02-05-2016 10:36 AM
So we're rolling out IPv6 to our network, one thought that just crossed my mind is what kind/if any support for IPv6 does GlobalProtect have?
An issue I see is when we start listed AAAA records for internal servers in DNS, external VPN users will get those responses and will try to access those directly (and be denied) unless I can route them over the tunnel.
I currently get an error adding a IPv6 range to the gateway config thought I can add an access route to the config for an IPv6 block but after some brief testing it doesn't make it to the client.
Any thoughts?
04-17-2016 04:48 AM
User has router in between or is directly connected to ISP?
ISP gives out only IPv6 or IPv6 and IPv4 both?
Can user uncheck "IPv6 checkbox" under adapter settings and try then?
Palo has IPv6 enabled or not?
04-17-2016 12:00 PM
Well,
The ISP of the end user is UPC and the IPv6 is provided by the ISP to the ISP provided router.
test ipv6 results:
ISP gives out only IPv6 or IPv6 and IPv4 both?
Both I guess.
Can user uncheck "IPv6 checkbox" under adapter settings and try then?
Same result,
IPv6 is disabled on PA, we haven't enabled it.
What IP address would i give it to the interface? I'd say I'd have to obtain one from ISP before I could enable it on the PA right ?
04-18-2016 03:12 AM
I have UPC at home but it does not give out IPv6.
Will chec with them if they can enable it so I could test.
02-26-2020 05:40 AM
How is this solved? Solution is showing that Global Protect VPN doesn't support IPv6. Is that it?
08-14-2021 11:49 AM
The thread started in 2016.
You may want to check out this page now:
Configure GlobalProtect and IPv6 | Palo Alto Networks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!