IPV6 ON 2.9.0
-
Hi All,
I upgraded to version 2.9.0 yesterday and since that upgrade my IPV6 is dead in the water.
No settings look to have changed, the interfaces are still getting an IPV6 address as before as do all the clients.
However when I try ipv6 pings or to browse ipv6 websites it goes nowhere.
I've checked the rules and IPV6 is still allowed outbound and this config was perfect before.
Are there any known issues with ipv6 and 2.9.0?
-
I have 2.9,0 and no problem with IPv6.
-
let's do some basic troubleshooting...
- can you ping your pfSense's GUA or ULA (
fd40...) from a LAN client? - are DNS results returning IPv6 addresses? (test with eg
dig aaaa ews.netgate.com) - make sure System > Advanced > Networking > Allow IPv6 checkbox is enabled
- make sure System > Routing has a default IPv6 gateway set
- paste a screenshot from https://test-ipv6.com
- can you ping your pfSense's GUA or ULA (
-
Hey thanks for the reply.
-
Yes I can ping from a client machine to the IPV6 addresses of the PFsense interfaces both link local and external ipv6 addresses and get a reply.
-
yes pinging ipv6 websites via name resolves their ipv6 addresses but the requests time out.
3 and 4 are both yes, like I say this config was fine on 2.8.1
- in work at the moment so can't paste screenshot but it shows my ipv4 address and IPV6 is not detected despite the PFsense interfaces having an ipv6 address
-
-
@ashleygavin ok when you get a chance, post screenshots of
- System > Routing
- LAN firewall rules that show your IPv6 allow rule
- take a peek at System Logs (System & Firewall) and post screens if you can
-
Mmm, I would also try pinging out from pfSense itself by host and/or IP.
-
@luckman212 Cheers mate. Just got home so I'll stick ipv6 back on then grab some screenshots. Appreciate the help.
-
-
-
Hmm, looks like it's prefix only? You might try setting the LAN as source. Though it looks to have chosen it anyway.
Could be an upstream issue at your ISP.
-
I would also check the state table whilst pinging to see that states appear on the expected interfaces.
And, to be certain, I'd run a pcap on WAN to double check traffic is there.
Can we assume your VPN interfaces do not have IPv6?
-
@stephenw10 Yes correct it is prefix only, Vodafone UK is the provider and that's the config I found worked from another post on here specifically for that ISP. So the LAN interface gets an IPV6 address but WAN doesn't
Agree it could be an ISP issue but I think it's too much of a coincidence it stopped working immediately after the update.
Tried ping from LAN as source and same result :(
-
@ashleygavin maybe a (redacted if you want) output of
cat /tmp/rules.debugmight shed some light -
this config was perfect before
like I say this config was fine on 2.8.1
it stopped working immediately after the update.
No need to repeatedly mention this as there's a decent chance that the 'issue' is the result of some welcome hardening of the default rules.
-
@tinfoilmatt Ok anything to help me work out what that may be?
-
A (redacted) dump of your ruleset, like @luckman212 suggests, would rule it in or out.
-
Firewall log?
-
File is here, if I blatantly missed something on the redaction please let me know and I'll remove the file.
-
This is probably PPPoE related (I don't have access to any PPPoE systems sadly) - but I'm not sure Outbound NAT should be getting performed on these:
# Outbound NAT rules (manual) nat on $WAN inet6 from $LAN__NETWORK to any -> (pppoe0) port 1024:65535 # LAN Subnets -
@luckman212 Just flicked that outbound NAT rule to IPV4 only and didn't make a difference.
I need the manual NAT on because I tunnel some ranges through a VPN and others through normal WAN.
Privacy Policy · Cookie Policy

