SonicOSX 7 Rules and Policies

Creating a WAN-to-WAN Security Policy for a NAT64

When an IPv6-only client initializes a connection to an IPv4 client/server, the IPv6 packets received by the NAT64 translator look like ordinary IPv6 packets:

  • Source zone is LAN
  • Destination zone is WAN

After these packets are processed through the NAT policy, they are converted IPv4 packets and are handled by SonicOSX again. At this point, the source zone for these packets is WAN, while the destination zone is the same as the original IPv6 packets. If the cache for these IPv4 packets is not already created, these packets undergo policy checking. In order to prevent these packets from being dropped, a WAN-to-WAN Allow security policy must be configured.

To create a WAN-to-WAN security policy

  1. Navigate to the POLICY | Rules and Policies > Security Policy page.

  2. Click Add. The Adding Access Rule dialog displays.

  3. Configure the options:

    Option Value
    Action Allow
    Source Zone/Interface WAN
    Destination Zone/Interface WAN
    Source Address Any
    Source Port/Services Any
    Destination Address

    All WAN IP

    All WAN IP is the default address group created by SonicOSX that includes all WAN IP addresses that belong to the firewall WAN interface(s). All WAN IP cannot be configured.
    Users Include All
    Schedule Always on
    Description IPv4 from Any to Any for Any service (optional)
    All other options Leave as is or optionally configure accordingly
  4. Click Save
  5. Click Close.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden