🌐 IPv6 Support Across PAN-OS Features
Palo Alto Networks' PAN-OS offers comprehensive IPv6 support across various features:
-
Security Features:
App-ID, Content-ID, User-ID, SSL Decryption, URL Filtering, DoS protection, and more.
-
Networking:
Static and dynamic routing (OSPFv3, BGP), NAT64, NPTv6, GRE tunneling, ECMP, and dual-stack interfaces.
-
Management:
IPv6 support for management interfaces, Panorama communication, and services like DNS, NTP, SNMP.
-
VPN:
GlobalProtect, IKEv2, IPSec tunnels supporting IPv6 traffic.
-
High Availability:
Active/Passive and Active/Active HA configurations with IPv6 support.
For a detailed compatibility matrix, refer to the official documentation:
IPv6 Support by Feature
🔧 IPv6 Addressing and NAT
PAN-OS supports various IPv6 addressing and translation mechanisms:
-
Static and Dynamic Addressing:
Configure interfaces with static IPv6 addresses or use DHCPv6 with Prefix Delegation (introduced in PAN-OS 11.0).
-
SLAAC:
Stateless Address Autoconfiguration for automatic IPv6 address assignment.
-
NAT64:
Allows IPv6-only clients to communicate with IPv4 servers.
-
NPTv6:
Network Prefix Translation for IPv6-to-IPv6 translation, useful in multi-homing scenarios.
For more information on configuring these features, visit:
DHCPv6 Client with Prefix Delegation
☁️ IPv6 in Prisma Access
Prisma Access extends IPv6 support for both private and public applications:
-
Private App Access:
Support for IPv6 connections to internal applications.
-
Public App Access:
Native IPv6 support for internet and SaaS applications (requires specific versions and configurations).
-
GlobalProtect Integration:
IPv6 support for mobile users connecting via GlobalProtect.
For comprehensive details, refer to:
IPv6 Support in Prisma Access