Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    System/Advanced/Networking -> Allow IPv6?

    Scheduled Pinned Locked Moved IPv6
    9 Posts 6 Posters 3.7k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      Red-Lichtie
      last edited by

      I have just wasted hours trying to figure out why my new IPv6 configuration wasn't working, only to find the "Allow IPv6" checkbox.

      Along with the description "All IPv6 traffic will be blocked by the firewall unless this box is checked", and "NOTE: This does not disable any IPv6 features on the firewall, it only blocks traffic.".

      Traffic is a feature and there is no indication anywhere, not even a warning when applying any changes, that this option has to be set.

      • Interfaces: IPv6 Configuration Type
      • Services: DHCPv6 Relay/Server, Router Advertisement
      • Diagnostics: NDP Table
      • . . .

      As soon as I set that checkbox all of my configuration options magically worked.

      Why aren't all the IPv6 configuration options disabled in the UI until that check box is set?
      Why isn't there a warning that there is a secret system option for IPv6 that doesn't exist for IPv4?

      1 Reply Last reply Reply Quote 0
      • tinfoilmattT Offline
        tinfoilmatt LAYER 8
        last edited by

        According to the docs, the "Allow IPv6" option is checked by defaut. So that begs the question: who was playing with your firewall configuration previously?

        johnpozJ 1 Reply Last reply Reply Quote 1
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator @tinfoilmatt
          last edited by

          Yeah that is checked out of the box - it would of had to been manually unchecked at some point. It normally quite easy to know its been unchecked because you will any ipv6 traffic blocked.. And clients even with no ipv6 address will send out stuff that would be blocked.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

          R 1 Reply Last reply Reply Quote 0
          • R Offline
            Red-Lichtie @johnpoz
            last edited by

            I bought it fully configured for my small business back in 2017 and I don't remember ever having turned it off. So probably the company that I bought it off of, removed that tick as a part of their out the box experience.

            Regardless of that, there should be, at the very least, a warning when saving any IPv6 related changes. Better still would be disabling the IPv6 options all together when disabled.

            Then people, like myself, would look for an option to enable IPv6 and not sit there frustrated thinking that the configuration is wrong.

            KOMK P 2 Replies Last reply Reply Quote 1
            • KOMK Offline
              KOM @Red-Lichtie
              last edited by

              @Red-Lichtie I get that you were frustrated by this, but it's not the job of an advanced firewall to hold people's hands. The flow for pfSense is to allow configuration of disabled services and then you enable or disable as you wish. Some services can't be enabled until they're configured. As an admin, I don't want to be bothered with warnings every time I fill in a field of a disabled service. A quick Google, LLM, or forum post would have had this solved for you in minutes. If you want to blame someone, blame your VAR. They should have just left the global IP6 toggle alone and removed the IP6 Allow All rule.

              R 1 Reply Last reply Reply Quote 3
              • P Offline
                Patch @Red-Lichtie
                last edited by

                @Red-Lichtie said in System/Advanced/Networking -> Allow IPv6?:

                Better still would be disabling the IPv6 options all together when disabled.

                Agree.
                A global disable switch should disable all dependant settings or at least show settings have no active effect.

                As for the logic: it is easy to tell when it's disabled as nothing works. That overlooks: all problems are easy to solve when the solution is known.

                1 Reply Last reply Reply Quote 0
                • R Offline
                  Red-Lichtie @KOM
                  last edited by

                  @KOM That was an elitist response.

                  When I change (almost) any configuration option, I get a warning all the time that it has to be applied before the changes are active so I guess, judging by your answer, that warning must bother you, as an admin, too.

                  Having what is effectively an invisible kill switch under System - Advanced - Networking with no other indication that option needs to be enabled for anything IPv6 related to function has absolutely nothing to do with pfSense being an advanced firewall or any hand holding but everything to do with a bad user experience.

                  Would it be that hard for, as you so aptly described it, "an advanced firewall" to detect IPv6 related changes being made and include it in the "apply changes" as a warning to the existing notification box? I think not.

                  P 1 Reply Last reply Reply Quote 0
                  • G Offline
                    giuliafw70
                    last edited by

                    I’d split the difference: keep the IPv6 pages editable, because it is useful to stage a config before enabling it, but show a passive warning on those pages when the global Allow IPv6 switch is off. That avoids the silent no-op without nagging on every save. For old or VAR-built installs I would also include that switch in the handover checklist/backups review, because it is exactly the kind of global setting that gets forgotten years later.

                    1 Reply Last reply Reply Quote 0
                    • P Offline
                      Patch @Red-Lichtie
                      last edited by

                      To be fair, while I support the user interface showing when setting are disabled (because of a global disable on another screen), prioritising what is actually implemented in the near term is a far more difficult question.

                      Personally have alias which don't remove an IP completely if a duplicate entry changes or silently stop populating alias tables at values dependant on a variable calculation order is far a far more pressing issue (although harder to solve) imo

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                      Privacy Policy · Cookie Policy