<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Fritzbox and Pfsense]]></title><description><![CDATA[<p dir="auto">I have a /48 subnet ( 2001:xxx:xxxx::/48 ) via my ISP (native and static). When directly connected to my Fritzbox 7340, IPv6 works fine. But when I put my Pfsense box (2.1.5) between my PC and the FB. I can only use IPv6 from the Pfsense box.</p>
<ul>
<li>The WAN on PFsense (2001:xxx:xxx:1:xxx:xxx:xxx:489b ) uses DHCPv6 to get the ip address</li>
<li>On the LAN side I defined a static IPv6 address (2001:xxx:xxx:f:xxx:xxx:xxx:254 /64)</li>
<li>Allowed IPv6 traffic on Pfsense (the checkbox)</li>
<li>Activated Router Advertisement (Unmanaged)</li>
<li>The default IPv6 allow rule is active</li>
<li>IPv6 DNS works also on clients</li>
<li>IPv4 is fine</li>
</ul>
<p dir="auto">Sometimes when I ping a host (using hostname or IP) on the WAN side using IPv6 on a client, I get one response, the rest times out.</p>
<p dir="auto">Do you guys have any idea how to fix this, so that I'll have internet access on my cliënts?</p>
]]></description><link>https://forum.netgate.com/topic/77328/fritzbox-and-pfsense</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 06:49:55 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/77328.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 25 Dec 2014 20:16:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Fritzbox and Pfsense on Fri, 26 Dec 2014 23:15:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maarten90">@<bdi>Maarten90</bdi></a>:</p>
<blockquote>
<p dir="auto">… some say that setting a MTU of 1492 fixes this...</p>
</blockquote>
<p dir="auto">Salvation of (jumbo) MTU issues for IPv6 are actually beyond control of the end-user; RFC4638 must come into effect first at all locations. The other problem is that many global server-admins block IPv6 ICMP signals. So the test is useless or excluded.</p>
<p dir="auto">The best you can do, I think, is maybe set the value to 1492 at the <em>first</em> host which is your FB. [see FB&gt;Internet&gt;Account Info&gt;IPv6&gt;Addtional Settings&gt;] So then the FB announces the right thing to pfSense (and you let that box to the default 1500)</p>
<p dir="auto">(Sofar I experience no webpage problems, my ISP FB-config ships max MTU 1492 as a temp. solution)</p>
<p dir="auto">N.B. some config changes require a reboot in download sequence of the 2 cascading boxes, and then a DHCP6(PD) ISP refresh-cycle (upto 1 or 2 hrs). So look &amp; wait until your pfSense-LAN IPv6 number is back and up…</p>
]]></description><link>https://forum.netgate.com/post/503314</link><guid isPermaLink="true">https://forum.netgate.com/post/503314</guid><dc:creator><![CDATA[hda]]></dc:creator><pubDate>Fri, 26 Dec 2014 23:15:16 GMT</pubDate></item><item><title><![CDATA[Reply to Fritzbox and Pfsense on Fri, 26 Dec 2014 20:56:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/hda">@<bdi>hda</bdi></a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maarten90">@<bdi>Maarten90</bdi></a>:</p>
<blockquote>
<p dir="auto">… sugesting to use a prefix hint &lt;64...</p>
</blockquote>
<p dir="auto">Well, you are in a cascading setup. pfSense askes a /64 and receives an <em>unique</em> other subnetvalue from the FB.<br />
The FB has the authority over the /48 from your ISP. pfSense will do RA for /64 to its clients.<br />
Evidence: my FB-LAN has subnetvalue :1: and my pfSense-LAN-ONE has :ff:</p>
</blockquote>
<p dir="auto">Thanks for the clarification. One strange thing though, test-ipv6.com is telling me that there's a problem with big packets, which may cause websites not to load. And thats exactly what I am experiencing currently. Searched thew forum here, and some say that setting a MTU of 1492 fixes this (tried on both the LAN and WAN interface (not simultaneously)), but that doesnt work for me. Someone else suggests setting MSS clamping to 1220, but that also breaks my IPv6 connection. The last thing I found on the forum was someone that said that changing the default allow any rule for IPv6 from 'LAN Net' to 'Any' worked for him. However that also doesnt work. Do you have any idea whats going wrong here? I am able to surf the web but sites just dont load completely.</p>
]]></description><link>https://forum.netgate.com/post/503297</link><guid isPermaLink="true">https://forum.netgate.com/post/503297</guid><dc:creator><![CDATA[Maarten90]]></dc:creator><pubDate>Fri, 26 Dec 2014 20:56:50 GMT</pubDate></item><item><title><![CDATA[Reply to Fritzbox and Pfsense on Thu, 25 Dec 2014 22:15:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maarten90">@<bdi>Maarten90</bdi></a>:</p>
<blockquote>
<p dir="auto">… sugesting to use a prefix hint &lt;64...</p>
</blockquote>
<p dir="auto">Well, you are in a cascading setup. pfSense askes a /64 and receives an <em>unique</em> other subnetvalue from the FB.<br />
The FB has the authority over the /48 from your ISP. pfSense will do RA for /64 to its clients.<br />
Evidence: my FB-LAN has subnetvalue :1: and my pfSense-LAN-ONE has :ff:</p>
]]></description><link>https://forum.netgate.com/post/503191</link><guid isPermaLink="true">https://forum.netgate.com/post/503191</guid><dc:creator><![CDATA[hda]]></dc:creator><pubDate>Thu, 25 Dec 2014 22:15:08 GMT</pubDate></item><item><title><![CDATA[Reply to Fritzbox and Pfsense on Thu, 25 Dec 2014 21:49:58 GMT]]></title><description><![CDATA[<p dir="auto">Wow, I just saw a post of you sugesting to use a prefix hint &lt;64 , and using track interface. It works! Thank you!</p>
]]></description><link>https://forum.netgate.com/post/503187</link><guid isPermaLink="true">https://forum.netgate.com/post/503187</guid><dc:creator><![CDATA[Maarten90]]></dc:creator><pubDate>Thu, 25 Dec 2014 21:49:58 GMT</pubDate></item><item><title><![CDATA[Reply to Fritzbox and Pfsense on Thu, 25 Dec 2014 20:56:27 GMT]]></title><description><![CDATA[<p dir="auto">Sure, solutions can be found on this forum. Browse my contributions if you like  :)</p>
]]></description><link>https://forum.netgate.com/post/503182</link><guid isPermaLink="true">https://forum.netgate.com/post/503182</guid><dc:creator><![CDATA[hda]]></dc:creator><pubDate>Thu, 25 Dec 2014 20:56:27 GMT</pubDate></item></channel></rss>