FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Franck_G
Staff & Editor
Staff & Editor
Article Id 200077
Description This article describes how to configure an ipV6 pool on a firewall policy46.
Scope FortiGate.
Solution

The screenshot below shows an existing firewall policy46.

 

Franck_G_0-1638371439412.png

 

As there is no ippool6 configured on this firewall policy46, the outgoing traffic will use the default ipV6 address configured under 'config system nat64'.

 

It may instead be necessary to use a particular ippool6, such as the one displayed in the following screenshot:

 

Franck_G_1-1638371796513.png

 

The next screenshot shows that it is not enough to enable ippool on the firewall policy46:

 

Franck_G_2-1638371939736.png

 

The poolname 'ipV6_pool' cannot be configured (if the name is entered anyway, an error will be displayed).

 

In order to be able to configure the chosen ippool6, the ipV6 range corresponding to this ippool6 has to be configured as secondary-prefix under 'config system nat64':

 

Franck_G_3-1638372225612.png

 

Then, it is possible to configure the ippool6 on the firewall policy46:

 

Franck_G_4-1638372281228.png

 

Note: 

The commands 'config firewall policy64' and 'config firewall policy46' are supported only in FortiOS versions 6.2.x through 7.0.0

In FortiOS 7.0.1, these commands were removed, and their functionality was merged into the firewall policy for simplified configuration: FortiOS 7.0.1 Release Notes | Add interface for NAT46 and NAT64 to simplify policy and routing confi....