Netskope supports enterprises who have dual stack (IPv6 and IPv4) environments where internal networks have IPv6 and IPv4 implemented. All native IPv6 enterprises can use Netskope’s client steering technology to reach the Netskope Cloud Platform. Users who want to connect to an IPv6 website will have their IPv6 traffic steered by the Netskope Client to the Netskope cloud where v6 to v4 translation is done and policies are applied to that traffic. After policy enforcement is done, any allowed traffic is forwarded to its destination using IPv4 address.
Netskope supports websites resolving to IPv6 and IPv4 addresses. It doesn’t support websites that only resolve to IPv6 addresses.
For traffic steered via IPSec or GRE tunnels, Netskope doesn’t support IPv6 traffic over the IPv4 tunnels.

In the above diagram, the Netskope Client steers the enterprise and remote user traffic.
IPv6 and Cloud Firewall
For Cloud Firewall, since it doesn’t support IPv6 traffic including the translation, it bypasses any non-web Cloud Firewall traffic locally. This leads to end users bypassing the Cloud Firewall policies when dual stack is enabled on the device. The end-users can access cloud content on IPv6 that can lead to a security threat. To avoid this, from version 119.0.0, you can block the IPv6 non-web traffic from an application by forcing the application to transition to IPv4(The application must support IPv4 fallback). The IPv4 traffic is then tunneled to Cloud Firewall and thereafter the admin can apply the real-time policies.
Supported OS: Windows and macOS
If the application does not support fallback to IPv4, you can bypass the IPv6 traffic using Destination Location or Domain exceptions.IPv6 and Netskope Private Access
IPv6 and Netskope Private Access
Netskope Private Access (NPA) supports dual-stack (IPv6 and IPv4) clients on Windows and macOS. On a dual-stack endpoint, the Netskope Client steers Private App traffic to the assigned Publishers so that users can reach their private applications regardless of whether the endpoint has an IPv6 or IPv4 address.
Supported OS: Windows and macOS
Access to IPv6 applications
NPA supports access to private applications that resolve to IPv6 addresses. This lets you reach IPv6-only and dual-stack private apps without re-addressing your backend to IPv4.
Both IPv4-only users and dual-stack (IPv6 and IPv4) users can access these applications. The Netskope Client and Publisher handle the connection to the IPv6 application, so the endpoint’s own address family does not restrict which private apps it can reach./in
Note the following requirements and behavior:
- Netskope is reached over IPv4. Even when accessing an IPv6 application, the publisher still requires outbound connectivity to the Netskope cloud over IPv4, either natively or through a translation device (for example, NAT64/DNS64) in the network path.
- Private apps must be defined by hostname. Connectivity to IPv6 applications is restricted to hostname-based (FQDN) Private App definitions. IPv6 literal addresses and CIDR ranges are not supported in Private App definitions.
Netskope Private Access (NPA) supports dual-stack (IPv6 and IPv4) clients on Windows and macOS. On a dual-stack endpoint, the Netskope Client steers Private App traffic to the assigned Publishers so that users can reach their private applications regardless of whether the endpoint has an IPv6 or IPv4 address.

