<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN users can't use IPV6 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-users-can-t-use-ipv6/m-p/1993353#M401164</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: justify;"&gt;Hi Bro&lt;/P&gt;&lt;P style="text-align: justify;"&gt;As you’re aware the Cisco Remote Access VPN doesn't support IPv6. You could refer to this Cisco document &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/vpnrmote.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/vpnrmote.html&lt;/A&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;under Guidelines and Limitations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;However, in your case, you’re using Cisco AnyConnect. Hence, it is possible to support IPv6 through a Cisco VPN Client connection by using host-based tunnels (dynamic or static). One example of this is to leverage Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) (RFC 5214) on the remote client along with an established Cisco VPN Client connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Remember that ISATAP is a host-based tunnel that can provide tunneled IPv6 connectivity between the host and a router, Layer 3 switch, or server. The idea is that after a Cisco VPN Client connection has been made, there should be a routing path between the host and the tunnel endpoint located inside the enterprise network. The Cisco VPN Client enables tunneled traffic through the IPv4 IPsec connection. You could refer to this URL for further details &lt;A href="http://what-when-how.com/ipv6-for-enterprise-networks/remote-access-for-ipv6-using-cisco-vpn-client/"&gt;http://what-when-how.com/ipv6-for-enterprise-networks/remote-access-for-ipv6-using-cisco-vpn-client/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Aug 2012 04:11:54 GMT</pubDate>
    <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
    <dc:date>2012-08-17T04:11:54Z</dc:date>
    <item>
      <title>VPN users can't use IPV6</title>
      <link>https://community.cisco.com/t5/network-security/vpn-users-can-t-use-ipv6/m-p/1993352#M401163</link>
      <description>&lt;P&gt;My VPN users are able to access IPV4 resources, but not IPV6, all of my other user who are not VPN users are able to access everything V4 and V6.&amp;nbsp; Can anyone help me figure out what I have configured wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my network goes: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPV4 flow = FIOS &amp;gt; ASA5505(IPV4 Router) &amp;gt; Switch &amp;gt; ipv4 Clients &lt;/P&gt;&lt;P&gt;IPV6 flow = FIOS &amp;gt; ASA5505(IPV4 Router) &amp;gt; switch &amp;gt; win2k8 (IPV6 Router / Tunnel) &amp;gt; ipv6 clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my current config: &lt;A href="https://gist.github.com/3276764" target="_blank"&gt;https://gist.github.com/3276764&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my tunnel info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPv6 Tunnel Endpoints&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Server IPv4 Address:216.66.22.2&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Server IPv6 Address:2001:470:&lt;STRONG style="font-size: 14px;"&gt;7&lt;/STRONG&gt;:1044::1/64&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Client IPv4 Address:&lt;A href="http://tunnelbroker.net/ipv4_update.php?tid=140115" id="edit_ipv4z" style="color: #222222; font-weight: bold; font-size: 14px;" title="Edit Endpoint" target="_blank"&gt;108.18.224.211&lt;/A&gt;&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Client IPv6 Address:2001:470:&lt;STRONG style="font-size: 14px;"&gt;7&lt;/STRONG&gt;:1044::2/64&lt;/P&gt;&lt;P style="padding: 3px; margin: 8px 0px 0px; border-style: solid none none; border-top-width: 1px; border-top-color: black; font-size: 14px; font-family: arial, sans-serif; font-weight: bold; color: #222222; background-color: #ffffff;"&gt;Available DNS Resolvers&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Anycasted IPv6 Caching Nameserver:2001:470:20::2&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Anycasted IPv4 Caching Nameserver:74.82.42.42&lt;/P&gt;&lt;P style="padding: 3px; margin: 8px 0px 0px; border-style: solid none none; border-top-width: 1px; border-top-color: black; font-size: 14px; font-family: arial, sans-serif; font-weight: bold; color: #222222; background-color: #ffffff;"&gt;Routed IPv6 Prefixes&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Routed /64:2001:470:&lt;STRONG style="font-size: 14px;"&gt;8&lt;/STRONG&gt;:1044::/64&lt;/P&gt;&lt;P style="padding: 3px; border: none; font-size: 14px; font-family: arial, sans-serif; color: #222222; background-color: #ffffff;"&gt;Routed /48:&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-users-can-t-use-ipv6/m-p/1993352#M401163</guid>
      <dc:creator>danbryan80</dc:creator>
      <dc:date>2019-03-11T23:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN users can't use IPV6</title>
      <link>https://community.cisco.com/t5/network-security/vpn-users-can-t-use-ipv6/m-p/1993353#M401164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: justify;"&gt;Hi Bro&lt;/P&gt;&lt;P style="text-align: justify;"&gt;As you’re aware the Cisco Remote Access VPN doesn't support IPv6. You could refer to this Cisco document &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/vpnrmote.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/vpnrmote.html&lt;/A&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;under Guidelines and Limitations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;However, in your case, you’re using Cisco AnyConnect. Hence, it is possible to support IPv6 through a Cisco VPN Client connection by using host-based tunnels (dynamic or static). One example of this is to leverage Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) (RFC 5214) on the remote client along with an established Cisco VPN Client connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Remember that ISATAP is a host-based tunnel that can provide tunneled IPv6 connectivity between the host and a router, Layer 3 switch, or server. The idea is that after a Cisco VPN Client connection has been made, there should be a routing path between the host and the tunnel endpoint located inside the enterprise network. The Cisco VPN Client enables tunneled traffic through the IPv4 IPsec connection. You could refer to this URL for further details &lt;A href="http://what-when-how.com/ipv6-for-enterprise-networks/remote-access-for-ipv6-using-cisco-vpn-client/"&gt;http://what-when-how.com/ipv6-for-enterprise-networks/remote-access-for-ipv6-using-cisco-vpn-client/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 04:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-users-can-t-use-ipv6/m-p/1993353#M401164</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-17T04:11:54Z</dc:date>
    </item>
  </channel>
</rss>

