Thanks a lot for your suggestion. Adding this rule has solved my problem.

pass out quick on trunk0 inet6 from 2a0a:e5c1:b18::/48 to any flags S/SA 
route-to 2a0a:e5c1:b18::12



> Le 5 oct. 2026 à 19:14, Stuart Henderson <[email protected]> a écrit :
> 
> On 2026-10-05, Pierre Dupond <[email protected]> wrote:
>> Hi All,
>>        I plan to do some policy routing to route some IPv6 address to a 
>> specific ISP.
>> 
>> I have installed a new routing table (with the numer 1) and I can route
>> correctly the packets with the following command:
>>                route -T 1 exec traceroute6 -s 2a0a:e5c1:b18:6000::9003 
>> www.ibm.com
>> but if I try to  pass the command
>>                traceroute6 -s 2a0a:e5c1:b18:6000::9003 www.ibm.com
>> the wrong route (the standard default route) is always followed.
>> 
>> The pf rules are quite minimalistic but does not seem to be used:
>> 
>> block return all
>> match in inet6 from 2a0a:e5c1:b18::/48 to any rtable 1
>        ^^
> by running traceroute6 on the host itself, there is no inbound packet
> 
>> pass all flags S/SA
>> block return in on ! lo0 proto tcp from any to any port 6000:6010
>> block return out log proto tcp all user = 55
>> block return out log proto udp all user = 55
>> 
>> By following the idea of this article: 
>> https://www.openbsdhandbook.com/advanced-networking/multi-wan-policy-routing/
>> I have tried the rule:
>>          pass in quick from 2a0a:e5c1:b18::/48  to any route-to 
>> 2a0a:e5c1:b18::12/128 keep state 
>> without more success.
>> 
>> Does somebody has an idea on what is wrong?
>> 
>> I have exhausted all my own ideas.
>> 
>> Thanks.
>> 
>> Best regards
>> 
>> 
> 
> 
> -- 
> Please keep replies on the mailing list.
> 

Reply via email to