Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL Remote Access VPN and IPv6

Hello,

I have my UTM 9.404 box setup for the remote access SSL VPN.  This works fine with IPv6 turned off.  However I would like to enable IPv6 (NOT FOR THE VPN) so that I can begin to leverage the expanded IP space for devices in my home.  However as soon as I get it all up and running the VPN breaks - I can connect but nothing routes.  If I switch IPv6 back off then the VPN starts working like it should.  I found this article (and tried the bottom 2 things) but it's still not working.  The first suggestion I am unable to do since both the IPv4 and ipV6 address on my WAN port are from DHCP.  

Just to make it clear I DO NOT care about using IPv6 on the SSL VPN but I don't see any way to disable it there.  Any advice would be appreciated.  I would rather not disable IPv6 globally just to get the VPN to work.

Thanks,

Dan



This thread was automatically locked due to age.
Parents
  • This just started happening to me, in this case on iOS using the OpenVPN client. The first time the vpn client connects to the vpn server (on a new IP) it works fine, the connection details show ipv4 ip and port..all is good. The second time around though, it somehow connects via ipv6, not even sure how....but once it connects via ipv6, I can't access any resources behind the VPN....any help?

     

    BTW, although it is apparent that my IPv4 addresses somehow have an IPv6 counterparts, I do not have ipv6 enabled anywhere in my UTM

  • Way to hijack my thread.  :(  My issue was never solved.  And it had nothing to do with IOS.  And it only happened with IPv6 enabled in the UTM.  So really your issue is in no way related.   ?????

  • Hi Dan,

    IPv6 enable can you please show me where do you enable this? I will try to test the scenario but, prerequisites will be:

    1. Upgrade your UTM on the latest version.

    2. Which iOS version and device.

    3. Which VPN client and version (latest preferred)

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi Sachin,

    If you look through the original thread you will see it has nothing to do with iOS.  Kent hijacked it with a presumable unrelated issue.  Back in August I was running the latest version of the UTM and both the official client and a stock OpenVPN client fail to function with IPv6 enabled on the UTM.  I haven't tried it since as no solution was provided and I need VPN more than I need IPv6.

    Thanks,

    Dan

  • Your thread was abandoned and quiet since August...I certainly did not mean to hijack your thread, but my issue looked somewhat related. Enjoy the holiday season, don't be grump.

     

    As to my issue, I was able to resolve it by enabling the "Seamless Tunnel" option in the openvpn client. The current hypothesis is that my mobile service provider started adopting nat64, and for whatever reason, the openvpn client was preferring the nat64 ipv6. I can't explain why "seamless tunnel" fixes the issue, but it does. Hope this helps someone

  • Sorry Kent, I was really just grumpy since this issues hasn't even been acknowledged as a problem.  I got excited when I saw a new post thinking it was maybe a solution.  I didn't mean to crap on your parade, so to speak, I'm just frustrated with Sophos that there isn't even any type of "yeah, this is an issue being worked on" response.

    Glad you got you issues resolved, and sorry for the grump.  :)  Cheers!


  • Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

Reply Children