FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Franck_G
Staff
Staff
Article Id 200077
Description This article describes how to configure an ipV6 pool on a firewall policy46.
Scope

The screenshot below shows an existing firewall policy46.

 

Franck_G_0-1638371439412.png

 

As there is no ippool6 configured on this firewall policy46, the outgoing traffic will use the default ipV6 address configured under '# config system nat64'.

 

If instead, it is needed to use a particular ippool6, for instance the one displayed in the following screenshot:

 

Franck_G_1-1638371796513.png

 

The next screenshot shows that it is not enough to enable ippool on the firewall policy46:

 

Franck_G_2-1638371939736.png

 

The poolname 'ipV6_pool' cannot be configured (if the name is entered anyway, an error will be displayed).

Solution

In order to be able to configure the chosen ippool6, the ipV6 range corresponding to this ippool6 has to be configured as secondary-prefix under '# config system nat64':

 

Franck_G_3-1638372225612.png

 

Then, it is possible to configure the ippool6 on the firewall policy46:

 

Franck_G_4-1638372281228.png
Contributors