Hi All,
After updating to 8.960-9, IPv6 is unusable again.
I tried the old trick of turning of IPS and/or web filtering but no effect.
This effects my servers and workstation that had a perfectly OK connect before the upgrade. ( I did reboot one server and the workstation, didn't help either)
According to the firewall log the packets are all being dropped:
ssh example from solaris server.
Same from freshly rebooted workstation.
So it should be allowed.
PS: access for you guys is still enabled.
After updating to 8.960-9, IPv6 is unusable again.
I tried the old trick of turning of IPS and/or web filtering but no effect.
This effects my servers and workstation that had a perfectly OK connect before the upgrade. ( I did reboot one server and the workstation, didn't help either)
According to the firewall log the packets are all being dropped:
Code:
21:05:38 Default DROP TCP
2001:6f8:1480:30::25 : 60909
→
2001:1938:81:164::2 : 22
[SYN] len=80 srcmac=2:8:20:aa:ea:74 dstmac=0:50:56:ab:52:e8
21:05:39 Default DROP TCP
2001:6f8:1480:30::25 : 60909
→
2001:1938:81:164::2 : 22
[SYN] len=80 srcmac=2:8:20:aa:ea:74 dstmac=0:50:56:ab:52:e8
21:05:41 Default DROP TCP
2001:6f8:1480:30::25 : 60909
→
2001:1938:81:164::2 : 22
[SYN] len=80 srcmac=2:8:20:aa:ea:74 dstmac=0:50:56:ab:52:e8
21:05:42 Default DROP TCP
2001:6f8:1480:30::25 : 42246
→
2001:6f8:334:0:5054:ff:fec4:ca99 : 6667
[SYN] len=80 srcmac=2:8:20:aa:ea:74 dstmac=0:50:56:ab:52:e8
21:05:46 Default DROP TCP
2001:6f8:1480:30::25 : 60909
→
2001:1938:81:164::2 : 22
[SYN] len=80 srcmac=2:8:20:aa:ea:74 dstmac=0:50:56:ab:52:e8
21:05:48 Default DROP TCP
2001:6f8:1480:30::25 : 39120
→
2001:1418:13:1::25 : 7000
[SYN] len=80 srcmac=2:8:20:aa:ea:74 dstmac=0:50:56:ab:52:e8
21:05:55 Default DROP TCP
2001:6f8:1480:30::25 : 60909
→
2001:1938:81:164::2 : 22
[SYN] len=80 srcmac=2:8:20:aa:ea:74 dstmac=0:50:56:ab:52:e8
Code:
21:06:56 Default DROP TCP
2001:6f8:1480:15:48da:790:350d:15b0 : 52854
→
2001:1938:81:164::2 : 22
[SYN] len=84 srcmac=e4:ce:8f:a:db:a8 dstmac=0:50:56:ab:52:ea
21:06:57 Default DROP TCP
2001:6f8:1480:15:48da:790:350d:15b0 : 52854
→
2001:1938:81:164::2 : 22
[SYN] len=84 srcmac=e4:ce:8f:a:db:a8 dstmac=0:50:56:ab:52:ea
21:06:58 Default DROP TCP
2001:6f8:1480:15:48da:790:350d:15b0 : 52854
→
2001:1938:81:164::2 : 22
[SYN] len=84 srcmac=e4:ce:8f:a:db:a8 dstmac=0:50:56:ab:52:ea
21:06:59 Default DROP TCP
2001:6f8:1480:15:48da:790:350d:15b0 : 52854
→
2001:1938:81:164::2 : 22
[SYN] len=84 srcmac=e4:ce:8f:a:db:a8 dstmac=0:50:56:ab:52:ea
21:07:00 Default DROP TCP
2001:6f8:1480:15:48da:790:350d:15b0 : 52854
→
2001:1938:81:164::2 : 22
[SYN] len=84 srcmac=e4:ce:8f:a:db:a8 dstmac=0:50:56:ab:52:ea
21:07:02 Default DROP TCP
2001:6f8:1480:15:48da:790:350d:15b0 : 52854
→
2001:1938:81:164::2 : 22
[SYN] len=84 srcmac=e4:ce:8f:a:db:a8 dstmac=0:50:56:ab:52:ea
So it should be allowed.
PS: access for you guys is still enabled.