Hi,
- FortiOS 7.2.10
Currently we are using Dialup Ikev2 with certificates and it is working, the issue is when some home users using latest NBN/Internet which by default use IPV6 are unable to connect to VPN and we are forced to change the source to IPV4 for the home users.
We are looking the best way to fix this issue, thinking if we enable IPV6 on the firewall external interface, it might fix it. If we enable IPV6 support on the External WAN interface and ensure the new IPV6 public is matching the VPN gateway, so that VPN users using IPV6 can connect to VPN and use IPV4 for client to server communication.
I can't see clear documentation for IPV6 on this.
Any advise or suggestions is highly appreciated.
TIA :)
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi,
We're still looking for an answers or help. In the meantime, if anyone has any input on the topic, it's very welcome!
Hi again, martyyy,
There's some confusion about 'and we are forced to change the source to IPV4 for the home users.' as you don't seem to be using IPv6 on the FortiGate WAN at the moment.
From what I've been told: if your ISP can provide IPv6 addressing to the FortiGate wan, you can allow the users to connect to the VPN over IPv6, and still be able to route IPv4 traffic inside this IPv6 tunnel.
The following documents are recommended reading:
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/600821/ipv6-ipsec-vpn
https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPv4-over-IPv6-IPSec-Tunnel/ta-p/253492
I hope these help!
User | Count |
---|---|
2270 | |
1232 | |
772 | |
452 | |
396 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.