sk174348 - Spark Firewall - IPv6 Limitations

Spark Firewall - IPv6 Limitations

Product: Spark Firewall
Version: R80.20.X (EOS), R81.10.X, R82.00.X
OS: Gaia Embedded
Platform: 1500, 1600, 1800, 1900, 2000, 2500
Last Modified: 2026-05-04

Solution

This article provides known limitations for IPv6 on Spark Firewall Appliances.

Non-Supported Features

Known Limitations

Non-Supported Features for IPv6

Management

Networking

Security

Services

Known Limitations

Enter the string to filter this table:

ID Description Reported
In
Resolved
In
### Gaia Clish
SMB-2186 In IPv6 mode, you can only configure a bridge to the internet in the WebUI, and not in Gaia Clish. R80.20.00 R80.20.00
Build
990171652
### Gaia WebUI
SMB-1541 During the reboot after you switch the device to IPv6 mode in the WebUI, a session timeout popup is sometimes shown. R80.20.00 -
### Networking
SMB-15419 Configuring a LAN port as internet connection is not supported with IPv6 internet connection types. R80.20.00 -
SMB-137 You cannot configure IPv6 addresses for SNMP Trap Receivers. R80.20.00 -
SMB-891 When you change a LAN interface that was previously defined with an IPv4 address and DHCP server to be pure IPv6, the DHCPv4 server must be disabled. R80.20.00 -
SMB-947 In IPv6-mode (dual stack), you can configure multiple IPv4 internet connections in HA/LS mode, but only a single IPv6 internet connection. R80.20.00 -
SMB-1529 Netflow is not supported for IPv6 traffic. R80.20.00 -
SMB-1206 Dynamic routing is not supported for IPv6 traffic. Specific options relevant for IPv6 in dynamic routing CLISH do not apply. R80.20.00 -
SMB-1021 Configuring additional loopback interfaces via CLISH does not support dual stack and IPv6. R80.20.00 -
SMB-2078 DNS trap functionality in Anti-Malware is not supported for IPv6 traffic. R80.20.00 -
SMB-2455 Bridging an IPv4 or IPv6 internet connection which is part of a dual stack is not supported. You must bridge both of the dual stack internet connections, or separate the connections on different interfaces before bridging. R80.20.00 -
SMB-15064 IPv6-only LAN alias isn't supported - an IPv4 address is required for each alias alongside the IPv6 address. R77.20.00 R80.20.00
### Security
SMBGWY-1291 Smart Accel does not support IPv6. R81.10.05 -
### Access and NAT
SMB-70 The ability to inspect 6in4 or 6to4 tunnels using a service called SIT_with_Intra_Tunnel_Inspection, and to handle IPv6 extension headers are not supported. R80.20.00 -
SMB-1256 In Small and Medium Business appliances, NAT related policy changes do not apply immediately on existing ICMPv6 traffic until timeout within the connections table or reboot. New ICMPv6 connections will use the new policy immediately. R80.20.00 -
SMB-1137 In locally managed appliances, server objects are network objects with automatic access and NAT configuration. In these appliances, server objects do not support IPv6 or dual stack. Functionality for IPv6 addresses can still be obtained by manually configuring access and NAT rules. R80.20.00 -
SMB-1385 In locally managed appliances, the ability to write a free IP address for a Rule Base source and destination (access, NAT, Threat Prevention exceptions) is only available for IPv4 addresses. For IPv6 / dual stack addresses, a network object must be defined and used. R80.20.00 -
SMB-1649 NAT64 is not supported for Embedded Gaia appliances (and is not supported in the R80.10 Security Management Server). R80.20.00 -
SMB-2122 Manual NAT rules that are configured on a dual stack locally managed cluster and that use "This gateway" object apply only to IPv4 VIP (Virtual IP address of the cluster). To create manual NAT rules for the IPv6 VIP, a manual network object must be created and used. R80.20.00 -
### Threat Prevention
SMB-15551 Threat Emulation is not supported in pure IPv6 mode. It is only supported in the Dual Stack mode. R80.20.00 -
SMB-490,
SMB-1214,
01170605
The Threat Emulation Software Blade does not support IPv6 traffic. R80.20.00 -
SMB-86 The Anti-Spam Software Blade does not support IPv6 traffic. R80.20.00 -
SMB-1848 In Centrally Managed 1430/1450 appliances, when IPv6 is enabled, installing policy with all blades active and a large IPS policy as the built-in strict profile may fail with an "Installation Failed. Reason: Failed to load Policy on Security Gateway" message. To optimize the IPS profile, refer to sk105217. R80.20.00 -
SMB-369 POP3 Deep Inspection is not supported for IPv6 traffic. R80.20.00 -
### Identity Awareness
SMB-1061 When using AD based rules, to make the rules apply both on IPv6 traffic and IPv4 traffic, the AD server must support dual stack and both its IPv6 and its IPv4 addresses must be configured in the Security policy. R80.20.00 -
SMB-978 The URL address for the Browser Based Authentication portal in Identity Awareness / User Awareness needs to use a "" string instead of a hardcoded IP address to work simultaneously in a dual stack environment for both IPv4 and IPv6 traffic. R80.20.00 -
SMB-1575 When you define a RADIUS server in a dual stack network for authentication purposes (for a Captive Portal or Hotspot), if an IPv4 address is configured, that will be the address used. You can configure an IPv6 address without also configuring an IPv4 address. In dual stack networks, configure the primary RADIUS server with an IPv4 address only, and the second RADIUS server with an IPv6 address only. R80.20.00 -
SMB-2495 "Invalid object name. Name should begin with a letter and contain up to 32 alphanumeric (0-9, a-z, _ -.) characters without spaces" error when creating pure IPv6 Active Directory. When adding Active Directory as an Authentication Server, it must be configured in Dual Stack mode. R80.20.00 -
### Management and Log Servers
SMB-1467 In the "Security Management" web page on the gateway, the IP address used in the recent connection between management and gateway is shown. If both are defined with dual stack IPv4 and IPv6 addresses, the web page will still show the single IP address which was used. R80.20.00 -
SMB-1764 An external syslog server cannot be configured with an IPv6 address. R80.20.00 -
SMB-15266 When configuring IPv6-only NTP servers, issues arise when changing mode to manual time and then back to NTP. R80.20.00 -
### Cluster
SMB-1674 In Locally Managed appliances, to change an existing cluster in pure IPv4 mode to dual stack mode, you should break and rebuild the cluster, as this is a major change in network configuration. Both cluster members should be configured in IPv6 mode. R80.20.00 -
- VPN
SMB-15573 IPv4 IPsec tunnel over an IPv6 non-IPsec tunnel is not supported. R80.20.00 -
SMB-15391 Site to Site VPN and Remote Access VPN are not supported when the Internet connection is of type DS-Lite. R80.20.00 -

Revision History

Date Description
25 Aug 2024 Improved formatting
12 July 2021 First release of this article

Article Properties

Access Level: General
Status: Approved
Date Created: 2021-07-05
Last Modified: 2026-05-04