IPv6 IPsec VPN
This topic describes how to configure the IPv6 IPsec VPN feature on your FortiGate device.
You can configure IPv6 using the CLI. To configure IPv6 using GUI, ensure IPv6 is enabled by going to System > Feature Visibility and enabling IPv6. |
Overview
FortiOS supports route-based IPv6 IPsec, but not policy-based. This section describes different ways IPv6 IPsec can be used:
IPv4 over IPv6 |
The VPN gateways have IPv6 addresses. The protected networks have IPv4 addresses. The phase 2 configurations at either end use IPv4 selectors. See Site-to-site IPv4 over IPv6 VPN example for sample configuration. |
IPv6 over IPv4 |
The VPN gateways have IPv4 addresses. The protected networks use IPv6 addresses. The phase 2 configurations at either end use IPv6 selectors. See Site-to-site IPv6 over IPv4 VPN example for sample configuration. |
IPv6 over IPv6 | Both the VPN gateways and the protected networks use IPv6 addresses. The phase 2 configurations at either end use IPv6 selectors. See Site-to-site IPv6 over IPv6 VPN example for sample configuration. |
Configuring IPv6 IPsec VPNs
Configuration of an IPv6 IPsec VPN follows the same sequence as for an IPv4 route-based VPN:
Phase 1 and Phase 2 settings | The configuration is the same as for an IPv4 route-based VPN, except that ip-version is set to 6 and the remote-gw6 keyword is used to specify an IPv6 remote gateway address. See Phase 1 configuration and Phase 2 configuration for more information. |
||
Security policies | To complete the VPN configuration, you need a security policy in each direction to permit traffic between the protected network’s port and the IPsec interface. You need IPv6 policies unless the VPN is IPv4 over IPv6. See VPN security policies for more information. | ||
Routing |
Appropriate routing is needed for both the IPsec packets and the encapsulated traffic within them:
Routing is dependent on the method:
|
You can configure Phase 1 and Phase 2 settings from VPN > IPsec Wizard.
To configure Phase 1 and phase 2 settings:
-
Go to VPN > IPsec Wizard.
-
Enter a name and set Template type to Custom.
-
Click Next.
-
Under Network, set IP Version to IPv6 .
-
Configure the rest of phase 1 and phase 2 settings as required and click OK.