Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    When using NAT64 does pfSense block routing in internal VLANs?

    Scheduled Pinned Locked Moved IPv6
    nat64pref64clat
    4 Posts 2 Posters 374 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      IonutIT
      last edited by

      So I'm testing a IPv6-mostly setup with a VLAN that has NAT64 and PREF64 and DHCP Option 108. Apple devices support CLAT natively and everything triggers and works as expected for outbound stuff.

      But I'm trying to ping a device in another VLAN inside my network through its IPv4 and it doesn't seem to work.

      Do I need to have some specific rule to allow this in pfSense, or does the NAT64 implementation fail to work with RFC1918 destinations when arriving via 64:ff9b::/96 ?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        The NAT64 RFC says you shouldn't be able to do that, so now it isn't allowed by default.

        https://redmine.pfsense.org/issues/16241

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        I 1 Reply Last reply Reply Quote 1
        • I Offline
          IonutIT @jimp
          last edited by

          @jimp

          That's weird, so when in an IPv6-only environment you have mechanisms to talk to anybody in the IPv4 world (with NAT64) except your own internal networks? How does that make sense?

          Is there a way to change the default behavior and allow this?

          jimpJ 1 Reply Last reply Reply Quote 0
          • jimpJ Offline
            jimp Rebel Alliance Developer Netgate @IonutIT
            last edited by

            @IonutIT Check "NAT64 Prefix Override" on System > Advanced, Firewall/NAT

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.