System/Advanced/Networking -> Allow IPv6?
-
I have just wasted hours trying to figure out why my new IPv6 configuration wasn't working, only to find the "Allow IPv6" checkbox.
Along with the description "All IPv6 traffic will be blocked by the firewall unless this box is checked", and "NOTE: This does not disable any IPv6 features on the firewall, it only blocks traffic.".
Traffic is a feature and there is no indication anywhere, not even a warning when applying any changes, that this option has to be set.
- Interfaces: IPv6 Configuration Type
- Services: DHCPv6 Relay/Server, Router Advertisement
- Diagnostics: NDP Table
- . . .
As soon as I set that checkbox all of my configuration options magically worked.
Why aren't all the IPv6 configuration options disabled in the UI until that check box is set?
Why isn't there a warning that there is a secret system option for IPv6 that doesn't exist for IPv4? -
According to the docs, the "
Allow IPv6" option is checked by defaut. So that begs the question: who was playing with your firewall configuration previously? -
Yeah that is checked out of the box - it would of had to been manually unchecked at some point. It normally quite easy to know its been unchecked because you will any ipv6 traffic blocked.. And clients even with no ipv6 address will send out stuff that would be blocked.
-
I bought it fully configured for my small business back in 2017 and I don't remember ever having turned it off. So probably the company that I bought it off of, removed that tick as a part of their out the box experience.
Regardless of that, there should be, at the very least, a warning when saving any IPv6 related changes. Better still would be disabling the IPv6 options all together when disabled.
Then people, like myself, would look for an option to enable IPv6 and not sit there frustrated thinking that the configuration is wrong.
-
@Red-Lichtie I get that you were frustrated by this, but it's not the job of an advanced firewall to hold people's hands. The flow for pfSense is to allow configuration of disabled services and then you enable or disable as you wish. Some services can't be enabled until they're configured. As an admin, I don't want to be bothered with warnings every time I fill in a field of a disabled service. A quick Google, LLM, or forum post would have had this solved for you in minutes. If you want to blame someone, blame your VAR. They should have just left the global IP6 toggle alone and removed the IP6 Allow All rule.
-
@Red-Lichtie said in System/Advanced/Networking -> Allow IPv6?:
Better still would be disabling the IPv6 options all together when disabled.
Agree.
A global disable switch should disable all dependant settings or at least show settings have no active effect.As for the logic: it is easy to tell when it's disabled as nothing works. That overlooks: all problems are easy to solve when the solution is known.
-
@KOM That was an elitist response.
When I change (almost) any configuration option, I get a warning all the time that it has to be applied before the changes are active so I guess, judging by your answer, that warning must bother you, as an admin, too.
Having what is effectively an invisible kill switch under System - Advanced - Networking with no other indication that option needs to be enabled for anything IPv6 related to function has absolutely nothing to do with pfSense being an advanced firewall or any hand holding but everything to do with a bad user experience.
Would it be that hard for, as you so aptly described it, "an advanced firewall" to detect IPv6 related changes being made and include it in the "apply changes" as a warning to the existing notification box? I think not.
-
I’d split the difference: keep the IPv6 pages editable, because it is useful to stage a config before enabling it, but show a passive warning on those pages when the global Allow IPv6 switch is off. That avoids the silent no-op without nagging on every save. For old or VAR-built installs I would also include that switch in the handover checklist/backups review, because it is exactly the kind of global setting that gets forgotten years later.
-
To be fair, while I support the user interface showing when setting are disabled (because of a global disable on another screen), prioritising what is actually implemented in the near term is a far more difficult question.
Personally have alias which don't remove an IP completely if a duplicate entry changes or silently stop populating alias tables at values dependant on a variable calculation order is far a far more pressing issue (although harder to solve) imo
Privacy Policy · Cookie Policy