OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • OPNsense blocking IP6 traffic
« previous next »
  • Print
Pages: [1]

Author Topic: OPNsense blocking IP6 traffic  (Read 824 times)

Alpha_DE

  • Newbie
  • *
  • Posts: 22
  • Karma: 1
    • View Profile
OPNsense blocking IP6 traffic
« on: June 27, 2024, 09:31:24 pm »
Hey!

A user of my system reported issues access my IMAP server by IPv6.

After some digging around, I found his IPv6 in the firewall-logs

Code: [Select]
17,,,02f4bab031b57d1e30553ce08e0ec131,vtnet4,match,block,in,6,0x00,0xeb111,64,tcp,6,40,2a01:XXXX:fe02::110,2a00:XXXX:ea05,993,61465,0,SA,3642631772,3523825403,21420,,mss;sackOK;TS;nop;wscale
Rule 17, label 02f4bab031b57d1e30553ce08e0ec131 is the global IPv4/6 Default deny / state violation rule

Code: [Select]
@16 block drop in log inet all label "02f4bab031b57d1e30553ce08e0ec131"
  [ Evaluations: 1886      Packets: 279       Bytes: 12488       States: 0     ]
  [ Inserted: uid 0 pid 79740 State Creations: 0     ]
@17 block drop in log inet6 all label "02f4bab031b57d1e30553ce08e0ec131"
  [ Evaluations: 1886      Packets: 427       Bytes: 45298       States: 0     ]
  [ Inserted: uid 0 pid 79740 State Creations: 0     ]

I inserted a specific rule for his addresses (beside that the mail server has it's v4/v6 rules allowing access to all mail ports). I see other v6 addresses with the same issue, on v4, it works.

OPNsense 24.1.9_4-amd64

Anybody a good idea how to solve that, I was told it started recently, might be around the 24.1.9 update.
Logged

Alpha_DE

  • Newbie
  • *
  • Posts: 22
  • Karma: 1
    • View Profile
Re: OPNsense blocking IP6 traffic
« Reply #1 on: June 28, 2024, 01:52:17 pm »
I did some more checks and the firewall blocks *all* IPv6 traffic with the "Default deny / state violation rule" even when a matching global ACCEPT rule on all interfaces is defined.

@Franco Looks like the packet filter is not processing any IPv6 rules despite that they're shown in the GUI.

Of course, IPv6 is enabled in the Interface settings.
Logged

abulafia

  • Full Member
  • ***
  • Posts: 156
  • Karma: 8
    • View Profile
Re: OPNsense blocking IP6 traffic
« Reply #2 on: September 25, 2024, 08:55:30 am »
I seem to be running into the same problem, I e. Opnsense blocking all ipv6 via "default deny" evev though there is ab express allow ipv6 to any rule.
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: OPNsense blocking IP6 traffic
« Reply #3 on: September 25, 2024, 08:56:46 am »
If you don't show your "allow" rules it's difficult to diaganose, what might be wrong with them.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • OPNsense blocking IP6 traffic
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2