Dual stack in SSLVPN tunnel mode (Forticlient) and NAT when using IPv6
Hello, we are planning to implement dual stack for Forticlient SSLVPN users. (FortiOS 7.0.14, Forticlient 7.0.7 free version)
We are aware that when using dual stack the firewall policies MUST be configured with both IPv4 and IPv6 stacks.
We have an SSL pool of addresses for IPv4 and another SSL pool of addresses for IPv6.
Questions:
1) - Does forticlient get both an IPv4 and an IPv6 when connected? (Dual stack enabled in Forticlient)
2)- Since NAT is required for IPv4 to work (in example: SSLVPN -> Internet ), how is IPv6 traffic handled?
Do you require to also use an IPv6 address in the outbound firewall rule to NAT the outgoing traffic?
Thanks
