Re: m0n0wall bug(?) when using IPv6

François Moreau <[email protected]> Fri, 31 Oct 2014 21:56:18 +0100
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
I actualy observe something like the Antonios issue.

It's happen on a PPPoE renew.


With m0n0wall 1.8.1, when I click on "Status: Interfaces ->
Disconnect", my WAN interface go down. After a time, when I click on
"Status: Interfaces -> Connect", my WAN interface go up, but, I lost my
IPv6 connection.

Into "Diagnostics: Ping",  from WAN interface, 100% of IPv6 packets are
loss.


To fix it I have to reboot m0n0wall and the IPv6 "Diagnostics: Ping" on
the WAN interface works fine.

The second step is to disable and re-enable a rule into "Firewall: IPv6
Rules" to retrieve an IPv6 connectivity for my LAN hosts. Unfortunately,
since the reboot the trafic was blocked.


I'm using an /56 adress with DHCP-PD on a PPPoE connection, IPv6 RA
enabled on LAN and SLAAC configured hosts (no DHCPv6, no flags).

Get here the last logs for a "renew" and for a "reboot":
http://pastebin.com/VjBuTKCR

I never had this problem when using SixXS 6to4 services.


So, take a look at https://forum.pfsense.org/index.php?topic=3D59996.0
where a similar problem is described (They solve it with an option
unavailable in m0n0).


>  From:  	Antonios Atlasis <antonios dot atlasis at gmail dot com>
>  To:  	m0n0wall at lists dot m0n0 dot ch
>  Subject:  	Re: m0n0wall bug(?) when using IPv6
>  Date:  	Sun, 19 Oct 2014 00:26:35 +0300

> Hi list,
>=20
> unfortunately the problem described in my e-mail quoted below still
> persists. To sum up, after rebooting m0n0wall, my outgoing IPv6 connection
> attempts are not block_ only_if_ I edit and "Apply" the IPv6 LAN rules,
> although I do _not_ actually change anything. If I do not follow this
> procedure, my IPv6 connection attempts are blocked. I verify at the
> Firewall logs the blocked connection attempts.
>=20
> Any help will be highly appreciated. status.php file is available, if
> requested.
>=20
> Best
>=20
> Antonios
>=20
> 2014-05-31 12:15 GMT+03:00 Antonios Atlasis <antonios dot atlasis at gmai=
l dot com>:
>=20
> > Dear list,
> >
> > a couple of days ago I installed the latest m0n0wall release (version
> > 1.8.1) to my ALiX box and I configured it to use IPv6 too (IPv6 mode at=
 WAN
> > interface: PPP, at LAN: DHCP-PD and sending RA messages at the LAN
> > interface too).
> >
> > Although my laptop got an IPv6 address, I realised that in order to acc=
ess
> > a web site using IPv6, access was blocked and there was a log message t=
hat
> > the outgoing traffic at this specific site had been blocked at the LAN
> > interface. So, I added an IPv6 rule at the LAN interface from "LAN net =
" ->
> > any to allow IPv6 traffic and it worked!
> >
> > Weird, I thought because I had assumed that this was the case by default
> > (to allow outgoing traffic) but no big deal.
> >
> > Next day, after shutting down and starting up again m0n0wall, I faced t=
he
> > same problem. Outgoing IPv6 traffic was blocked although my laptop had =
got
> > a unicast IPv6 address, but the rule that I had added was still there t=
oo.
> > I confirmed that there were similar logs that showed that the outgoing
> > traffic was blocked. I "Edit" the rule, then I DID NOT change anything,=
 I
> > pressed "Save", "Apply", and it worked again.
> >
> > Has anyone else experienced similar problem? Am I missing sthg?
> >
> > Best
> >
> > Antonios

--=20
Fran=E7ois Moreau