Fortinet white logo
Fortinet white logo

CLI Reference

config firewall ippool6

config firewall ippool6

Configure IPv6 IP pools.

config firewall ippool6
    Description: Configure IPv6 IP pools.
    edit <name>
        set add-nat46-route [disable|enable]
        set comments {var-string}
        set endip {ipv6-address}
        set external-prefix {ipv6-network}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set internal-prefix {ipv6-network}
        set nat46 [disable|enable]
        set startip {ipv6-address}
        set type [overload|nptv6]
        set uuid {uuid}
    next
end

config firewall ippool6

Parameter

Description

Type

Size

Default

add-nat46-route

Enable/disable adding NAT46 route.

option

-

enable

Option

Description

disable

Disable adding NAT46 route.

enable

Enable adding NAT46 route.

comments

Comment.

var-string

Maximum length: 255

endip

Final IPv6 address (inclusive) in the range for the address pool (format = xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx, default = ::).

ipv6-address

Not Specified

::

external-prefix

External NPTv6 prefix length (32 - 64).

ipv6-network

Not Specified

::/0

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

internal-prefix

Internal NPTv6 prefix length (32 - 64).

ipv6-network

Not Specified

::/0

name

IPv6 IP pool name.

string

Maximum length: 79

nat46

Enable/disable NAT46.

option

-

disable

Option

Description

disable

Disable NAT46.

enable

Enable NAT46.

startip

First IPv6 address (inclusive) in the range for the address pool (format = xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx, default = ::).

ipv6-address

Not Specified

::

type

Configure IPv6 pool type (overload or NPTv6).

option

-

overload

Option

Description

overload

IPv6 addresses in the IP pool can be shared by clients.

nptv6

NPTv6 one to one mapping.

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config firewall ippool6

config firewall ippool6

Configure IPv6 IP pools.

config firewall ippool6
    Description: Configure IPv6 IP pools.
    edit <name>
        set add-nat46-route [disable|enable]
        set comments {var-string}
        set endip {ipv6-address}
        set external-prefix {ipv6-network}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set internal-prefix {ipv6-network}
        set nat46 [disable|enable]
        set startip {ipv6-address}
        set type [overload|nptv6]
        set uuid {uuid}
    next
end

config firewall ippool6

Parameter

Description

Type

Size

Default

add-nat46-route

Enable/disable adding NAT46 route.

option

-

enable

Option

Description

disable

Disable adding NAT46 route.

enable

Enable adding NAT46 route.

comments

Comment.

var-string

Maximum length: 255

endip

Final IPv6 address (inclusive) in the range for the address pool (format = xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx, default = ::).

ipv6-address

Not Specified

::

external-prefix

External NPTv6 prefix length (32 - 64).

ipv6-network

Not Specified

::/0

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

internal-prefix

Internal NPTv6 prefix length (32 - 64).

ipv6-network

Not Specified

::/0

name

IPv6 IP pool name.

string

Maximum length: 79

nat46

Enable/disable NAT46.

option

-

disable

Option

Description

disable

Disable NAT46.

enable

Enable NAT46.

startip

First IPv6 address (inclusive) in the range for the address pool (format = xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx, default = ::).

ipv6-address

Not Specified

::

type

Configure IPv6 pool type (overload or NPTv6).

option

-

overload

Option

Description

overload

IPv6 addresses in the IP pool can be shared by clients.

nptv6

NPTv6 one to one mapping.

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.