• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[Resolved] Unable to browse internet firewall with IPv6

Scheduled Pinned Locked Moved Firewalling
7 Posts 3 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    codeblue2k
    last edited by May 9, 2015, 9:27 PM May 9, 2015, 8:37 PM

    I have a fresh install of pfSense and I am having some weird firewall rule issues with an IPv6 network. I added a pfSense admin rule and removed the default any any rules. I also added ICMP, DNS and HTTP/HTTPS rules. But even with those rules I am not able to browse to the internet.

    • can ping Googles IPv6 DNS IP from the pfSense WAN and LAN
      can ping Googles IPv6 DNS IP from a host behind the firewall
      can ping google.com from a host behind the firewall
      can NOT browse to google.com in IE from a host behind the firewall

    I have attached screenshots of my floating, WAN and LAN rules. Any help you can provide would be much appreciated.
    WAN_Rules.JPG_thumb
    WAN_Rules.JPG
    LAN_Rules.JPG_thumb
    LAN_Rules.JPG
    Floating_Rules.JPG_thumb
    Floating_Rules.JPG

    1 Reply Last reply Reply Quote 0
    • H
      hda
      last edited by May 9, 2015, 8:54 PM May 9, 2015, 8:48 PM

      Allow ICMP for IPv6 is recommended.

      How is DNS config setup ?

      How is RA management setup ?

      IPv6 takes priority for browsing. If IPv6 not available, switch  to IPv4 may take a while. Use SixOrNot 1.0.1 in browser for your information ?

      1 Reply Last reply Reply Quote 0
      • H
        Harvy66
        last edited by May 9, 2015, 9:01 PM

        I thought floating rules get processed first, and if you're blocking TCP for 4 and 6, then your TCP connections are going to get blocked. yes?

        1 Reply Last reply Reply Quote 0
        • C
          codeblue2k
          last edited by May 9, 2015, 9:09 PM

          @hda:

          Allow ICMP for IPv6 is recommended.

          How is DNS config setup ?

          How is RA management setup ?

          IPv6 takes priority for browsing. If IPv6 not available, switch  to IPv4 may take a while. Use SixOrNot 1.0.1 in browser for your information ?

          DNS on the pfSense server and on the hosts behind the firewall all point to Google DNS

          Sorry, can you clarify what RA management is? Im still learning my way around pfSense.

          So my pfsense host and all of the hosts behind my firewall are only using IPv6 addresses.

          1 Reply Last reply Reply Quote 0
          • H
            hda
            last edited by May 9, 2015, 9:10 PM

            @Harvy66:

            I thought floating rules get processed first, and if you're blocking TCP for 4 and 6, then your TCP connections are going to get blocked. yes?

            You're right there. I read it for ICMP i.s.o. TCP…

            1 Reply Last reply Reply Quote 0
            • C
              codeblue2k
              last edited by May 9, 2015, 9:13 PM

              @Harvy66:

              I thought floating rules get processed first, and if you're blocking TCP for 4 and 6, then your TCP connections are going to get blocked. yes?

              If that was the case wouldn't the ICMP rule that I have setup on the LAN rules be blocked? But as I mentioned I am able to ping IPs and hostnames. Just for covering my bases i disabled the floating rules and the issues still exists. Thanks for the suggestion

              1 Reply Last reply Reply Quote 0
              • C
                codeblue2k
                last edited by May 9, 2015, 9:25 PM

                Scratch that… it indeed seemed to have resolved the issue. Not sure why it took so long for the rule to stop blocking traffic.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received