Add an IP tunnel
IP tunnels encapsulate traffic to enable communication across IPv4 or IPv6 networks. Configure the settings to establish a tunnel between local and remote endpoints.
IP tunnel settings
Configure the tunnel interface, select the tunnel type, and specify the local and remote endpoints required to establish the tunnel.
- Go to Network > IP tunnels and click Add.
-
Enter a name. You can change it later.
Maximum number of characters: 58
The interface's customizable name rather than the hardware name is shown in other settings.
-
Enter a hardware name for the interface. The firewall uses this name to identify the interface. You can't change it later.
Maximum number of characters: 10
Allowed characters: (A-Za-z0-9_)
Restriction
The hardware name can't contain the following system-reserved names:
all,gre,oct,mv-pcimux0,mvmgmt0,pport_,lo,ipsec0,tun,ppp,imq,ifb,mast,sit,WWAN1,_ppp,vxlan,xfrm,USB,erspan0,Port,MGMT,eth,GE,gretap0,ip6tnl0,host,reds,wlnet,WLAN,Sophos,GuestAP,spq, andHalink. -
Select a Tunnel type from the following options:
Tunnel type Description When to use 6in4 Encapsulates IPv6 packets inside IPv4 packets, allowing IPv6 networks to communicate across IPv4 infrastructure. For connectivity between IPv6 networks across IPv4 infrastructure. 6to4 An automatic IPv6-over-IPv4 tunneling mechanism that derives an IPv6 prefix from a local public IPv4 address.
Unlike 6in4, 6to4 doesn't require a configured remote endpoint. It automatically determines the destination gateway based on the destination IPv6 address.
For connectivity between IPv6 networks across IPv4 infrastructure when native IPv6 isn't available.
6to4 is a legacy IPv6 transition technology.
6rd Also known as IPv6 Rapid Deployment, 6rd encapsulates IPv6 packets inside IPv4 packets to provide IPv6 connectivity across an ISP's IPv4 infrastructure.
Unlike 6to4, 6rd is managed by the ISP and uses ISP-provided IPv6 prefixes and relay gateways.
When your ISP provides 6rd service and native IPv6 isn't available.
If native IPv6 is available, use that instead.
4in6 Encapsulates IPv4 packets inside IPv6 packets, allowing IPv4 networks and applications to communicate across IPv6 infrastructure. For connectivity between IPv4 networks across IPv6 infrastructure. -
Select a Zone to assign to the tunnel.
-
Specify the Local endpoint and Remote gateway of the tunnel as follows:
Tunnel type Local endpoint Remote gateway 6in4 IP address associated with an interface. IPv4 address or FQDN. 6to4 IP address associated with an interface. Not required.
The firewall determines it automatically.
6rd IPv4 address associated with an interface. Not required.
The firewall automatically determines the ISP-provided relay gateway.
4in6 IPv6 interface. IPv6 address or FQDN.
Advanced settings
Configure packet handling and quality-of-service settings for the tunnel.
TTL and ToS settings
Specify the time-to-live (TTL) and type-of-service (ToS) values that the firewall applies to traffic sent through the tunnel.
-
Enter a TTL value.
TTL specifies the maximum number of routers that an encapsulated packet can traverse before the firewall discards it. This helps prevent routing loops.
-
Specify the ToS settings.
- Optional. For 4in6 tunnels, select Inherit ToS to use the inner packet's ToS value.
-
Enter a ToS value.
ToS specifies how network devices prioritize and handle traffic based on quality of service (QoS) requirements, such as latency, throughput, and reliability.
Additional 4in6 settings
For 4in6 tunnels, configure the maximum transmission unit (MTU) and optionally override the maximum segment size (MSS).
-
Enter an MTU value.
MTU is the largest packet size, in bytes, that can be transmitted over the tunnel without being fragmented.
Default: Physical interface MTU minus 48 bytes. The reduction accounts for 4in6 encapsulation overhead.
-
Optional. Select Override MSS to manually specify the MSS value.
MSS is the largest TCP payload size, in bytes, that can be sent in a single TCP packet without fragmentation. Override the MSS value to prevent fragmentation or accommodate path MTU limitations.
Default: MTU value minus 40 bytes.
Save the settings
Save the tunnel configuration. For 6to4 and 6rd tunnels, add any additional IPv6 routes required for your network.
-
Click Save.
The IP tunnel is created. For 6to4 and 6rd tunnels, the firewall automatically creates a static IPv6 unicast route. You can see the route in Routing > Static routes.
When you delete the tunnel, the firewall also deletes the route.
-
In the pop-up that appears, do as follows:
- To add more routes, enter the Destination IP (IPv6) and Gateway (IPv6) and click Save.
- If you don't want to add more routes, click Cancel.