IPv6 breaks after a while and stays DEAD after upgrading from opnsense 25 to 26

Started by DWM89, July 21, 2026, 03:25:15 AM

Previous topic - Next topic
July 21, 2026, 03:25:15 AM Last Edit: July 21, 2026, 02:47:14 PM by DWM89 Reason: completed information about running config
Hi!

I was running opnsense 25 for a good while and everything worked fine, now i tried to update to the current version 26.1.11_10 and all seemed fine at first.

I still had to manually tell my WAN interface to reload so I could get a DHCP lease from my ISP but then I got an IPv4 address and an IPv6 address and routes/dns and I was finally happy (I tried upgrading from 25 to 26 twice in the past with the same result as now!).
i could ping IPv4 and IPv6 hosts and generally use IPv6 sites normally.

Then, a few hours later (maybe 2 or 3) i realize that my IPv6 is not working anymore!
But I still have an IP...forcefully renewing the WAN interface didn't help.

IPv4 traffic still works like a charm.

the last 2 times I tried this upgrade I ended up ditching 26.1 and reverted back to my older opnsense 25 because i couldn'T solve the problem.
I am annoyed by this because it is obviously something that changed from opnsense 25 to 26 since when i revert to a backup from before the upgrade it works again with no problem.

On a side note:
I get a static public IPv4 and a static /56 prefix from my ISP
EDIT:
my configuration:
opnsense VM running on TrueNAS scale with dual intel i-226 NIC directly passed through to the VM
previously working version: 25.7.11_9 (Commit   2e9ac2def)
I have WAN and LAN configured on the 2 NICs, WAN DHCP on v4 and v6 (DHCPv6)
LAN uses Track WAN Interface for v6
I use ISC-DHCP for lan addresses and unbound for dns resolving

Could someone PLEASE help me with that issue?

Best regards

You do not tell anything about your IPv6 setup:

DHCPv6 or SLAAC? Which daemon(s) for both? Do your clients still get an IPv6 assigned? What gateway do they get?

Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, Leox LXT-010H-D

1100 down / 450 up, Bufferbloat A+

Well actually I thought I did say: DHCP (so for v6 its DHCPv6 on WAN) and track interface on LAN

I don't get a v6 IP on my LAN interface after the v6 breaks and the ipv6 traffic on connected devices to the LAN interface doesn't work either

That does not answer how you distribute the IPv6 on your LAN. You can do that via DHCPv6 or via SLAAC, with different daemons for each.

But FWIW, if your LAN loses its IPv6, then that seems to be the problem. You should set your LAN interface to "Identity assosication" instead of "Track Interface".
Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, Leox LXT-010H-D

1100 down / 450 up, Bufferbloat A+

Quote from: DWM89 on July 21, 2026, 03:25:15 AMLAN uses Track WAN Interface for v6
I use ISC-DHCP for lan addresses and unbound for dns resolving
Between OPNsense 25.7.x and 26.1.x there have been big changes for both of those, so I suggest having a look at both of them :
- ISC DHCP Server got moved to a plug-in.
So if you are still using it then maybe that let's say "migration" borked something the developers don't yet know about ?!
- Track WAN Interface for IPv6 has gotten a new sibling so to speak called 'Identity Assosication' that's new and different, but does the same pretty much...

So I would suggest reading both the forum and https://docs.opnsense.org/ about these two pretty big changes and then decide what do do next.
Perhaps it's just a matter of configuring some existing settings again and saving them or maybe you decide to migrate to KEA or DNSmasqd anyway...


Good luck! :)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

LAN: track interface = the opnsense doesn'T do squat for the clients

But as i already wrote:
IPv6 doesn'T work!
not even on the opnsense itself!

forget about the LAN interface or the clients

also: identity association doesn'T work either

and i wont use it as long as i have to manually configure the whole shitload of IPs, RA, Gateways and so on....what medieval bullshit is that...dhcp was invented for a reason...

so please, tell me how to further debug the WAN interface so the opnsense can communitate via IPv6 again...
when that is fixed, i guess if LAN still wont work I'm open to suggestions but i highly doubt that that will still be the case

That is new information. You first wrote that IPv6 initially works and it works fron OpnSense itself, now it does not. When exactly does it stop working? After initial connection or only after a while?

You can see which IPv6 you get in the interfaces overview - however, there are two sides to this even when we factor out the LAN connection first and concentrate on WAN:

1. IA_NA - which is the IPv6 your WAN interface gets via DHCPv6 as a client. That is, iff it gets one - some ISPs do not hand out an IA_NA and some even do not answer DHCPv6 requests at all if one is requested. That is the reason why the advanced setting "Request prefix only" exists. Using that is usually safe, because then:

2. IA_PD - which is the /56 prefix that can be split up and delegated to each (V)LAN and as of now, also to the WAN interface itself if "Request prefix only" is set. Note that you have to choose different 8-bit prefixes for all interfaces.

If your WAN has got an IPv6 and if the IPv6 gateway is set correctly, you should be able to ping e.g. "2600::" from OpnSense itself.

Ideally, you would then assign one of the 256 possible /64 IA_PD prefixes to your LAN interface and see that as well in the overview. This prefix will be the one that gets distributed to your LAN clients by whatever means you choose (i.e. DHCPv6 or SLAAC, but this time in the server role).

My preferred way of doing this is described here, BTW.

Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, Leox LXT-010H-D

1100 down / 450 up, Bufferbloat A+

Thanks for the reply.

My current situation is this:
I have a static /30 IPv4 and static IPv6 subnet from my ISP (Vodafone business in BaWü Germany) (but no texactly sure whether /56, /59 or /62 since those are common prefix lengths that customers could get according to my research. i configured /56 and it works)

When on 25.7 all just works fine but when upgrading I didn't get neither IPv4 nor v6 address but when I clicked on the renew button in the interfaces overview my opnsense got the whole shebang. correct IPv4 and v6 and everything works fine in the beginning. I can connect to hosts that are only v6 and also other hosts that are only v4.

after a while not actively using the v6 I realize that I can't connect to v6 hosts via ssh anymore nor can I ping them.
not from my main client in my LAN net nor directly from my opnsense terminal.
in Interfaces overview the IPs are still shown on the WAN interface but as mentioned, only IPv4 remains working and reboots/removing and plugging back in the cable wont fix the issue

I didn'T configre "request only prefix" only "send prefix hint"

on 25.7 i see 3 v6 IPs/networks:
a public  /128 and /64 and a fe80:/64
also I see a fe80: IP as a gateway

on my LAN interface I assigned prefix ID 0 and on my other 2 networks the IDs  1 and 2

are these helping information?
should I provide some more specifics?

best regards

The /128 on the WAN must be the IA_NA IPv6. But if you use a /56 prefix, there must be the least significant 8 bits that are used for any other interface - I understand the prefixes 0, 1 and 2 for your internal interfaces. But what is the /64 on the WAN made up from?

Let's leave out the fe80::/64, because those are link-local and of no special interest apart from that the WAN uses a link-local gateway as well.

I wonder what the /64 GUA on the WAN is? What is the 8-bit prefix of that? Are the first 56 bits shared with the IA_PD from your LAN interfaces?

And now I see: You are using OpnSense virtualized under some kind of KVM (i.e. TrueNAS Scale). That complicates things A LOT.

What do I mean by this? See: https://forum.opnsense.org/index.php?topic=44159.0, especially the part about "bridge-mcsnoop 0", which could well explain what you are seeing, because the known bug manifests in IPv6 connectivity breaking after a short while.

That being said, I have no experience with TrueNAS Scale at all.

Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, Leox LXT-010H-D

1100 down / 450 up, Bufferbloat A+