Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [Resolved] Unable to browse internet firewall with IPv6

    Firewalling
    3
    7
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      codeblue2k
      last edited by

      I have a fresh install of pfSense and I am having some weird firewall rule issues with an IPv6 network. I added a pfSense admin rule and removed the default any any rules. I also added ICMP, DNS and HTTP/HTTPS rules. But even with those rules I am not able to browse to the internet.

      • can ping Googles IPv6 DNS IP from the pfSense WAN and LAN
        can ping Googles IPv6 DNS IP from a host behind the firewall
        can ping google.com from a host behind the firewall
        can NOT browse to google.com in IE from a host behind the firewall

      I have attached screenshots of my floating, WAN and LAN rules. Any help you can provide would be much appreciated.
      WAN_Rules.JPG_thumb
      WAN_Rules.JPG
      LAN_Rules.JPG_thumb
      LAN_Rules.JPG
      Floating_Rules.JPG_thumb
      Floating_Rules.JPG

      1 Reply Last reply Reply Quote 0
      • H
        hda
        last edited by

        Allow ICMP for IPv6 is recommended.

        How is DNS config setup ?

        How is RA management setup ?

        IPv6 takes priority for browsing. If IPv6 not available, switch  to IPv4 may take a while. Use SixOrNot 1.0.1 in browser for your information ?

        1 Reply Last reply Reply Quote 0
        • H
          Harvy66
          last edited by

          I thought floating rules get processed first, and if you're blocking TCP for 4 and 6, then your TCP connections are going to get blocked. yes?

          1 Reply Last reply Reply Quote 0
          • C
            codeblue2k
            last edited by

            @hda:

            Allow ICMP for IPv6 is recommended.

            How is DNS config setup ?

            How is RA management setup ?

            IPv6 takes priority for browsing. If IPv6 not available, switch  to IPv4 may take a while. Use SixOrNot 1.0.1 in browser for your information ?

            DNS on the pfSense server and on the hosts behind the firewall all point to Google DNS

            Sorry, can you clarify what RA management is? Im still learning my way around pfSense.

            So my pfsense host and all of the hosts behind my firewall are only using IPv6 addresses.

            1 Reply Last reply Reply Quote 0
            • H
              hda
              last edited by

              @Harvy66:

              I thought floating rules get processed first, and if you're blocking TCP for 4 and 6, then your TCP connections are going to get blocked. yes?

              You're right there. I read it for ICMP i.s.o. TCP…

              1 Reply Last reply Reply Quote 0
              • C
                codeblue2k
                last edited by

                @Harvy66:

                I thought floating rules get processed first, and if you're blocking TCP for 4 and 6, then your TCP connections are going to get blocked. yes?

                If that was the case wouldn't the ICMP rule that I have setup on the LAN rules be blocked? But as I mentioned I am able to ping IPs and hostnames. Just for covering my bases i disabled the floating rules and the issues still exists. Thanks for the suggestion

                1 Reply Last reply Reply Quote 0
                • C
                  codeblue2k
                  last edited by

                  Scratch that… it indeed seemed to have resolved the issue. Not sure why it took so long for the rule to stop blocking traffic.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.