IPv6 support
The features below support IPv6-to-IPv6 forwarding in Reverse Proxy, Offline Protection, True Transparent Proxy, and Transparent Inspection operation modes.
NAT64 and NAT46 are supported only in Reverse Proxy mode. No matter the virtual server and the back-end server are in IPv4 or IPv6 addresses, or mixed with both, IPv4-to-IPv6 and IPv6-to-IPv4 forwarding are fully supported by the following features in Reverse Proxy mode.
- IP/Netmask for all types of network interfaces and DNS settings
- Gateway and Destination IP/Mask for IP-layer static routes
- Virtual Server/V-zone
- Server Pool
- Server Health Check
- Protected Hostnames
- Configuring an HTTP server policy
- X-Forwarded-For
- Session Management
- Cookie Security Policy
- Signatures
- Custom Policy
- Parameter Validation
- Hidden Fields Protection
- File Security
- HTTP Protocol Constraints
- Configuring a protection profile for inline topologies
- URL Access
- Configuring a protection profile for inline topologies (page order)
- Configuring a protection profile for inline topologies
- Allow Method
- IP List (manual, individual IP blacklisting/whitelisting)
- File Compress
- Vulnerability scans
- Configuring the global object white list
- Chunk decoding
- FortiGuard server IP overrides (see Connecting to FortiGuard services)
- URL Rewriting (also redirection)
- HTTP Authentication and LDAP, RADIUS, and NTLM profiles
- Geo IP
- DoS Protection Policy
- SNMP traps & queries
- IP Reputation
- Device Tracking (see Monitoring currently tracked devices )
- HTTP Header Security (see Addressing security vulnerabilities by HTTP Security Headers)
Features not yet supported are:
If a policy has any virtual servers or server pools that contain physical or domain servers with IPv6 addresses, it does not apply these features, even if they are selected. |
- Shared IP
- Policy bypasses for known search engines
- Firewall
- Log-based reports
- Alert email
- Syslog and FortiAnalyzer IP addresses
- NTP
- FTP immediate/scheduled
- SCEP
- Anti-defacement
- HA/Configuration sync
exec restore
exec backup
exec traceroute
exec telnet