Project

General

Profile

Actions

Bug #6451

closed

IPv6 GIF tunnels to HE broken since 2.3-RELEASE

Added by Adam Thompson almost 8 years ago. Updated almost 8 years ago.

Status:
Not a Bug
Priority:
High
Assignee:
-
Category:
Unknown
Target version:
-
Start date:
06/05/2016
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.3.1
Affected Architecture:

Description

I've just confirmed that since upgrading from 2.2.x to 2.3-RELEASE (and subsequently to 2.3.x-whatever's current) none of my firewalls that had working IPv6 GIF tunnels to HE have, well, working tunnels to HE any more.

I can only confirm this for 32-bit, since none of the 64-bit instances have/need a tunnel.

I see GIF packets leaving the firewall WAN interface, but nothing coming back. Typically, in my experience, this is because of malformed or incorrect packets reaching HE, but since I no longer have a 2.2 instance to compare pcaps against, I'm having difficulty narrowing down the problem.

Marking as high priority, because in one case (the one that made me notice this!) the only way I can get NTP service is over IPv6. (Thanks, stupid "business grade" ISP for "protecting" me from NTP attacks...)

Hopefully I'm just doing something wrong or missed something in the release notes.


Files

config-remote.avant.ca-20160605201826.xml (90.7 KB) config-remote.avant.ca-20160605201826.xml HE tunnel definitely was working on this one Adam Thompson, 06/05/2016 08:27 PM
config-pfSense.localdomain-20160610010853.xml (27 KB) config-pfSense.localdomain-20160610010853.xml No previous tunnel, can't make new one work. Adam Thompson, 06/05/2016 08:31 PM
Actions

Also available in: Atom PDF