Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

stefszab
New Contributor II

5.2.5 firmware and ipv6 web filtering

hi,

does anyone of you have ipv6 policies in use and in those policies webfilter enable?

i upgrade my 1000c from 5.2.4 to 5.2.5 last night and it seems that webfilter on ipv6 is not blocking anymore facebook.com.

on ipv4 is fine and is doing what we need but in ipv6 policies which uses the same security profiles like ipv4 is not blocking websites.

2 REPLIES 2
krahemat_FTNT

Hi Stefan,

Have you done a debug flow of the packets arriving back to the firewall?  My guess is that the returning traffic is still IPv4 not IPv6 thus not hitting your IPv6 policies.  Do you also have ant NAT6to4 configuration?

 

Regards,

 

Karim

Stepmerc

Just a warning for all the parents who are exploitation associate IPv6 DNS address from OpenDNS. there's no content filtering if you have got originated their filtering service. One resolution bestowed was to leverage their basic family defends addresses reborn to IPv6: Best Essay Writing Service UK