Silly question, but do you have IPv6 enabled on your firewall? Stands to reason if you are getting IPv6 recorded that you simply have IPv6 enabled across one of your interfaces, and thus the traffic is getting recorded. I haven't seen any abnormal IPv6 traffic generation across my 10.1 lab endpoints where I don't actively have IPv6 enabled.
Sorry, but it says it's fixed in 10.1.3 and some users reported that it temporarily worked. I'm currently working with support which hasn't produced results yet.
(PA-800 and PA-7000 Series firewalls and the PA-220 firewall only) Fixed an issue where ACC and scheduled reports (
Monitor > Manage > Manage Custom Reports) incorrectly displayed the IPv6 address instead of the IPv4 address.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!