On the other hand, the corporate VPN I use publishes a support matrix on their public web site, and specifically says that IPv6 is not supported. I don't think they're embarrassed about it. Most people using VPNs will be in a weird state with NAT64 anyway, assuming that they use the VPN's DNS server (e.g., to access internal resources by name). A split-tunnel VPN user will lose access to v4-only sites, since it will lose dns64 translation (and will simultaneously lose the ability to detect the nat64 via the rfc7050 lookup mechanism). Does this mean "don't bother with split tunnel VPNs in a nat64 network"? Bill |