<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Properly routing IPv6 across site-to-site IPSEC tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/properly-routing-ipv6-across-site-to-site-ipsec-tunnel/m-p/443971#M100279</link>
    <description>&lt;P class=""&gt;&lt;FONT color="#000000"&gt;Configuration:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;I have two /56 IPv6 prefixes, one which is used in our Bay Area office, and one which is unused. I have taken a /64 from the unused /56 prefix and assigned it for use by our office in The Netherlands. They will use DHCP to assign the addresses to a small set of workstations that need to send IPv6 traffic across our site-to-site tunnel (PA-820 and PA-220 endpoints) and out our local ISP (to bypass GeoIP filtering that is making testing difficult for the engineering team there).&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;I believe what I need to do is create a PBF rule on the NL side PA that takes the source interface/zone and IPv6 range and forwards packets to the tunnel interface as egress. I 'm fairly certain that I need to define a next-hop IP, and I am uncertain how to proceed. Do I need to assign IPv6 to both tunnel interfaces, and if so, what is the correct way to determine IPs for these. IPv6 is enabled on the tunnel interfaces so they presumably have link-local IPv6 addresses I can get from the CLI, but I am not sure if these are the correct way to proceed . On the local side, the traffic should just follow the default route to the internet and return traffic should route back through our edge and I'll just need to set up a static route for the /64 block to route back across the tunnel to NL.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;Any input is appreciated.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Oct 2021 16:43:07 GMT</pubDate>
    <dc:creator>Antonio_719</dc:creator>
    <dc:date>2021-10-29T16:43:07Z</dc:date>
    <item>
      <title>Properly routing IPv6 across site-to-site IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/properly-routing-ipv6-across-site-to-site-ipsec-tunnel/m-p/443971#M100279</link>
      <description>&lt;P class=""&gt;&lt;FONT color="#000000"&gt;Configuration:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;I have two /56 IPv6 prefixes, one which is used in our Bay Area office, and one which is unused. I have taken a /64 from the unused /56 prefix and assigned it for use by our office in The Netherlands. They will use DHCP to assign the addresses to a small set of workstations that need to send IPv6 traffic across our site-to-site tunnel (PA-820 and PA-220 endpoints) and out our local ISP (to bypass GeoIP filtering that is making testing difficult for the engineering team there).&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;I believe what I need to do is create a PBF rule on the NL side PA that takes the source interface/zone and IPv6 range and forwards packets to the tunnel interface as egress. I 'm fairly certain that I need to define a next-hop IP, and I am uncertain how to proceed. Do I need to assign IPv6 to both tunnel interfaces, and if so, what is the correct way to determine IPs for these. IPv6 is enabled on the tunnel interfaces so they presumably have link-local IPv6 addresses I can get from the CLI, but I am not sure if these are the correct way to proceed . On the local side, the traffic should just follow the default route to the internet and return traffic should route back through our edge and I'll just need to set up a static route for the /64 block to route back across the tunnel to NL.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;Any input is appreciated.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;FONT color="#000000"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 16:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/properly-routing-ipv6-across-site-to-site-ipsec-tunnel/m-p/443971#M100279</guid>
      <dc:creator>Antonio_719</dc:creator>
      <dc:date>2021-10-29T16:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Properly routing IPv6 across site-to-site IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/properly-routing-ipv6-across-site-to-site-ipsec-tunnel/m-p/444015#M100284</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/198098"&gt;@Antonio_719&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can forward traffic to tunnel interface directly without mentioning any IP address as a next hop. PFB snap for ref. Did you tried this? This should work as per your requirement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SutareMayur_0-1635415210207.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37312i79D41CB9248E4A63/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SutareMayur_0-1635415210207.png" alt="SutareMayur_0-1635415210207.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 10:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/properly-routing-ipv6-across-site-to-site-ipsec-tunnel/m-p/444015#M100284</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-10-28T10:00:40Z</dc:date>
    </item>
  </channel>
</rss>

