Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Meni
New Contributor II

VPN SSL double stack IPV4 and IPV6

Hi i have a problem to ativate double stack for  vpn ssl

 

config vpn ssl settings
    set dual-stack-mode enable
end

Response in cli mode

 

set dual-stack-mode enable
To enable dual-stack-mode, all SSL-VPN policies must be configured with IPv4 and IPv6.
node_check_object fail! for dual-stack-mode enable 

 

I have only one vpn policie. do you have an idea ?

Regards

2 Solutions
Meni
New Contributor II

where do you pu this argument ?

View solution in original post

edson2024
New Contributor II

Hello, when dual-stack is configured on the fortigate and you connect with Forticlient 7.0.7 with "Enable Dual-stack IPv4/IPv6 address". Do you get ONLY an IPv6 address?. Also, once connected. In example, if you have an SSLVPN zone to Internet zone Firewall policy. How does that work? For IPv4 you would need NAT, but for IPv6. You would not need NAT.  Can you have one policy for IPv4 (NAT'ing) and different policy for IPv6 not NAT'ing?

View solution in original post

11 REPLIES 11
dbu
Staff
Staff

Hi @Meni ,
Have you included IPv4 and IPv6 on the SSL VPN policy?

Have a look at the guide here:
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/766455/dual-stack-ipv4-and-ipv6-supp...

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Meni
New Contributor II

Hi @dbu 

 

Thanks for your response

I changed my policy. Before i have a policy for v4 and one for v6. I put all V4 and V6 and the same.

Now the dual stack is ok but when i connect vpn i only have v6 address and ip V4 is not forwarding

Regards

 

dbu

What do you mean ?
Do you have an IPv4 stack configured on your client ?

Check with ipconfig /all .


If yes, try to ping
execute ping www.bing.com

 

You can use this command and check if you see any traffic:
diagnose sniffer packet any icmp 4



Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Meni
New Contributor II

 

find the problem but not the solution

 

When i make connection, i don't have ipv4 adresse distributed by fortigtate

 

Adresse IPv6. . . . . . . . . . . . . .: fdff:ffff::2(préféré)
Adresse d’autoconfiguration IPv4 . . . : 169.254.196.34(tentative)

 

 

Meni
New Contributor II

I made some test. Its very strange

When i made connection to vpn SSL with IPV6 address i can access only on ipv6 devices

When i made connection to vpn SSL with IPV4 address i can access only on ipv4 devices

 

Really strange 

dbu

I have not tested this myself, but i think dual stack means that client can use either IPv4 or IPv6 to connect to the destination address. 
In your case when you connect with IPv6 you can reach only IPv6 destinations available . 
So you choose which stack to use.  You will get an IPv6 assigned and not an IPv4. 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Meni
New Contributor II

I have the impression but it's still not very friendly
It will be difficult to choose the V4 or v6 connection depending on the servers to reach

Thansk for your help

 

I'm still looking

 

 

 

dbu

If you are using the web mode, users can access both IPv4 and IPv6 bookmarks in the portal.
The attribute, 
prefer-ipv6-dns can be enabled to prefer querying IPv6 DNS first, or disabled to prefer querying IPv4.

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Meni
New Contributor II

where do you pu this argument ?

Labels
Top Kudoed Authors