When an IPv6-only client initializes a connection to an IPv4 client/server, the IPv6 packets received by the NAT64 translator look like ordinary IPv6 packets:
After these packets are processed through the NAT policy, they are converted IPv4 packets and are handled by SonicOS again. At this point, the source zone for these packets is WAN, while the destination zone is the same as the original IPv6 packets. If the cache for these IPv4 packets is not already created, these packets undergo policy checking. In order to prevent these packets from being dropped, a WAN-to-WAN Allow access rule must be configured.
To create a WAN-to-WAN access rule
Navigate to the POLICY | Rules and Policies > Access Rules page.
Click +Add. The Adding Rule dialog displays.
Configure the options:
Option | Value |
---|---|
Action | Allow |
Source Zone/Interface | WAN |
Destination Zone/Interface | WAN |
Source Address | Any |
Source Port/Services | Any |
Destination Port/Services | Any |
Destination Address |
All WAN IP All WAN IP is the default address group created by SonicOS that includes all WAN IP addresses that belong to the firewall WAN interface(s). All WAN IP cannot be configured. |
Users Included | All |
Users Excluded | None |
Schedule | Always on |
Comment | IPv4 from Any to Any for Any service (optional) |
All other options | Leave as is or optionally configure accordingly |