Compatibility Matrix
IPv6 Support by Feature
Table of Contents
                    IPv6 Support by Feature
Use the following table to review PAN-OS® features (listed by category) that support IPv6
            traffic.
| PAN-OS Feature | PAN-OS 9.1 | PAN-OS 10.1 | PAN-OS 10.2 | PAN-OS 11.0 | PAN-OS 11.1 | PAN-OS 11.2 | 
|---|---|---|---|---|---|---|
| Security | ||||||
| WildFire® Appliance | — | √ | √ | √ | √ | √ | 
| App-ID™ and Firewalling in Layer 2 and Layer 3 | √ | √ | √ | √ | √ | √ | 
| User-ID™ | √ | √ | √ | √ | √ | √ | 
| Content-ID™ | √ | √ | √ | √ | √ | √ | 
| Block IPv6 in IPv4 Tunneling (via App-ID) | √ | √ | √ | √ | √ | √ | 
| Zone Protection | √ | √ | √ | √ | √ | √ | 
| Packet-Based Attack Protection | √ | √ | √ | √ | √ | √ | 
| Reconnaissance Protection | √ | √ | √ | √ | √ | √ | 
| URL Filtering | √ | √ | √ | √ | √ | √ | 
| SSL Decryption | √ | √ | √ | √ | √ | √ | 
| SSH Decryption | √ | √ | √ | √ | √ | √ | 
| DoS Rulebase | √ | √ | √ | √ | √ | √ | 
| IPv6 Access to PAN-DB | √ | √ | √ | √ | √ | √ | 
| DNS Sinkhole | √ | √ | √ | √ | √ | √ | 
| External Dynamic List (EDL) | √ | √ | √ | √ | √ | √ | 
| Management & Panorama™ | ||||||
| SSH Management (dedicated MGMT port) | √ | √ | √ | √ | √ | √ | 
| Web Interface Management (dedicated MGMT
                                port) | √ | √ | √ | √ | √ | √ | 
| Interface Management (ping, telnet, ssh, http,
                                https - all ports) | √ | √ | √ | √ | √ | √ | 
| Device to Panorama SSL TCP Connection | √ | √ | √ | √ | √ | √ | 
| Panorama HA Connection Between Peers | √ | √ | √ | √ | √ | √ | 
| DNS | √ | √ | √ | √ | √ | √ | 
| Dynamic DNS Support for Firewall Interfaces (DHCP-based
                                interfaces) | √ | √ | √ | √ | √ | √ | 
| RADIUS | √ | √ | √ | √ | √ | √ | 
| LDAP | √ | √ | √ | √ | √ | √ | 
| SYSLOG | √ | √ | √ | √ | √ | √ | 
| SNMP | √ | √ | √ | √ | √ | √ | 
| NTP | √ | √ | √ | √ | √ | √ | 
| Device DNS (device only) | √ | √ | √ | √ | √ | √ | 
| DNS Proxy | √ | √ | √ | √ | √ | √ | 
| Reporting and Visibility in to IPv6 | √ | √ | √ | √ | √ | √ | 
| IPv6 Address Objects | √ | √ | √ | √ | √ | √ | 
| IPv6 FQDN Address Objects | √ | √ | √ | √ | √ | √ | 
| SD-WAN | ||||||
| SD-WAN IPv6 Basic Connectivity | — | — | — | √ (11.0.2 & later) | √ | √ | 
| SD-WAN for NGFW IPv6 support | — | — | — | — | √ | √ | 
| Networking | ||||||
| IPv6 Static Routes | √ | √ | √ | √ | √ | √ | 
| PBF | √ | √ | √ | √ | √ | √ | 
| PBF Next-Hop Monitor (v6 endpoint) | √ | √ | √ | √ | √ | √ | 
| OSPFv3 | √ | √ | √ | √ | √ | √ | 
| MP-BGP | √ | √ | √ | √ | √ | √ | 
| GRE Tunneling Support | √ | √ | √ | √ | √ | √ | 
| ECMP | √ | √ | √ | √ | √ | √ | 
| Dual Stack Support for L3 Interfaces | √ | √ | √ | √ | √ | √ | 
| QoS Policy | √ | √ | √ | √ | √ | √ | 
| QoS Marking | √ | √ | √ | √ | √ | √ | 
| DSCP (session based) | √ | √ | √ | √ | √ | √ | 
| Neighbor Discovery and Duplicate Address Detection | √ | √ | √ | √ | √ | √ | 
| Tunnel Content Inspection | √ | √ | √ | √ | √ | √ | 
| Virtual Wires | √ | √ | √ | √ | √ | √ | 
| NPTv6 (stateless prefix translation) | √ | √ | √ | √ | √ | √ | 
| NAT64 (IP-IPv6 protocol translation) | √ | √ | √ | √ | √ | √ | 
| LLDP (Link Layer Discovery Protocol) | √ | √ | √ | √ | √ | √ | 
| Bidirectional Forwarding Detection (BFD) | √ | √ | √ | √ | √ | √ | 
| IPv6 PPPoE Client | — | — | — | — | √ | √ | 
| Dynamic IPv6 Addressing on the Management Interface | — | — | — | — | √ | √ | 
| VPN | ||||||
| GlobalProtect™ | √ | √ | √ | √ | √ | √ | 
| IKE/IPSec | √ | √ | √ | √ | √ | √ | 
| IKEv2 | √ | √ | √ | √ | √ | √ | 
| IPv6 over IPv4 IPSec Tunnel | √ | √ | √ | √ | √ | √ | 
| Large Scale VPN (LSVPN) | √ | √ | √ | √ | √ | √ | 
| Host Dynamic Address Configuration | ||||||
| DHCPv6 Relay | √ | √ | √ | √ | √ | √ | 
| DHCPv6 Client with Prefix Delegation (Dataplane Interface
                                    only) | — | — | — | √ | √ | √ | 
| SLAAC (Router Advertisements) | √ | √ | √ | √ | √ | √ | 
| SLAAC (Router Preference) | √ | √ | √ | √ | √ | √ | 
| SLAAC (RDNSS) | √ | √ | √ | √ | √ | √ | 
| Device | ||||||
| High Availability (HA)—Active/Active | √ | √ | √ | √ | √ | √ | 
| HA—Active/Passive | √ | √ | √ | √ | √ | √ | 
| HA—IPv6 transport for HA1 & HA2 | √ | √ | √ | √ | √ | √ | 
| HA Path Monitoring (IPv6 Endpoint) | √ | √ | √ | √ | √ | √ | 
| HA Clustering | — | √ | √ | √ | √ | √ | 
| User-ID | ||||||
| Map IPv6 Address to Users | √ | √ | √ | √ | √ | √ | 
| Captive Portal for IPv6 | √ | √ | √ | √ | √ | √ | 
| Connection to User-ID Agents over IPv6 | √ | √ | √ | √ | √ | √ | 
| User-ID XML API for IPv6 | √ | √ | √ | √ | √ | √ | 
| Terminal Server Agent IPv6 | √ | √ | √ | √ | √ | √ | 
