Description | This article describes how to use IPv6 ISDB objects in a firewall policy for SSL VPN dual-stack and is valid when using SSL VPN with the 'set dual-stack-mode enable' option. |
Scope | FortiGate up to v7.0.X, v7.2.10,v 7.4.5 and v7.6.0. |
Solution |
This feature was introduced first in FortiOS 7.0.0. Please keep in mind that dual-stack tunnel mode support requires a supported client. Check if the FortiClient version currently in use, supports the dual-stack feature.
The problem occurs when configuring IPv4+IPv6 policy, with source interface dual-stack SSL VPN. When internet-service is enabled, dstaddr in the firewall policy will not be used. Dual-stack feature for SSL VPN originally does not support internet-service, so when trying to configure IPv4-IPv6 policy with ISDB objects for dual-stack it will result in the error message:
FW81FD-4 (451) # sh FW81FD-4 (451) # end
A similar error is visible when trying to configure the same policy from the GUI: If an SSL VPN firewall policy is set to either internet-service or internet-service6, then dual-stack-mode cannot be enabled in vpn.ssl.settings. This behavior changed in v7.6.1+ and v7.4.6+ where ISDB is possible to be configured directly, without any errors. For all firmware versions, it is possible to apply a workaround, where the firewall policy is first configured with a normal IPv6 destination address and saved. After that, the admin can edit the policy and add ISDB objects.
The ISDB support for dual-stack SSL VPN was added starting from v7.6.1 and v7.4.6. |