Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - mahescho

#61
Well, now I'm on 18.7.2 and it's all the same as described above ..

Any suggestions?

Suggestion to make life easier: The default net mask for IPv6 should (IMO) be 64 and not 128 for Interfaces.
#62
Hi Franco,

In my setup I use a Microtik router to connect to my ISP. There I get a /29 IPv4 net and a /48 IPv6 net. I do not delegate subnets right now I just use static configurations of subnets and routes. So I use a static IPv6 setup on the firewall.

Now I've upgraded from 18.1-amd64 to 18.7-amd64 and it's all the same as soon as I reboot. I've to disable IPv6 on the WAN interface and re enable it to get back IPv6 connectivity. Wen I check the configuration on the shell with "netstat -rn" and "netstat -in" every thing looks fine but it just does not work. When I monitor the WAN interface with "tcpdump" while I'm pinging I don't see a single packet. I think it's some kind of problem in conjunction with "pf". It looks linke all outgoing packets get droppe silently. When I ping the firewall from the router and monitor the WAN interface with "tcpdump" I can see the ICMP echo request bur no replies.

In addition there is a problem with the dashboard. I'm currently pinging a v4 and v6 destination from the firewall without any packet loss and the status of the two gateways on the dashboard flaps every now and then from green to red and vice versa.

One last thing: "ntpd" does not survive the IPv6 reconfiguration. I've to start it afterwards.

Currently the firewall is not in production use. I'm just testing and tying to get familiar with the system. I've no IPv6 on the LAN interface so I can't say if it's affected too.

cheers
Matthias
#63
18.7 Legacy Series / Strange IPv6 behavior after update
September 07, 2018, 05:00:44 PM
Hi,

to day I revived my new OPNsense appliance. I set it up with IPv4 and IPv6 and everything worked as expected. The I've updated it to the current version 18.1.13_1-amd64 and IPv6 stopped working. I found that just no IPv6 packets left the appliance. I've seen arrive my ICMP echo requests but no answers. IMHO The packets got dropped. I had to remove the IPv6 address from the WAN interface and the re add it to make it work again.

Just want to let the devs know about this strange behavior.

Matthias