Help Center/ Cloud Firewall/ FAQs/ Troubleshooting/ Why Is the IP Address Translated Using NAT64 Blocked?
Updated on 2024-07-05 GMT+08:00

Why Is the IP Address Translated Using NAT64 Blocked?

A firewall instance cannot protect the real source IP address before NAT64 translation. If you enable IPv6 translation for EIPs, NAT64 will translate a source IP address into a CIDR block of 198.19.0.0/16 for ACL access control.

For IPv6 access, you are advised to allow traffic from the predefined address group NAT64 Address Set. Access from all the IP addresses in the 198.19.0.0/16 CIDR block will be allowed. You can configure the blacklist or a blocking policy to block specific IP addresses.