Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zeihold_von_SSL
New Contributor

IPv6 with FWF60C

Hello guys, first of all, I' am totally new to ipv6. I have heared much about it (in theory) but I have never laid my hands on it. At our headquarter we have a /48 network (pa space) which is currently NOT in use (we are planning the ipv6 implementation within the next 12 months). One of the reasons why we are not up and running with ipv6 were the lack of ipv6 capable counterparts. Today, I noticed that my homeoffice router (AVM FritzBox) got an ipv4 AND and ipv6 address. To be precisely I got an /56 network assigned to my router. My home(lab) network looks like this: Internet <--> AVM Fritz Box <---> FWF60C <--> PC, FAP220B, ... Now I would like to assign an ipv6 address to all devices behind the FWF60C. My router assigns ipv6 address to all network devices DIRECTLY attatched to it via dhcpv6. I also redirects parts of the /56 network to other routers attatched to it (IA_PD and IA_NA). I was able to get an ipv6 address on the FWF60C wan1 port. But how to get ipv6 addresses distributed to the clients connected to the Fortigate? Cause I dont' t know if the assigned ipv6 network is " static" . What is the first thing I have to do to reach that goal? Thanks for you help! :) EDIT: I already added a ipv6 static route and a ipv6 firewall policy from the internal network (zone) to the internet (zone). EDIT2: I now know, that the assigned ipv6 network is dynamic. With every reconnect (which occurs every 24h) I get an other /56 ipv6 network. I have verified that with the logfiles of my router (AVM Fritzbox). EDIT3: I' am searching for something like this: http://www.juniper.net/techpubs/en_US/junos/topics/concept/subscriber-management-dual-stack-dhcpv6-iana-plus-pd.html EDIT4: This is exactly what I want/need for my/our homeoffice Fortigate units. So do the Fortigate supports prefix delegation? http://www.youtube.com/watch?v=EVD61Fteb_s

Regards Rene ---

[size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size]

Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B

Regards Rene --- [size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size] Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B
4 REPLIES 4
Zeihold_von_SSL
New Contributor

I have Feedback from the TAC support team. Unfortunately IPv6 prefix delegation is not implemented in OS5. So I have to raise a feature request. But this is awkward, I thought that Fortinet were fully IPv6 ready.... :\

Regards Rene ---

[size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size]

Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B

Regards Rene --- [size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size] Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B
tinyadmin

The FortiGate support IMHO more IPv6 features than other vendors. The marketing context for this it " fully IPv6 ready" . But there is much room for improvements, even at TAC support team.
emnoc
Esteemed Contributor III

Agreed Also ipv6 delegation is not commonly used in a lot of vendors 7 the same with DHCPv6 client support.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Zeihold_von_SSL

So, with FortiOS 5.4, prefix delegation is *finally* supported.

 

Before I start reconfiguring my FWF60D, I wanted to ask if someone got this up and running?!

Regards Rene ---

[size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size]

Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B

Regards Rene --- [size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size] Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B
Labels
Top Kudoed Authors