Skip to main content
Visitor III
July 10, 2026
Solved

IPv6 Best Security Practices for Beginner

  • July 10, 2026
  • 5 replies
  • 141 views

How to Protect Fortigate from IPv6 Security Risks

Best answer by sjoshi

Create explicit IPv6 deny policies for known-bad sources.
The local-in policy (config firewall local-in-policy6) controls inbound traffic to the FortiGate itself over IPv6 — the equivalent of filtering management plane access.

5 replies

JasonXXAuthor
Visitor III
July 10, 2026

So if I am unfamiliar with how to set up the IPv6 dual stack properly would I be best to disable all incoming IPv6 traffic to my SDWAN through the local in policies? Can someone please give me the CLI command to do this as I’m still on 7.4.12 and cannot edit the local in policies from the GUI. Are there any other security risks I should be aware of? Currently one ISP is giving me a /64 and the other a /128 neither of which are very useful as I have a number of VLANS. I plan to research IPv6 and learn about it but just want to make sure that my set up is secure for now.

New Member
July 11, 2026

I too am interested in learning more about this, there isn’t a lot of information available.

sjoshi
Staff
sjoshiAnswer
Staff
July 11, 2026

Create explicit IPv6 deny policies for known-bad sources.
The local-in policy (config firewall local-in-policy6) controls inbound traffic to the FortiGate itself over IPv6 — the equivalent of filtering management plane access.

Thanks, Salon
JasonXXAuthor
Visitor III
July 23, 2026

Trying to set up an implicit local-in-policy6 to deny outside traffic. Followed Fortinet documentation but when I look at the policy it doesn’t state deny. How do I do this?

JasonXXAuthor
Visitor III
July 20, 2026

So until I have time to study and set up a working dual stack would I be best to put a local in implicit deny IPv6 policy as well? Are there any other mitigations or best practices to consider?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.