FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Article Id 274872
Description This article describes how to change the default 'Block IPv6' setting within the FortiClient XML configuration file to enable IPv6 connectivity, ensuring a successful Dual Stack IPv4 and IPv6 configuration.
Scope FortiOS all Firmware, Forticlient v7.0+


In a situation where Dual Stack IPv4 and IPv6 are configured and FortiClient and FortiGate are used to establish a connection, it is possible to face an issue where the IPv6 address and route are not being received.


Within the FortiClient XML configuration file, the default setting for blocking IPv6 is set to '1'.



To modify this setting, follow these steps:


  1. Open FortiClient and Unlock the configuration by selecting the lock IconPicture25.png.
  2. Go to Picture26.png and Backup the configuration by selecting  Picture27.png.
  3. Enter the Config File name, Select the repository to save the file into, enter any password then select 'OK' to export.


  1.  Open the config file using Notepad or Notepad++.
  2. Search in the File for 'IPv6' using CTRL+F and there are two options: Under SSL VPN and under IPsec:



  1. Change the value from 1 to 0 then save the file.
  2. Import back the settings by selecting Restore in FortiClient settings (The password is the one previously chosen while exporting the config).


Now that the Block_IPv6 value has been changed from 1 to 0, it will be possible to receive the IPv6 address and the default route.


  1. Verify that the IPv4 and IPv6 addresses are assigned by FortiGate Dialup Config mode in FortiClient.



  1. Run CMD and type ipconfig to verify the IPv6 address received.


If any problem occurs, feel free to contact Fortinet Support: