• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Problem routing ipv6 interfaces

Scheduled Pinned Locked Moved IPv6
12 Posts 3 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    marcos.viana
    last edited by Feb 24, 2015, 5:38 PM Feb 23, 2015, 4:50 PM

    good afternoon

    I have a problem with ipv6 routing
    I have a prefix /48

    router isp  xxxx:xxxx:xxxx::1/48

    pfsense config

    WAN IP xxxx:xxxx:xxxx::2/126 and gateway xxxx:xxxx:xxxx::1

    this works OK I can ping internet from the interface wan.

    LAN IP xxxx:xxxx:xxxx:yyyy::1/64

    PC  xxxx:xxxx:xxxx:yyyy::2/64

    From the lan interface I can not ping the ip of the router

    from the PC I can ping the wan interface pfsense but not the ip router

    I have ipv6 enabled and firewall rules let pass all traffic ipv6 in the 2 interfaces

    edit photo

    thanks for the help

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Feb 24, 2015, 3:27 PM

      Why do you have a different mask on your wan IP then your gateway mask of /48?  The mask of your interface that talks to the gateway should match the mask on the gateway.  You have /126, but in your pic you list /64 on your pfsense wan ipv6 IP?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      1 Reply Last reply Reply Quote 0
      • M
        marcos.viana
        last edited by Feb 24, 2015, 5:33 PM

        The router I have no access my isp routed me prefixed with the mask / 48

        I proble to change the mask of wan to pfsense a / 126 to be more restrictive but does not work

        apart, then I have a default route pointing to the ISP router

        1 Reply Last reply Reply Quote 0
        • M
          marcos.viana
          last edited by Feb 24, 2015, 5:44 PM

          if someone could give me an alternative functional configuration, would appreciate.

          any help is welcome;)

          1 Reply Last reply Reply Quote 0
          • H
            hda
            last edited by Feb 24, 2015, 5:49 PM

            When communicating with outside, you should adhere to /64 IP mask per interface, else things break.

            1 Reply Last reply Reply Quote 0
            • M
              marcos.viana
              last edited by Feb 24, 2015, 6:01 PM

              I changed the mask wan pfsense a / 64 and the problem persists, there is no response from the ISP router.

              The strange thing is that from any pc I answered the wan ip of pfsense, and from the wan interface of the router responds pfsense me.

              But since the pcs isp router interface is unresponsive.

              thx

              1 Reply Last reply Reply Quote 0
              • H
                hda
                last edited by Feb 24, 2015, 6:03 PM

                Assure your connection with a reboot of ISP-router and the pfSense-box in cascading sequence.

                1 Reply Last reply Reply Quote 0
                • M
                  marcos.viana
                  last edited by Feb 24, 2015, 6:19 PM

                  hi

                  I 've tried several times even simulations with another pfsense a PC emulating the ISP router and the same result

                  1 Reply Last reply Reply Quote 0
                  • H
                    hda
                    last edited by Feb 24, 2015, 6:27 PM Feb 24, 2015, 6:22 PM

                    Hmmm, tell us how do you issue IP to PC's ?
                    i.e. Static, DHCP6-server and/or SLAAC ? How is your radvd settings ?

                    1 Reply Last reply Reply Quote 0
                    • M
                      marcos.viana
                      last edited by Feb 24, 2015, 10:09 PM

                      in test environment emulating the isp router with routing pc changing the mask / 48 to /64 and creating a static route routing prefix / 48 to the wan ip of pfsense
                      working properly

                      It is normal to have to do this? should not route all traffic to the mask / 48?

                      Thx

                      1 Reply Last reply Reply Quote 0
                      • M
                        marcos.viana
                        last edited by Feb 24, 2015, 10:11 PM

                        not use or dhcp or Ra ips the assigned manually

                        1 Reply Last reply Reply Quote 0
                        • H
                          hda
                          last edited by Feb 25, 2015, 12:22 PM Feb 24, 2015, 10:20 PM

                          You get an /48 space supply. Of this /48 you can chop something like say /56 up into subnets of /64 (these are 255 LAN's or NIC's)

                          Reliable communication goes with /64.

                          So you can do a Static like 2A02:babe:face:1::1/64 for LAN-1
                          And you can do a Static like 2A02:babe:face:2::1/64 for LAN-2

                          Suppose you connect a switch to LAN-1.
                          Then you can attach a PC on that switch (to LAN-1) give it a Static, say 2A02:babe:face:1::beef

                          And you need RA to set on Router Only if you do Static, else no routing…

                          1 Reply Last reply Reply Quote 0
                          12 out of 12
                          • First post
                            12/12
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received