gseidler
        last edited by

        My IPv6 configuration for my ISP (Nio Fibra from Brazil):

        System > Advanced > Networking
        System: Advanced: Networking - pfsense.cdm.lan.png

        Interfaces > WAN
        Interfaces: WAN (em0) - pfsense.cdm.lan.png

        Interfaces > LAN
        Interfaces: LAN (em1) - pfsense.cdm.lan.png

        Services > Router Advertisement > LAN
        Services: Router Advertisement: LAN - pfsense.cdm.lan.png

        Services > DHCPv6 Server > LAN (I cut my static leases at the end)
        Services: DHCPv6 Server: LAN - pfsense.cdm.lan.png

        patient0P 1 Reply Last reply Reply Quote 0
        • patient0P Offline
          patient0 @gseidler
          last edited by

          @gseidler on first glance your setting look correct.

          if I understood you correctly, your clients can connect to the internet by IPv6 just fine. You can ping e.g. 2620:fe::fe (Quad9) from a client. Does an IPv6 test site succeed, like https://ipv6-test.com/?

          Then from pfSense, can you ping 2620:fe::fe and does DNS work on pfSense itself? E.g.

          /root: host files.netgate.com
          files.netgate.com has address 208.123.73.207
          files.netgate.com has address 208.123.73.209
          files.netgate.com has IPv6 address 2610:160:11:18::209
          files.netgate.com has IPv6 address 2610:160:11:18::207
          
          G 1 Reply Last reply Reply Quote 0
          • G Offline
            gseidler @patient0
            last edited by

            @patient0 said in IPv6 Gateway problems on 25.11:

            Then from pfSense, can you ping 2620:fe::fe and does DNS work on pfSense itself? E.g.

            I tried some commands with the IPv6 gateway enabled and I'm even more confused since the IPv6 variants of the commands work just fine on pfSense, only pkg doesn't.

            This is the output from a client:
            Screenshot 2025-12-16 at 08.02.56.png

            And this is the output from pfsense:
            Screenshot 2025-12-16 at 08.06.07.png

            patient0P 1 Reply Last reply Reply Quote 0
            • patient0P Offline
              patient0 @gseidler
              last edited by

              @gseidler it's at least good to see that IPv6 wise it works as it should.

              Maybe you can go through some point in the Netgate Troubleshooting guide. If pfSense runs on ZFS, create a snapshot beforehand.

              https://docs.netgate.com/pfsense/en/latest/troubleshooting/upgrades.html#upgrade-not-offered-library-errors

              The section Repository Metadata Version Errors:

              pkg-static bootstrap -f

              It looks as if something with in relation with pkg is f-up.

              G 1 Reply Last reply Reply Quote 0
              • G Offline
                gseidler @patient0
                last edited by gseidler

                @patient0 said in IPv6 Gateway problems on 25.11:

                The section Repository Metadata Version Errors:

                pkg-static bootstrap -f

                It looks as if something with in relation with pkg is f-up.

                Looks like it. Here's the output I get:
                Screenshot 2025-12-16 at 09.57.29.png

                I'm doing a reinstall of all packages with:

                pkg-static -4 upgrade -f
                

                I'll reboot and see if it changes anything.

                G 1 Reply Last reply Reply Quote 0
                • G Offline
                  gseidler @gseidler
                  last edited by

                  Update: No dice. The behavior continues the same.

                  patient0P 1 Reply Last reply Reply Quote 0
                  • patient0P Offline
                    patient0 @gseidler
                    last edited by

                    @gseidler I don't anything else to do, maybe @stephenw10 can help.

                    I don't know to what pfsense-plus-pkg.netgate.com should resolve.

                    It's defined in /usr/local/etc/pfSense/pkg/repo/pfSense-repo-0000.conf, you got that file (and the others with the name but different extensions)?

                    G 1 Reply Last reply Reply Quote 0
                    • G Offline
                      gseidler @patient0
                      last edited by

                      @patient0 said in IPv6 Gateway problems on 25.11:

                      /usr/local/etc/pfSense/pkg/repo/

                      I don't I only have a include directory at /usr/local/etc/pfSense

                      Screenshot 2025-12-16 at 13.58.23.png

                      I'll try to do a fresh reinstall and see if I can get it fixed.

                      patient0P 1 Reply Last reply Reply Quote 0
                      • patient0P Offline
                        patient0 @gseidler
                        last edited by

                        @gseidler not /usr/local/pfSense but /usr/local/*etc*/pfSense/pkg/repo/

                        G 1 Reply Last reply Reply Quote 0
                        • G Offline
                          gseidler @patient0
                          last edited by

                          So I basically did a fresh reinstall and things seem to be working so far. I ditched my saved config and I'm now 60% though on the fight to remember all my configs. Thanks for all the help, @patient0.

                          S 1 Reply Last reply Reply Quote 0
                          • S Offline
                            SteveITS Rebel Alliance @gseidler
                            last edited by

                            @gseidler if it help you can restore parts of a config file.

                            Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                            Upvote 👍 helpful posts!

                            G 1 Reply Last reply Reply Quote 0
                            • G Offline
                              gseidler @SteveITS
                              last edited by

                              @SteveITS Thanks! I'm taking the opportunity to review and learn from this reconfiguration effort. Especially the IPv6 part and NAT.

                              J 1 Reply Last reply Reply Quote 0
                              • J Offline
                                jerryj @gseidler
                                last edited by

                                I've been following this thread because I have the same issues. I have to say, I'm very disappointed with the Microsoft like solution of - just reinstall. First I had the VIP issue with pfblocker. Really, they have to uninstall it then reinstall the new and it looses this configuration?? Now I'm down to the IPv6 problems. Everyone's happy with IPv6 but pfsense. It can't update packages or pfblocker feeds with IPv6 enabled.

                                I've been running pfsense for several years without issue but honestly if I have to start over I'd have to look closely whether pfsense is the answer or not.

                                G 1 Reply Last reply Reply Quote 0
                                • G Offline
                                  gseidler @jerryj
                                  last edited by

                                  @jerryj I had problems updating lists in pfBlockerNG right after I upgraded to 25.11, that's what got me into the command line and discover the problems with pkg. Sadly I wasn't able to figure out where the problem was, maybe I could troubleshoot it a little more. I disables services, uninstalled packages, disabled firewall rules and nothing changed. Since I had already messed around my configuration as it was, reinstalling was a logical next step for me anyway. With the basic now working I can focus on other stuff like DNS NAT reflecting to a couple of services I have running on my local network. HAProxy seems a bit daunting for my taste.

                                  Good luck!

                                  J 1 Reply Last reply Reply Quote 0
                                  • J Offline
                                    jerryj @gseidler
                                    last edited by

                                    @gseidler Thanks, I get that. After troubleshooting I was close to reinstalling but I was afraid just reloading the old configuration would likely put me back where I was. Thanks for @SteveITS comment, I didn't know you could reload only parts.

                                    IPv6 was a pain to get working. I'm going to disable it for now and then go back through all the related settings to see if I have something misconfigured.

                                    G 1 Reply Last reply Reply Quote 0
                                    • G Offline
                                      gseidler @jerryj
                                      last edited by

                                      @jerryj so far I got Limiters, Access to Modem interface, IPv6, local DNS with static leases, pfBlockerNG and a few FW rules all working with no bad side effects. But I'm doing it all by hand, no config restoration.

                                      GertjanG 1 Reply Last reply Reply Quote 0
                                      • GertjanG Offline
                                        Gertjan @gseidler
                                        last edited by

                                        @gseidler

                                        This :

                                        edfe8784-aab7-4fe4-a604-d5d5221222b9-image.png

                                        should work, but you could select the obvious :

                                        36847621-aac7-4b7a-a2db-3dc25583e937-image.png

                                        as that's what I have.

                                        But it won't resolve your issue.
                                        This is what I did : https://forum.netgate.com/topic/199602/maybe-some-one-else-sees-it-..../5 - it forces pfSense to uses Ipv4 for it's own stuff, and suddenly, updates are back again.
                                        Not a solution, see it as a temp "fix".

                                        No "help me" PM's please. Use the forum, the community will thank you.

                                        G 1 Reply Last reply Reply Quote 0
                                        • G Offline
                                          gseidler @Gertjan
                                          last edited by

                                          @Gertjan I did both and it didn't work. You can see the second solution (Prefer to use IPv4...) activated on one of my screenshots. Reinstalling did work and things are running smoothly now.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.