sk39374 - FAQ - IPv6 support for Security Gateways R80.20 and lower

FAQ - IPv6 support for Security Gateways R80.20 and lower

Product: Security Gateways

Version: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20.X (EOS)

OS: Gaia Embedded

Last Modified: 2024-08-25

Solution

For R80.30 and higher, see sk163313 - IPv6 features and limitations in R80.30 and higher

VPN Support with IPv6

These VPN features are not supported for IPv6:

IPv6 is supported in IPsec VPN communities with the following limitations:

Does VSX support IPv6?

Do you need a license to enable support for IPv6?

No IPv6-specific license is required on the Security Gateway. Starting from R75.40, no special license is required on the Security Management Server or Multi-Domain Management Server.

New IPv6 support

R80.20 introduces support for:

Advanced Routing and Clustering Enhancements Hotfix for R80.10 introduces support for:

Features not supported with IPv6

The following features are NOT supported:

Is Full HA supported with IPv6?

Full HA is supported with the following limitations:

How to enable IPv6 support on the Security Gateway

For Gaia OS, go to System Management -> System Configuration, turn on IPv6 Support, and click "Apply".

CLI command: # set ipv6-state on

For SecurePlatform OS, refer to sk34552.

For IPSO OS, if the interfaces are configured for IPv6 prior to Security Gateway installation, all the required IPv6 related files are automatically enabled during the install process. To enable IPv6 functionality at a later stage, run this command and reboot:

ipso[admin]# $FWDIR/scripts/fwipv6_enable

Note: This requires a reboot to activate!

Can I have a Security Gateway that only runs IPv6?

Starting from R76, it is possible to operate a Security Gateway (regular or VS mode) entirely with IPv6, except for one IPv4 address that is required on the interface used for management.

How to disable IPv6 on the machine

For Gaia OS, go to System Management -> System Configuration, turn off IPv6 Support, and click "Apply".

Note: this will immediately reboot your gateway!

CLI command: # set ipv6-state off

For SecurePlatform and IPSO, run this command and reboot:

# $FWDIR/scripts/fwipv6_enable off

To disable IPv6 functionality completely, remove the IPv6 license from the Security Management Server and disable IPv6 on all the Security Gateways.

How does the Security Gateway handle fragmented IPv6 traffic?

In IPv6, fragmentation is handled by the client. If the Gateway receives a packet that it cannot transmit due to an MTU issue, the Gateway sends back the relevant ICMP message to tell the client they need to send a smaller packet. The client sends the Gateway a smaller (fragmented) packet, which the Gateway does inspect.

How to handle IPv6 Extension Headers

By default, the Check Point Security Gateway drops all extension headers, except fragmentation. This can be adjusted by editing the allowed_ipv6_extension_headers section of $FWDIR/lib/table.def file on the Security Management Server.

Furthermore, there is an option to block type zero even if the Routing header is allowed. To block type zero, configure the kernel parameter fw6_allow_rh_type_zero. The default of 0 means it is always blocked. If the value is set to 1, then the action is according to allowed_ipv6_extension_headers.

IPv6 support in R77.x, and R80.x

Can we inspect 6in4 or 6to4 tunnels?

If you define an IPv6 rule and the traffic is tunneled in IPv4, the Gateway cannot enforce it unless you use in addition a service called SIT_with_Intra_Tunnel_Inspection. If the Security Gateway does the tunnel termination, then the firewall kernel does enforce the rule because it sees the IPv6 packet.

Note: this feature requires IPv6 support to be enabled. This is because the tunneled IPv6 traffic is inspected by the IPv6 kernel, not the IPv4 kernel.

Can link-local addresses be used for virtual IPs in ClusterXL and/or VRRP?

Link-local VIP is available only with VRRPv3. The administrator must make sure that all physical link-local addresses are unique. For example, no two interfaces must be configured with fe80::1.

Does SmartConsole support IPv6?

Yes. However, the operating system on which SmartConsole is installed must be configured to work with IPv6.


Old versions

What are the most common unsupported features/products with IPv6 in pre-R76 versions?

The following are some of the common IPv4 features that are not supported for IPv6:

IPv6 support in R75.4x and R75.40VS

What is the IPv6Pack?

The IPv6Pack is an optional Gateway package for SecurePlatform that enables additional features for IPv6 traffic (e.g., ClusterXL HA, SecureXL, CoreXL). The IPv6Pack is available for R60, R65 HFA_50 and R70.1 releases on SecurePlatform, as well as for R60 on IPSO.

Refer to the Release Notes for the exact list of features enabled in the IPv6Pack.

Does any release incorporate IPv6Pack-level functionality?

R75.40 and higher for SecurePlatform and Gaia incorporates IPv6 support for CoreXL, SecureXL, and ClusterXL HA. No special hotfix is required.

Without IPv6Pack installed in pre-R75.40 releases, what features are supported in Security Gateway?

The following is a list of supported features in the standard Security Gateway releases:

What IPv6 features are supported in VSX R68?

The following is a list of IPv6-specific features supported in VSX R68:

Is there any performance degradation when IPv6 is enabled?

In releases prior to R75.40 where IPv6Pack is not installed, enabling IPv6 has the following impact:

Is there any protection if unsupported features are used with IPv6?

If unsupported features are used with IPv6, there are no warning or error messages during policy compilation and installation. If unsupported features are used, the results are unpredictable and system crashes or other security related problems may occur.

Why do SecurePlatform and IPSO not support IPv6 in R76 and higher?

The changes required to support additional features with IPv6 in R76 and higher utilize OS-related infrastructure not present in SecurePlatform OS or IPSO OS.

Which IPSO release has support for IPv6 for Security Gateway?

IPSO 3.7 and higher has support for IPv6 in Security Gateway.