Skip to main content
Franck_G
Staff & Editor
Staff & Editor
December 1, 2021

Technical Tip: How to configure an IPv6 IP Pool for usage in firewall policy46 (Legacy, FortiOS 7.0.0 and older)

  • December 1, 2021
  • 0 replies
  • 1172 views
Description

This article describes how to configure an IPv6 IP Pool object for usage in a NAT46 Firewall Policy (aka config firewall policy46).

Scope FortiGate.
Solution

Important: This article discusses a legacy method of configuring NAT46 and NAT64 on the FortiGate. In FortiOS 7.0.0 and earlier, these NAT policies were configured separately from standard firewall policies (i.e., config firewall policy46 and policy64 in the CLI), but as of FortiOS 7.0.1 and later these commands have been removed and the NAT46/64 functionality has been merged into standard firewall policies. See also: Add interface for NAT46 and NAT64 to simplify policy and routing configurations. This article has been preserved for historical purposes and continues below.

 

The following screenshot shows an example of an existing NAT46 policy configured under config firewall policy46:

 

Franck_G_0-1638371439412.png

 

With this configuration, IPV4 clients coming in via port1 and destined for the external IPv4 address of 'VIP46' will then source NAT to IPv6 and transmitted out port2 towards the mapped IPv6 address of the VIP. As part of this, the FortiGate will source NAT the client's traffic to an address in the IPv6 prefix specified under config system nat64.

 

If a specific IPv6 address should be used for NAT'ing these outgoing connections then it is necessary to add an IPv6 IP Pool object to the policy. The following screenshot shows an example of an IPv6 pool under config firewall ippool6:

 

Franck_G_1-1638371796513.png

 

However, when attempting to add the above IP Pool object to the policy46, it does not appear as an available option and cannot be applied:

 

Franck_G_2-1638371939736.png

 

In order to make the IPv6 IP Pool object eligible for usage in NAT46 policies, the IPv6 prefix must be added as a secondary-prefix under config system nat64:

 

Franck_G_3-1638372225612.png

 

After adding the prefix to config system nat64, it becomes possible to set this IPv6 IP Pool in the NAT46 policy:

 

Franck_G_4-1638372281228.png

 

Related documents:

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!