VPC firewall rule for IPv6

Viewed 779

It seems that the firewall rules for the current VPN setting doesn't allowing entering IPv6 address at all, ::/0 etc are not implemented.

Is there a way to work around this? It's interesting if that's the case that VPC allowing creating IPv6 network but not allowing firewall to allow incoming.

2 Answers

IPv6 is not supported: https://cloud.google.com/vpc/docs/vpc#specifications

VPC networks only support IPv4 unicast traffic. They do not support broadcast, multicast, or IPv6 traffic within the network: VMs in the VPC network can only send to IPv4 destinations and only receive traffic from IPv4 sources. It is possible to create an IPv6 address for a global load balancer, however.

Google cloud now supports external ipv6 on VM instances. Each instance can get a /96 external ip range and it can be used to access internet (without NAT) or be used for VM to VM traffic.

At this moment (July 2021) it's only supported limited regions:

  • asia-east1
  • asia-south1
  • europe-west2
  • us-west2

See more detailed in

https://cloud.google.com/compute/docs/ip-addresses/configure-ipv6-address

https://cloud.google.com/vpc/docs/vpc#ipv6-addresses

VPC firewall rules also supports IPv6 now: https://cloud.google.com/vpc/docs/firewalls#specifications

  • Firewall rules support IPv4 connections. IPv6 connections are also supported in VPC networks that have IPv6 enabled. When specifying a source for an ingress rule or a destination for an egress rule by address, you can specify IPv4 or IPv6 addresses or blocks in CIDR notation.
  • Each firewall rule can contain either IPv4 or IPv6 ranges, but not both.
Related