LAN to WAN IPv6 traffic need manually add NAT policy

Description

LAN to WAN IPv6 traffic need manually add NAT policy.

Different from IPv4, SonicWall Firewall does not automatically create NAT policies for interfaces assigned as DMZ or LAN ports. When connect an IPv6 client to a LAN port (e.g. X0) and intend to surf the IPv6 Internet, you need to manually create an NAT policy for this client.

Resolution

Step 1:  Configure IPv6 client, LAN interface and WAN interface.
E.g.
X1:  2001:470:80b7:6714:X:X:X:X
X2: 2002:C0A8:88A8:1::1
Laptop: 2002:C0A8:88A8:1::2

Note: For IPv4 after configuration, by default, client can access the Internet. However,  for IPv6, after complete configuration on the firewall, client still cannot surf the IPv6 Internet.

Step 2: Navigate to Network | NAT Policies | Add.

Image

Add the above policy to translate source X0 IPv6 network address  to X1 IPv6 address when traffic from X0 to the outbound interface X1.
After adding this policy, client can access the IPv6 Internet.

How to test:

 Ping any Internet IPv6 address (google.com 2401:6800:4005:886::1013) from client. Ping should work.

Related Articles

  • SonicWall UTM throws an error : " Invalid Authentication " Error: SN and EPAID Do Not Match
    Read More
  • Firewall logs show frequent probe status changes after upgrade
    Read More
  • SSO Agent 4.0: Installation, Configurations, and troubleshooting
    Read More
not finding your answers?
was this article helpful?