Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mithu
Contributor

IPv4 traffic over IPv6 IPSec tunnel

I am not sure this is the correct place to address this requirement..

Recently one of my customer had a requirement to create an IPSec tunnel with their partner company, peer side having only IPv6 public IP address and customer having IPv6 and IPv4 public address, and customer and partner side infrastructure network is utilizing IPv4 address scheme. Then we realized this requirement cannot be fulfilled by Checkpoint as of now. So I managed to terminate IPSec using an opensource firewall instance in VM environment and the help of NAT, somehow the solution is provided.

My concern is why checkpoint does not support this feature.  Google quoted that 30% of the internet is using IPv6 at this point of time, so near future most of the ISP connection would be IPv6 only addresses. Big enterprises will adopt IPv6 for their environment but small and medium enterprises will continue with IPv4 addressing for their infrastructure. My prediction is  IPv4 traffic inside an IPv6 IPSec tunnel will be the common use-case within a year or two not to mention some of the customers already started to utilize this technology. 

I hope Checkpoint will release this functionality with upcoming releases.

 

6 Replies
PhoneBoy
Admin
Admin

We can do separate tunnels with IPv4 and IPv6, but currently can’t tunnel one in the other.
I recommend engaging with your local Check Point office around this requirement.

Wolfgang
Authority
Authority

@PhoneBoy are there any news about 4in6?

We had the similar use case, IPv6 IPSEC-tunnel between gateways and only IPv4 networks in the encryption domains of the gateways. Something new with R81.10 or R81.20 or something on the roadmap ?

PhoneBoy
Admin
Admin

Haven't seen/heard anything about this in the roadmap.
As I said above, best to engage with the local Check Point office around this requirement.

0 Kudos
Yasushi_Kono1
Contributor
Contributor

Hi Daemon,

I have got a request for a migration of an old firewall environment to something new. I would love to get the opportunity to migrate to Check Point. This will be a multi-million Dollar project in the heart of Germany in an OT infrastructure. One requirement is that the IPv4 packets to be forwarded into an IPv6 IPSec Tunnel. I haven't tested this, but is there a special requirement for this? As even in R82, NAT64 is not supported. I haven't tested a configuration in which the external interface of a gateway is IPv6 only and the internal ones IPv4 only. Does this work? If not, you need to acquire programmers to code this as soon as possible.

0 Kudos
PhoneBoy
Admin
Admin

NAT46 / NAT64 is supported from R81.10: https://support.checkpoint.com/results/sk/sk163313 
If/how it works with VPN is a separate question.

_Val_
Admin
Admin

Open an RFE

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events