IPv6 VPN Client Split Tunneling for DNS64 and IPv4 Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition from IPv4-only or dual stack networks to IPv6-only networks poses challenges for VPN clients, complicating split tunneling management and DNS resolution, necessitating improved techniques for secured data communication and resource access.

Innovation Solution

A VPN client is created in a single stack IPv6 environment, utilizing a virtual adapter configured for IPv6-only traffic, enforcing IPv4/IPv6 split tunneling rules, and managing DNS resolution through internal IPv6 DNS servers to ensure secure and efficient data traffic management in mixed IP address networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a dual stack network configuration is used to support both IPv4 and IPv6, then compatibility with legacy systems is improved, but network complexity and management difficulty increase

Engineering Contradiction:
ImprovecompatibilityVSAvoidnetwork complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network is segmented into IPv4-only network and IPv6 network with clear boundaries. The IPv4 network maintains legacy resources while the IPv6 network handles modern traffic, reducing overall network complexity through structured division

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An IPv6 gateway acts as an intermediary between IPv6-only clients and IPv4 resources. The gateway provides translation and routing services, enabling seamless communication without requiring dual-stack configuration on end devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPv6-only configuration is implemented, then network security and modernization are improved, but compatibility with IPv4 resources deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The IPv6 gateway serves as a mediator that translates IPv6 traffic to IPv4 and vice versa, allowing IPv6-only devices to access IPv4 resources securely without compromising security posture

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

IP address parameters are dynamically changed through translation mechanisms. The gateway converts IPv6 addresses to IPv4 addresses and adjusts protocol parameters to maintain compatibility while preserving security

Inventive Principle:
Principle #35Parameter changes

3Reliability

If split tunneling is configured to route all IPv4 traffic through VPN, then security is improved, but network performance and bandwidth utilization worsen

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Different quality of routing is applied locally based on traffic type: IPv4 traffic receives secure VPN routing while IPv6 traffic uses direct high-speed paths, optimizing both security and performance for each protocol

Inventive Principle:
Principle #3Local quality

4Ease of operation

If DNS queries are allowed to external servers, then resource accessibility is improved, but network security and data privacy worsen

Engineering Contradiction:
Improveresource accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

An internal IPv6 DNS server acts as an intermediary between clients and external DNS servers. It receives DNS queries, translates them appropriately, and forwards only necessary queries externally, reducing security exposure while maintaining accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

DNS resolution is handled locally for internal resources through the IPv6 DNS server, while external DNS queries are selectively forwarded with enhanced security controls, optimizing both accessibility and security

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260067253A1VPN CLIENT CREATION IN A SINGLE STACK IPv6
Publication Date: 2026.03.05 IVANTI INC
  • US20260067253A1 patent drawing
  • US20260067253A1 patent drawing
  • US20260067253A1 patent drawing

AI summary

A method includes creating a virtual adapter at an endpoint that is configured for split tunneling of data traffic via a virtual private network (VPN) connection with an internet protocol version 6 (IPv6) only internal network. The method includes assigning only an IPv6 address to the virtual adapter, such that it does not have an internet protocol version 4 (IPv4) address or an automatic private IP address (APIPA) IPv4 address. The method includes blocking domain name server (DNS) traffic when a source internet protocol (IP) address of the DNS traffic being a physical adapter IP address of a physical adapter. The method includes accessing excluded resources configured for IPv4 and IPv6 split tunneling policies via the physical adapter, forcing access to excluded IPv4 only resources via the physical adapter in DNS64/NAT64 environments, and forcing applications that prefer IPv4 over IPv6 to use IPv6 while accessing dual stack resources.