Fortigate 7.6.4 - VPN IPsec SAML Dialup IPv4/IPv6
Hello everyone,
we are currently running a FortiGate on firmware 7.6.4 with an IPsec dialup VPN using SAML authentication over IPv4. This setup works without any issues.
However, more and more of our users are receiving IPv6-only connections from their ISPs (no public IPv4 available anymore), which causes the IPsec tunnel to fail. Because of this, we want to migrate the dialup VPN to IPv4/IPv6 (dual stack).
I have several questions regarding the required prerequisites:
Does the FortiGate WAN interface need a public IPv6 address from the ISP in order for IPv6-only clients to connect?
Does the FQDN used for the dialup VPN also need a AAAA DNS record, so clients can resolve the FortiGate over IPv6?
Is switching the Phase1/Phase2 interface to “IPv4/IPv6”, and adding IPv6 firewall policies enough? What about the DNS resolution of the internal hosts?
Thanks in advance, is there any migrating doc available? I can only see SSL VPN IPV6 docs.
