ipv6 tunneled in ipv4 (protocol 41) - Hurricane Electric Free IPv6 Tunnel Broker

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

ipv6 tunneled in ipv4 (protocol 41) - Hurricane Electric Free IPv6 Tunnel Broker

L0 Member

I am trying to setup ipv6 tunneled in ipv4 on one of my mac client machine that is behind nat. (192.168.1.100)

Is this supported by PA-200 firewall or do i need to setup special rules to allow it or even some sort of destination NAT?

Lets say in the example public IP is 1.1.1.1 and private ip is 192.168.1.100 and commands required to setup a tunnel one the client are:

Macos example:

ifconfig gif0 create
ifconfig gif0 tunnel 1.1.1.1 184.105.253.14
ifconfig gif0 inet6 2001:111:1111:d5::2 2001:111:1111:d5::1 prefixlen 128
route -n add -inet6 default 2001:111:1111:d5::1

 

It does not work for me and tunnel is not established.

 

1 REPLY 1

Community Team Member

Hi @Bartosz ,

 

ipv6 over ipv4 tunneling is supported by Palo. I would recommend following the PAN-OS Admin Guide.

in setting up your tunnel.

 

Additionally, be sure to check the following:

1. IPv6 is enabled on the firewall.

2. Necessary Security Policies are created to allow the tunnel traffic to pass through.

3. Configure NAT since your Mac client, configure a DNAT policy to map the public IP to the internal IP of your Mac.

4. Verify Firewall zones and interfaces are configured correctly

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 1584 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!