North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

IPv6 firewall support

  • From: michael.dillon
  • Date: Fri Oct 26 17:08:25 2007

Some people have claimed that they cannot yet sell
IPv6 Internet access because there is no IPv6 firewall
support. According to this ICANN study:
this is not quite true. At least 30% of the 42 vendors
surveyed, had IPv6 support.

According to this talk 
many open-source and commercial firewalls supporting IPv6 are available.

IPCop is based on Linux

m0n0wall is based on FreeBSD

pfSense is also based on FreeBSD

FWBuilder is a management tool that builds filter setups for 
several different firewalls.

Checkpoint FW1 NGX R65 on SecurePlatform supports IPv6

FortiGate supports IPv6 in FortiOS 3.0 and up.

Juniper SSG (formerly Netscreen) supports IPv6 in ScreenOS 6.0 and up.

Cisco ASA (formerly PIX) supports IPv6 in version 7.0 and up.

I suspect that the people complaining about IPv6 support are 
partially complaining because they have older hardware that 
the vendor does not plan to upgrade to IPv6 support until 
they have all features implemented in their newer products, 
and partially complaining because their vendor has not 
implemented some feature which they happen to use.

Commercial firewall support may be lagging behind OS and 
router support, but not by much. And if commercial vendors 
are not responsive, maybe you should try pricing out an open 
source solution with a consultant. I believe there is a gap 
here that startup firewall companies could fill if they 
understand the enterprise market.

--Michael Dillon