IKEv2 IPv6 tunnel with dynamic endpoint from one IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IKEv2 IPv6 tunnel with dynamic endpoint from one IP

L3 Networker

With IPv4 it is possible to build multiple IPSec tunnels from one interface IP with dynamic/unknown destinations and separate them based on the IKE peer IDs. That configuration is accepted by the firewall.

As for IPv6, as soon as one source interface is used for multiple IPSec tunnel with dynamic peers, the following error is shown during commit:

• IKEv2 gateway CUSTOMER1-GW peer gateway address :: is not unique among gateways using local address xxxx:xxx:xx:x::2/64.(Module: ikemgr)
• IKEv2 gateway CUSTOMER2-GW peer gateway address :: is not unique among gateways using local address xxxx:xxx:xx:x::2/64.(Module: ikemgr)

 

As soon as source IPv6 for one of the tunnel is changed to a different one - commits succeeds.

 

This looks like a unnecessary limitation to me as IPv4 is accepting this configuration just fine.

Maybe not the most widely used configuration, but any input on this?

2 REPLIES 2

Community Team Member

Hi @nikoo ,

 

Looks like a missing feature.  Please check with your account manager if it's something that's on the roadmap or have him create a feature request for you which you can then add your vote to.

 

NGFW 

 

Cheers,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L0 Member

Noticed this aswell, I have a few branch sites where wanted to avoid NAT with IPSEC. Remote VPN endpoints are behind ISP provided routers which can only provide public IPv6 addresses to devices behind it. 

  • 1618 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!