Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS forwarder and IPv6

    Scheduled Pinned Locked Moved DHCP and DNS
    8 Posts 2 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • empbillyE
      empbilly
      last edited by

      Hello guys,

      In a real test environment I set ipv6 and the principle clients are taking the ip correctly by RA. On a pc with linux, I did the test on the site http://www.test-ipv6.com/ but there was an error in resolving AAAA names. The dns configured in General setup is from my provider. I tested this dns separately and it solves AAAA names. Pings on v6 works too.

      I need an extra configuration in DNS forwarder or only the three options below?

      • Enable DNS forwarder
      • Register DHCP leases in DNS forwarder
      • Register DHCP static mappings in DNS forwarder

      Where can be the error?

      https://eliasmoraispereira.wordpress.com/

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        What is the exact error your getting for AAAA, is it like this?

        This just means that your not using IPV6 to get to your dns..  Not that you can not actually lookup AAAA, is pfsense forwarder actually listening on IPV6, and your clients are using the ipv6 address for your dns?

        exacterror.png
        exacterror.png_thumb

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • empbillyE
          empbilly
          last edited by

          What is the exact error your getting for AAAA, is it like this?

          Yes, the same error of the image you posted.

          This just means that your not using IPV6 to get to your dns..  Not that you can not actually lookup AAAA, is pfsense forwarder actually listening on IPV6, and your clients are using the ipv6 address for your dns?

          My dns is pfsense, so my clients need to use the pfsense IP address or I can set the ISP dns in General Configs?

          https://eliasmoraispereira.wordpress.com/

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            if you want that test to past then your client needs to be using a dns via IPV6 not ipv4..

            so for example - see how I have ipv6 dns setup for this client.  But I have it set to prefer to use ipv4..  Which is why I get that warning.

            ipv6pref.png
            ipv6pref.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • empbillyE
              empbilly
              last edited by

              if you want that test to past then your client needs to be using a dns via IPV6 not ipv4..

              In General Setup > DNS: I set both dns ipv4 and ipv6. The order of the configuration of the DNS influence on something? Eg: ipv4 before ipv6 or ipv6 before ipv4.

              https://eliasmoraispereira.wordpress.com/

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Again what do your client point to for dns???  See when I did nslookup on my client it pointed to IPV6 for dns..

                Post yours!!

                Make sure it can resolve using that IPv6 address of pfsense as its dns server…  This has NOTHING to do with what pfsense is using for dns, or forwarding too..  This has to do with the client making its dns query via a ipv6 dns.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • empbillyE
                  empbilly
                  last edited by

                  For me pointed 172.16.0.1

                  This is a nat gw from lan of my pfsense.

                  I believe it will never work that way, right?

                  https://eliasmoraispereira.wordpress.com/

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    It can work just fine that way, its just your not asking a ipv6 server for your dns.. Which is why your getting that specific error.

                    So your not using ipv6 all they way through your still using ipv4 for the dns aspect of looking up some ipv6 based site..  Not really an issue..  Also comes down to what exactly your wanting to do…  And how you want to do it..

                    Do you want to pass some test for ipv6 functionality or do you just want to get to ipv6 sites?  There is no actual sites, other than maybe some p0rn or backnet stuff that is ipv6 only..  So doesn't really matter in the big picture.  If you resolve something io ipv6 via AAAA can you get there is the question.  Not that you look up that AAAA via dns via ipv4 address or ipv6 address.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.