Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
IPv6 checksum issues
« previous
next »
Print
Pages: [
1
]
Author
Topic: IPv6 checksum issues (Read 2248 times)
bebef
Newbie
Posts: 18
Karma: 1
IPv6 checksum issues
«
on:
September 07, 2019, 04:13:04 pm »
Hi everyone!
I run my OPNsense behind another router that provides IPv6 and a bunch of /64 prefixes to my local networks. The IPv6 setup as such seems to work just fine (at least I can use things like IPv6 websites from my local networks).
I want to use OpenVPN via IPv6, so I set up everything in the other router and OPNsense to make it work. It somehow works routing-wise as I can see SYN packets from the client and OPNsense replying with SYN-ACK which also arrive on the client. However, the TCP checksum of the packets is not OK and therefore not recognized by the client. I already did a diff of the packets on the OPNsense and the client. Both are the same, so I think I can rule out the other router manipulating packets.
What is interesting is that everything works "internally". I get several prefixes that I use in different networks. Connections from a prefix to the OPNsense OpenVPN port work just fine, so at least it can't be a general checksum calculation issue. I also played around with the offloading flags, but nothing really did help.
Also, everything works just fine in IPv6, it's just the replies to external connections to my OPNsense WAN port that get messed up. Also, connections initiated from OPNsense on WAN to the client work just fine. It's just the SYN-ACK replies from WAN which get the wrong checksums.
Any hints and ideas are highly appreciated
Cheers
Bebef
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
IPv6 checksum issues