Forum Discussion
Always on VPN Device Tunnel with IPv6 ikev2
Hi everyone,
i have a huge Problem with always on VPN and IPv6. We have a working configuration, with RAS Server and Windows 11 Clients using always on VPN with IPv4 and computer certificates (IKEv2) from internal CA. External Clients connect over Internet to Firewall -> RAS -> VPN CONNECT (with certificate) -> Access to internal. Works.
But now we are facing some problems with IPv6. Many Internet providers are working with IPv6 only Addresses for private internet connection. When users are trying to connect over IPv6 with their Certificate, it is not working. So, we tried to rebuild the configuration. I configured a second RAS Server for testing. I recreated the config and VPN settings but tried to connect from internal network, just to test connection for VPN with IPv6 without any routing problems or anything like that. Even if i try to connect to the RAS Server directly from the same Network (IPv6) it is not connecting. Server is reachable, configuration for IPV6 is set, certificate is installed, PKI is reachable... anything seems fine. But, as soon as i try to connect to RAS with IPv6 AND IKEv2 Certificate, it wont connect. It seems, that the client doesnt even really trying. I hit "connect" and in less than a second the error appears that it cannot connect. There is no real error message in eventlog or anywhere else. It's just saying... no, not working.
So, my question is:
Doese anyone ever had a working IPv6 Always on VPN Device Tunnel with Computer Certificates and IKEv2? Because i dont have any more ideas what could be the Problem!
Thanks!