Prisma Access
Enable IPv6 Networking for Remote Networks
Table of Contents
Expand All
|
Collapse All
Prisma Access Docs
-
- Prisma Access China
- 4.0 & Later
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
-
-
-
- 5.2 Preferred and Innovation
- 5.1 Preferred and Innovation
- 5.0 Preferred and Innovation
- 4.2 Preferred
- 4.1 Preferred
- 4.0 Preferred
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
Enable IPv6 Networking for Remote Networks
Enable IPv6 networking in a Prisma Access remote network deployment.
Where Can I Use
This? | What Do I Need? |
---|---|
|
|
For remote network connections, you can use IPv6
subnets for static routes. For BGP routing, you can enter IPv6 peer addresses and
specify that BGP use IPv6 routing only or both IPv4 and IPv6 routing.
To configure IPv6 networking for remote network connections, complete the following
task.
Enable IPv6 Networking for Remote Networks (Strata Cloud Manager)
Strata Cloud Manager
)Enable IPv6 networking in a Prisma Access remote network deployment.
- Select.ManageRemote NetworksRemote Networks SetupIf you're using Strata Cloud Manager, go toandWorkflowsPrisma Access SetupRemote NetworksAdd Remote Networks.
- EnableIPv6.
- Add a new remote network connection or select an existing remote network connection to edit it.
- Set up IPv6 routing for your remote network.
- (Static Routing Deployments Only) Enter one or moreCorporate Subnetsin theStatic Routestab.
- (BGP Routing Deployments Only) Specify the method to exchange IPv4 and IPv6 BGP routes; then, enter an IPv6Peer AddressandLocal Address.
- To use a single IPv4 BGP session to exchange both IPv4 and IPv6 BGP peering information, selectExchange both IPv4 and IPv6 routes over IPv4 peering.
- To an IPv4 BGP session to exchange IPv4 BGP peering information and an IPv6 session to exchange IPv6 BGP peering information, selectExchange IPv4 routes over IPv4 peering and IPv6 routes over IPv6 peering.
- To use a single IPv6 BGP session to exchange IPv6 BGP peering information, selectExchange IPv6 routes over IPv6 peering.
- If your secondary WAN uses a different peer or local address, deselectSame as Primary WANand enter the IPv6Peer AddressandLocal Addressfor the secondary WAN.
- (Optional) If your internal DNS servers use are reachable by IPv6 addresses, selectand findManageService SetupRemote NetworksRemote Networks SetupAdvanced SettingsDNS Proxy,Adda rule or specify the default rule, and specifyCustom DNS ServerIPv6 addresses for thePrimary DNSandSecondary DNSserver.Prisma Access allows you to specify DNS servers to resolve both domains that are internal to your organization and external domains. If you do not specify any settings, Prisma Access does not proxy DNS requests for remote networks. You also need to select aRegion.You can enter any combination of IPv4 or IPv6 addresses for primary and secondary DNS servers.
- IPv4 addresses use A records, while IPv6 addresses use AAAA records. Some DNS servers can perform AAAA DNS lookups over IPv4 transport; therefore, you might not need a server with an IPv6 IP address.
- If you're using Strata Cloud Manager, go tofindWorkflowsPrisma Access SetupRemote NetworksAdvanced SettingsDNS Proxy.
- If you have not yet completed the remote network connection setup, complete it now.IPv6 internet access for remote network connections is enabled by an underlay connection, in which IPv6 traffic is passed through an IPv4 tunnel.
- Push Configto deploy your changes to you network.
Enable IPv6 Networking for Remote Networks (Panorama)
Panorama
)Enable IPv6 networking in a
Prisma Access
remote network deployment.- (Optional) Enter IPv6 addresses to your custom DNS server proxy configuration.
- Selectand edit the settings by clicking the gear icon in thePanoramaCloud ServicesConfigurationRemote NetworksSettingsarea.
- In theDNS Proxyarea, enter IPv6Custom DNS Serveraddresses for your DNS proxy settings.
- Select.PanoramaCloud ServicesConfigurationRemote Networks
- Adda new remote network connection or select an existing remote network connection to edit it.
- Enable IPv6.
- Set up IPv6 routing for your remote network.
- (Static Routing Deployments Only) Enter one or moreCorporate Subnetsin theStatic Routestab.
- (BGP Routing Deployments Only) Specify the method to exchange IPv4 and IPv6 BGP routes; then, enter an IPv6Peer AddressandLocal Address.
- To use a single IPv4 BGP session to exchange both IPv4 and IPv6 BGP peering information, selectExchange both IPv4 and IPv6 routes over IPv4 peering.
- To an IPv4 BGP session to exchange IPv4 BGP peering information and an IPv6 session to exchange IPv6 BGP peering information, selectExchange IPv4 routes over IPv4 peering and IPv6 routes over IPv6 peering.
- To use a single IPv6 BGP session to exchange IPv6 BGP peering information, selectExchange IPv6 routes over IPv6 peering.
- If your secondary WAN uses a different peer or local address, deselectSame as Primary WANand enter the IPv6Peer AddressandLocal Addressfor the secondary WAN.
- (Optional) If your internal DNS servers use are reachable by IPv6 addresses, select, click the gear icon to edit the settings, select thePanoramaCloud ServicesConfigurationRemote NetworkSettingsDNS Proxytab,Adda rule or specify the default rule, and specifyCustom DNS ServerIPv6 addresses for thePrimary DNSandSecondary DNSserver.Prisma Accessallows you to specify DNS servers to resolve both domains that are internal to your organization and external domains. If you do not specify any settings,Prisma Accessdoes not proxy DNS requests for remote networks. You also need to select aRegion.You can enter any combination of IPv4 or IPv6 addresses for primary and secondary DNS servers.IPv4 addresses use A records, while IPv6 addresses use AAAA records. Some DNS servers can perform AAAA DNS lookups over IPv4 transport; therefore, you might not need a server with an IPv6 IP address.
- If you have not yet completed the remote network connection setup, complete it now.
- Commit and Pushyour changes.
- Selectand make a note of thePanoramaCloud ServicesStatusNetwork DetailsRemote NetworksEBGP Routeraddresses.After you commit your changes, you will have an IPv6EBGP Routeraddresses for service connections.Because the IPSec tunnel used for the remote network connection uses IPv4 addressing, theService IP Addressstays as an IPv4 address.IPv6 internet access for remote network connections is enabled by an underlay connection, in which IPv6 traffic is passed through an IPv4 tunnel.