Skip to main content
edson2024
New Member
February 29, 2024
Question

Dual stack in SSLVPN tunnel mode (Forticlient) and NAT when using IPv6

  • February 29, 2024
  • 8 replies
  • 3864 views

Hello, we are planning to implement dual stack for Forticlient SSLVPN users. (FortiOS 7.0.14, Forticlient 7.0.7 free version)

We are aware that when using dual stack the firewall policies MUST be configured with both IPv4 and IPv6 stacks.

We have an SSL pool of addresses for IPv4 and another SSL pool of addresses for IPv6. 

 

Questions:

1) - Does forticlient get both an IPv4 and an IPv6 when connected? (Dual stack enabled in Forticlient)

2)- Since NAT is required for IPv4 to work (in example: SSLVPN -> Internet ), how is IPv6 traffic handled?

     Do  you require to also use an IPv6 address in the outbound firewall rule to NAT the outgoing traffic?

 

Thanks

8 replies

Anthony_E
Staff
Staff
March 4, 2024

Hello edson2024,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
March 6, 2024

Hello edson2024,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Best Regards
Anthony_E
Staff
Staff
March 11, 2024

Hello edson 2024,

 

Did you have a look at this document?:

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/766455/dual-stack-ipv4-and-ipv6-support-for-ssl-vpn

 

Tell me if it helping. If not, we will continue to investigate.

 

Regards,

Best Regards
edson2024
edson2024Author
New Member
March 11, 2024

Hi.. yes, i had a look into that document, it does not address the issue... We are not using (or planning to use)  the "Enabled based on policy destination" option, for us, Split tunneling is disabled and the policies will be source All destination All... 

 

thanks

Anthony_E
Staff
Staff
March 11, 2024

Hello edson,

 

Oh ok! We will continue to have a look then.

 

Regards,

Best Regards
edson2024
edson2024Author
New Member
March 20, 2024

hi, anything? ... it cannot be that complex

btan
Staff & Editor
Staff & Editor
March 21, 2024

Hi edson2024,

1) Yes, FCT does get both ipv4 and ipv6 when dual stack enabled, albeit in FCT GUI it will only show ipv4 IP it gets.

 

2) As it is full tunnel, I'd reckon you will need to include ipv6 address in FW policy.

jwhite_FTNT
Staff
Staff
May 9, 2024

Per the dual-stack referenced, you would enable Dual-Stack on the FortiGate VPN Gateway setup as well as in the EMS FortiClient setup.  If NAT is enabled on the dual-stack Firewall Policy, it enables both IPv4 NAT and IPv6 NAT66 (both enabled by default when selecting NAT option), thus NAT sources from the egress interface's IP address (IPv4/6 address election depends on if the client initiates traffic on IPv4 or IPv6).  There are other NAT options, such as: NAT46, NAT64, NAT Pools or you could choose to setup central NAT...

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.