IPv6 address pushed through FortiGate FG100/FG200 instead of assigned IPv4 address
Hi All,
According to FortiGate support, I am the only person in the whole world who has had this problem.
Configuration: FortiClient 7.0.2/.3 on MAC (Monterey) -> FG100/200 (6.4.8) IPsec VPN -> Cloudflare -> Secure Website
IPv6 is not configured on the FortiGates.
Depending on the Internet provider (xFinity) and Verizon (hotspot), The user receives a block on Cloudflare because it see the xFintiy IPv6 address instead of the FG100/200 Internet IPv4 address. Cloudflare only allows the FG100/200 IPv4 address access to the website. If the user swaps to their hotspot, then the user can access the website.
It doesn't matter what user is used to sign into the IPSec VPN.
Fortinet support believe the issue is FortiClient, but since we don't have EMS, they won't provide support.
I believe the issue is on the FortiGate side as the IPv4 IP address assigned to the IPSec connection should be the address that is pushed through the FortiGate and seen by Cloudflare. (Yes. The Cloudflare error page shows the IPv6 IP of the user. And No. Split tunneling is not active. If it was, the user would not be able to access the website as their local IP (xFinity and hotspot) are not allowed through Cloudflare.)
Any ideas you may have would be helpful.
