Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

RamoFlor
New Contributor

NAT64

Hello, I'm new to the community.
I am currently doing a lab with IPv6, seeing that fortigate has the characteristic of doing NAT64, I have version 6.2.0

I have followed the guide of this link:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/443324/nat64-policy-and-dns64-dns-proxy

But I have some variants regarding the topology, the internal interface is a vlan as well as the external one.

I have navigation via IPv6, I have enabled my dns server for DNS64, but when I want to go to an IPv4 site the fortigate apparently does not perform the translation.
When I query an IPv4 site, my DNS server sends me the AAAA record: 64: ff9b :: 36cb: 46c9, but I get the impression that the fortigate doesn't know how to translate from 6 to 4. In the policy log NAT64 I have no match.

For a better visualization see the following diagram, hehehe I did it fast.

UploadedImages_epayH6F4SBWWjBFdtMBT_ipv6-nat64.png


Any help is welcome.
0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.