{"id":1185,"date":"2026-10-01T16:29:11","date_gmt":"2026-10-01T16:29:11","guid":{"rendered":"https:\/\/blog.miguelsarmiento.com\/?p=1185"},"modified":"2026-10-01T16:29:11","modified_gmt":"2026-10-01T16:29:11","slug":"ipv6-delegation-pfsense-cisco-oh-my","status":"publish","type":"post","link":"https:\/\/blog.miguelsarmiento.com\/?p=1185","title":{"rendered":"IPv6 Delegation, PfSense, Cisco, Oh My!"},"content":{"rendered":"\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Hello there,<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">The topic of this blog may not be that relevant since IPv6 is being around now for many years.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">However, I still see issues once in a while on forums, with IPv6 delegation and how to configure it on PfSense.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Since I can not control how my ISP delegates IPv6 to me, the next best thing is to lab the hell out of it.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Keep on reading.<\/span><\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 id=\"motivation\" class=\"wp-block-heading\"><strong>Motivation<\/strong><\/h2>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">I have used delegation from my ISP, today I use a consumer router that gives you a \/64, in the past I have used a Fedora box running IPTABLES. <\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">You request a prefix via DHCPv6, store what your provider gives you, configure the LAN interface with one those prefixes and voila you are ready to go.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">I have a blog showing how I did it using Fedora as my Internet router.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">You would think that PfSense would be that easy, since it is running a secure version of Linux. Well you would be wrong!<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">So, I decided to be my own ISP, use a Cisco router, delegate prefixes to a Cisco router acting as a client and a PfSense firewall.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">You probably did guess it.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">On Cisco devices is a piece of cake, on the PfSense well you will see.<\/span><\/p>\n\n\n\n<h2 id=\"setup-ipv6-delegation-and-routing\" class=\"wp-block-heading\"><strong>Setup, IPv6 Delegation and Routing<\/strong><\/h2>\n\n\n\n<p><span style=\"font-size: large;\">The following figure shows the network I am using<\/span>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.miguelsarmiento.com\/wp-content\/uploads\/2026\/09\/IPv6-Delgation.png\" target=\"_blank\" rel=\" noreferrer noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"607\" src=\"https:\/\/blog.miguelsarmiento.com\/wp-content\/uploads\/2026\/09\/IPv6-Delgation-1024x607.png\" alt=\"\" class=\"wp-image-1322\" srcset=\"https:\/\/blog.miguelsarmiento.com\/wp-content\/uploads\/2026\/09\/IPv6-Delgation-1024x607.png 1024w, https:\/\/blog.miguelsarmiento.com\/wp-content\/uploads\/2026\/09\/IPv6-Delgation-300x178.png 300w, https:\/\/blog.miguelsarmiento.com\/wp-content\/uploads\/2026\/09\/IPv6-Delgation-768x455.png 768w, https:\/\/blog.miguelsarmiento.com\/wp-content\/uploads\/2026\/09\/IPv6-Delgation.png 1336w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/a><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Figure 1. Delegation Diagram.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li style=\"font-size:18px\">It has a Cisco 7600 acting as the ISP router. It will delegate IPv6 prefixes.<\/li>\n\n\n\n<li style=\"font-size:18px\">A Cisco router (test) that receives a prefix and then gets configured.<\/li>\n\n\n\n<li style=\"font-size:18px\">A PfSense router (second client) that also gets a prefix and gets configured.<\/li>\n\n\n\n<li style=\"font-size:18px\">A couple of devices to test what addresses Pf Sense gives.<\/li>\n<\/ol>\n\n\n\n<h3 id=\"ipv6-delegation\" class=\"wp-block-heading\"><i><b>IPv6 Delegation<\/b><\/i><\/h3>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">First we need some background on how delegation works since every time that I see issues on forums, people do not seem to understand how IPv6 works, how routing works and how delegation is used.<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Delegation of prefixes is done by a DHCPv6 server. If you are an ISP you have a device in the network that receives requests and handles the prefixes needed.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">DHCPv6 does not handle routing information, <\/span> <span style=\"font-size: large;\"><strong>I repeat it does not provides the default route needed.<\/strong><\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">That is the job of a RADVD server which needs access to as many network segments you may have to correctly configure IPv6 addresses.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Above is crucial, RADVD will only handle routes. Using SLAAC an interface will auto configure itself using an fe80 address (these are link-local addresses).<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">I am simplifying things quit a bit, the point is that the RADVD has an interface that the client also sees via NDP and has a link-local address that can be ping by other devices on that segment only.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">That is the reason RADVD servers are usually on routers or L2\/L3 switches that will have access to as many segments networks via interfaces or VLANS.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">A DHCPv6 server on the other hand can reside on a particular segment and be accessed using a relay (like you do with IPv4).<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Another point is that the WAN interface does not necessarily needs a global address, instead every ISP will use unique local address (ULC) or link local addresses for communications.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">The UCL space is fec0::\/7. By its definition this prefix is not routable on the Internet (like 10.0.0.0\/8 on IPv4).<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Thus, your WAN interface gets a UCL, or some ISPs will just use the link-local address. This is perfectly find, if you can access the shell of you router you will notice that the default route is via a link-local address.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">So, you request a prefix from your ISP, the RADVD server gets the request, sends routing information then it notifies the client to use a DHCPv6 server to get any other information it needs. This will include, a prefix, DNS information and any other stuff that a DHCP server hands out.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">You then need to choose a \/64 network from the delegated prefix and configure your LAN interface (or let the device do it automatically by some means).<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Finally configure DHCPv6 (or not) on your other LAN interfaces and give additional IPv6 \/64 prefixes if any.<\/span><\/li>\n<\/ul>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">As you can see it is straight forward somehow though, this trips a lot of users, and this makes sense in a way, a lot of consumers are not IT literate.<br><\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">However, I see it also trips a lot of guys that know a bit more about networking go figure.<\/span><\/p>\n\n\n\n<h3 id=\"ipv6-addressing\" class=\"wp-block-heading\"><i><strong>Ipv6 Addressing<\/strong><\/i><\/h3>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">We need to understand IPv6 addressing since if you do not, the lab will not work correctly. I will go over very quickly please read more comprehensive documentation.<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">By design, you do not get an network smaller than a \/64, from an ISP provider. This does not mean you could not use a \/65 or a \/66 on your local network.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">But if you do you it will break stateless autoconfiguration (SLAAC).<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Obviously if your are configuring routers, which by their definition need static routes, you can subnet your network. You will never use a RADVD or DHCPv6 server on those segments. This is a very special case.<\/span><\/li>\n<\/ul>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Thus your ISP will give you a prefix smaller or equal than \/64. For our purpose we will assume that we have the following global addresses assgined to the segment in question, 2001:DB8:2::\/58. This super net now is capable of being<br>subnetted.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">In our case we have decided to give clients a \/62 prefix. A \/62 is four networks (to keep it simple and recognize right away what prefix we got), and we will have 16 such networks to give.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">A quick calculation should convince you, 62-58=4, 2^4 is 16, the number of networks available.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">So the following is a list of all the available networks:<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><span style=\"font-size: small;\">2001:db8:2:0::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:4::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:8::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:12::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:16::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:20::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:24::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:28::\/62 <\/span>\n<span style=\"font-size: small;\">2001:db8:2:32::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:36::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:40::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:44::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:48::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:52::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:56::\/62<\/span>\n<span style=\"font-size: small;\">2001:db8:2:60::\/62<\/span><\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Another point to make is that the prefixes above are first come first serve. Thus you may get a different prefix after you reboot. This makes sense unless you talk to your ISP so he can reserve a prefix based on the UUID of your device.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Every device is different on how you find it, and the technical term is actually IAID (Identity Association Identifier) or DUID (DHCP Unique Identifier).  <\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">In either case it is assigned to the device which prevents it to change, unlike if it only was based on the interface, in that case there is a chance it may change.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">An ISP may or may not honor this, (if you have a business account they should since your servers will need to be registered with a DNS provider somewhere and the FQDN needs to be the same across reboots, meaning the IPv6 address).<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Now that we have an idea how IPv6 addresses and delegation works, we can proceed to configured the router that will give routing information and delegate prefixes.<\/span><\/p>\n\n\n\n<h2 id=\"configurations\" class=\"wp-block-heading\"><strong>Configurations<\/strong><\/h2>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">We will start with the Cisco 7200. Configuration may vary and will be probably different on newer routers.<\/span><\/p>\n\n\n\n<h3 id=\"cisco-7200\" class=\"wp-block-heading\"><em>Cisco 7200<\/em><\/h3>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">I will not go over the whole configuration of the router, you can Google it. The relevant parts are shown.<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted has-small-font-size\">ip domain name isp.com\u00a0<br>ip name-server x.x.x.x <br>! Your DNS resolver<br>ip cef\u00a0<br>ipv6 unicast-routing\u00a0<br>! So Ipv6 will work<br>ipv6 cef\u00a0<br>ipv6 dhcp pool MY_DHCPV6_POOL <br>! Declare the pool name\u00a0<br>prefix-delegation pool CUSTOMER-PD-POOL <br>! Declare the delegation pool\u00a0<br>domain-name example.com<br><br>interface Ethernet1\/0 <br>! Management IP access to outside\u00a0if you need to access the router<br>ip address dhcp<br>! Self explanatory<br>ip nat outside\u00a0<br>! So I can access the Internet and mimic it on the <br>! clients for IPv4 if I need to <br>ip virtual-reassembly in\u00a0<br>duplex half\u00a0<br>! This should be full of course <br>! for the lab it does not matter<br>!<br>interface Ethernet1\/1\u00a0<br>ip address 172.16.1.1 255.255.255.0\u00a0<br>ip nat inside ! For IPv4 Clients inside \u00a0I<br>ip virtual-reassembly in\u00a0<br>duplex half\u00a0<br>ipv6 address FC00:DB8:100::1\/64\u00a0<br>! Usind UCL address<br>ipv6 dhcp server MY_DHCPV6_POOL <br>! Declaring the pool to use for DHCPv6<br><br>ip nat inside source list 1 interface Ethernet1\/0 overload <br>! For completeness <br>!<br>access-list 1 permit 172.16.1.0 0.0.0.255<br>ipv6 local pool CUSTOMER-PD-POOL 2001:DB8:2::\/58 62 <br>! The actual prefix, \/58 carved into \/62 networks<br>!<br><\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">That is it! Fairly straight forward.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">However we need to look a little bit deeper. Clever readers and I know you are will have noticed that I did not configure \u201cnd\u201d flags.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">On a cisco router the \u201cipv6 nd\u201d command under an interface is the equivalent of configuring RADVD.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">As you see we did not tell the router to do anything, if you typed the following command:<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted has-small-font-size\">isp1#sh ipv6 interface ethe 1\/1 prefix \nIPv6 Prefix Advertisements Ethernet1\/1\nCodes for 1st column:\n       A - Address, P - Prefix-Advertisement, O - Pool\n       U - Per-user prefix\nCodes for 2nd column and above:\n       D - Default\n       N - Not advertised, C - Calendar\n\nPD default [LA] Valid lifetime 2592000, preferred lifetime 604800\nAD FC00:DB8:100::\/64 [LA] Valid lifetime 2592000, preferred lifetime 604800\n<\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">And:<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted has-small-font-size\">isp1#sh ipv6 interface ethe 1\/1\nEthernet1\/1 is up, line protocol is up\n  IPv6 is enabled, link-local address is FE80::C801:ABFF:FED7:1D \n  No Virtual link-local address(es):\n  Global unicast address(es):\n    FC00:DB8:100::1, subnet is FC00:DB8:100::\/64 \n  Joined group address(es):\n    FF02::1\n    FF02::2\n    FF02::1:2\n    FF02::1:FF00:1\n    FF02::1:FFD7:1D\n    FF05::1:3\n  MTU is 1500 bytes\n  ICMP error messages limited to one every 100 milliseconds\n  ICMP redirects are enabled\n  ICMP unreachables are sent\n  Input features: Common Flow Table Stile classification\n  Output features: Common Flow Table Stile Classification\n  ND DAD is enabled, number of DAD attempts: 1\n  ND reachable time is 30000 milliseconds (using 30000)\n  ND advertised reachable time is 0 (unspecified)\n  ND advertised retransmit interval is 0 (unspecified)\n  ND router advertisements are sent every 200 seconds\n  ND router advertisements live for 1800 seconds\n  ND advertised default router preference is Medium\n  Hosts use stateless autoconfig for addresses.\n<\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">The relevant info is in the middle. It is by default doing ND advertisements every 200 seconds to any client that request it.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Thus, clients will received a default route and a UCL prefix as you will see next.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">When will you configure ND settings, if you are using another DHCPv6 server to handle addresses, then the router is acting a a relay, then you need to tell clients to redirect their requests to obtain what they need besides a default route only.<\/span><\/p>\n\n\n\n<h3 id=\"cisco-3275\" class=\"wp-block-heading\">Cisco 3275<\/h3>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">This is a 3275 (not a 3250 as I thought same diff).<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">The relevant bits are:<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">ipv6 unicast-routing\n interface FastEthernet0\/0\n  no ip address\n  duplex auto\n  speed auto\n  ipv6 address autoconfig default\n  ipv6 enable\n  ipv6 dhcp client pd WAN-PREFIX\n !\n interface FastEthernet0\/1\n  no ip address\n  duplex auto\n  speed auto\n  ipv6 address WAN-PREFIX ::1\/64\n  ipv6 enable<\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Interface 0\/0, auto configures itself. Then we request a delegate prefix and we put it into the string \u201dWAN Prefix\u201d.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Then Interface 0\/1 uses that prefix, we tell to configure an IPv6 address. It will configure IPv6 addresses in order, in this case it start with the first \/64 given and so on.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">If you check the IPv6 address given you will see:<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">test#sh ipv6 int br\nFastEthernet0\/0            [up\/up]\n    FE80::C004:FDFF:FE28:0\n    FC00:DB8:100:0:C004:FDFF:FE28:0\nFastEthernet0\/1            [up\/up]\n    FE80::C004:FDFF:FE28:1\n    2001:DB8:2::1\n<\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">As you can see, interface 0\/0 received a UCL address plus a link local address. Interface 0\/1 configured itself using the first prefix delegated.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Remember if you have x::1\/64, it means it is actualy x:0::1\/64 since when there are zeros the notation is condensed.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Finally do a show ipv6 route:<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted has-small-font-size\">test#sh ipv6 route\nIPv6 Routing Table - 7 entries\nCodes: C - Connected, L - Local, S - Static, R - RIP, B - BGP\n       U - Per-user Static route, M - MIPv6\n       I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary\n       O - OSPF intra, OI - OSPF inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2\n       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2\n       D - EIGRP, EX - EIGRP external\nS   ::\/0 [1\/0]\n     via FE80::C801:ABFF:FED7:1D, FastEthernet0\/0\nS   2001:DB8:2::\/62 [1\/0]\n     via ::, Null0\nC   2001:DB8:2::\/64 [0\/0]\n     via ::, FastEthernet0\/1\nL   2001:DB8:2::1\/128 [0\/0]\n     via ::, FastEthernet0\/1\nC   FC00:DB8:100::\/64 [0\/0]\n     via ::, FastEthernet0\/0\nL   FC00:DB8:100:0:C004:FDFF:FE28:0\/128 [0\/0]\n     via ::, FastEthernet0\/0\nL   FF00::\/8 [0\/0]\n     via ::, Null0<\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">As you can see, you have:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list has-small-font-size\">\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">A default route via the 7200 link local address.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">A connected route using the UCL address.<\/span><\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">A static address configured automatically for the \/62 via the :: and Null0. This is a normal Cisco way of having the \/62 in the routing table.<\/span><\/li>\n<\/ul>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Notice I did not request an IPv4 address, you could.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">As you noticed the only thing we needed, was to declare the pool to store the delegated prefix and a general way of assigning \/64 to whatever interfaces on the LAN.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">I was expecting something similar on the PfSense. It does it at the end but it was not clear how to go about it even after reading PfSense own documentation.<\/span><\/p>\n\n\n\n<h3 id=\"pfsense\" class=\"wp-block-heading\"><i>PfSense<\/i><\/h3>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">I am running 2.6.0-RELEASE, which may be a bit old however the behavior should be same.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Let\u2019s look at the finished result before we go deeper. <\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">If we look at vtnet0 (wan interface)<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted has-small-font-size\">2.6.0-RELEASE][<a href=\"mailto:admin@pfSense.example.com\">admin@pfSense.example.com<\/a>]\/root: ifconfig vtnet0&nbsp;<br>vtnet0: flags=8843&lt;UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST&gt; metric 0 mtu 1500&nbsp;<br>description: WAN&nbsp;<br>options=800b8&lt;VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,LINKSTAT&nbsp;<br>ether 50:01:00:02:00:00&nbsp;inet6 fe80::5201:ff:fe02:0%vtnet0 prefixlen 64 scopeid 0x1&nbsp;inet6 fc00:db8:100:0:5201:ff:fe02:0 prefixlen 64 autoconf&nbsp; inet 172.16.1.10 netmask 0xffffff00 broadcast 172.16.1.255 media: Ethernet 10Gbase-T<br>status: active<br>nd6 options=23&lt;PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL&gt; <br><\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Notice we have a local link address and also got a UCL address plus in this case I requested also an IPv4 address (acting as our IPv4 from the ISP).<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">If you issue: netstat -6 -rWh, you see:<\/span><\/p>\n\n\n\n<pre class=\"wp-block-preformatted has-small-font-size\">Internet6:\nDestination        Gateway            Flags       Use    Mtu    Netif Expire\ndefault            fe80::c801:abff:fed7:1d%vtnet0 UGS      362   1500   vtnet0\nlocalhost          link#6             UH            0  16384      lo0\n2001:db8:2:4::\/64  link#2             U            13   1500   vtnet1\npfSense            link#2             UHS           0  16384      lo0\nfc00:db8:100::\/64  link#1             U             8   1500   vtnet0\nfc00:db8:100:0:5201:ff:fe02:0 link#1  UHS           0  16384      lo0\nfe80::%vtnet0\/64   link#1             U        358893   1500   vtnet0\nfe80::5201:ff:fe02:0%vtnet0 link#1    UHS           0  16384      lo0\nfe80::%vtnet1\/64   link#2             U           318   1500   vtnet1\nfe80::1:1%vtnet1   link#2             UHS           0  16384      lo0\nfe80::5201:ff:fe02:1%vtnet1 link#2    UHS           0  16384      lo0\nfe80::%vtnet2\/64   link#3             U             0   1500   vtnet2\nfe80::5201:ff:fe02:2%vtnet2 link#3    UHS           0  16384      lo0\nfe80::%lo0\/64      link#6             U             0  16384      lo0\nfe80::1%lo0        link#6             UHS           0  16384      lo0\n<\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">The relevant info here is the default destination, as you can see it points to the ISP router.<\/span><\/p>\n\n\n\n<p style=\"font-size:18px\"><span style=\"font-size: large;\">On vtnet1 you will see if you issue \u201cifconfig vtnet1\u201d<\/span> using a shell.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted has-small-font-size\">vtnet1: flags=8843&lt;UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST&gt; metric 0 mtu 1500&nbsp;<br>description: LAN&nbsp;<br>options=800b8&lt;VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,LINKSTATE&gt;&nbsp;<br>ether 50:01:00:02:00:01<br>inet6 fe80::5201:ff:fe02:1%vtnet1 prefixlen 64 scopeid 0x22<br>inet6 fe80::1:1%vtnet1 prefixlen 64 scopeid 0x2<br>inet6 2001:db8:2:4:5201:ff:fe02:1 prefixlen 64<br>inet 192.168.100.1 netmask 0xffffff00 broadcast 192.168.100.255<br>media: Ethernet 10Gbase-T &lt;full-duplex&gt;<br>status: active <br>nd6 options=21&lt;PERFORMNUD,AUTO_LINKLOCAL&gt;&nbsp;<br><\/pre>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Notice that PfSense did acquire an IPv6 address \u201c2001:db8:2:4:5201:ff:fe02:1\u201d, this is the address that will automatically be configured after you get the settings for the PfSense correct.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">On your client, you will see that if you configured the DHCPv6 on PfSense you will get an IPv6 address. In our case I configured it to assign addresses in the following range: ::100 to ::200, where if things are done correctly it will prepend the LAN interface prefix.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">So in my case the IP the client got was: 2001:db8:2:4::200, notice that in this case if you remember I got the prefix 2001:db8:2:4::\/62 which is the next prefix available and it configure the LAN interface accordingly using a \/64.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">I will try to explain the pitfalls I encountered and how finally got it work correctly.<\/span><\/p>\n\n\n\n<h2 id=\"troubleshooting-delegation-pfsense\" class=\"wp-block-heading\"><strong>Troubleshooting Delegation PfSense<\/strong><\/h2>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">I was confused on how to request a prefix. I was not clear from the GUI and event after going to the \u201chorse\u2019s mouth\u201d, Pfsense documentation, it was not working until I re-booted the PfSense. Rather than show sreen-shots I will go old school.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">This is what you do:<\/span><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">On the interfaces page, select the WAN interface.<\/span>\n<ul class=\"wp-block-list\">\n<li><span style=\"font-size: large;\">Enable it.<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">Ipv6 Configuration should be DHCP6<\/span><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Under \u201cDHCP 6 Client Configuration\u201d<\/span>\n<ul class=\"wp-block-list\">\n<li><span style=\"font-size: large;\">Select \u201cRequest only an IPv6 prefix, do not request an IPv6 address\u201d<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">Here is the tricky part, some ISPs may give you a hint, however \u201cyou need to call your ISP and ask what is the prefix they are delegating to you\u201d<span style=\"font-weight: normal;\">, otherwise PfSense will not accept the delegation.<\/span><\/span><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Go to Intefaces again and choose LAN<\/span>\n<ul class=\"wp-block-list\">\n<li><span style=\"font-size: large;\">Enable it (of course).<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">On \u201cIpv6 Configuration Type\u201d, select \u201cTrack Interface\u201d.<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">Scroll down and under \u201cTrack IPv6 Interface\u201d, select \u201cWAN\u201d. This tells PfSense to obtain a delegated prefix via WAN but use it for the LAN interface.<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">For Ipv6 Prefix ID keep as the default 0, this will use the prefixes as delegated starting in order 1<sup>st<\/sup>, 2<sup>nd<\/sup> , etc&#8230;<\/span><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Go to \u201cServices\u201d and choose \u201cDHCPv6 Server &amp; RA\u201d<\/span>\n<ul class=\"wp-block-list\">\n<li><span style=\"font-size: large;\">Enable DHCPv6 for the interfaces in the LAN you want to use.<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">You should see the actual prefix delegated to the particular LAN interface. It<\/span> <span style=\"font-size: large;\">will show after a reboot.<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">Choose the range, since it obtained a prefix you just need to enter the range ::100 to ::200 for example.<\/span><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li class=\"has-small-font-size\"><span style=\"font-size: large;\">Go to \u201cRouter Advertisements\u201d<\/span>\n<ul class=\"wp-block-list\">\n<li><span style=\"font-size: large;\">For \u201cRouter Mode\u201d, select \u201cManaged \u2013 RA Flags {managed, other stateful],Prefix\u2026.\u201d<\/span><\/li>\n\n\n\n<li><span style=\"font-size: large;\">You can actually look for more information by clicking on the \u201ci\u201d icon.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Save the configuration.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Now you would think that after this your client will acquire an IP. <\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Not so fast.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">After a lot of digging including tcpdump and seen the DHCLIENT on the PfSense requesting but not obtaining a prefix, as a last resort I rebooted the PfSense.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">And what do you know, it now works.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">This should not be the case, as I mentioned PfSense is actually Linux underneath.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">It uses the WIDE-DHCPv6 (dhcp6c) client, this type of client will (using the correct cli switches) give you the prefix the ISP is giving you and you can then store it in a variable. I have done this multiple types (in Fedora for example and then under Ubuntu), on those cases the distros use the standard \u201cdhclient\u201d.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">However, the behavior should be the same. Of course perhaps I was expecting a bit too much.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">A reboot as stated did fix it. I have not looked to see the output on the CLI of the PfSense or the logs to see what is now getting in terms of prefixes.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Obviously it is getting the correct ones. Also I am using  an old PfSense version perhaps newer versions behaves better.  <\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">You should familiarized with IPv6 as it is done on the PfSense, look at other settings in particular under &#8216;Diagnostic&#8221;, check the &#8220;NDP Table&#8221; for example, it will give you instructive output. <\/span><\/p>\n\n\n\n<p style=\"font-size:18px\">Finally as an after thought I decided to add an Alpine Linux server. Other than you need to do a couple of extra things to have IPv6 to work, it acquired an IPv6 address with no problem.  <\/p>\n\n\n\n<p style=\"font-size:18px\">I will also make a comment, I was expecting PfSense to allow configuration of your LAN as you did with the DHCP ranges.<\/p>\n\n\n\n<p style=\"font-size:18px\">In this fashion you have more control and give the LAN an IP of ::1, like Cisco does. You can configure this manually, but if the ISP does not honor the AIAD, you will have to manually reconfigured.<\/p>\n\n\n\n<p style=\"font-size:18px\">That in my opinion defeats the purpose of receiving prefixes automatically. Just a thought.<\/p>\n\n\n\n<h1 id=\"conclusions\" class=\"wp-block-heading\"><strong>Conclusions<\/strong><\/h1>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Not as straight forward as I thought. Nevertheless, it works.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Now if your ISP is only giving you a \/64, I can hear all the rants that it should be giving you at least a \/56 (a lot I will say, are we spoiled?).<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">There are ways around that if you only get a \/64 and you need VLANS and Wi-Fi, etc.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Perhaps a topic for a future blog.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">There you have it.<\/span><\/p>\n\n\n\n<p class=\"has-small-font-size\"><span style=\"font-size: large;\">Ciao.<\/span><\/p>\n\n\n\n<p><span style=\"font-size: large;\">&nbsp;<\/span><\/p>\n\n\n\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello there, The topic of this blog may not be that relevant since IPv6 is being around now for many years. However, I still see issues once in a while on forums, with IPv6 delegation and how to configure it on PfSense. Since I can not control how my ISP delegates IPv6 to me, the &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.miguelsarmiento.com\/?p=1185\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;IPv6 Delegation, PfSense, Cisco, Oh My!&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1185","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=\/wp\/v2\/posts\/1185","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1185"}],"version-history":[{"count":143,"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=\/wp\/v2\/posts\/1185\/revisions"}],"predecessor-version":[{"id":1344,"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=\/wp\/v2\/posts\/1185\/revisions\/1344"}],"wp:attachment":[{"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1185"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.miguelsarmiento.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}