Why Is the IP Address Translated Using NAT64 Blocked?
A firewall instance cannot protect the real source IP address before NAT64 translation. If you enable IPv6 translation for EIPs, NAT64 will translate a source IP address into a CIDR block of 198.19.0.0/16 for ACL access control.
For IPv6 access, you are advised to allow traffic from the predefined address group NAT64 Address Set. Access from all the IP addresses in the 198.19.0.0/16 CIDR block will be allowed. You can configure the blacklist or a blocking policy to block specific IP addresses.
- For details about the IPv6 EIP function, see Assigning or Releasing an IPv6 EIP.
- For details about NAT64 Address Set, see NAT64 Address Set.
- For details about how to configure the blacklist, see Adding an Item to the Blacklist or Whitelist.
- For details about how to configure a blocking policy, see Adding a Protection Rule.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot