Description |
This article describes how it is possible to configure the FortiGate to get the IPv6 IP from the Internet and delegate it to the LAN. This article may be used as a reference to configure on other ISPs. However, it may not work as certain ISPs have their own setting to be followed, as more and more ISPs now have provided IPv6 to their subscriber. |
Scope | FortiGate with 7.2 and above. |
Solution |
Prerequisite: have a PPPoE setup for IPv4 and make sure the Internet is working.
Step 1: In the PPPoE VLAN 500 (UNIFI PPPoE interface VLAN) enable IPv6 as below:
config system interface
After this, check if IPv6 is getting from PPPoE:
And FortiGate will start communicating with FortiGuard using IPv6:
hostname # diag debug rating IP Weight RTT Flags TZ FortiGuard-requests Curr Lost Total Lost Updated Time
Step 2: In the LAN, enable IPv6 and delegation as below:
config system interface
After some time, there will be IPv6 in the LAN:
hostname # diag ipv6 address list ...
After reconnecting all machines in the LAN, all the devices should get an IPv6 public IP in this stage.
Step 3: Configure an IPv6 policy:
config firewall policy
Lastly, do not forgot to do an IPv6 Test: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.