Chapter 11 IPsec VPN for FortiOS 5.0 : IPv6 Features : IPv6 policies : IPv6 explicit web proxy
  
IPv6 explicit web proxy
With FortiOS 5.0, you can use the explicit web proxy for IPv6 traffic. To do this you need to:
Enable the Explicit Proxy from the dashboard.
Enable the IPv6 explicit web proxy from the CLI.
Enable the explicit web proxy for one or more FortiGate interfaces. These interfaces also need IPv6 addresses.
Add IPv6 web proxy security policies to allow the explicit web proxy to accept IPv6 traffic.
Use the following steps to set up a FortiGate unit to accept IPv6 traffic for the explicit web proxy at the Internal interface and forward IPv6 explicit proxy traffic out the wan1 interface to the Internet.
1. Go to System > Dashboard > Status and turn on Explicit Proxy under the Features > Security Features widget.
2. Enter the following CLI command to enable the IPv6 explicit web proxy:
config web-proxy explicit
set status enable
set ipv6-status enable
end
3. Go to System > Network > Interfaces and edit the internal interface, select Enable Explicit Web Proxy and select OK.
4. Go to Policy > Policy > IPv6 Policy and select Create New to add an IPv6 explicit web proxy security policy with the following settings shown in Figure 287.
This IPv6 explicit web proxy policy allows traffic from all IPv6 IP addresses to connect through the explicit web proxy and through the wan1 interface to any IPv6 addresses that are accessible from the wan1 interface.
 
If you have enabled both the IPv4 and the IPv6 explicit web proxy, you can combine IPv4 and IPv6 addresses in a single explicit web proxy policy to allow both IPv4 and IPv6 traffic through the proxy.
Figure 287: Example IPv6 Explicit Web Proxy security policy