Technical Tip: How to configure an IPv6 IP Pool for usage in firewall policy46 (Legacy, FortiOS 7.0.0 and older)
| Description | This article describes how to configure an IPv6 IP Pool object for usage in a NAT46 Firewall Policy (aka config firewall policy46). |
| Scope | FortiGate. |
| Solution | Important: This article discusses a legacy method of configuring NAT46 and NAT64 on the FortiGate. In FortiOS 7.0.0 and earlier, these NAT policies were configured separately from standard firewall policies (i.e., config firewall policy46 and policy64 in the CLI), but as of FortiOS 7.0.1 and later these commands have been removed and the NAT46/64 functionality has been merged into standard firewall policies. See also: Add interface for NAT46 and NAT64 to simplify policy and routing configurations. This article has been preserved for historical purposes and continues below.
The following screenshot shows an example of an existing NAT46 policy configured under config firewall policy46:
With this configuration, IPV4 clients coming in via port1 and destined for the external IPv4 address of 'VIP46' will then source NAT to IPv6 and transmitted out port2 towards the mapped IPv6 address of the VIP. As part of this, the FortiGate will source NAT the client's traffic to an address in the IPv6 prefix specified under config system nat64.
If a specific IPv6 address should be used for NAT'ing these outgoing connections then it is necessary to add an IPv6 IP Pool object to the policy. The following screenshot shows an example of an IPv6 pool under config firewall ippool6:
However, when attempting to add the above IP Pool object to the policy46, it does not appear as an available option and cannot be applied:
In order to make the IPv6 IP Pool object eligible for usage in NAT46 policies, the IPv6 prefix must be added as a secondary-prefix under config system nat64:
After adding the prefix to config system nat64, it becomes possible to set this IPv6 IP Pool in the NAT46 policy:
Related documents: |





