# Firewalld and IPv6 routing on Rocky 8.6

**URL:** <https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482>\
**Category:** Rocky Linux Help & Support\
**Created:** [July 4, 2022, 5:20am UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482 "2022-07-04T05:20:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![lee](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/lee/32/807_2.png) [@lee](https://forums.rockylinux.org/u/lee)\
**Post date:** [July 4, 2022, 5:20am UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482/1 "2022-07-04T05:20:21Z")

</div>

I had configured IPv6 routing on a Rocky Linux base machine and a Rocky Linux VirtualBox VM (both migrated from CentOS 8.5)  
My issue started after upgrading Rocky from 8.5 to 8.6.

The issue on the VM:

1. cannot update via DNF (timeout).
2. letsencrypt does not update (connection timeout).

ping6 to inside from outside and outside to inside works on VM.  
curl -6 [www.google.com](http://www.google.com), curl -6 [www.bing.com](http://www.bing.com) works from inside VM.

Everything works if I stop the firewalld service on the base machine, but the ssh connection to the VM is disconnected, and I have to re-login.

What should I do?

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [July 4, 2022, 6:53pm UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482/2 "2022-07-04T18:53:02Z")

</div>

Are you saying that under CentOS 8.5 you were able to connect from a VirtualBox guest (via it’s hardware based host) to the DNF endpoints using pure IPv6, via some kind of router and without any translation?

I think you’re also saying it’s only the VM guest that’s broken, and that the hardware based host connects perfectly to the DNF endpoints using pure IPv6?

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [July 4, 2022, 8:10pm UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482/3 "2022-07-04T20:10:00Z")

</div>

Which 8.6’s kernel, the initial `4.18.0-372.9.1.el8` or the recent `4.18.0-372.13.1.el8_6` ?

> [@lee](#):
>
> Everything works if I stop the firewalld service on the base machine, but the ssh connection to the VM is disconnected, and I have to re-login.

First, I don’t know VirtualBox for I do use libvirt/KVM “out of the box”. On the latter, if VM’s are in “virtual subnet” (I also tend to use _bridged_ i.e. VM’s are on the external “concrete” subnet), then the host must route between subnets and there are nftables rules injected by libvirt/firewalld that make that routing happen. Shutting down firewall probably erases those rules, which changes routing and in turn affects connections. Presumably.

---

<div class="post-metadata">

**Author:** ![lee](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/lee/32/807_2.png) [@lee](https://forums.rockylinux.org/u/lee)\
**Post date:** [July 5, 2022, 2:45am UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482/4 "2022-07-05T02:45:10Z")

</div>

> [@gerry666uk](#):
>
> Are you saying that under CentOS 8.5 you were able to connect from a VirtualBox guest (via it’s hardware based host) to the DNF endpoints using pure IPv6, via some kind of router and without any translation?

Yes,

It is a Hetzner Dedicated Server.

---

<div class="post-metadata">

**Author:** ![lee](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/lee/32/807_2.png) [@lee](https://forums.rockylinux.org/u/lee)\
**Post date:** [July 5, 2022, 2:47am UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482/5 "2022-07-05T02:47:10Z")

</div>

> [@jlehtone](#):
>
> Shutting down firewall probably erases those rules, which changes routing and in turn affects connections. Presumably.

OK, I have done some sysctl settings also.

---

<div class="post-metadata">

**Author:** ![lee](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/lee/32/807_2.png) [@lee](https://forums.rockylinux.org/u/lee)\
**Post date:** [July 5, 2022, 2:52am UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482/6 "2022-07-05T02:52:09Z")

</div>

Many thanks for the replies.  
I was trying many changes to sysctl.conf and firewalld.  
Today morning I see that everything is working fine.  
I am still unsure whether my settings did the trick or if some system update solved the issue.

@jlehtone  
I updated everything, including the kernels, which are now at 4.18.0-372.13.1.el8\_6.

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 3:46am UTC](https://forums.rockylinux.org/t/firewalld-and-ipv6-routing-on-rocky-8-6/6482/7 "2023-08-25T03:46:29Z")

</div>


