This article provides a summary of information about IPv4 and IPv6 IP-IP tunnel supported features and limitations in SRX series devices encountered while configuring IKE peer gateway addresses as IPv6 addresses.
When you try to configure IKE peer gateway addess as IPv6 address, then SRX returns the following error messages:
error: invalid ip address or hostname: error: statement creation failed:
As of Junos OS Release 12.1X46-D10, the following tunnel modes are supported on SRX Series devices:
IPv6-in-IPv6 tunnels encapsulate IPv6 packets inside IPv6 packets.
IPv4-in-IPv6 tunnels encapsulate IPv4 packets inside IPv6 packets.
Only one-to-one site-to-site VPN is supported. Many-to-one site-to-site VPN (NHTB) is not supported. NHTB configuration cannot be committed for tunnel modes other than IPv4-in-IPv4 tunnels.
As with IPv4 tunnels, peer gateway address changes in the DNS name are not supported with IPv6 tunnels.
NAT-T is supported only for IPv6-in-IPv4 and IPv4-in-IPv4 tunnel modes with IKEv1. IPv6-in-IPv6 and IPv4-in-IPv6 tunnel modes are not supported. IKEv2 is not supported for NAT-T. NAT-T from IPv6 to IPv4 or from IPv4 to IPv6 is not supported.
Multiple traffic selector pairs are supported with IKEv1 only.
IPv6 dynamic endpoint VPNs are blocked during negotiation and IPv6 dialup VPNs are blocked during negotiation.
For more information, refer to the Release notes for 12.1x46 .