Hi all,
I recently switched from a Juniper SSG firewall cluster to a Fortigate 111c cluster and now my IPv6 routing is broke and can' t get it to work.
In our data-center we have a native IPv6 connection (dual stack) and a transparent link to our headquarters. In the previous setup the firewall cluster had an interface in the same VLAN (transparent) as the core switch on the headquarters.
In this VLAN most servers are present. I configured the firewall cluster as a router, but not to send router advertisements. The core switch had the IPv6 address of the cluster as it' s gateway. This was working fine.
Now with the fortigate, no traffic is routed by the firewall cluster. The core switch and firewall can ping each other. When I set the ip6-send-adv my servers get 2 gateways, resulting in some servers to be able to reach the systems in the data-center and the public internet, but not the computers at the headquarters (other VLAN). And servers that can access all on the headquarters but nothing in the data-center.
It appears to me that when ip6-send-av is not set, the interface does not route ipv6 traffic.
I can' t really change it to another VLAN so only the core switch and the firewall cluster see eachother, because of the IPv4 config that uses the same setup.
I can' t disable IPv6 routing for that VLAN on the core-switch in the headquarters because then all client to server traffic would first go to the data-center firewall cluster for routing.
Any suggestions on this?
Thanks,