EA Feature: IPv6 in SD-WAN

This section describes an SD-WAN feature in the Early Availability stage.

Important:

  • Contact the SD-WAN team to get information about the new R82 SD-WAN Early Availability features before starting your journey.

  • To get this feature, you must install the R82 Early Availability packages on the SD-WAN Security Gateway.

    See the "Downloads" section in sk180605.

Overview

SD-WAN supports IPv6 traffic only for Local Breakout scenarios.

SD-WAN can steer IPv6 traffic to local IPv6 Internet links.

SD-WAN does not support IPv6 for Overlay VPN and tunnel selection.

SD-WAN ignores "Overlay" rules that contain IPv6 objects (a warning appears).

Important - SD-WAN features that are related to Overlay (such as tunnel-based steering) operate only on IPv4.

Prerequisite

Enable IPv6 support on the SD-WAN Security Gateway and reboot it.

See the Gaia Administration Guide for your version.

Important - Without IPv6 support enabled, the Security Gateway does not install IPv6 SD-WAN rules. As a result, it handles IPv6 traffic using the OS routing (not SD-WAN routing).

SD-WAN Behavior in IPv6

When IPv6 support and SD-WAN are enabled on the Security Gateway:

  • The Security Gateway loads a separate IPv6 Firewall instance.

    This IPv6 Firewall instance handles SD-WAN rule matching for IPv6 traffic.

  • The Security Gateway loads a separate SD-WAN steering process (sdwan_steering6).

    This process handles all probes over IPv6 and steering decisions for IPv6.

  • The Security Gateway inspects IPv6 traffic independently from IPv4 traffic.

IPv6 Support in SD-WAN Interfaces

An SD-WAN interface can operate in one of these modes:

  • IPv4 single-stack.

  • IPv6 single-stack.

  • Dual-stack (IPv4 and IPv6 on the same interface).

Depending on the configuration, an interface can have:

  • Only an IPv4 next hop.

  • Only an IPv6 next hop.

  • Both IPv4 and IPv6 next hops.

Configuring SD-WAN Next Hop for IPv6

Configuring "Accessible via NAT"

SD-WAN supports configuring NAT accessibility separately for IPv4 and IPv6.

Note - This configuration applies to future IPv6 Overlay support.

Overlay does not support IPv6 at this time.

WAN Link Mapping

SD-WAN Policy Behavior with IPv6

NAT per ISP with IPv6

See SD-WAN NAT for ISP.

Monitoring and Statistics

Internal Architecture and Troubleshooting