IPv6 Support by Feature
Table of Contents
Expand all | Collapse all
- CN-Series Firewalls
- MFA Vendor Support
-
- Cloud Identity Engine Cipher Suites
-
- PAN-OS 11.2 GlobalProtect Cipher Suites
- PAN-OS 11.2 IPSec Cipher Suites
- PAN-OS 11.2 IKE and Web Certificate Cipher Suites
- PAN-OS 11.2 Decryption Cipher Suites
- PAN-OS 11.2 Administrative Session Cipher Suites
- PAN-OS 11.2 HA1 SSH Cipher Suites
- PAN-OS 11.2 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 11.2 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 11.1 GlobalProtect Cipher Suites
- PAN-OS 11.1 IPSec Cipher Suites
- PAN-OS 11.1 IKE and Web Certificate Cipher Suites
- PAN-OS 11.1 Decryption Cipher Suites
- PAN-OS 11.1 Administrative Session Cipher Suites
- PAN-OS 11.1 HA1 SSH Cipher Suites
- PAN-OS 11.1 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 11.1 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 11.0 GlobalProtect Cipher Suites
- PAN-OS 11.0 IPSec Cipher Suites
- PAN-OS 11.0 IKE and Web Certificate Cipher Suites
- PAN-OS 11.0 Decryption Cipher Suites
- PAN-OS 11.0 Administrative Session Cipher Suites
- PAN-OS 11.0 HA1 SSH Cipher Suites
- PAN-OS 11.0 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 11.0 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 10.2 GlobalProtect Cipher Suites
- PAN-OS 10.2 IPSec Cipher Suites
- PAN-OS 10.2 IKE and Web Certificate Cipher Suites
- PAN-OS 10.2 Decryption Cipher Suites
- PAN-OS 10.2 Administrative Session Cipher Suites
- PAN-OS 10.2 HA1 SSH Cipher Suites
- PAN-OS 10.2 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 10.2 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 10.1 GlobalProtect Cipher Suites
- PAN-OS 10.1 IPSec Cipher Suites
- PAN-OS 10.1 IKE and Web Certificate Cipher Suites
- PAN-OS 10.1 Decryption Cipher Suites
- PAN-OS 10.1 Administrative Session Cipher Suites
- PAN-OS 10.1 HA1 SSH Cipher Suites
- PAN-OS 10.1 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 10.1 Cipher Suites Supported in FIPS-CC Mode
-
- PAN-OS 9.1 GlobalProtect Cipher Suites
- PAN-OS 9.1 IPSec Cipher Suites
- PAN-OS 9.1 IKE and Web Certificate Cipher Suites
- PAN-OS 9.1 Decryption Cipher Suites
- PAN-OS 9.1 Administrative Session Cipher Suites
- PAN-OS 9.1 HA1 SSH Cipher Suites
- PAN-OS 9.1 PAN-OS-to-Panorama Connection Cipher Suites
- PAN-OS 9.1 Cipher Suites Supported in FIPS-CC Mode
- Prisma Access
- Strata Cloud Manager and Panorama Feature Parity
- User-ID Agent
- Terminal Server (TS) Agent
- Strata Logging Service Software Compatibility
- Cortex XDR
- Endpoint Security Manager (ESM)
- IPv6 Support by Feature
- Mobile Network Infrastructure Feature Support
IPv6 Support by Feature
Use the following table to review PAN-OS® features (listed by category) that support IPv6
traffic.
PAN-OS Feature | PAN-OS 9.1 | PAN-OS 10.1 | PAN-OS 10.2 | PAN-OS 11.0 | PAN-OS 11.1 | PAN-OS 11.2 |
---|---|---|---|---|---|---|
Security | ||||||
WildFire® Appliance | — | √ | √ | √ | √ | √ |
App-ID™ and Firewalling in Layer 2 and Layer 3 | √ | √ | √ | √ | √ | √ |
User-ID™ | √ | √ | √ | √ | √ | √ |
Content-ID™ | √ | √ | √ | √ | √ | √ |
Block IPv6 in IPv4 Tunneling (via App-ID) | √ | √ | √ | √ | √ | √ |
Zone Protection | √ | √ | √ | √ | √ | √ |
Packet-Based Attack Protection | √ | √ | √ | √ | √ | √ |
Reconnaissance Protection | √ | √ | √ | √ | √ | √ |
URL Filtering | √ | √ | √ | √ | √ | √ |
SSL Decryption | √ | √ | √ | √ | √ | √ |
SSH Decryption | √ | √ | √ | √ | √ | √ |
DoS Rulebase | √ | √ | √ | √ | √ | √ |
IPv6 Access to PAN-DB | √ | √ | √ | √ | √ | √ |
DNS Sinkhole | √ | √ | √ | √ | √ | √ |
External Dynamic List (EDL) | √ | √ | √ | √ | √ | √ |
Management &
Panorama™ | ||||||
SSH Management (dedicated MGMT port) | √ | √ | √ | √ | √ | √ |
Web Interface Management (dedicated MGMT
port) | √ | √ | √ | √ | √ | √ |
Interface Management (ping, telnet, ssh, http,
https - all ports) | √ | √ | √ | √ | √ | √ |
Device to Panorama SSL TCP Connection | √ | √ | √ | √ | √ | √ |
Panorama HA Connection Between Peers | √ | √ | √ | √ | √ | √ |
DNS | √ | √ | √ | √ | √ | √ |
Dynamic DNS Support for Firewall Interfaces (DHCP-based
interfaces) | √ | √ | √ | √ | √ | √ |
RADIUS | √ | √ | √ | √ | √ | √ |
LDAP | √ | √ | √ | √ | √ | √ |
SYSLOG | √ | √ | √ | √ | √ | √ |
SNMP | √ | √ | √ | √ | √ | √ |
NTP | √ | √ | √ | √ | √ | √ |
Device DNS (device only) | √ | √ | √ | √ | √ | √ |
DNS Proxy | √ | √ | √ | √ | √ | √ |
Reporting and Visibility in to IPv6 | √ | √ | √ | √ | √ | √ |
IPv6 Address Objects | √ | √ | √ | √ | √ | √ |
IPv6 FQDN Address Objects | √ | √ | √ | √ | √ | √ |
SD-WAN | ||||||
SD-WAN IPv6 Basic Connectivity | — | — | — | √ (11.0.2 & later) | √ | √ |
SD-WAN for NGFW IPv6 support | — | — | — | — | √ | √ |
Networking | ||||||
IPv6 Static Routes | √ | √ | √ | √ | √ | √ |
PBF | √ | √ | √ | √ | √ | √ |
PBF Next-Hop Monitor (v6 endpoint) | √ | √ | √ | √ | √ | √ |
OSPFv3 | √ | √ | √ | √ | √ | √ |
MP-BGP | √ | √ | √ | √ | √ | √ |
GRE Tunneling Support | √ | √ | √ | √ | √ | √ |
ECMP | √ | √ | √ | √ | √ | √ |
Dual Stack Support for L3 Interfaces | √ | √ | √ | √ | √ | √ |
QoS Policy | √ | √ | √ | √ | √ | √ |
QoS Marking | √ | √ | √ | √ | √ | √ |
DSCP (session based) | √ | √ | √ | √ | √ | √ |
Neighbor Discovery and Duplicate Address Detection | √ | √ | √ | √ | √ | √ |
Tunnel Content Inspection | √ | √ | √ | √ | √ | √ |
Virtual Wires | √ | √ | √ | √ | √ | √ |
NPTv6 (stateless prefix translation) | √ | √ | √ | √ | √ | √ |
NAT64 (IP-IPv6 protocol translation) | √ | √ | √ | √ | √ | √ |
LLDP (Link Layer Discovery Protocol) | √ | √ | √ | √ | √ | √ |
Bidirectional Forwarding Detection (BFD) | √ | √ | √ | √ | √ | √ |
IPv6 PPPoE Client | — | — | — | — | √ | √ |
Dynamic IPv6 Addressing on the Management Interface | — | — | — | — | √ | √ |
VPN | ||||||
GlobalProtect™ | √ | √ | √ | √ | √ | √ |
IKE/IPSec | √ | √ | √ | √ | √ | √ |
IKEv2 | √ | √ | √ | √ | √ | √ |
IPv6 over IPv4 IPSec Tunnel | √ | √ | √ | √ | √ | √ |
Large Scale VPN (LSVPN) | √ | √ | √ | √ | √ | √ |
Host Dynamic
Address Configuration | ||||||
DHCPv6 Relay | √ | √ | √ | √ | √ | √ |
DHCPv6 Client with Prefix Delegation ( Dataplane Interface
only ) | — | — | — | √ | √ | √ |
SLAAC (Router Advertisements) | √ | √ | √ | √ | √ | √ |
SLAAC (Router Preference) | √ | √ | √ | √ | √ | √ |
SLAAC (RDNSS) | √ | √ | √ | √ | √ | √ |
Device | ||||||
High Availability (HA)—Active/Active | √ | √ | √ | √ | √ | √ |
HA—Active/Passive | √ | √ | √ | √ | √ | √ |
HA—IPv6 transport for HA1 & HA2 | √ | √ | √ | √ | √ | √ |
HA Path Monitoring (IPv6 Endpoint) | √ | √ | √ | √ | √ | √ |
HA Clustering | — | √ | √ | √ | √ | √ |
User-ID | ||||||
Map IPv6 Address to Users | √ | √ | √ | √ | √ | √ |
Captive Portal for IPv6 | √ | √ | √ | √ | √ | √ |
Connection to User-ID Agents over IPv6 | √ | √ | √ | √ | √ | √ |
User-ID XML API for IPv6 | √ | √ | √ | √ | √ | √ |
Terminal Server Agent IPv6 | √ | √ | √ | √ | √ | √ |